Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice states that driver personal data may be transferred internationally including to the United States, and that EU/EEA transfers are covered by Standard Contractual Clauses or other approved mechanisms.
This analysis describes what Uber's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Cross-border data transfers of EU/EEA driver data to the US and other third countries require valid transfer mechanisms under GDPR Chapter V, and the adequacy and supplementary safeguards supporting SCCs must be documented and available for supervisory authority review, particularly given the volume and sensitivity of the data categories involved.
Interpretive note: The notice does not specify whether Uber participates in the EU-US Data Privacy Framework or relies solely on SCCs, and does not detail transfer impact assessment processes, creating uncertainty about the completeness of transfer mechanism documentation.
This provision establishes that driver personal data including biometric, location, and identification data may be transferred to the United States and other countries under Standard Contractual Clauses or other transfer mechanisms; EU and UK drivers' data is subject to these cross-border transfer arrangements.
How other platforms handle this
In certain circumstances, the right to data portability, which means that you can request that we provide certain Personal Data we hold about you in a machine-readable format
If you want to see what information we have collected about you, you can request a copy of your data in the Data & Privacy section of your User Settings. You should receive your data packet within 30 days.
For data portability requests, We will select a format to provide Your personal information that is readily useable and should allow You to transmit the information from one entity to another entity without hindrance.
Monitoring
Uber has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Uber operates globally and may transfer personal data to countries outside of the country in which it was collected, including to the United States where Uber Technologies, Inc. is headquartered. Uber relies on Standard Contractual Clauses approved by the European Commission, and other approved transfer mechanisms, to transfer personal data from the EU/EEA to other countries.Excerpt from Uber's Privacy Notice (Drivers and Delivery People)
1) REGULATORY LANDSCAPE: GDPR Chapter V governs transfers of personal data to third countries. The EU-US Data Privacy Framework (adopted July 2023) provides an adequacy mechanism for transfers to certified US entities; where Uber relies on SCCs rather than the DPF, the Schrems II transfer impact assessment requirements apply. UK GDPR and the UK-US data bridge govern UK driver data transfers. The Irish Data Protection Commission is Uber's lead supervisory authority for EU operations. 2) GOVERNANCE EXPOSURE: Medium. The notice references SCCs as a transfer mechanism but does not specify whether Uber also participates in the EU-US Data Privacy Framework. Given the sensitivity of driver data categories (biometric, location, government ID), transfer impact assessments documenting US government access risks are required under post-Schrems II guidance and should be current and accessible. 3) JURISDICTION FLAGS: EU/EEA (GDPR Chapter V, lead supervisory authority scrutiny), UK (UK GDPR, ICO guidance on international transfers), Brazil (LGPD international transfer provisions), other jurisdictions with data localization or transfer restriction requirements (India DPDPA, China PIPL for any operations in those markets). 4) CONTRACT AND VENDOR IMPLICATIONS: All third-party vendors and subprocessors receiving EU/EEA driver data in third countries must be covered by appropriate transfer mechanisms. SCC annexes should be current (2021 EU Commission SCC modules) and reflect the actual data flows, controller-processor relationships, and categories of data transferred. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify that transfer impact assessments are documented for all significant data flows from EU/EEA to non-adequate countries, that SCC annexes accurately reflect current processing activities, and that the notice is updated to reflect the EU-US DPF where applicable. Annual review of transfer mechanism adequacy is recommended given ongoing regulatory developments.
Regulatory citations, enforcement risk, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Cross-border data transfers of EU/EEA driver data to the US and other third countries require valid transfer mechanisms under GDPR Chapter V, and the adequacy and supplementary safeguards supporting SCCs must be documented and available for supervisory authority review, particularly given the volume and sensitivity of the data categories involved.
This provision establishes that driver personal data including biometric, location, and identification data may be transferred to the United States and other countries under Standard Contractual Clauses or other transfer mechanisms; EU and UK drivers' data is subject to these cross-border transfer arrangements.
ConductAtlas has identified this type of provision across 295 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Uber.