The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, or AP) announced on 21 August 2026 that it has fined Uber €824,990,000 — roughly $966 million — for running a driver-deactivation system that let software, not people, decide when a driver stopped earning. Between 2018 and 2022, the AP found, Uber tracked driving behavior and customer ratings and automatically triggered account deactivations when those systems flagged suspected fraud or ratings judged too low: temporary suspension for fraud flags, permanent removal for persistent low scores, with no human reviewer in the loop and no adequate disclosure to drivers that a machine had made the call (Autoriteit Persoonsgegevens). It is now the second-largest fine ever issued under the GDPR, trailing only Ireland's €1.2 billion penalty against Meta in 2023 for unlawful EU–US data transfers (Insurance Journal / Reuters).
What the AP actually found
The legal theory is narrow: Article 22 of the GDPR bars decisions "based solely on automated processing" that produce legal or similarly significant effects on a person, unless an exception applies and meaningful human safeguards exist. Losing your income on a platform you depend on clearly counts as "significantly affecting" someone. The AP concluded Uber's fraud- and rating-based deactivation pipeline crossed that line, and separately that Uber failed to meet its transparency duties — drivers were not told, in terms they could act on, that automated decision-making was determining their livelihood (ppc.land).
The case did not start in the Netherlands. In June 2021, the Ligue des droits de l'Homme filed a complaint with France's CNIL on behalf of 171 VTC drivers who said they'd been banned by "strictly identical, automatically generated messages" with no real avenue to contest the decision (Business & Human Rights Resource Centre). Because Uber's EU headquarters sits in the Netherlands, the GDPR's one-stop-shop mechanism made the AP the lead supervisory authority, with CNIL and other national regulators as "concerned" parties feeding into a single cross-border decision — five years, in the end, from complaint to fine.
Steelmanning the regulator
The AP's underlying concern deserves to be stated plainly rather than waved away. Gig platforms sit on an unusual amount of leverage over people who have no employer, no HR department, and often no ability to reach a human being when an algorithm cuts them off mid-shift. A driver deactivated by a fraud-detection model has no manager to appeal to, no union grievance process, and — per the French drivers' account — sometimes not even a specific reason. Article 22 exists precisely because automated systems can encode errors, bias, or brittle heuristics at scale, and because "the algorithm decided" is a genuinely inadequate answer when someone's income disappears overnight. A regulator insisting on meaningful human review before that happens is not engaging in tech-hostile overreach; it is enforcing a rule the EU legislature wrote in 2016 specifically for this scenario, and Uber has already lost this argument once, in French courts, over algorithmic deactivation logic.
Where the fine outruns the harm
Even granting the underlying violation, €825 million is a number that should prompt scrutiny of the AP's calculation, not deference to it. The conduct the AP is punishing ended in 2022 — the fine lands four years after Uber, by the regulator's own account, stopped the practice. Deterrence value against behavior that has already been discontinued is limited; what's left is closer to a retrospective levy sized to Uber's global revenue rather than to the scale of documented harm in this specific record. Uber disputes the number outright, calling it "disproportionate" and noting its current process already includes human review and a dispute path — precisely the remedy Article 22 exists to compel (Insurance Journal).
That gap between remedy and penalty matters beyond this one case. This is Uber's fourth AP fine since 2018 — after €600,000, €10 million in 2023, and €290 million in 2024 for improper US data transfers, with three of the four now under appeal (ppc.land). A regulator that keeps reaching for maximal, revenue-scaled fines against a company that has already changed its practices risks training platforms to treat GDPR penalties as a cost of doing business rather than a signal to fix root causes — while giving smaller platforms, which can't absorb nine-figure fines and years of appeals, a much stronger incentive to simply avoid algorithmic tools that would actually improve fraud detection and service quality. Article 22 is the right rule. Calibrating its penalties to genuinely deter future harm, rather than to maximize headline size against whichever company has the deepest pockets, would do more for drivers than this fine will.
What comes next
Uber has confirmed it will appeal, joining the 2023 and 2024 decisions already working through Dutch courts. Given the multi-year timelines on those appeals, any final resolution — and any actual payment — is likely years away. In the meantime, the decision is a clear marker for every platform running algorithmic account-management systems in the EU: automated deactivation without a human reviewer and clear disclosure is now a demonstrated €825-million-scale liability, appeal or not.