Skip to content

EU Fines Yango €100M Over Russia Data Transfers

May 14, 202658 second read

The Dutch Data Protection Authority, together with regulators from Finland and Norway, imposed a €100 million GDPR fine on Yango’s operator MLU B.V. for allegedly transferring EU user data to Russia without adequate safeguards.

Regulators said the company failed to demonstrate that Russian authorities could not access sensitive user data, including:
• Precise location data
• Home addresses
• Driver license scans
• Passenger & driver information

Authorities also ordered an immediate halt to EU-Russia data transfers linked to European Yango users.

This case is significant because it marks one of the first coordinated EU enforcement actions specifically targeting data transfers to Russia — reinforcing that geopolitical risk is now a core compliance issue under GDPR.

Key Takeaway
Cross-border data transfers are no longer just a legal paperwork exercise. Regulators are increasingly assessing:
• Foreign government access risks
• Local surveillance laws
• Technical accessibility of data
• Real-world effectiveness of safeguards

For multinational companies operating across high-risk jurisdictions, transfer impact assessments and localization strategies are becoming enforcement-critical.

At S8fe.ai, we help organizations navigate complex global data compliance challenges — including GDPR cross-border transfer assessments, data localization mapping, AI/data governance, and multi-jurisdiction compliance operations.

Source: https://nltimes.nl/2026/05/08/dutch-watchdog-fines-taxi-app-yango-eu100-million-alleged-data-transfers-russia

Share this article

Back To Top