This week’s biggest developments share one lesson: governance is being judged by what controls actually do and not by what policies say they should do.

Uber’s automated decisions trigger a €825 million penalty

The Dutch Data Protection Authority fined Uber €824.99 million after finding that driver accounts were temporarily or permanently deactivated for suspected fraud or low ratings without human intervention. A blocked driver could no longer earn through the platform.

Human oversight must be capable of changing the outcome. Organizations using automated systems for employment, access, fraud or eligibility decisions should test who can intervene, what evidence they see, how quickly appeals work and whether reversals are logged.

Brazil puts age assurance and default settings on the enforcement table

Brazil’s ANPD fined ByteDance R$153.7 million for processing children’s and teenagers’ data without a valid legal basis across TikTok’s registered and guest feeds. The order also requires deletion of unlawfully collected data and a compliance plan. Measures include stricter defaults for users under 16 and suspension of advertising in the guest experience. The fine may be appealed.

A date-of-birth box is no longer persuasive evidence of child-safety compliance. Product teams need defensible age-assurance, data-minimization and default-setting decisions and proof that those controls work.

U.S. banking supervisors reset the GRC signal

The OCC and FDIC issued a final rule creating common standards for unsafe or unsound practices and Matters Requiring Attention. Examiners are directed to prioritize material financial risks and substantive legal violations over stand-alone policy, process and documentation concerns.

This is not permission to neglect controls. Banks should connect findings to exposure, law, operational consequences and accountable remediation. Weak issue narratives will now be harder to defend.

PaperCut warns of active exploitation across NG and MF

PaperCut confirmed attacks affecting all versions of NG and MF and released Emergency Patch 2 for versions 24–26. Internet-facing application servers should be restricted to trusted addresses immediately.

Why it matters: security leaders should inventory exposure, apply the latest patch, preserve and review logs, and trigger incident response where compromise is suspected. Older installations should move to a supported version.

Governance fails when a control cannot change the outcome. — Privacy Bytes

Executive action:

Pick one automated decision, one age-gated journey and one exposed enterprise tool. Ask the responsible owner to show and not just describe the control evidence.

Which of these developments will change your work first? Reply and let us know.

If you found this piece useful, share with a friend via https://privacybytes.net

Stay Informed, Stay Ahead,

Daniel Opio

Privacy Bytes provides general professional information, not legal advice.