You are assuming you (or I) know the safeguards they already have in place. For example, if they have an audit trail for anyone that access this data or if they have independent audits on data access, it could be sufficient. Both of these are norms at major corporations. I am not privy to the specifics of what Uber has in place beyond hearing that they have controls in place that are industry norms.