France France CNIL GDPR enforcement Big Tech

The €825 Million Uber Fine Shows GDPR's Automated-Decision Rule Has Teeth — But the Penalty Is Out of Proportion to the Fix

Dutch and French regulators fined Uber nearly €825M for auto-deactivating drivers without human review, testing GDPR Article 22's real-world limits.

Uber's €825M GDPR Penalty, By the Numbers People of Internet Research · France €824.99M Total fine imposed Second-largest GDPR fine ever, aft… ~1.85% Share of global revenue Nearly half the statutory 4% GDPR … 170+ Drivers in original complaint French drivers represented by La L… €300M combined Prior related Uber fines €10M (Dec 2023, driver notice fail… peopleofinternet.com
Uber's €825M GDPR Penalty, By the Numb… People of Internet Research · France €824.99M Total fine imposed ~1.85% Share of global revenue 170+ Drivers in original complai… €300M combined Prior related Uber fines peopleofinternet.com

Key Takeaways

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens), working with France's CNIL, fined Uber €824,990,000 on August 21, 2026 for running driver account deactivations through automated systems with no meaningful human being in the loop — a direct violation of Article 22 of the GDPR, which bars decisions "based solely on automated processing" that produce legal or similarly significant effects on a person. It is the second-largest GDPR fine in the regulation's history, behind only the €1.2 billion Meta received in 2023, and it turns a provision many compliance teams treated as boilerplate into one of the most consequential rules on the books.

What Uber actually did

According to CNIL's published account, between 2018 and 2022 Uber's fraud-detection software would flag "suspicious" driving patterns — detours, unusual routing — and temporarily suspend the associated account. Separately, drivers whose customer ratings fell below a threshold could be permanently deactivated. Both processes ran without a human meaningfully reviewing the underlying decision before it took effect. For a driver, deactivation meant an immediate, total loss of income on a platform many depend on as their sole livelihood, with no chance to contest the call before it hit their bank balance.

The case did not start in the Netherlands. It began when La Ligue des droits de l'Homme, a French civil liberties group, filed a collective complaint with CNIL in 2020 on behalf of more than 170 Uber drivers, later supplemented in 2021. Because Uber's EU headquarters sits in the Netherlands, jurisdiction under GDPR's one-stop-shop mechanism fell to the Dutch authority — but CNIL stayed embedded throughout, according to its own release, "cooperating closely" on investigation and evidence review. The fine is a genuine cross-border product, and CNIL is treating it as a template for future joint Article 22 cases rather than a one-off.

The steelman: why this fine is not regulatory theater

Article 22 exists because algorithmic decisions at platform scale can be effectively unappealable in practice, even when a formal appeals channel exists on paper. A driver flagged by a fraud model has no way to interrogate the model's logic, and a rating-based deactivation triggered automatically removes any window to intervene before the harm occurs. Regulators are right that "gig" platforms sit at the sharpest edge of this problem: the people affected are economically dependent on the platform, often lack the resources to litigate, and the decision-to-harm gap is measured in seconds, not weeks. The Dutch and French authorities are not inventing a novel theory — Article 22 has been law since 2018, and Uber has already been fined twice by CNIL and the Dutch DPA on related issues (a €10 million CNIL fine in December 2023 for failing to properly inform drivers, and a €290 million Dutch fine in July 2024 over unlawful data transfers). A company operating a compliance-sensitive business model at Uber's scale had ample notice that automated deactivation without human review was a live legal risk.

Where the fine overshoots the harm

That said, €825 million — about 1.85% of Uber's 2025 global revenue, nearly half the statutory 4% ceiling — is calibrated closer to Meta's systemic, years-long, knowingly-unlawful data-transfer violations than to a fixable process defect. Uber's public response calls the fine "disproportionate" and notes it has already rebuilt its deactivation pipeline to include human review and a driver appeals process; the company is appealing, and the penalty is suspended pending that appeal. The proportionality question is legitimate: GDPR fines are supposed to be effective, dissuasive, and proportionate, not simply as large as the statute allows because the regulator can reach for the ceiling. A fine at this scale, applied to a violation that is straightforwardly remediable through engineering and process changes Uber says it has already made, risks looking punitive rather than corrective — and gives every platform operating automated moderation, ranking, or account-management systems in Europe a strong incentive to over-lawyer every automated touchpoint rather than to build genuinely better appeals processes.

The pattern to watch

This fine lands alongside a broader CNIL enforcement wave — the regulator fined Google €325 million and Shein €150 million in September 2025 over cookie-consent violations — and France has become, per the DLA Piper GDPR tracker, one of only two jurisdictions (with Ireland) to cross €1 billion in cumulative GDPR fines. The Uber case sets a specific, exportable template: any platform using automated account, ranking, or eligibility decisions against workers or users now has a concrete, high-dollar precedent for what "solely automated" means and what it costs to get it wrong. The compliance answer — genuine human review with authority to overturn the algorithm, not a rubber-stamp reviewer — is achievable and proportionate. The fine size attached to teaching that lesson is the part regulators should revisit.

Sources & Citations

  1. CNIL: Automated decisions — Uber fined nearly €825 million
  2. CNIL (FR): Décisions automatisées — sanction contre UBER
  3. CNIL: Google fined €325 million over cookies
  4. VinciWorks: A computer cut off their income — Uber's €825m GDPR fine
  5. Dastra: €825 million fine — Uber sanctioned for automated decision-making