AP (The Netherlands) - 2025-005323
| AP - 2025-005323 | |
|---|---|
| Authority: | AP (The Netherlands) |
| Jurisdiction: | Netherlands |
| Relevant Law: | Article 5(1)(a) GDPR Article 5(2) GDPR Article 44 GDPR Article 45(2) GDPR Article 46 GDPR Article 58(2)(f) GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | 05.12.2023 |
| Decided: | 01.04.2026 |
| Published: | 08.05.2026 |
| Fine: | 100,000,000 EUR |
| Parties: | MLU B.V. Ridetech Yandex.Taxi LLC and Yandex LLC |
| National Case Number/Name: | 2025-005323 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Dutch |
| Original Source: | AP (in NL) |
| Initial Contributor: | ap |
The DPA fined a taxi ride app €100,000,000 for transferring personal data of data subjects in Finland and Norway to recipients in Russia without demonstrating that it had implemented appropriate safeguards.
English Summary
Facts
MLU B.V. is a company under the Yandex group that has its main establishment in the Netherlands. MLU B.V owns the “Yango for users” and “Yango Pro for drivers” apps (“the Yango app”). The Yango app is a platform that connects drivers with customers who wish to book a taxi ride. The case was originally against Ridetech, however, Ridetech was dissolved and MLU B.V. informed the DPA that it was the successor in title to all rights and obligations. Ridetech was established in the Netherlands and provided the Yango app to data subjects in the EEA. Ridetech transferred data from the Yango app to Yandex.Taxi LLC and Yandex LLC, which are both established in Russia. MLU B.V. is the parent company of both Ridetech and Yandex.Taxi LLC, who were considered joint controllers during the investigation.
In 2021 and 2022, the DPA received a report from the Finnish DPA regarding the controllers (Ridetech at the time) possibly transferring personal data to Russia without appropriate safeguards in place. The Finnish DPA issued a decision on an urgency procedure (Article 66 GDPR). The Finnish DPA stated that the data transfer was unlawful under Articles 44 and 46 GDPR, and prohibited the transfer under Article 58(2)(f) GDPR. This was a provisional measure valid from September to November 2023. The Norwegian DPA also initiated an urgency procedure in August 2023. As the lead DPA, the Dutch DPA initiated a joint investigation with the Finnish and Norwegian DPAs in December 2023. During its investigations, the controllers claimed in 2025 that it no longer offered services through the Yango app in Norway in Finland. The DPA, however, found that the providers of the app were still registered and continued to provide the Yango app to data subjects.
The Yango app processed a wide range of categories of personal data of customers and drivers, including contact information, use of the app (conversations, cookies), location, and bank information. For drivers, the app additionally processed data subject’s social security, ID and photos. The data was transferred and stored in Russia until 2023 (including the encryption keys). After 2023, the controller stored the data and encryption keys in the Amazon Web Services (AWS) data centres in Germany. However, the controller continued to transfer data to Russia based on standard contractual clauses. The controllers implemented additional organisational measures such as encrypting the data prohibiting Russian government agencies from accessing data from EEA/EU data subjects. Under Russian law, taxi drivers must keep a record of data related to each taxi ride, retain it for a minimum of six months, and provide the data to competent authorities when requested.
Ridetech argued that Yandex.Taxi LLC was a processor and not a joint controller, as it was simply a software provider. In addition, Ridetech argued that it did not unlawfully transfer the data, as it implemented appropriate technical and organisational measures. Finally, it denied that Yandex.Taxi LLC was required to grant general and direct access to their information systems to Russian authorities under national law.
Holding
The DPA first stated that Ridetech and Yandex.Taxi LLC were joint controllers, as they jointly determined the purposes and means of processing personal data through the Yango app. The DPA also took into account the fact that the companies belonged to the same group.
The DPA found a violation of Articles 44 and 46 GDPR, read in conjunction with Articles 5(1)(a) and (2) GDPR. This is because the controllers had not implemented appropriate safeguards when transferring data through standard contractual clauses. The DPA made a distinction between the period in which the controller stored the encryption keys in Russia (before November 2023) and in Germany (after November 2023). Before November 2023, the DPA found that the controller did not implement appropriate safeguards, as the personal data was stored in the same servers as the encryption keys. The DPA noted that the controllers failed to follow its own standard provisions, as they included the obligation to store the encryption keys within the EEA or a country with an equivalent level of protection.
After November 2023, while the data was first stored in AWS servers in Germany, the data was still forwarded to Russia. The DPA considered that Yandex.Taxi LLC and Yandex LLC (as recipients of the data) had means to reasonably enable them to identify Norwegian and Finnish data subjects. This is because both the recipients and Ridetech (later MLU B.V.) were managed by the same person. The DPA stated that the director had full authority and access to data within the companies, and the companies had a close interdependence. This meant that Yandex.Taxi LLC could identify data subjects in Norway and Finland without needing significant resources, even if the data was pseudonymised and encrypted.
Finally, the DPA stated that while Russian law applies mostly to data subjects in Russian territory, it is still possible for Russian authorities to request Yandex.Taxi LLC to provide data of EEA data subjects if they (temporarily) stay in Russia or possess a phone number from a Russian telecom provider. This means that standard contractual clauses may be insufficient to ensure, in practice, the effective protection of personal data transferred to a third country.[1] The DPA noted that Russian supervisory authority could not be considered an independent supervisory authority within the meaning of Article 45(2) GDPR, as it part of the Ministry of Digital Development. Therefore, the controllers failed to demonstrate that it had set appropriate safeguards to prevent Yandex.Taxi LLC and Yandex LLC from making the data of Norwegian and Finnish data subjects accessible to Russian authorities.
The DPA fined the controllers €100,000,000. The DPA considered this a serious violation of the GDPR, as it involved a high number of data subjects and a violation of long duration. In addition, the DPA prohibited MLU B.V from transferring data of Norwegian and Finnish data subjects using the Yango app to Russia.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Dutch original. Please refer to the Dutch original for more details.
1
Dutch Data Protection Authority
P.O. Box 93374, 2509 AJ The Hague
Hoge Nieuwstraat 8, 2514 EL The Hague
T 070 8888 500
autoriteitpersoonsgegevens.nl
Confidential/Registered
MLU B.V.
Attn: Mr. [CONFIDENTIAL]
P.O. Box 40198
8004 DD ZWOLLE
Date
1 April 2026
Our reference
2025-005323
Contact person
[CONFIDENTIAL]
Subject
Decision to impose an administrative fine for violating the General Data Protection Regulation
Dear Mr. [CONFIDENTIAL],
The Dutch Data Protection Authority (hereinafter: AP) has decided to impose an administrative fine on MLU B.V. as the legal successor of all
rights and obligations of the now dissolved company Ridetech International B.V. to impose an administrative fine of € 100,000,000 on (hereinafter:
Ridetech). This fine is imposed due to the
violation of the General Data Protection Regulation (GDPR). Ridetech is guilty
of transferring personal data of data subjects from Finland and Norway to
recipients in Russia without Ridetech having demonstrated that it has taken appropriate safeguards for this. This constitutes a violation of Articles 44 and 46 of the GDPR in conjunction with Article 5, paragraph 1,
subparagraph a and paragraph 2, of the GDPR. The violation commenced on 23 May 2022 and is still ongoing.
The DPA is of the opinion that imposing an administrative fine on MLU B.V. is not only appropriate, but
also necessary. The DPA has found that MLU B.V. has not safeguarded the intended interest of the
continuity of the high level of protection of the GDPR when transferring personal data to
a third country. The AP considers this serious and has therefore proceeded to take enforcement action against
MLU B.V.
Part of this enforcement action is that the AP imposes a ban on MLU B.V. regarding the processing of
personal data. This means that MLU B.V. must cease the transfer of personal data of
Norwegian and Finnish users of the Yango app to recipients in Russia.
Date
1 April 2026
Our reference
2025-005323
2/45
The administrative sanctions are explained in this decision. To this end, the
facts, the viewpoint, the established violation, the amount of the fine, and the processing ban are discussed in succession.
Finally, the operative part follows. 1. Background to the investigation
1. In 2021 and 2022, the Dutch Data Protection Authority (AP) received a signal from the Finnish privacy supervisory authority, Tietosuojavaltuutetun toimisto (hereinafter: the Finnish privacy supervisory authority), regarding Ridetech. This signal concerned a possible transfer of personal data of data subjects from the European Economic Area (hereinafter: EEA) to Russia by Ridetech, without a valid mechanism being applicable for international transfer of personal data within the meaning of the GDPR. In particular, the signal concerned the ‘ride-hailing’ apps ‘Yango for users’ and ‘Yango Pro for drivers’ (hereinafter collectively: Yango app).1 The Yango app is a platform on which independent drivers are matched with customers who wish to book a taxi ride.
2. Ridetech is an Amsterdam-based company that offers the Yango app within the EEA to data subjects in Finland and Norway. In the context of the provision of the Yango app,
Ridetech transfers (personal) data from the EEA to Yandex.Taxi LLC and Yandex LLC. Both
companies are established in Russia. Ridetech, Yandex.Taxi LLC, and Yandex LLC are companies
belonging to the same group.
3. On 4 August 2023, the Finnish Data Protection Authority took a decision in an expedited procedure
(Article 66 GDPR). This decision contained provisional measures that were valid from 1 September 2023 to
30 November 2023. In that decision, the Finnish Data Protection Authority ruled, inter alia, that the
transfer of personal data from Finland to Russia in the case of the Yango app is in violation of
Articles 44 and 46 GDPR. In view of this, the Finnish privacy supervisory authority has prohibited the transfer on the basis of Article 58, paragraph 2, point f, GDPR.2
4. The Norwegian privacy supervisory authority, Datatilsynet (hereinafter: the Norwegian privacy supervisory authority), has also initiated expedited proceedings against Ridetech regarding the transfer of personal data from Norway to Russia. It notified Ridetech, Yandex LLC, and Yango Norway AS of this on 7 August 2023.3
5. On 30 August 2023, the Finnish privacy supervisory authority suspended the decision of 4 August 2023. On 31 August 2023, the Norwegian privacy supervisory authority notified Ridetech, Yandex LLC, and Yango Norway AS
1 Investigation report, p 7.
2 File document 12 to the investigation report.
3 File document 13 to the investigation report. Date
1 April 2026
Our reference
2025-005323
3/45
informed that it would not take provisional measures, but would initiate further investigation into
the processing of personal data.4
6. On 5 December 2023, the AP initiated an investigation into the transfer by Ridetech of
personal data to Russia in the context of Ridetech's aforementioned services. The Finnish
and Norwegian privacy supervisory authorities joined this AP investigation on 18 December 2023.
7. The purpose of this joint investigation was to determine whether Ridetech complies with the GDPR rules regarding the international transfer of personal data from the
EEA to Russia in the period from 23 May 2022
to the present. The International Investigations Department of the AP therefore investigated whether
personal data of the drivers and customers using the Yango app (hereinafter collectively:
users) from the EEA are being transferred to Russia. The AP's International Investigation Department also investigated whether Ridetech had implemented appropriate safeguards within the meaning of Article 46 of the GDPR for the transfer of personal data to Russia.
2. Findings of the investigation report and course of proceedings
2.1 Course of proceedings
8. The AP's International Investigation Department recorded the findings of the investigation in a report dated 2 April 2025.5 By letter dated 8 April 2025, the AP informed Ridetech of its intention to take enforcement measures. The AP gave Ridetech the opportunity to provide a view on the intended enforcement and the underlying report.
Ridetech provided its view on the report on 10 June 2025. On 16 June 2025, Ridetech explained its view orally. 9. The director of Ridetech informed the AP by letter dated 28 October 2025 that Ridetech was dissolved as of 24 October 2025 and that its parent company, MLU B.V., will assume all rights and obligations of Ridetech as of that date.6 In addition, the director of Ridetech stated that all services of the Yango app in Norway and Finland have been discontinued. Upon request, the Norwegian and Finnish privacy supervisory authorities established that the Norwegian and Finnish providers of the Yango app are still registered in the Commercial Registers of both countries and that the services of the Yango app are currently still being offered.7
10. The main findings of the investigation report are summarized below.
4 File document 59 accompanying the investigation report.
5 The investigation report was sent to Ridetech on 8 April 2025.
6 Appendix 2 to this decision.
7 Appendix 3 to this decision. Date
1 April 2026
Our reference
2025-005323
4/45
2.2 Controller
11. Ridetech's privacy statement indicates that it is the controller for the processing of
personal data of users of the Yango app within the EEA territory. Ridetech was established in
Amsterdam until it was dissolved on 24 October 2025.8 Ridetech is part of a large
group structure. For better readability of this decision, the AP will continue to
use the name ‘Ridetech’.
12. Until it was dissolved on 24 October 2025, Ridetech was a subsidiary of MLU B.V., which
in turn was a subsidiary of Yandex N.V. Holding Company.9 MLU B.V. became a subsidiary of Y.E.
following a restructuring in February 2024. Holding Limited, established
in the United Arab Emirates.10 Y.E. Holding Limited is, as of July 24, 2024, a subsidiary
of Y.E. Holding doo Beograd, established in Serbia. Consortium.First is the sole shareholder of Y.E.
Holding doo Beograd. By way of illustration, the following group structure11 is included:
8 File document 134 attached to the investigation report.
9 File document 29 attached to the investigation report.
10 File documents 81 and 111 attached to the investigation report.
11 File document 112 attached to the investigation report.
Date
April 1, 2026
Our reference
2025-005323
5/45
13. Yandex.Taxi LLC is established in Russia. Until July 15, 2024, Yandex.Taxi LLC was a subsidiary
of Ridetech International B.V. After July 15, 2024, Yandex.Taxi LLC is a subsidiary of
Yandex.Technologies LLC, based in Russia.12
After change of business model (March 1, 2025)
14. On February 27, 2025, Ridetech notified the AP of a proposed change to the
business model of the Yango app.13 Effective March 1, 2025, the Yango app is offered via
a franchise model, whereby service provision is arranged per country. Effective March 1, 2025,
the Finnish company CABS TEK OY provides the services of the Yango app to consumers in
Finland. As of March 1, 2025, the Norwegian company SENTRAL OSLO CABS AS provides the services of the Yango app to consumers in Norway.14
15. As of March 7, 2025, Ridetech considers itself, together with the Finnish and Norwegian companies, as joint controllers for processing activities within the EEA.15
2.3 Processing of personal data
16. The services of the Yango app are provided via two mobile phone apps, ‘Yango for users’ and
‘Yango Pro for drivers’. Customers can request taxi rides via ‘Yango for users’ and drivers can accept the requests via
‘Yango Pro for drivers’.
17. Customers must first provide a valid telephone number to use the Yango app.
Ridetech also requests contact details and other data. This depends on the legal rules applicable in
the relevant country. For example, in Norway it is not possible to order a taxi without registering
a valid bank account number. Ridetech initially used ‘Yandex ID’ to register customers.16 Yandex ID gives users access to all Yandex services, such as Yandex Pay.The services of Yandex ID are offered by Yandex LLC, based in Russia.17 Ridetech
will no longer use Yandex ID as of March 19, 2025.18
18. After completing the registration process, customers can request a taxi ride. They do this by providing the
address of the pickup point. Customers do not need to give permission for the sharing of
other location-related data. When the customer gives permission for the sharing of their location,
12 File document 113 to the investigation report.
13 File document 123 to the investigation report.
14 File document 123 to the investigation report.
15 File documents 123 and 131 to the investigation report.
16 File document 20 to the investigation report.
17 File documents 20 and 49 to the investigation report. 18 Yango Privacy Policy (March 19, 2025), https://yango.com/legal/yango_privacy_notice/en/19032025/.
Date April 1, 2026
Our reference
2025-005323
6/45
the driver can see the precise location of customers on the map based on GPS data, Wi-Fi networks, or
a combination of both. Customers can also track the driver's location live.19
19. Ridetech may request access rights from data subjects via the Yango app to:20
a) take photos and videos, so that the customer can take a photo or scan of the bank card number
with the phone camera instead of manually typing this number.
The app does not store images;
b) read GPS data and network-based location information, so that the exact
pickup location of the customer is determined. This information may originate from GPS,
known Wi-Fi networks, or both;
c) to gain access to the microphone. In some countries, customers can use
voice recognition to provide a destination address or to send messages
to the driver. This is also possible in Norway;
d) to call phone numbers directly, so that the customer can call the driver via the app with just one
click;
e) to read the status and identifying information of the phone. If the customer does not grant the app access to the identifying information of the phone, related to Android
device ID (IMEI), the customer cannot use discount codes. According to the policy, users' promo codes are linked to their device IDs to prevent fraud;
f) to modify, delete, or read data in the USB storage for the purpose of being able to
save maps on the phone. This would make the Yango app better and faster and save
mobile data, storage, and battery. If the customer does not grant access rights for this function, the app will work slower, as the customer will then constantly have to wait until the cards are uploaded;
g) to read synchronization settings/to enable and disable synchronization;
h) to view network connections and gain full access to the network. The authorized system checks which internet connections are available and selects the most suitable internet connection.
i) to prevent the phone from going into sleep mode. Notifications can be sent when there is an order update, for example when the driver has arrived at the pickup location;
j) to view Wi-Fi connections and to be able to connect to or disconnect from these Wi-Fi connections, so that the app's ability to determine the customer's location can be improved;
k) to receive data from the internet, for the operability of the app. This function cannot be disabled;
l) to vibrate when the phone camera successfully recognizes the card number after scanning; 19 Yango access to device, yango.com/legal/app-permissions_en/.
20 Research report, p 18 and 19).
Date
April 1, 2026
Our reference
2025-005323
7/45
m) to play the ‘install referrer API’. This allows developers to receive non-identifying
information about the installation of apps, such as where users find them and
when they install them. It is a means to monitor distribution channels and to
protect against fraud;
n) to run the app in the background so that certain information can be updated. When the app runs in the background, the app does not use the
access rights to the camera or microphone.
20. For the services it offers via the Yango app, Ridetech processes the following (categories) of
customer personal data:
a. Telephone number;
b. Email address;
c. Electronic identification data;
d. Date and time of access to and use of the services and/or the phone app;
e. Information regarding activities that take place during the use of
the services and/or the phone app;
f. Chat conversations;
g. Telephone calls;
h. Login information;
i. (Geo)location;
j. Details of the orders;
k. Cookies (or similar technologies); 21
l. Details of the browser and/or phone app;22
m. Bank details (such as information about the payment method).23
21. For the services it offers via the Yango app, Ridetech processes the following (categories) of
personal data of drivers:24
a. Name;
b. Social security number;
c. Identification number;
d. Date of birth;
e. Place of birth;
f. Gender;
g. Nationality;
h. Photo;
i. Telephone number; 21 File document 43 attached to the investigation report, p. 11.
22 File document 87 attached to the investigation report.
23 File document 87 attached to the investigation report, p. 31.
24 File document 43 attached to the investigation report, p. 11.
Date
1 April 2026
Our reference
2025-005323
8/45
j. Official residential address;
k. Details of the driver's license: first and last name, expiry date, entity that issued the
driver's license, document number, place where the driver's license was
issued, car category or categories for which the driver's license applies, scanned
copies of the said documents.
l. Chat conversations;
m. Telephone conversations;
n. Bank details.25
2.4 Transfer to Russia
22. Yandex.Taxi LLC, established in Russia, is the recipient of personal data transferred to Russia. Yandex.Taxi LLC transfers these personal data in Russia to (sub)processor Yandex LLC. Prior to November 27, 2023, personal data of all data subjects were stored and processed in data centers in Russia. The personal data were stored in encrypted form in Russia. The encryption keys were also stored in Russia.26 Submitted documentation shows that after November 27, 2023, Ridetech processes personal data of data subjects from Finland and Norway in the Amazon Web Services (AWS) data centers in Frankfurt.
23. After pseudonymization and encryption, personal data are still transferred to Russia as of November 27, 2023, where they are stored and processed on the servers of Yandex.Taxi LLC and Yandex LLC. Ridetech uses standard contractual clauses for this transfer of personal data.
Standard contractual clauses are model contracts approved by the European Commission. When a
controller uses standard contractual clauses and applies the rules contained therein to
the transfer of personal data to a third country, the
controller is deemed to have thereby implemented appropriate safeguards.
24. The standard contractual clauses of 21 September 202127 mention (in Annex II) the following additional
technical measures:
a. Use of strict access restrictions to protect order data and
(geo)location of data subjects. All data is encrypted.
b. Use of strong encryption prior to transfer to Russia: e.g. key length,
operating mode and type of encryption can be considered robust
against cryptoanalysis by the government;
c. Correct implementation of the encryption algorithm and by properly
maintained software, without known vulnerabilities, the
conformity of which with the specification of the chosen algorithm has been verified,
for example by certification;
25 Document 87 to the investigation report, p. 31.
26 File documents 19 and 73 accompanying the investigation report.
27 File document 56 accompanying the investigation report.
Date
1 April 2026
Our reference
2025-005323
9/45
d. The reliable management of the encryption keys (generated,
managed, stored and, where relevant, linked to the identity of an
intended recipient, and revoked);
e. The exclusive retention of the encryption keys under the control of the
data exporter or by an entity in the EEA trusted by the exporter or within a jurisdiction that offers a level of protection that is
essentially equivalent to the level guaranteed within the EEA. 25. The standard provisions of 21 September 2021 mention (in Annex II) the following additional
organizational measures:
a. Marking and segregation of EEA/EU data in the information systems
is implemented when checking access to data on trips
made in different areas in the ‘admin panel’;
b. Prohibition of access to this data by Russian government authorities;
c. Implementation of the Data Protection Officer approval policy for any disclosure/transfer of data to
third parties, including Russian government authorities;
d. Introduction of mechanisms for eliminating automatisms for
attempts by government authorities to access EU data;
e. Establishment and publication of conditions for public requests (official,
reasoned, etc.);
f. Regular conduct of information security audits by the
data exporter;
g. Implementation of information security policies, ‘Bring Your Own Device’,
remote access, passwords, data sharing at the request of
authorities and other strict data security and privacy policies within the
importing subsidiary. The policy must be based on EU
certification or codes of conduct or international standards (e.g. ISO standards) and ‘best practices’ (e.g. ENISA: European Cybersecurity Agency), taking into account the state of the art, depending
on the risk of the categories of data processed;
h.Establishing the process for implementing the instructions of the
data exporter regarding the rights of data subjects and the erasure of
data (who and how, accepting, evaluating, recording instructions, who will
execute the instructions and in what manner, and reporting the status to the
Data Protection Officer (hereinafter: DPO) of the exporter);
i. Establishing an adequate internal process with clear assignment of
responsibilities for data transfers, notification channels and
standard operating procedures in the event of formal or informal requests from
public authorities;
j. Training on data protection for all personnel
involved in the processing of EU data;
k. Conducting ‘refreshers’;
Date
1 April 2026
Our reference
2025-005323
10/45
l. Development of specific training procedures for personnel charged
with managing requests for access to personal data originating from
public authorities. This must be updated periodically to take into account
new developments in legislation and
case law in the third country and in the EEA;
m. Documentation and recording of access requests received from
public authorities and the response to these access requests, together with the
legal reasoning and the actors involved (for example, whether the exporter has been
notified and their response, the assessment of the team charged with
handling such requests, etc.);
n. Regular publication of transparency reports or summaries
relating to requests from the government for access to data and the type
of response given thereto, insofar as publication thereof is permitted
under local legislation;
o. Development of ‘best practices’ to appropriately and timely involve the DPO and the legal and internal
audit departments and grant them access
to information on matters relating to international
data transfers;
p. Establishment and regular evaluation of internal policy to assess the suitability
of the additional measures implemented. If necessary, identify and implement additional
or alternative solutions to ensure that a
level of protection of the transferred personal data is
maintained that is essentially equivalent to the level guaranteed within the EEA.
26. The standard provisions (in Annex II) further mention the following additional legal and contractual
measures:
a. The data importer is contractually obliged to assist the exporter in his
assessment of access to data by public authorities;
b. There are guarantees whereby the importer declares that (1) he has not knowingly
created ‘backdoors’ or similar programming that can be
used to gain access to the system and/or the transferred
personal data; (2) he has not knowingly created
or modified his business processes in a way that facilitates access to the transferred personal data or
systems; and (3) national law or government policy does not require the importer to create or maintain 'backdoors' or to facilitate access to the transmitted personal data or systems
or that the importer must be in possession of the encryption key or must hand over the encryption key;
c. The exporter's authority to terminate the contract on short notice
in those cases where the importer fails to bring to light the existence of a 'backdoor' or
similar programming or manipulated business processes or an
obligation to carry out any of these or fails to
notify the exporter immediately as soon as he becomes aware of their existence;
Date
1 April 2026
Our reference
2025-005323
11/45
d. Establishing specific and strict time limits and procedures for the rapid
suspension of the transmission of data and/or termination of the contract
and the return or deletion of the data received by the importer;
e. The data importer must monitor all legal or policy developments that may result in it being unable to fulfill its obligations, and notify the data exporter without delay of such changes and developments, and where possible, before their implementation, so that the data exporter can recover the data from the data importer;
f. The importer must commit to examining the lawfulness of any order for disclosure of data, in particular whether it falls within the powers granted to the requesting public authority, and challenge the order if, after careful assessment, it concludes that there are grounds to do so under the law of the receiving country.
27. On 4 April 2024, Ridetech updated the standard provisions.28 In addition to the above measures, Ridetech has taken new technical and organisational measures. 28. Ridetech mentions the following
additional technical measures in (in Annex II of ) the updated standard provisions of 4 April 2024:
a. Pseudonymisation (tokenisation: replacing the plaintext with a
randomly generated pseudonym (only in the EU) before it is sent to Russia for processing. Profile data of end users and drivers
are replaced by tokens) taking place within the EU before
personal data is transferred to Russia;
b. Obfuscation of personal data (applicable to geospatial data) – altering or reducing the accuracy of data and aggregating
it, thereby making the location less accurate;
c. Masking of personal data – replacement of the substantial part of
data that makes data structurally similar to original data,
but is useless for linking to a data subject and is not valuable to
unauthorised personnel;
d. Decoupling principle (identifying information is separated from the rest of the data to reduce the likelihood that data can still be linked);
e. Encryption prior to transmission without access by the importers to plain text data, encryption of data in transit without access by the importers to plain text data;
f. Encryption of the rest of personal data using modern encryption algorithms (AES 256);
g. Encryption of personal data in transit (HTTPS, TLS (up to and including version 1.3)) to ensure communication security;
28 File Document 87 accompanying the investigation report.
Date
1 April 2026
Our reference
2025-005323
12/45
h. Storage of encryption keys within the EU;
i. Access controls applied by the data exporter, including
authorizations to deny, suspend
or revoke access to personal data, also in the importer's systems, and to manage the general
configurations of the access control system;
j. Configuration management of the Yango app, including authorizations to
confirm or suspend the
functionality of the application in certain countries or geographic areas and
availability for partners and integrations with other applications and services;
k. Continuous automated monitoring of processing activity, including
log files and system reports;
l. Security maintenance;
m. Measures to safeguard the system configuration, including the
default configuration;
n. The regular testing, assessment, and evaluation of the effectiveness of
technical and organizational measures to ensure the security of processing
, including regular audits, the automation of 24/7
audits, regular penetration tests, ‘bug bounty’ program;
o. Measures for user identification and authorization, including 2FA (OTP) —
login and password authentication, together with a second factor such as an SMS code, company device policy: access to data is only permitted via
business devices, authentication verification based on the 802.1X protocol,
working outside the office only via VPN;
p. Measures to ensure that event logging, including system user actions, is recorded and stored for audit purposes and that all user actions are recorded, internal audit automation to analyze event logging to detect abnormal deviations, a dedicated comprehensive audit system to verify user actions regarding personal data (this audit includes actions between micro-services);
q. Measures for internal IT and IT security governance and management, including an endpoint detection and response tool that analyzes and detects malicious activities, antivirus protection, backups, network-level access control, access control manager, operational security center;
r. Access control manager, enabling the administrator of an exporter to configure site access rules (DPO approval policy);
s. Network-level access control;
t. Logical segregation of data by country and product (brand) at the program level
to ensure that all data is stored in accordance with
the applicable requirements.
29. Ridetech mentions the following
additional organizational measures in (in Annex II of ) the updated standard provisions of 4 April 2024:
Date
1 April 2026
Our reference
2025-005323
13/45
a. Instructions and policies;
b. Awareness mechanisms and regular training;
c. Data protection obligations are included in contracts with
employees;
d. Background checks for employees;
e. Physical security measures, including measures to ensure that the availability of and access to data are restored in a timely manner in the event of a physical or technical incident;
f. All data is stored in the importers' own data centers, which are under physical control 24/7; g. Security of business premises and physical access control.
2.5 Russische wetgeving
30. De geldende Russische wetgeving is als volgt:
Criminal Procedure Code of the Russian Federation No.174-FZ of December 18,
2001
Code of Administrative Offences of the Russian Federation No. 195-FZ of
December 30, 2001
Federal Law of the Russian Federation No. 149-FZ of July 27, 2006 on
Information, Information Technologies and Protection of Information
Federal Law of the Russian Federation No. 152-FZ of July 27, 2006 on Personal
Data
Decree of the Government of the Russian Federation No. 228 of March 16, 2009
on the Federal service for Supervision of Communications, Information
Technology and Mass Media
Decree of the Government of the Russian Federation No. 743 of July 31, 2014 on
the Rules of Cooperation of Organizers of Distribution of Information on the
Internet
Federal Law of the Russian Federation No. 374-FZ and No. 376-FZ of July 6,
2016
Order of the Ministry of Digital Development and Communications No. 571 of
October 29, 2018
Decree of the Government of the Russian Federation No. 1526 of September 23,
2020
Datum
1 april 2026
Ons kenmerk
2025-005323
14/45
31. Het toezicht op de naleving van de privacywetgeving is in Rusland belegd bij de Federal Service for Supervision
of Communications, Information Technology, and Mass Media (hierna: Roskomnadzor). Roskomnadzor is een
uitvoerende instantie, die onderdeel uitmaakt van het Ministerie van Digitale Ontwikkeling,
Communicatie en Massamedia van Rusland. De voorzitter van Roskomnadzor wordt aangesteld en
ontslagen door de overheid van Rusland op advies van de minister van communicatie en massamedia.29
Russische Taxiwet
32. De Russische Taxiwet is per 1 september 2023 in werking getreden. Deze wet verplicht taxivervoerders om
een digitaal of analoog ‘logboek’ bij te houden.30 Taxivervoerders moeten voor iedere taxirit de onderstaande
gegevens invullen in een logboek:
a. Het bestelnummer van de taxi;
b. Tijd en datum waarop de taxibestelling is geaccepteerd;
c. Datum waarop de taxibestelling is voltooid;
d. Het begin- en eindpunt van de taxirit;
e. Het merk, model en kenteken van het voertuig, en de achternaam, voornaam en
patroniem (indien van toepassing) van de chauffeur;
f. De geplande en werkelijke aankomsttijd en de tijdsduur van de taxirit;
g. De methode waarmee de taxibestelling was geplaatst en het telefoonnummer van
de klant die de bestelling heeft geplaatst;
h. Elke aanvullende eis die is gesteld door de klant die de bestelling heeft geplaatst,
met inbegrip van de eis om elk kind van een kinderbeveiligingssysteem te voorzien
of het vervoeren van een passagier die mindervalide is en diens rolstoel.
29 Dossierstuk 86 bij het onderzoeksrapport.
30 Artikel 11, zevende lid, en artikel 19, elfde lid, Russische Taxiwet.
Decree of the Government of the Russian Federation, No. 1101 of 4 July 2023
Federal Law of the Russian Federation No. 580-FZ of September 1, 2023 on the
Organization of Passengers and Baggage Transportation by Passenger taxi in
Russia
Order of the Government of the Russian Federation No. 256 of March 1, 2024
Federal Law of the Russian Federation No. 144-FZ of August 12, 1995 on
Operational Search Activities
Datum
1 april 2026
Ons kenmerk
2025-005323
15/45
33. De taxivervoerders zijn verplicht om de hierboven genoemde gegevens voor minstens zes maanden te
bewaren na het voltooien van de taxirit.31 Ook zijn taxivervoerders verplicht om gegevens te verschaffen, in
de door de wet omschreven gevallen, wanneer een bevoegde instantie daarnaar vraagt. De bevoegde
instantie is de federale uitvoerende instantie (of een regionaal kantoor daarvan) die verantwoordelijk is
voor de veiligheid, of de federale uitvoerende instantie die verantwoordelijk is voor het ontwikkelen en
implementeren van staatsbeleid en juridische regulering op het gebied van binnenlandse zaken of diens
regionaal kantoor.
34. Taxivervoerders zijn ook verplicht om aan de federale uitvoerende instantie, verantwoordelijk voor de
veiligheid, toegang te verschaffen tot informatiesystemen en databases die gebruikt worden voor het
ontvangen, bewaren, verwerken en doorgeven van taxibestellingen op een wijze die voorgeschreven is
door de Russische overheid.32
35. In de ‘Decree of the Government of the Russian Federation of 4 July 2023, No. 1101’ staan voorschriften die gelden
voor de toegang door de Russische autoriteiten tot de informatiesystemen en databases van
taxivervoerders. Hieruit volgt tevens dat taxivervoerders gebonden zijn aan een geheimhoudingsplicht ten
aanzien van de interacties met de FSB (de Russische binnenlandse veiligheidsdienst).
SORM
36. De ‘Federal Law of the Russian Federation No. 149-FZ of July 27, 2006’ (hierna: Information Act) bepaalt wat een
Internet Communications Organisers (hierna: ICO) is.33 Dat is een persoon of entiteit die zorgt voor de werking
van informatiesystemen en/of programma’s voor elektronische apparaten, met als doel het ontvangen,
verzenden, leveren en/of verwerken van elektronische communicatie op het internet. Zowel Yandex.Taxi
LLC als Yandex LLC zijn aangemerkt als een ICO. Zij staan ook als zodanig geregistreerd in het ICO-
register. Daarmee is de Information Act op hen van toepassing.
37. Voor ICO’s zijn in 2016 aanvullende verplichtingen geïntroduceerd in de ‘Federal Law of the Russian Federation
No. 374-FZ and 376-FZ of July 6, 2016’ (hierna samen: ‘Yarovaya Law’). Sindsdien zijn ICO’s verplicht bepaalde
informatie te verstrekken aan rechtshandhavingsinstanties of veiligheidsdiensten.34 Ook zijn ICO’s
verplicht om alle informatie te verstrekken die nodig is om versleutelde elektronische communicatie te
decoderen.35
38. Om genoemde informatie te kunnen verschaffen, moeten ICO’s de vereiste apparatuur op hun
softwaresystemen installeren. Deze apparatuur wordt aangemerkt als de System for Operative Investigative
Activities (hierna: SORM). Alle organisaties, waaronder ICO’s, zijn verplicht tot geheimhouding. Zij mogen
geen informatie delen over de SORM of de technische details van de integratie van de SORM in hun
31 Artikel 11, achtste lid, Russische Taxiwet.
32 Artikel 14, zevende lid, Russische Taxiwet.
33 Artikel 10.1, eerste lid, Information Act.
34 Artikel 10.1, derde lid, Information Act.
35 Artikel 10.1, vierde lid, Information Act.
Datum
1 april 2026
Ons kenmerk
2025-005323
16/45
systemen.36 Het delen van deze informatie wordt gestraft met een maximale administratieve boete tot 6
miljoen Russische Roebels.37
39. In het onderzoeksrapport is geconcludeerd dat Ridetech en Yandex.Taxi LLC gezamenlijke
verwerkingsverantwoordelijke zijn voor de onderzochte gegevensverwerking.38 Daarnaast is in het
onderzoeksrapport geconcludeerd dat Ridetech niet heeft kunnen aantonen dat de doorgifte van
persoonsgegevens aan Yandex.Taxi LLC en Yandex LLC voldoet aan hoofdstuk V van de AVG. Ridetech
heeft onvoldoende aangetoond dat zij met de door haar genomen maatregelen, die bestaat uit het gebruik
maken van standaardbepalingen, in het kader van de doorgifte naar Rusland een beschermingsniveau
waarborgt dat in elk geval gelijkwaardig is aan het beschermingsniveau binnen de Europese Unie.
3. Juridisch kader
40. Het relevante juridisch kader is in bijlage 1 opgenomen en maakt onderdeel uit van dit besluit.
4. Zienswijze Ridetech
41. Ridetech heeft –samengevat – de volgende zienswijze op het onderzoeksrapport gegeven.
42. Volgens Ridetech is er geen sprake van gezamenlijke verwerkingsverantwoordelijkheid tussen Ridetech en
Yandex.Taxi LLC. Daarnaast vindt Ridetech dat er geen sprake is van ongeoorloofde doorgifte van
persoonsgegevens.
Verwerkingsverantwoordelijkheid
43. Volgens Ridetech wordt in het onderzoeksrapport ten onrechte geconcludeerd dat Ridetech en
Yandex.Taxi LLC gezamenlijke verwerkingsverantwoordelijke zijn. Yandex.Taxi LLC verwerkt geen
persoonsgegevens voor haar eigen doeleinden. Yandex.Taxi LLC is slechts een softwareleverancier die een
Software as a Service-oplossing (hierna: SaaS-oplossing) aanbiedt. Ridetech heeft met Yandex.Taxi LLC
een licentieovereenkomst gesloten voor het afnemen van de SaaS-oplossing. Deze licentieovereenkomst
bevat standaardbepalingen. Eén daarvan is dat Ridetech zonder toestemming van Yandex.Taxi LLC de
software niet mag wijzigen.
44. Ridetech vindt dat de AP in het onderzoeksrapport het karakter en de eigenschappen van een SaaS-
oplossing miskent. De afnemer van een SaaS-oplossing heeft beperkte zeggenschap over de software zelf,
omdat de softwareleverancier verantwoordelijk is voor het onderhoud en beheer ervan. De SaaS-oplossing
van Yandex.Taxi LLC is een op zichzelf staande dienst die Ridetech afneemt en verder aankleedt met het
36 Artikel 10.1, vierde lid, Operational Search Activities Act (hierna: OSAA).
37 Artikel 13.31
, Code of Administrative Offences of the Russian Federation.
38 Onderzoeksrapport, pagina 35.
Datum
1 april 2026
Ons kenmerk
2025-005323
17/45
doel om haar diensten via de Yango-app aan te bieden. Ridetech stelt dat zij de Yango-app ook zou kunnen
aanbieden indien een andere softwareontwikkelaar de SaaS-oplossing hiervoor zou leveren.
Passende waarborgen
45. Ridetech benadrukt dat zij privacy hoog in het vaandel heeft staan. Zij heeft vanaf het eerste moment
volledig meegewerkt met de toezichthouders over de verwerking van persoonsgegevens. Ridetech heeft
vragen altijd direct en volledig beantwoord en haar systemen en/of werkwijze op verzoek van
toezichthouders aangepast.
46. De maatregelen die Ridetech tot op heden heeft genomen, zijn verbeteringen ten opzichte van de situatie
in mei 2022 en die in het najaar van 2023. Er vinden nu regelmatig audits plaats binnen de Ridetech
Group. Deze audits worden uitgevoerd door het Security Team in Servië. Ook is Ridetech sinds januari
2025 bezig met het aanpassen van de werkwijze waarmee gegevens aan Yandex.Taxi LLC worden
verstrekt. Sinds 11 juli 2025 lopen alle datastromen volledig via dataservers in de EU en dus ook de
datastromen waarin geen persoonsgegevens worden verwerkt. Dit betekent dat Ridetech alleen maar
versleutelde gegevens aan Yandex.Taxi LLC in Rusland kan verstrekken.47. Ridetech further argues that sufficient technical, organizational, and contractual measures have been taken. Contrary to the conclusion of the investigation report, Ridetech does comply with the requirements applicable to the international transfer of personal data. First, because Ridetech has pseudonymized this data. Second, because Ridetech has encrypted this data. The keys or linking codes required to trace the aggregated and encrypted data back to natural persons are located in the data center in the EU. Ridetech states that, with the technical measures taken, it is not possible for Yandex.Taxi LLC and Yandex LLC to trace the imported data back to natural persons. Therefore, as such, this data is not personal data.
48. Insofar as the Russian authorities were to make a request to gain access to data of data subjects from the EU, Yandex.Taxi LLC and Yandex LLC do not have the capability to comply with such a request. Even in the most extreme scenario where Russian authorities were to gain access to the encrypted and pseudonymized data, this data would be of no use whatsoever, because the Russian authorities cannot access the underlying, original data via Yandex.Taxi LLC or Yandex LLC.
Risk-based approach
49. Ridetech further points out that the right to protection of personal data, enshrined in Article 8 of the Charter, is not absolute. This right must be weighed against other fundamental rights and freedoms, such as the right to freedom of enterprise. Ridetech has adopted a risk-based approach for the transfer of data to Russia. It has prepared a Transfer Impact Assessment (hereinafter: TIA) and thereby assessed the risks associated with the transfer of the data to Russia
Date
1 April 2026
Our reference
2025-005323
18/45
. According to Ridetech, the AP wrongly focuses in the investigation report on the theoretical
possibility of access by the Russian authorities to the data processed via transmission in Russia.
Russian law
50. According to Ridetech, it does not fall within the scope of Russian legislation. Yandex.Taxi LLC and Yandex LLC, on the other hand, do fall under the Russian Information Act. They are designated as an
ICO and are also registered with certain services in the Russian ICO register. According to Ridetech, however, it is incorrect that Yandex.Taxi LLC and Yandex LLC are required under the Information Act to grant general and
direct access to the information systems to the Russian authorities. Furthermore, insufficient evidence has been provided in the
investigation report to support the conclusion that the Russian authorities do have
general and direct access to the imported data.
51. According to Ridetech, Yandex.Taxi LLC and Yandex LLC are required under the Information Act to implement the
SORM. SORM has various variants, and the variant for Yandex.Taxi LLC and
Yandex LLC is called ‘HSS ICO’. HSS ICO is a collective term for the software and hardware that
ICOs must implement in their internal infrastructure. Through HSS ICO, Russian authorities can
request data from ICOs, and ICOs can subsequently select for themselves which information they share with the Russian authorities via this
system. Based on Russian regulations (Order No. 571), there are
four channels through which information can be exchanged within HSS ICO:
• Channel 1: the control channel;
• Channel 2: the data channel;
• Channel 3: the configuration channel;
• Channel 4: the unstructured channel.
52. Based on Russian regulations, ICOs are not obliged to provide further cooperation than the
above description of HSS ICO. Yandex.Taxi LLC and Yandex LLC are indeed ICOs, but
they do not, however, fall under the regime that applies to telecom providers. According to Ridetech, the research report therefore incorrectly referred to rulings by the ECtHR (case Zakharov39 and case Podchasov40) which concerned the provision of data by telecom providers. Only telecom providers have the duty under the Information Act and ‘Order No. 268’ to offer the option of tapping. Consequently, this obligation does not apply to Yandex.Taxi LLC and
Yandex LLC.
39 ECtHR 4 December 2015, ECLI:CE:ECHR:2015:1204JUD004714306 (
Zakharov v. Russia ).
40 ECtHR 13 February 2024, ECLI:CE:ECHR:2024:0213JUD003369619 (
Podchasov v. Russia). Date
1 April 2026
Our reference
2025-005323
19/45
53. Finally, Ridetech has informed the AP that all servers of the ‘Yango Group’ have been moved to Serbia in 2025. In this regard, Ridetech has submitted a news article to substantiate the information.41
5. Assessment
5.1 Jurisdiction of the AP
54. Ridetech is established in the Netherlands and offers its services via the Yango app in Norway and Finland.
As of 1 March 2025, Ridetech’s services in Norway and Finland have been transferred to two newly established subsidiaries in Norway and Finland, respectively.42 In this case, Ridetech processes personal data in more than one Member State. Ridetech has its main establishment (and until 1 March 2025, the only establishment in the EEA) in the Netherlands. This means that there is cross-border processing and that (therefore) the AP, as the lead supervisory authority, is authorized to take action against this processing.43
5.2 Processing of personal data
55. Ridetech processes personal data of data subjects via the Yango app for its services. Paragraph 2.3 sets out which personal data Ridetech processes for its services. In addition, Ridetech shares personal data with the Russian recipients, Yandex.Taxi LLC and Yandex LLC. The transfer of personal data to another entity also qualifies as processing within the meaning of Article 4, opening words and point 2, GDPR.
5.3 Controller
56. In the investigation report, Ridetech and Yandex.Taxi LLC have been jointly identified as the controller for the processing of personal data of data subjects via the Yango app. Ridetech takes the position that only it should be regarded as the controller and that Yandex.Taxi LLC is merely the processor of the personal data of data subjects using the Yango app.
57. The Court of Justice of the European Union (hereinafter: CJEU) has ruled that involvement in the determination of the purpose and means of processing may take various forms and may result from both a joint decision by two or more entities and from converging decisions by those entities.44 When it concerns converging decisions, then
41 Annex 4 to this decision: UAE-based The Yango app Group to open flagship data centre hub in Serbia to boost its global infrastructure’
of 12 June 2025.
42 File 123 to the investigation report.
43 Article 56, paragraph 1, GDPR. 44 CJEU 7 March 2024, ECLI:EU:C:2024:214 (
IAB Europe), paragraph 59.
Date
1 April 2026
Our reference
2025-005323
20/45
those decisions complement each other so that each of them has a concrete effect on the determination of the purpose and the means of processing.45
58. It is established that Ridetech was part of a group with a very extensive
organizational structure until February 2024 and that Yandex.Taxi LLC was a subsidiary of
Ridetech at least until February 2024. 46
59. In the period between February and July 2024, the group was restructured and as a result Yandex.Taxi LLC
became a subsidiary of the Russian Yandex Technologies LLC. 60. Schematically, the – simplified – organizational structure before July 2024 looks as follows:
61. After July 2024, Yandex N.V. was acquired by Consortium.First. Schematically, the – simplified –
organizational structure looks as follows:
45 CJEU 7 March 2024, ECLI:EU:C:2024:214 (
IAB Europe), ro. 59.
46 File documents 29, 35 and 110 accompanying the investigation report.
Yandex N.V.
(Netherlands)
MLU. B.V.
(Netherlands)
Ridetech
International
B.V. (Netherlands)
Yandex.Taxi LLC
Yandex
Technologies
LLC (Russia)
Yandex LLC
(Russia)
Date
April 1, 2026
Our reference
2025-005323
21/45
62. It follows from the foregoing that, although Ridetech and Yandex.Taxi LLC are legally separate entities, they nevertheless belong to the same group. The Yango app is built using the software on which the intellectual property rights of Yandex.Taxi LLC rest. This software (the so-called SaaS solution) is offered by Yandex.Taxi LLC, by way of service, to its sister companies, including Ridetech. The aforementioned software is essential for the ride-hailing services provided within the group by Ridetech and its sister companies.
As the developer and supplier of this software, Yandex.Taxi LLC determines the appearance of the Yango app and which personal data must be processed via this app. Furthermore, parties other than Yandex.Taxi LLC are not permitted to make changes to the software..47
63. At the same time, Ridetech has the task of operating the Yango app in Norway and Finland, and for that purpose Ridetech has entered into various agreements with, for example, AWS for data storage, or with DPO Europe GmbH for the hiring of a Data Protection Officer. The fact that Ridetech enters into an agreement with users of the Yango app and acts as a point of contact for, among other things, access requests from users or reports data breaches to the Dutch Data Protection Authority (AP), constitute actions of an ancillary nature in this context. In fact, the situation is such that the Yango app has been marketed as a service in Norway and Finland and that two entities, belonging to the same group, deploy resources with the aim of making and keeping the Yango app available as a service for users in Norway and Finland. 64. In view of the foregoing, the AP is of the opinion that Ridetech and Yandex.Taxi LLC jointly determine the purpose and means of processing personal data via the Yango app and are therefore, as entities belonging to the same group, jointly responsible for such processing operations.47 File document 45 to the investigation report, p. 4.
Consortium.First
(Russia)
Y.E. Holding
d.o.o. Belgrade
(Serbia)
Y.E. Holding
Limited (UAE)
MLU. B.V.
(Netherlands)
Ridetech
International
B.V. (Netherlands)
IPJSC Yandex
(Russia)
Yandex
Technologies
LLC (Russia)
Yandex.Taxi LLC
Yandex LLC
(Russia)
Date
1 April 2026
Our reference
2025-005323
22/45
5.4 International transfer of personal data
65. Transfer of personal data to a third country or to an international organisation may
take place when the European Commission has adopted a so-called adequacy decision
for the country or international organisation concerned.48
66. The European Commission has not adopted an adequacy decision for Russia. It is also not in dispute that Russia does not guarantee an appropriate level of protection that broadly corresponds to
the level of protection offered in the EU/EEA. 67. In the absence of an adequacy decision, transfer may nevertheless take place if appropriate safeguards are provided and data subjects have enforceable rights and effective remedies.49 Appropriate safeguards may be provided by, inter alia, standard contractual clauses (the so-called SCCs) adopted by the European Commission.50 In this case, Ridetech used such standard contractual clauses for the transfer of personal data to Russia.
Therefore, the DPA must assess whether this instrument provides appropriate safeguards for the protection of personal data.
68. Ridetech used standard contractual clauses51 that apply to the transfer of personal data between a controller and a processor. However, the DPA concluded in paragraph 64 that Ridetech and Yandex.Taxi LLC are joint controllers. Therefore, Ridetech should have used standard contractual clauses that apply to the transfer of personal data between two controllers. This means that Ridetech, by using
standard clauses applicable to the transfer of personal data between a
controller and a processor, has therefore not used the correct standard clauses to
provide appropriate safeguards for the transfer of personal data of users of the Yango app
to recipients in Russia.52 Despite this circumstance, the DPA will nevertheless subsequently assess whether
Ridetech has provided appropriate safeguards for said transfer of personal data.
5.4.1 Appropriate safeguards
69. As stated in paragraph 2.4 of this decision, Ridetech uses standard clauses.
In order to assess whether Ridetech has provided appropriate safeguards with its standard clauses for the
transfer of personal data of Finnish and Norwegian data subjects to Russia, the DPA distinguishes
48 Article 45, paragraph 1, GDPR.
49 Article 46, paragraph 1, GDPR.
50 Article 46, paragraph 2, point c, GDPR. 51 File documents 6, 79 and 87 accompanying the investigation report.
52 The standard provisions contain general provisions and three different modules: I) transfer between two
controllers, 2) transfer between controller and processor and 3) transfer between two
processors. The controller(s) and processor(s) must choose the module that applies to their situation.
Date
1 April 2026
Our reference
2025-005323
23/45
between, on the one hand, the period (until 27 November 2023) during which the encryption keys were stored in
data centers in Russia and, on the other hand, the period (after 27 November 2023) during which these encryption keys
were stored in data centers in Frankfurt. 70. The AP establishes that Ridetech transferred personal data to Russia at least until 27 November 2023 without having taken appropriate safeguards. Paragraphs 22 and 23 of this decision state that, although Ridetech processed personal data only in encrypted form on the servers in Russia until 27 November 2023, the encryption keys with which this personal data could be ‘decrypted’ were also stored on the same servers – in Russia.
71. It has emerged that personal data processed by Ridetech via the Yango app were first stored in the data centers of AWS in Frankfurt. After storage at AWS, Ridetech forwarded this personal data to the ‘backend’ server in Russia. The ‘backend’ server replaced the personal data with pseudonymized ‘identifiers’ which were subsequently encrypted on the ‘personal’ server. The corresponding
encryption keys were stored in the RAM (working memory) of that same server. This means that
the personal data in the ‘personal’ server could also be decrypted again using the encryption keys
that were stored on this server.53
72. The AP further notes on this point that, according to its standard provisions (of 21 September 2021), Ridetech may only store
encryption keys within the EEA or in a country with an equivalent
level of protection. This was therefore not the case. After all, the encryption keys were stored in Russia,
under the control of the local ‘Security Team’. Ridetech therefore acted even in violation of its own
standard provisions.
73. Moreover, Ridetech has not demonstrated in what (other) way its standard provisions of
21 September 2021 could have prevented the risk of access by the Russian authorities
during the period in which the encryption keys were stored
in Russia together with the encrypted personal data. 74. Since Ridetech kept the encryption keys on the same servers in Russia as the encrypted personal data of Finnish and Norwegian users of the Yango app until at least 27 November 2023, it has, in the opinion of the AP, failed to implement appropriate safeguards for the transfer of personal data.
75. In the period after 27 November 2023, Ridetech changed the method of transferring personal data to Russia. This change entails that personal data of Finnish and Norwegian users of the Yango app were encrypted and subsequently stored on AWS servers in Frankfurt (‘data at rest’). The encryption keys of the encrypted personal data were also stored on AWS servers in Frankfurt. The encrypted personal data were subsequently transferred to Yandex.Taxi LLC and Yandex LLC in Russia (‘data in transfer’).
53 Document 19 accompanying the investigation report. Date
1 April 2026
Our reference
2025-005323
24/45
76. The AP must therefore assess whether Yandex.Taxi LLC and Yandex LLC, as recipients of personal data of Finnish and Norwegian users of the Yango app, possess means which can reasonably be expected to be used to identify the Norwegian and Finnish users.
77. The AP is of the opinion that Yandex.Taxi LLC and Yandex LLC possess these means and explains this as
following. 78. Ridetech was managed by one director, Mr. [CONFIDENTIAL], during the period from September 15, 202054 to May 31, 202455. He was also a director of MLU B.V., the parent company of Ridetech, during the period from May 1, 202057 to May 31, 202458. As of September 27, 2022, Mr. [CONFIDENTIAL], together with Mr. [CONFIDENTIAL], is a director of MLU B.V.60 It is established that Mr. [CONFIDENTIAL] was still a director of MLU B.V. on at least August 27, 2024.61 In addition, Mr. [CONFIDENTIAL] is also a director of the Russian Yandex.Taxi LLC. This follows from
the standard provisions of 21 September 202162 and 4 April 2024,63 signed by Mr. [CONFIDENTIAL] as
director of Yandex.Taxi LLC.
79. It follows from the preceding paragraph that both the recipient of personal data (Yandex.Taxi LLC) and
the exporter of such personal data (MLU B.V.) were managed by the same person, Mr.
[CONFIDENTIAL]. The AP sees in these circumstances ample grounds for the conclusion that
it is reasonably to be expected that Yandex.Taxi LLC can be used to
identify Finnish and Norwegian users. After all, the director of an enterprise has all powers and access to
data within the enterprise(s) he manages. This illustrates the close interrelationship between
Ridetech and Yandex.Taxi LLC, as entities within the group. The AP concludes from this that identifying the Finnish and Norwegian users would not require much cost, time, or manpower from
Yandex.Taxi LLC. The fact that the personal data of the Finnish and Norwegian users were pseudonymized and encrypted (‘in transit’ and ‘at rest’) in the period after 27
November 2023, and that the encryption keys are no longer stored in Russia, does not alter the fact that the possibility exists that the said
personal data could still be decrypted via the director of Yandex.Taxi LLC in Russia.
64 This means that the encrypted data are not merely anonymized
data for Yandex.Taxi LLC, but rather personal data. The AP also takes into account the circumstance that Ridetech and
Yandex.Taxi LLC belong to the same group and are hierarchically subordinate to the wishes of
the board of their parent company, regardless of whether both companies have the same person as
54 Dossier document 21 to the investigation report. 55 Document 107 attached to the investigation report.
56 Document 21 attached to the investigation report.
57 Document 11 attached to the investigation report.
58 Document 117 attached to the investigation report.
59 Document 11 attached to the investigation report.
60 Document 11 attached to the investigation report.
61 Document 117 attached to the investigation report.
62 Document 42 attached to the investigation report.
63 Document 87 attached to the investigation report.
64 In this context, compare CJEU 4 September 2025, ECLI:EU:C:2025:645 ( GAR/EDPS), paragraphs 68-90. Date
1 April 2026
Our reference
2025-005323
25/45
have a driver. The AP is therefore of the opinion that Yandex.Taxi LLC and Yandex LLC can gain access
to personal data of Finnish and Norwegian users of the Yango app stored on the ‘backend’ server
in Russia. Under these circumstances, the AP concludes that Ridetech has not taken appropriate
safeguards for the transfer of personal data.
5.4.2 Scope of Russian legislation
80. The AP will also assess whether the safeguards Ridetech believes it has taken are appropriate in light of Russian regulations.
81. Paragraph 36 states that Yandex.Taxi LLC and Yandex LLC are classified as ICOs pursuant to the Russian Information Act. While it does not follow from the Information Act and the so-called ‘Yarovaya Law’ that all ICOs must grant the authorities general and direct access to their data, certain ICOs are obliged to transmit information to the authorities via the so-called SORM. This concerns data from:
a) Registered users with IP addresses that the ICO determines are used within Russian territory;
b) Authorized users with IP addresses that the ICO determines are used within Russian territory;
c) Users who, during registration or while using the functionalities of the ICO, have submitted a Russian identity document;
d) Users who use devices and/or programs to access the ICO that transmit location data to the ICO, when the location data indicate that the user is (temporarily) located within Russian territory;
e) Users who, during registration or while using the functionalities of the ICO, provide a telephone number as contact details that has been assigned by a Russian telecom provider;
f) Users of whom the ICO has been informed by the relevant Russian authorities that they are located on Russian territory.
82. The aforementioned data mainly concerns users located within the territory of Russia, but it is not excluded that a user of the Yango app from Finland or Norway may have stayed (temporarily) in Russia or possesses a telephone number provided by a Russian telecom provider. When one of these situations occurs, the personal data of the relevant users from Finland and Norway of the Yango app may be requested by the Russian authorities.
83. The AP has taken note of Ridetech's position that Yandex.Taxi LLC and Yandex LLC, as ICOs, possess internal information systems (‘IS ICO’) and that this system does not grant general and direct access to the data in these internal information systems.
Date
1 April 2026
Our reference
2025-005323
26/45
According to Ridetech, the Russian authorities can only request information and ICOs can share the requested information with the Russian authorities via the so-called ‘HSS ICO’. Regardless of Ridetech's unsubstantiated and unverifiable position that Yandex.Taxi LLC and Yandex LLC, as ICOs, possess internal information systems ('IS ICO') and that this system does not grant general and direct access to the data in these internal information systems, the AP maintains that it cannot be ruled out that the Russian authorities in practice possess broader access rights regarding the information systems of Yandex.Taxi LLC and Yandex LLC.
Moreover, Ridetech also addressed in its Transfer Impact Assessment the circumstance that the Russian authorities possess very broad powers of access to personal data and that there is a real risk of abuse of power and arbitrariness in Russia.65 This reflection, recorded by Ridetech itself, supports the AP's judgment. 84. The foregoing means that Ridetech has failed to demonstrate that, in view of the applicable Russian legislation, it has implemented appropriate safeguards to prevent Yandex.Taxi LLC and Yandex LLC from making personal data of Finnish and Norwegian users of the Yango app accessible to the Russian authorities.
85. In view of the foregoing, the DPA is of the opinion that, even after 27 November 2023, Yandex.Taxi LLC and Yandex LLC received personal data of Finnish and Norwegian users of the Yango app without Ridetech providing appropriate safeguards within the meaning of Article 46 of the GDPR.
5.4.3 Enforceable rights and effective remedies
86. Another requirement under Article 46, paragraph 1, of the GDPR that the DPA must assess in the context of appropriate safeguards is whether data subjects have enforceable rights and effective remedies when Ridetech transmits their personal data to Yandex.Taxi LLC and Yandex LLC in Russia. 87. The CJEU has ruled that the transfer of personal data by means of standard clauses depends on the state of the law and practice of the third country concerned (in this case, Russia). According to the CJEU, situations may arise in which the provisions of the standard clauses may be insufficient to ensure the effective protection of the personal data transferred to the third country concerned. This is particularly the case when the law of that third country permits the public authorities of that country to interfere with the rights of the data subjects in relation to those data.66
88. Standard clauses are based on a contract between the controller and the recipient of personal data. They are therefore not binding on the authorities of the third country to which personal data are transferred. It is therefore essential that in the country where the
65 Document 86 accompanying the investigation report, pp. 46-47. 66 CJEU 16 July 2020, ECLI:EU:C:2020:559 (Schrems I), paragraph 126.
Date
1 April 2026
Our reference
2025-005323
27/45
recipient of personal data is established, an independent supervisory authority is present.
67
89. Paragraph 2.4 of this decision states that the Russian Roskomnadzor monitors compliance with privacy regulations. Roskomnadzor is part of the Ministry of Digital
Development, Communications and Mass Media of the Russian Federation. Furthermore, Roskomnadzor is charged with monitoring compliance with the Information Act and the so-called ‘Yarovaya law’. On the basis of the ‘Yarovaya law’, Roskomnadzor can block the provision of services by enterprises that do not comply with said legislation. One of the obligations resting on supervised entities under the ‘Yarovaya law’ is that they must hand over data encryption keys to the Russian authorities upon request. The AP notes that Roskomnadzor is both the supervisory authority for the protection of personal data and the supervisory authority for compliance with the ‘Yarovaya law’, which is anti-terrorism legislation and thereby serves interests that conflict with the interests involved in the protection of personal data.
90. In addition, the European Data Protection Supervisor has conducted an analysis of access to personal data during transfers to countries outside the EEA.68 It was established therein that Roskomnadzor in practice imposes fines or warnings exclusively on private organizations and natural persons69, while Roskomnadzor's powers vis-à-vis government agencies are not explicitly defined. In this context, it is relevant that Roskomnadzor falls under the responsibility of the Ministry of Digital Development, Communications and Mass Media of the Russian Federation. The AP notes that, in the context of the transfer of personal data to Russia, protection against government interference is of essential importance. The AP concludes that Roskomnadzor's independent oversight of government agencies is not guaranteed because, firstly, Roskomnadzor is hierarchically subordinate to the aforementioned ministry; secondly, because Roskomnadzor must implement two conflicting interests (protection of personal data versus anti-terrorism legislation); and thirdly, because Roskomnadzor evidently does not apply its oversight to the protection of personal data against government institutions. Therefore, in the opinion of the AP, it cannot be stated that the rights of data subjects are sufficiently protected by Roskomnadzor. 91. In view of the foregoing, the AP is of the opinion that Roskomnadzor cannot be regarded as an
independent supervisory authority within the meaning of Article 45, paragraph 2, of the GDPR. Consequently,
data subjects do not have enforceable rights and effective remedies, as required by Article 46, paragraph 1, of the GDPR.
67 European Commission decision of 10.7.2023 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on
the adequate level of protection of personal data under the EU-US Data Privacy Framework, para. 58.
68 EDPS, November 2021, ‘Government access to data in third countries’, EDPS/2019/02-13.
69 EDPS, November 2021, ‘Government access to data in third countries’, EDPS/2019/02-13, p.49. Date
1 April 2026
Our reference
2025-005323
28/45
5.5 Final Conclusion
92. The AP has established that Ridetech processes personal data of users of the Yango app from the EEA.
This personal data is transferred to Yandex.Taxi LLC, which, together with Ridetech, acts as a joint controller.
This personal data is furthermore transferred to the processor, Yandex LLC. Both recipients of the personal data are established in Russia.
Therefore, the transfer of personal data of data subjects from the EEA was only permitted if appropriate safeguards were provided and if data subjects had enforceable rights and effective remedies.
In the opinion of the AP, this has not been demonstrated.
93. In the opinion of the AP, Ridetech has not provided appropriate safeguards within the meaning of Article 46 GDPR since at least 23 May 2022. The AP has determined that, at least between 23 May 2022 and 27 November 2023, personal data in encrypted form, together with the corresponding encryption keys, were transferred to Russia without adequate safeguards being provided. Although Ridetech took measures after 27 November 2023, including re-encrypting the personal data and storing the encryption keys within the EEA, in the AP's opinion, these measures are not sufficient to provide an adequate level of protection to data subjects from the EEA.94. In addition, Ridetech has failed to demonstrate that Russian authorities do not have access to personal data of data subjects processed on the servers of Yandex.Taxi LLC and Yandex LLC. Nor do data subjects from the EEA have enforceable rights and effective remedies regarding the transfer of personal data.
95. This leads the DPA to the conclusion that Ridetech has transferred personal data of data subjects from the EEA to a third country that does not guarantee an adequate level of protection. This means that data subjects from the EEA are disadvantaged by this transfer. In view of the foregoing, the DPA is of the opinion that Ridetech has been in violation of Articles 44 and 46 of the GDPR, read in conjunction with Article 5, paragraph 1, point (a), and paragraph 2, of the GDPR, at least from 23 May 2022 to the present.
96. It has neither been argued nor established that Ridetech can rely on the exceptions of Article 49 of the GDPR. 6. Administrative fine
6.1 Power to impose a fine
97. The AP is authorized, pursuant to Article 58, paragraph 2, opening words and (i), in conjunction with Article 83 of the GDPR and
read in conjunction with Article 14, paragraph 3, of the UAVG, to impose an administrative fine. It follows from
the case law of the CJEU that the wording of Article 83, paragraph 2, of the GDPR implies that
infringements of the provisions of the GDPR committed by the controller in a culpable
Date
1 April 2026
Our reference
2025-005323
29/45
—that is to say, infringements committed intentionally or through negligence—may lead to an administrative fine being imposed on
the controller pursuant to that Article.70
98. The DPA has established that Ridetech committed an infringement of Articles 44 and 46 of the GDPR in conjunction with Article 5, paragraph 1, point (a) and paragraph 2, of the GDPR. Ridetech could have known under the GDPR that it should have taken appropriate safeguards for the transmission of personal data to recipients in Russia. Because of this infringement and its seriousness, the DPA sees grounds to
exercise its power to impose an administrative fine. 6.2 Methodology for determining the amount of the fine
99. In its plenary session of 24 May 2023, the EDPB adopted the final text of the
Guidelines 04/2022 on the calculation of administrative fines under the GDPR (hereinafter: the
Guidelines).71 The AP will apply these Guidelines to this case.72
100. The Guidelines on the calculation of administrative fines describe the following method for calculating
administrative fines for infringements of the GDPR:
1. identify which and how many acts and infringements are
subject for assessment;
2. determine the baseline amount for the further calculation of the fine;
3. determine whether there are mitigating or aggravating circumstances that necessitate
an increase or decrease of the fine;
4. determine which maximum amounts apply to the infringements and whether those
maximum amounts are not exceeded as a result of increases applied in previous or
subsequent steps; 5. verify whether the calculated final amount of the fine meets the requirements of
effectiveness, deterrence and proportionality, and, if necessary,
adjust the fine accordingly.
101. These steps are followed successively below.
6.3 Calculation of the fine amount
6.3.1 Step 1: Determining acts and infringements
102. To determine the starting amount of the fine, it must first be considered whether there is one or
multiple sanctionable conduct.
70 CJEU 5 December 2023, ECLI:EU:C:2023:949 (
NVSC) paragraphs 73 and 83; CJEU 5 December 2023, ECLI:EU:C:2023:950 (
Deutsche Wohnen)
paragraph 68 and 76.
71 See also Guidelines 04/2022 for the calculation of administrative fines under the GDPR.
72 See also https://www.autoriteitpersoonsgegevens.nl/actueel/nieuw-boetebeleid-voor-overtredingen-avg
Date
1 April 2026
Our reference
2025-005323
30/45
103. The AP has determined that there is one conduct, namely the transfer of personal data
to recipients in Russia for which an administrative fine will be imposed.
6.3.2 Step 2: Determining the starting amount
104. Subsequently, the AP must determine the starting amount of the fine. This amount forms the
starting point for the further calculation in later steps, in which all relevant facts and
circumstances are taken into account. The base amount is determined on the basis of
three elements:
i) the categorization of the infringements under Article 83, paragraphs four to six, of the GDPR;
ii) the severity of the infringement; and
iii) the turnover of the undertaking.
Re: i) Categorization of the infringements under Article 83, paragraphs four to six, of the GDPR
105. Virtually all obligations of the controller are categorized in the provisions of
Article 83, paragraphs four to six, of the GDPR. The GDPR distinguishes between two types of infringements. On the one hand, the infringements that are sanctionable under Article 83, paragraph 4, of the GDPR, for which a maximum fine of €10 million applies (or in the case of an undertaking, 2% of annual turnover, if higher); on the other hand, the infringements that are sanctionable under Article 83, paragraphs 5 and 6, of the GDPR, for which a maximum fine of €20 million applies (or in the case of an undertaking, 4% of annual turnover, if higher). With this distinction, the legislator has provided an initial indication of the severity of the infringement: the more severe the infringement, the higher the fine.
106. In this case, the DPA may impose an administrative fine of up to €20 million (or in the case of an undertaking, 4% of worldwide annual turnover, if higher). It follows from this categorization that the infringement of these provisions is considered by the legislator (in abstracto) to be serious. Ad ii) Severity of the infringement
107. When determining the severity of the infringement, the AP takes into account the nature, seriousness and duration of the infringement, as well as the intentional or negligent nature of the infringement and the categories of personal data involved.
108. With regard to the nature of the infringement, the AP considers the interest that the infringed provision aims to protect.
The AP finds that Ridetech has not ensured the continuity of the high level of protection under the GDPR regarding the transfer of personal data to a third country. Due to the lack of appropriate safeguards during the period of the infringement, Ridetech improperly transferred personal data to recipients established in Russia. This is despite the fact that Russia has an inadequate level of protection, because Russian authorities can gain access to personal data of data subjects from Norway and Finland on the basis of local legislation
Date
1 April 2026
Our reference
2025-005323
31/45 This infringement constitutes a
direct danger to the right to private life and the right to the protection of personal data as
laid down in Article 7 and Article 8 of the Charter respectively.
109. With regard to the seriousness of the infringement, the DPA takes into account relevant circumstances regarding the
nature, scope and purpose of the processing, the number of data subjects and the (potential) extent of the damage.
110. In this case, the DPA attaches great weight to the nature of the processing because the processing enables
Russian authorities to gain access to personal data of data subjects from
Norway and Finland. The DPA also attaches great weight to the scope of the processing because
it concerns cross-border processing of personal data to a third country without
appropriate safeguards having been put in place for this. Furthermore, the DPA attaches neutral weight to the purpose of the
processing because it has not been established in what way the personal data transferred to Russia serve
the core activities of Ridetech in Norway and Finland or the improvement of the
software of the Yango app. 111. Furthermore, the AP takes into account that the personal data of tens of thousands of data subjects in Norway and Finland have been transferred to recipients in Russia.
112. The AP also considers that the infringement took place at least since May 23, 2022, and that the infringement is still ongoing. The violation has therefore been of long duration.
113. Finally, the AP takes into account that the processing in question involves many categories of personal data (see paragraphs 20 and 20). In the processing of personal data of drivers, social security numbers and photos were also part of the processing. These are sensitive personal data that require extra protection.
Ad iii) Turnover of the enterprise
114. The AP relates a fair starting amount for the fine to the size of the enterprise. The size of the enterprise is determined on the basis of turnover. The starting amount for a small enterprise is lower, and the starting amount increases as the enterprise's turnover is higher. If an undertaking has a turnover of more than € 500 million, the amount of the fine is determined as a percentage of the undertaking's annual turnover.73 Consequently, the size and turnover of the undertaking are already factored into the amount of the fine, so that the starting amount does not require adjustment on that ground.
115. As stated in Recital 150 of the GDPR, when imposing a fine on an undertaking, the “undertaking” must be regarded as an undertaking within the meaning of Articles 101 and 102 of the Treaty on the Functioning of the European Union. It follows from settled case law of the CJEU that
73 From an annual turnover of € 500 million, 4% of the annual turnover exceeds € 20 million, so that this percentage must be taken into account as the maximum fine (Article 83, paragraph 5, opening words, of the GDPR). Date
1 April 2026
Our reference
2025-005323
32/45
an undertaking is any unit that carries out an economic activity, regardless of its legal form and the
manner in which it is financed. It therefore concerns the economic unit of the undertaking and not
the legal entities within it. Various companies or entities within the same
economic unit can therefore together constitute an undertaking within the meaning of the aforementioned provisions.116. Until it was dissolved on 24 October 2025, Ridetech was a wholly owned subsidiary of MLU B.V., which in turn (via Y.E. Holding Limited from the United Arab Emirates and Y.E. Holding d.o.o. Beograd from Serbia) is a subsidiary of the Russian Consortium First, which is listed on the Moscow Stock Exchange via IPJSC YANDEX. The AP considers these companies to be part of the same economic unit for the purposes of Article 83 of the GDPR.
117. IPJSC YANDEX has published the annual accounts for 2024 on its website.74 According to that publication, the company's global turnover for 2024 amounts to 1,094.6 billion Russian Rubles. That corresponds to € 12.08 billion.75
118. Pursuant to Article 83, paragraph 5, of the GDPR, the maximum fine amounts to 4% of annual turnover.
Based on an annual turnover of € 12.08 billion, the maximum fine for the infringement amounts to € 483.2 million.
119. The assessment of the circumstances and factors cited above determines the overall severity of the infringement committed by Ridetech. This involves a thorough assessment of the specific circumstances of the case, in which all circumstances must be viewed in conjunction.
120. In view of what has been considered under i) and ii), the AP is of the opinion that the level of severity of the infringement must be qualified as “high”. According to the Guidelines, for infringements with a
high level of severity, the starting amount must be determined at a point between 20% and 100%
of the maximum fine of, in this case, € 483.2 million. This corresponds to an amount between € 96.6 million and € 483.2 million. As a general rule, the more serious the infringement is within its own
category, the higher the starting amount will be.
121. The AP is of the opinion that, in view of the described circumstances, the infringement is serious.
122. Based on the categorization of the infringement, the severity of the infringement, and the turnover of the undertaking,
the AP sets the starting amount for the present violation at € 100 million.
6.3.3 Step 3: Assessing other relevant circumstances
Next, the AP must determine whether, in the circumstances of the case, there is reason to set the fine
higher or lower than the starting amount determined above. The circumstances to be taken into account are listed in Article 83, paragraph 2, opening words and points a through k, GDPR. The circumstances mentioned in that
74 Available via Financials 2024 | Investor Relations | Yandex
75 Exchange rate as of March 31, 2026: 100 Russian Rubles = € 1.07.
Date
April 1, 2026
Our reference
2025-005323
33/45
provision must each be considered only once. In the previous step, the
AP has already taken into account the severity of the infringement (part a), the intentional or negligent
nature of the infringement (part b) and the categories of personal data (part g). Consequently, parts c through f and h through k remain. 123. The only applicable circumstance is the manner in which the DPA became aware of the infringement, in particular whether, and if so to what extent, the controller reported the infringement (part h). In this case, Ridetech did not report the infringements itself, but the DPA became aware of the infringement in question via the Norwegian and Finnish privacy supervisory authorities. However, according to the Guidelines, this is assessed as “neutral” and therefore has no consequences for the amount of the fine to be imposed.
6.3.4 Step 4: relevant maximum amounts
124. In view of the turnover of Ridetech’s parent company, a
maximum fine of 4% of the company’s worldwide annual turnover will apply to the infringement found. The annual turnover
amounts to € 12.08 billion, so the maximum fine for the infringement amounts to € 483.2 million. 125. Based on the above considerations, the AP sets the fine amount for the observed violation at €100 million. This is below the statutory maximum, so that no exceeding of it occurs.
6.3.5 Step 5: Assessment of requirements of effectiveness, proportionality, and deterrence
126. Finally, the AP assesses whether the fine is effective, proportionate, and deterrent. Also pursuant to Articles 3:4 and 5:46, paragraph 2, of the General Administrative Law Act, the administrative fine may not lead to a disproportionate outcome, given the circumstances of the specific case. This is also laid down in Article 49 of the Charter.
127. As described in the Guidelines, the imposition of a fine can be considered effective if it achieves the objective for which it was imposed. That objective may lie in, on the one hand, punishing unlawful conduct and, on the other hand, promoting compliance with the applicable regulations. 128. Having regard to all factors referred to in Article 83, paragraph 2, of the GDPR, as assessed above, the DPA is of the opinion that imposing an administrative fine of €100 million under these circumstances is proportionate, effective, and deterrent. The violation can be attributed to Ridetech.
Date
1 April 2026
Our reference
2025-005323
34/45
7. Processing prohibition
129. The DPA decides, pursuant to Article 58, paragraph 2, opening words and (f), of the GDPR, to impose a prohibition on MLU B.V. effective from the date of this decision. That prohibition entails that MLU B.V. is not permitted to allow the transfer of personal data of Norwegian and Finnish users of the Yango app to the recipients in Russia.
130. The purpose of the processing prohibition is to terminate the ongoing violation. For the sake of completeness, the AP points out that failure to comply with the processing prohibition can be fined independently.
The AP is authorized to do so pursuant to Article 83, paragraph 5, opening words and (e), of the GDPR.
8. Decision
- The AP imposes an administrative fine of € 100,000,000.76 on MLU B.V., which assumed all rights and obligations of Ridetech following the dissolution of Ridetech, for violation of Articles 44 and 46 of the GDPR in conjunction with Article 5, paragraph 1, (a) and paragraph 2, of the GDPR, in the period from 23 May 2022 up to and including the present.
- The AP imposes a processing prohibition on MLU B.V., which assumed all rights and obligations of Ridetech following the dissolution of Ridetech, effective immediately, for the transfer of personal data of Norwegian and Finnish users of the Yango app to recipients in Russia. Sincerely,
Dutch Data Protection Authority,
W.G.
A. Wolfsen, Chairman
76 The AP will hand over the aforementioned claim to the Central Judicial Collection Agency (CJIB).
Date
1 April 2026
Our reference
2025-005323
35/45
Legal remedies clause
If you do not agree with this decision, you may submit a notice of objection to the Dutch Data Protection Authority digitally or on paper within six weeks of the date of dispatch of the
decision. Pursuant to
Article 38 of the UAVG, the submission of a notice of objection suspends the effect of the decision to
impose the administrative fine. For submitting a digital objection, see
www.autoriteitpersoonsgegevens.nl, under the heading Contact, item “Objection or complaint about the AP”.77
The address for submission on paper is:
Dutch Data Protection Authority
P.O. Box 93374
2509 AJ The Hague. Write ‘Awb-bezwaar’ on the envelope and put ‘bezwaarschrift’ in the title of your letter.
In your letter of objection, write at least:
- your name and address;
- the date of your letter of objection;
- the reference number mentioned in this letter (case number), or enclose a copy of this decision;
- the reason(s) why you disagree with this decision;
- your signature.
77 The direct URL is <https://www.autoriteitpersoonsgegevens.nl/over-de-autoriteit-persoonsgegevens/bezwaar-maken>.
Date
1 April 2026
Our reference
2025-005323
36/45
Appendix 1
General Data Protection Regulation
Article 4
Definitions
For the purposes of this Regulation, the following definitions apply:
1) “personal data”: any information relating to an identified or identifiable natural
person (“the data subject”); A natural person is considered identifiable if they can be identified directly or indirectly, in particular by means of an identifier such as a name, an identification number, location data, an online identifier, or one or more elements characteristic of the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person; 2) processing”: any operation or set of operations performed on personal data
or on a set of personal data, whether or not performed by automated means, such as
collecting, recording, organizing, structuring, storing, updating or modifying, retrieving, consulting,
using, providing by transmission, disseminating or otherwise making available,
aligning or combining, restricting, erasing or destroying data;
3) “restriction of processing”: marking stored personal data with the aim of
restricting future
processing thereof
4) “profiling”: any form of automated processing of personal data whereby certain personal aspects of a natural person are
evaluated on the basis of personal data, in particular with the aim of analyzing or predicting his professional performance, economic situation, health,
personal preferences, interests, reliability, behaviour, location or movements;
5) “pseudonymisation”: the processing of personal data in such a way that the personal data can no longer be linked to a specific data subject without the use of additional data, provided that these additional data are kept separately and technical and organisational measures are taken to ensure that the personal data are not linked to an identified or identifiable natural person;
6) “file”: any structured set of personal data that is accessible according to certain criteria, regardless of whether this set is centralised or decentralised or distributed on functional or geographical grounds; 7) controller”: a natural or legal person, a public authority, agency or other body which, alone or jointly with others, determines the purpose of and
Date
1 April 2026
Our reference
2025-005323
37/45
the means of processing personal data; where the purposes of and the means of such processing are determined by Union law or Member State law, it may be specified therein who the controller is or according to which criteria it is designated;
8) “processor”: a natural or legal person, a public authority, agency or other body which processes personal data on behalf of the controller;
9) “recipient”: a natural or legal person, a public authority, agency or other body, whether or not a third party, to whom personal data are provided.However, public authorities that may receive personal data in the context of a specific investigation
in accordance with Union law or Member State law shall not be considered recipients; the processing
of those data by those public authorities is consistent with the data protection rules applicable to the
processing purpose concerned;
10) third party”: a natural or legal person, a public authority, an agency or another
body, other than the data subject, the controller, the processor, or the persons authorised
to process the personal data under the direct authority of the controller or the processor;
11) consent” of the data subject: any freely given, specific, informed and unambiguous
expression of will by which the data subject accepts the processing of personal data concerning him or her by means of a statement or an unambiguous active
act;
12) “personal data breach”: a security breach that accidentally or unlawfully results in the destruction, loss, alteration, or unauthorized disclosure of, or unauthorized access to, transmitted, stored, or otherwise processed data;
13) “genetic data”: personal data relating to the inherited or acquired genetic characteristics of a natural person which provide unique information about the physiology or health of that natural person and which, in particular, result from an analysis of a biological sample from that natural person;
14) “biometric data”: personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person which enables or confirms the unique identification of that natural person, such as facial images or fingerprint data; 15) “health data”: personal data relating to the physical or mental
health of a natural person, including data on health services provided
which provide information about his state of health;
16) “main establishment”:
a) with regard to a controller having establishments in more than one
Member State, the place where its central administration in the Union is situated, unless decisions on
the purposes of and the means for the processing of personal data are taken
in another establishment of the controller which is also situated in the Union
Date
1 April 2026
Our reference
2025-005323
38/45
and which is also authorised to implement those decisions, in which case the establishment where
those decisions are taken shall be regarded as the main establishment;
b) with regard to a processor which has establishments in more than one Member State, the place where its central administration in the Union is situated or, where the processor has no central administration in the Union, the establishment of the processor in the Union where the principal processing activities within the framework of the activities of an establishment of the processor take place, insofar as specific obligations apply to the processor under this Regulation;
17) “representative”: a natural or legal person established in the Union who has been designated in writing by the controller or the processor pursuant to Article 27 to represent the controller or the processor in connection with their respective obligations under this Regulation;
18) “undertaking”: a natural or legal person which carries out an economic activity, regardless of its legal form, including partnerships and sole proprietorships or associations which regularly carry out an economic activity; 19) “group”: an undertaking exercising control and the undertakings over which that control is exercised;
20) “binding corporate rules”: a policy on the protection of personal data which a controller or processor established in the territory of a Member State applies to the transfer or series of transfers of personal data to a controller or processor in one or more third countries within a group or a grouping of undertakings carrying out a joint economic activity;
21) “supervisory authority”: an independent public authority established by a Member State pursuant to Article 51;
22) “concerned supervisory authority”: a supervisory authority involved in the processing of personal data because:
a) the controller or processor is established in the territory of the Member State of that supervisory authority;
b) the data subjects residing in the Member State of that supervisory authority are or are likely to be substantially affected by the processing; or
c) a complaint has been lodged with that supervisory authority;
23) “cross-border processing”:
a) processing of personal data in the context of the activities of establishments in more than
one Member State of a controller or processor in the Union established in more than
one Member State; or
Date
1 April 2026
Our reference
2025-005323
39/45
b) processing of personal data in the context of the activities of one establishment of a controller or processor in the Union, as a result of which data subjects in more than one Member State are or are likely to be substantially affected;
24) “relevant and reasoned objection”: an objection to a draft decision regarding the existence of an infringement of this Regulation or regarding whether the proposed measure concerning the controller or processor is consistent with this Regulation, which clearly demonstrates the extent of the risks the draft decision poses to the fundamental rights and freedoms of the data subjects and, where applicable, to the free movement of personal data within the Union;
25) “information society service”: a service as defined in Article 1(1)(b) of Directive (EU) 2015/1535 of the European Parliament and of the Council;
26) “international organisation”: an organisation and the public international law bodies or other bodies falling under it established by or pursuant to an agreement between two or more countries. Article 5
1. Personal data must:
a) be processed in a manner that is lawful, fair and transparent with regard to the data subject
“lawfulness, fairness and transparency”);
b) be collected for specified, expressly defined and legitimate purposes and
may not subsequently be processed in a manner incompatible with those purposes;
further processing for archiving purposes in the public interest, scientific or historical
research or statistical purposes shall not be considered incompatible with
the original purposes in accordance with Article 89(1) (“purpose limitation”);
c) be adequate, relevant and limited to what is necessary for the purposes for which they
are processed (“data minimization”);
d) be accurate and, where necessary, updated; all reasonable measures must be taken to
without delay erase or rectify the personal data which, having regard to the purposes for which they are processed, are inaccurate (“accuracy”);
e) be kept in a form that allows the data subjects to be identified for no longer than is necessary for
the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data are processed solely for
archiving purposes in the public interest, scientific or historical research or statistical purposes
in accordance with Article 89(1), provided that the appropriate
technical and organisational measures required by this Regulation are taken to protect the rights and freedoms of the
data subject (“storage limitation”); Date
1 April 2026
Our reference
2025-005323
40/45
f) are processed by taking appropriate technical or organisational measures in such a way
that adequate security is ensured, and that they are protected, inter alia,
against unauthorized or unlawful processing and against accidental loss, destruction or
damage (“integrity and confidentiality”).
2. The controller is responsible for compliance with paragraph 1 and can demonstrate
(“accountability”).
Article 44
Personal data which are processed or which are intended to be processed after transfer to a third country or an
international organisation may only be transferred if, without prejudice to
the other provisions of this Regulation, the controller and the processor have complied with the conditions laid down in
this chapter; this also applies to further transfers of
personal data from the third country or an international organisation to another third country or another
international organisation. All provisions of this Chapter shall be applied so as not to undermine the level of protection guaranteed to natural persons by this Regulation.
Article 46
1. In the absence of a decision pursuant to Article 45(3), a transfer of personal data to a third country or an international organisation by a controller or processor may only take place provided that it offers appropriate safeguards and that data subjects have enforceable rights and effective remedies.
2. The appropriate safeguards referred to in paragraph 1 may be provided by the following instruments, without requiring specific authorisation from a supervisory authority:
a) a legally binding and enforceable instrument between public authorities or bodies;
b) binding corporate rules in accordance with Article 47;
c) standard data protection clauses adopted by the Commission pursuant to the examination procedure referred to in Article 93(2); d) standard data protection clauses adopted by a supervisory authority and approved by the Commission in accordance with the examination procedure referred to in Article 93(2);
e) a code of conduct approved in accordance with Article 40, together with binding and enforceable commitments by the controller or processor in the third country to apply appropriate safeguards, including for the rights of data subjects; or
f) a certification mechanism approved in accordance with Article 42, together with binding and enforceable commitments by the controller or processor in the third country to apply appropriate safeguards, including for the rights of data subjects.3. Subject to the authorization of the competent supervisory authority, the appropriate safeguards referred to in paragraph 1 may also be provided by, in particular: a) contractual provisions between the
Date
1 April 2026
Our reference
2025-005323
41/45
controller or processor and the controller, processor or recipient of the personal data in the third country or international organisation; or b) provisions to be included in administrative arrangements between public authorities or bodies, including enforceable and effective rights of data subjects.
4. The supervisory authority shall apply the consistency mechanism referred to in Article 63 in the cases referred to in paragraph 3
of this Article. 5. Authorisations granted by a Member State or a supervisory authority pursuant to Article 26(2) of Directive 95/46/EC shall remain valid until they are amended, replaced or withdrawn by that supervisory authority, if necessary. Decisions adopted by the Commission pursuant to Article 26(4) of Directive 95/46/EC shall remain in force until they are amended, replaced or withdrawn by a Commission decision adopted in accordance with paragraph 2 of this Article, if necessary.
Article 58
1. Each supervisory authority shall have all the following investigative powers to:
a) order the controller, the processor and, where appropriate, the representative of the controller or processor to provide all information required for the performance of its tasks;
b) conduct investigations in the form of data protection checks;
c) review certifications issued in accordance with Article 42(7); d) to notify the controller or the processor of an alleged infringement of this Regulation; e) to obtain access from the controller and the processor to all personal data and all information necessary for the performance of its tasks; and f) to obtain access to all business premises of the controller and the processor, including all data processing equipment and means, in accordance with Union or Member State procedural law.
2. Each supervisory authority shall have all the following powers to take corrective measures:
a) to warn the controller or the processor that the intended processing operations are likely to infringe provisions of this Regulation;
b) to reprimand the controller or the processor when processing operations have infringed provisions of this Regulation;
c) to order the controller or the processor to comply with the data subject's requests to exercise his or her rights under this Regulation; d) order the controller or the processor, where appropriate, to bring processing operations into conformity with the provisions of this Regulation in a manner and within a specified period;
Date 1 April 2026
Our reference 2025-005323 42/45
e) order the controller to notify the data subject of a personal data breach;
f) impose a temporary or permanent restriction on processing, including a ban on processing;
g) order the rectification or erasure of personal data or the restriction of processing pursuant to Articles 16, 17 and 18, as well as the notification of such operations to recipients to whom the personal data have been disclosed, in accordance with Article 17(2) and Article 19; h) withdraw a certification or order the certification body to withdraw a certification issued pursuant to Articles 42 and 43, or to order the certification body not to issue a certification if the certification requirements are no longer met;
i) depending on the circumstances of each case, in addition to or instead of the measures referred to in this paragraph, impose an administrative fine pursuant to Article 83; and
j) order the suspension of data flows to a recipient in a third country or to an international organisation.
3. Each supervisory authority shall have full authorisation and advisory powers to:
a) provide the controller with advice in accordance with the prior consultation procedure of Article 36;
b) provide advice, on its own initiative or at the request of the national parliament, the government of the Member State, or, in accordance with Member State law, other institutions and bodies as well as the public, on matters relating to the protection of personal data; c) to authorise processing as referred to in Article 36, paragraph 5, if such prior authorization is required by Member State law;
d) to give advice on and approve the draft codes of conduct in accordance with Article 40, paragraph 5;
e) to accredit certification bodies in accordance with Article 43;
f) to issue certifications and approve certification criteria in accordance with Article 42, paragraph 5;
g) to adopt the standard data protection clauses referred to in Article 28, paragraph 8, and Article 46, paragraph 2, point d);
h) to authorise the contractual clauses referred to in Article 46, paragraph 3, point a);
i) to authorise the administrative arrangements referred to in Article 46, paragraph 3, point b); j) to approve binding corporate rules in accordance with Article 47.
4. Appropriate safeguards shall apply to the exercise of the powers conferred on the supervisory authority under this Article, including effective remedies and a fair administration of justice, as laid down in Union law and Member State law in accordance with the Charter.
Date
1 April 2026
Our reference
2025-005323
43/45
5. Each Member State shall provide by law that its supervisory authority is empowered to notify the judicial authorities of infringements of this Regulation and, where appropriate, to institute legal proceedings or otherwise take legal action in order to ensure compliance with the provisions of this Regulation.
6. Each Member State may provide by law that its supervisory authority has additional powers in addition to the powers referred to in paragraphs 1, 2 and 3. The exercise of those powers shall not prejudice the effective operation of Chapter VII. Article 83
1. Each supervisory authority shall ensure that the administrative fines imposed under this Article for the infringements of this Regulation referred to in paragraphs 4, 5 and 6 are effective, proportionate and dissuasive in each case.
2. Administrative fines shall be imposed, depending on the circumstances of the specific case, in addition to or instead of the measures referred to in Article 58, paragraph 2, points (a) to (h) and (j). When deciding on the decision to impose an administrative fine and on the amount thereof, due account shall be taken of the following for each specific case:
a) the nature, seriousness and duration of the infringement, having regard to the nature, scope or purpose of the processing in question as well as the number of data subjects affected and the extent of the damage suffered by them;
b) the intentional or negligent nature of the infringement; c) the measures taken by the controller or processor to limit the damage suffered by data subjects;
d) the extent to which the controller or processor is responsible in view of the technical and organisational measures implemented by it in accordance with Articles 25 and 32;
e) previous relevant infringements by the controller or processor;
f) the extent to which cooperation with the supervisory authority has taken place to remedy the infringement and limit its potential negative consequences;
g) the categories of personal data to which the infringement relates;
h) the manner in which the supervisory authority became aware of the infringement, in particular whether, and if so to what extent, the controller or processor reported the infringement;
i) compliance with the measures referred to in Article 58(2), insofar as they have previously been taken with regard to the controller or processor in question concerning the same matter; Date
1 April 2026
Our reference
2025-005323
44/45
j) adherence to approved codes of conduct pursuant to Article 40 or to approved
certification mechanisms pursuant to Article 42; and
k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as
financial gains made, or losses avoided, whether or not resulting directly from the infringement.
3. If a controller or processor intentionally or negligently infringes several
provisions of this Regulation in relation to the same or related processing activities, the total fine shall not exceed that for the most serious infringement. 4. Infringements of the following provisions shall be subject, in accordance with paragraph 2, to administrative fines of up to EUR 10,000,000 or, for an undertaking, up to 2% of the total worldwide annual turnover in the preceding financial year, if this figure is higher: a) the obligations of the controller and the processor in accordance with Articles 8, 11, 25 to 39, and 42 and 43; b) the obligations of the certification body in accordance with Articles 42 and 43; c) the obligations of the supervisory authority in accordance with Article 41, paragraph 4.
5. Infringements of the following provisions shall be subject to administrative fines of up to EUR 20,000,000 in accordance with paragraph 2 or, for an undertaking, up to 4% of the total worldwide annual turnover in the preceding financial year, if this figure is higher:
a) the basic principles regarding processing, including the conditions for consent, in accordance with Articles 5, 6, 7 and 9;
b) the rights of data subjects in accordance with Articles 12 to 22;
c) transfers of personal data to a recipient in a third country or an international organisation in accordance with Articles 44 to 49;
d) all obligations under law established by the Member States pursuant to Chapter IX; e) non-compliance with an order or a temporary or permanent restriction on processing or a suspension of
data flows by the supervisory authority in accordance with Article 58, paragraph 2, or failure to grant
access in violation of Article 58, paragraph 1.6. Non-compliance with an order of the supervisory authority referred to in Article 58, paragraph 2, shall be subject, in accordance with paragraph 2 of this Article, to administrative fines of up to EUR 20,000,000 or, for an undertaking, to 4% of the total worldwide annual turnover in the preceding financial year, if this figure is higher.
7. Without prejudice to the powers of the supervisory authorities to take corrective measures in accordance with Article 58, paragraph 2, each Member State may adopt rules regarding the question whether and to what extent administrative fines may be imposed on public authorities and public bodies established in that Member State.
8. The exercise by the supervisory authority of its powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union law and Member State law, including an effective remedy and a fair administration of justice. Date
1 April 2026
Our reference
2025-005323
45/45
9. Where the legal system of the Member State does not provide for administrative fines, this Article may be applied
in such a way that fines are initiated by the competent supervisory authority
and imposed by competent national courts, ensuring that these remedies
are effective and have the same effect as the
administrative fines imposed by supervisory authorities. The fines shall in any event be effective, proportionate and dissuasive.
Those Member States shall notify the Commission, no later than 25 May 2018, of the legislative provisions they adopt pursuant to
this paragraph, as well as any subsequent amendments thereto and any
amending legislation affecting them. Implementing Act General Data Protection Regulation
Article 14
Tasks and powers of the Data Protection Authority
[…]
3. In the event of a violation of the provisions of Article 83, paragraphs four, five or six, of the Regulation, the Data Protection Authority may impose an administrative fine not exceeding the amounts referred to in those paragraphs.
- ↑ See C‑311/18, Schrems I, margin 126




