The Dutch Data Protection Authority (Autoriteit Persoonsgegevens), working with France's CNIL, fined Uber €824,990,000 on August 21, 2026 for running driver account deactivations through automated systems with no meaningful human being in the loop — a direct violation of Article 22 of the GDPR, which bars decisions "based solely on automated processing" that produce legal or similarly significant effects on a person. It is the second-largest GDPR fine in the regulation's history, behind only the €1.2 billion Meta received in 2023, and it turns a provision many compliance teams treated as boilerplate into one of the most consequential rules on the books.
What Uber actually did
According to CNIL's published account, between 2018 and 2022 Uber's fraud-detection software would flag "suspicious" driving patterns — detours, unusual routing — and temporarily suspend the associated account. Separately, drivers whose customer ratings fell below a threshold could be permanently deactivated. Both processes ran without a human meaningfully reviewing the underlying decision before it took effect. For a driver, deactivation meant an immediate, total loss of income on a platform many depend on as their sole livelihood, with no chance to contest the call before it hit their bank balance.
The case did not start in the Netherlands. It began when La Ligue des droits de l'Homme, a French civil liberties group, filed a collective complaint with CNIL in 2020 on behalf of more than 170 Uber drivers, later supplemented in 2021. Because Uber's EU headquarters sits in the Netherlands, jurisdiction under GDPR's one-stop-shop mechanism fell to the Dutch authority — but CNIL stayed embedded throughout, according to its own release, "cooperating closely" on investigation and evidence review. The fine is a genuine cross-border product, and CNIL is treating it as a template for future joint Article 22 cases rather than a one-off.
The steelman: why this fine is not regulatory theater
Article 22 exists because algorithmic decisions at platform scale can be effectively unappealable in practice, even when a formal appeals channel exists on paper. A driver flagged by a fraud model has no way to interrogate the model's logic, and a rating-based deactivation triggered automatically removes any window to intervene before the harm occurs. Regulators are right that "gig" platforms sit at the sharpest edge of this problem: the people affected are economically dependent on the platform, often lack the resources to litigate, and the decision-to-harm gap is measured in seconds, not weeks. The Dutch and French authorities are not inventing a novel theory — Article 22 has been law since 2018, and Uber has already been fined twice by CNIL and the Dutch DPA on related issues (a €10 million CNIL fine in December 2023 for failing to properly inform drivers, and a €290 million Dutch fine in July 2024 over unlawful data transfers). A company operating a compliance-sensitive business model at Uber's scale had ample notice that automated deactivation without human review was a live legal risk.
Where the fine overshoots the harm
That said, €825 million — about 1.85% of Uber's 2025 global revenue, nearly half the statutory 4% ceiling — is calibrated closer to Meta's systemic, years-long, knowingly-unlawful data-transfer violations than to a fixable process defect. Uber's public response calls the fine "disproportionate" and notes it has already rebuilt its deactivation pipeline to include human review and a driver appeals process; the company is appealing, and the penalty is suspended pending that appeal. The proportionality question is legitimate: GDPR fines are supposed to be effective, dissuasive, and proportionate, not simply as large as the statute allows because the regulator can reach for the ceiling. A fine at this scale, applied to a violation that is straightforwardly remediable through engineering and process changes Uber says it has already made, risks looking punitive rather than corrective — and gives every platform operating automated moderation, ranking, or account-management systems in Europe a strong incentive to over-lawyer every automated touchpoint rather than to build genuinely better appeals processes.
The pattern to watch
This fine lands alongside a broader CNIL enforcement wave — the regulator fined Google €325 million and Shein €150 million in September 2025 over cookie-consent violations — and France has become, per the DLA Piper GDPR tracker, one of only two jurisdictions (with Ireland) to cross €1 billion in cumulative GDPR fines. The Uber case sets a specific, exportable template: any platform using automated account, ranking, or eligibility decisions against workers or users now has a concrete, high-dollar precedent for what "solely automated" means and what it costs to get it wrong. The compliance answer — genuine human review with authority to overturn the algorithm, not a rubber-stamp reviewer — is achievable and proportionate. The fine size attached to teaching that lesson is the part regulators should revisit.