Netherlands data protection

The Dutch AP's €825 Million Uber Fine Makes Article 22 a Real Constraint on Algorithmic Firing

The Netherlands' privacy regulator fined Uber €824.99M for auto-deactivating drivers with no human review, the second-largest GDPR penalty ever.

Uber's €825M GDPR Fine, By the Numbers People of Internet Research · Netherlands €825M Fine imposed by Dutch AP Second-largest GDPR penalty ever i… 2018–2022 Automated deactivation period Years Uber ran fraud- and rating-b… 171 French drivers behind the case Drivers whose 2021 complaint to Fr… 3 Prior AP fines against Uber 2018, 2023 and 2024 penalties, mos… peopleofinternet.com
Uber's €825M GDPR Fine, By the Numbers People of Internet Research · Netherlands €825M Fine imposed by Dutch AP 2018–2022 Automated deactivation per… 171 French drivers behind the case 3 Prior AP fines against Uber peopleofinternet.com

Key Takeaways

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, or AP) announced on 21 August 2026 that it has fined Uber €824,990,000 — roughly $966 million — for running a driver-deactivation system that let software, not people, decide when a driver stopped earning. Between 2018 and 2022, the AP found, Uber tracked driving behavior and customer ratings and automatically triggered account deactivations when those systems flagged suspected fraud or ratings judged too low: temporary suspension for fraud flags, permanent removal for persistent low scores, with no human reviewer in the loop and no adequate disclosure to drivers that a machine had made the call (Autoriteit Persoonsgegevens). It is now the second-largest fine ever issued under the GDPR, trailing only Ireland's €1.2 billion penalty against Meta in 2023 for unlawful EU–US data transfers (Insurance Journal / Reuters).

What the AP actually found

The legal theory is narrow: Article 22 of the GDPR bars decisions "based solely on automated processing" that produce legal or similarly significant effects on a person, unless an exception applies and meaningful human safeguards exist. Losing your income on a platform you depend on clearly counts as "significantly affecting" someone. The AP concluded Uber's fraud- and rating-based deactivation pipeline crossed that line, and separately that Uber failed to meet its transparency duties — drivers were not told, in terms they could act on, that automated decision-making was determining their livelihood (ppc.land).

The case did not start in the Netherlands. In June 2021, the Ligue des droits de l'Homme filed a complaint with France's CNIL on behalf of 171 VTC drivers who said they'd been banned by "strictly identical, automatically generated messages" with no real avenue to contest the decision (Business & Human Rights Resource Centre). Because Uber's EU headquarters sits in the Netherlands, the GDPR's one-stop-shop mechanism made the AP the lead supervisory authority, with CNIL and other national regulators as "concerned" parties feeding into a single cross-border decision — five years, in the end, from complaint to fine.

Steelmanning the regulator

The AP's underlying concern deserves to be stated plainly rather than waved away. Gig platforms sit on an unusual amount of leverage over people who have no employer, no HR department, and often no ability to reach a human being when an algorithm cuts them off mid-shift. A driver deactivated by a fraud-detection model has no manager to appeal to, no union grievance process, and — per the French drivers' account — sometimes not even a specific reason. Article 22 exists precisely because automated systems can encode errors, bias, or brittle heuristics at scale, and because "the algorithm decided" is a genuinely inadequate answer when someone's income disappears overnight. A regulator insisting on meaningful human review before that happens is not engaging in tech-hostile overreach; it is enforcing a rule the EU legislature wrote in 2016 specifically for this scenario, and Uber has already lost this argument once, in French courts, over algorithmic deactivation logic.

Where the fine outruns the harm

Even granting the underlying violation, €825 million is a number that should prompt scrutiny of the AP's calculation, not deference to it. The conduct the AP is punishing ended in 2022 — the fine lands four years after Uber, by the regulator's own account, stopped the practice. Deterrence value against behavior that has already been discontinued is limited; what's left is closer to a retrospective levy sized to Uber's global revenue rather than to the scale of documented harm in this specific record. Uber disputes the number outright, calling it "disproportionate" and noting its current process already includes human review and a dispute path — precisely the remedy Article 22 exists to compel (Insurance Journal).

That gap between remedy and penalty matters beyond this one case. This is Uber's fourth AP fine since 2018 — after €600,000, €10 million in 2023, and €290 million in 2024 for improper US data transfers, with three of the four now under appeal (ppc.land). A regulator that keeps reaching for maximal, revenue-scaled fines against a company that has already changed its practices risks training platforms to treat GDPR penalties as a cost of doing business rather than a signal to fix root causes — while giving smaller platforms, which can't absorb nine-figure fines and years of appeals, a much stronger incentive to simply avoid algorithmic tools that would actually improve fraud detection and service quality. Article 22 is the right rule. Calibrating its penalties to genuinely deter future harm, rather than to maximize headline size against whichever company has the deepest pockets, would do more for drivers than this fine will.

What comes next

Uber has confirmed it will appeal, joining the 2023 and 2024 decisions already working through Dutch courts. Given the multi-year timelines on those appeals, any final resolution — and any actual payment — is likely years away. In the meantime, the decision is a clear marker for every platform running algorithmic account-management systems in the EU: automated deactivation without a human reviewer and clear disclosure is now a demonstrated €825-million-scale liability, appeal or not.

Sources & Citations

  1. Autoriteit Persoonsgegevens — Uber fine announcement
  2. EUR-Lex — GDPR (Regulation 2016/679), Article 22
  3. ppc.land — Dutch regulator fines Uber 825 million euros
  4. Insurance Journal (Reuters) — Dutch Regulator Fines Uber $966M
  5. Hunton Andrews Kurth — Dutch DPA fines Uber €290 million (French drivers' LDH/CNIL complaint)