Didi fined for over-collecting personal data of users
The Cyberspace Administration of China fined Didi Global Inc. for violating data protection laws. The investigation found that Didi had over-collected personal data from passengers and drivers, including facial recognition, location, and clipboard information, totaling billions of records. The violations began in 2015 and continued until the investigation in 2021. Didi was ordered to pay a penalty and correct its practices.
- Date it happened
- 2021-07-01
- Organisation involved
- 滴滴全球股份有限公司 (Didi Global Inc.)
- Product, system or model
- Didi ride-hailing apps
This incident was imported from cac.gov.cn. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.