On 21 August 2026 the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) fined Uber €824,990,000 for taking fully automated decisions about drivers. According to the AP's announcement, when Uber suspected fraud or a driver's customer ratings were too low, accounts were automatically deactivated, temporarily or, for persistent low ratings, permanently. No human assessed the decision, and the practice ran from 2018 to 2022. Uber has since stopped it. The fine is the second-largest ever under the GDPR, and Uber says it has appealed.
The strongest case for the AP
The regulator's argument deserves a fair hearing. For a full-time driver, an account is the entire livelihood. Deactivation ends income immediately, and a false fraud flag or a run of unfair ratings can trigger it. GDPR Article 22 gives people the right not to be subject to a decision based solely on automated processing that significantly affects them, and drivers losing their income plainly fit that description. The AP also found that Uber did not adequately inform drivers about the automated processing, a transparency failure under the GDPR. Deputy chair Monique Verdier put the principle plainly: "A computer should not make decisions on its own that have major consequences for you. These decisions should have been looked at first by a human being."
The origin of the case matters too. It began with complaints from 171 French drivers, reported through a French human rights organisation. The Dutch authority took it up because Uber's European establishment is in the Netherlands. This is workers using data protection law to contest algorithmic management, which is the system working as designed.
Where the principle holds
We support the substance of the finding. Automated tools are legitimate and valuable: platforms operating at scale cannot manually review every rating or every anomaly, and fraud detection protects riders and honest drivers alike. But the decision to cut someone off from earning a living is different from the decision to flag an account. A human reviewer who can see context, hear the driver's side and override the model is a cheap safeguard compared with the harm of a wrongful ban. Pro-innovation does not mean pro-opacity. Technology that people can contest earns more trust, and trust is what sustains adoption.
Where proportionality strains
The size of the penalty is harder to defend. By one calculation, the fine is roughly 1.85% of Uber's 2025 global turnover of about €44.5 billion, against a statutory ceiling of 4%. It is about 2.8 times the €290 million fine of 2024 for unlawful transfers of driver data to the United States. This is Uber's fourth fine from the AP, after €600,000 in 2018, €10 million in 2023 and €290 million in 2024. Uber is contesting the 2023 and 2024 penalties as well, so none of these fines has yet been through full judicial review.
Three concerns follow.
- Signal versus calibration. A turnover-based fine tells every company that the cost of getting Article 22 wrong is existential, but it does not tell them what compliant human review looks like. Does a reviewer clicking "confirm" on a model's output count? How many reviewers, with how much time per case? The decision announcement is a regulator's view of one company's practice over four years, not a standard.
- Fraud controls. If compliance is read to mean that every automated suspension needs prior human sign-off, platforms may delay blocking accounts that really are fraudulent. The cost of that falls on riders and on honest drivers who share the platform with bad actors. A better reading separates temporary, reversible holds from permanent terminations and puts the human check where the harm is greatest.
- Concentrated enforcement. A few giant fines make headlines, but a drivers' appeal channel working within days would help workers more than a penalty paid years later, and smaller platforms cannot absorb comparable exposure. Regulators who want better practice across the market should publish detailed guidance on meaningful human review alongside enforcement.
What platforms and regulators should take from this
Platforms that deactivate accounts, ban sellers or demonetise creators using automated scoring should now assume that regulators will look at who, if anyone, reviews the outcome. The practical steps are modest: route permanent terminations and income-critical suspensions to a trained human with authority to reverse, tell users in plain language that automated processing is used and what its logic is, and keep an appeal path that actually works.
Regulators, for their part, should treat the Uber decision as the start of the conversation. The appeal courts will decide whether the fine is proportionate and whether the AP's reading of "solely automated" is right. Until then, the sensible lesson is narrow. Automated systems can recommend and flag, but a person should decide when someone's income is at stake. That rule protects workers and does not stop innovation. A fine large enough to alarm every compliance department in Europe, set without clear guidance on how to comply, risks teaching companies to avoid the question rather than answer it.