San Francisco Chronicle

Uber to protect rider data to settle FTC case

- By Tom Krisher

Ride-hailing service Uber has agreed to protect data and audit use of rider informatio­n to settle a complaint from the federal government that it deceived customers.

The Federal Trade Commission, in a complaint settled on Tuesday, alleged that Uber failed to secure data about rider trips and neglected to monitor employee access to the informatio­n. It’s another in a long string of missteps for the San Francisco company, which faces a separate federal investigat­ion for allegedly using a phony app to block city inspectors from monitoring its service.

Uber misreprese­nted how well it monitored employee access to personal informatio­n about users

and drivers, and it misstated that it took steps to secure customer data, acting FTC Chairwoman Maureen Ohlhausen said in a statement. “This case shows that even if you’re a fast-growing company, you can’t leave consumers behind: You must honor your privacy and security promises.”

Uber said the allegation­s date to 2014, and that before the government complaint, it had already put safeguards in place to protect data. Since then, it has strengthen­ed privacy and data security and will keep investing in security programs, the company said.

But the FTC alleged in its complaint that after news reports of Uber employees improperly accessing customer data, the company said in November 2014 that it had a strict policy prohibitin­g employees from viewing the data except for legitimate business purposes. The company also said employee access would be closely monitored.

But Uber stopped using a monitoring system less than a year later and for nine months rarely monitored access to customer and driver informatio­n.

Also, Uber claimed that data was securely stored in its databases, but an intruder gained access to driver data in May 2014, including 100,000 names and driver’s license numbers, the complaint said.

“The FTC alleges that Uber did not take reasonable, low-cost measures that could have helped the company prevent the breach,” the agency said.

To settle the complaint, Uber agreed to stop misreprese­nting how it monitors access to customer informatio­n and to stop misreprese­nting how it secures the data, the FTC said. Uber also agreed to put a program in place to protect customer privacy. It also must do an audit every two years for the next two decades to make sure the privacy program remains in place.

The FTC voted 2-0 to accept the agreement. The public will be able to comment for 30 days, after which a final decision will be made.

Uber said it hired its first chief security officer in 2015 and now has hundreds of employees who work to protect consumer informatio­n. “This settlement provides an opportunit­y to work with the FTC to further verify that our programs protect user privacy and personal informatio­n,” a company statement said.

The settlement comes as the world’s largest ride-hailing company tries to recover from a series of costly blunders this year that damaged its reputation and forced out combative CEO Travis Kalanick. Many riders deleted Uber’s app after it tried to capitalize on a New York taxi driver strike in protest of government immigratio­n policies. Then a female former Uber engineer published a blog detailing sexual harassment at the company. That led to Uber’s hiring of two law firms to investigat­e; 20 people, including some managers, were fired as a result. The company says it has increased the size of its human resources department and is working to change its culture.

 ?? Nicole Boliaux / The Chronicle ?? Uber allegedly failed to secure data on customers.
Nicole Boliaux / The Chronicle Uber allegedly failed to secure data on customers.

Newspapers in English

Newspapers from United States