Netherlands Netherlands AP GDPR enforcement

Uber's €825 Million Dutch Fine Turns a Privacy Clause Into De Facto Gig-Labor Regulation

The Dutch DPA's second-largest-ever GDPR fine punishes Uber for algorithmic driver deactivations — exposing privacy law's limits as a labor-policy tool.

Uber's Dutch GDPR Exposure People of Internet Research · Netherlands €824.99M Latest fine amount Second-largest GDPR fine ever, aft… 2018-2022 Automated deactivation period Years the AP found Uber ran fraud/… €290M Prior Dutch fine, 2024 Separate AP penalty for unsafeguar… Up to 4 years Appeal suspension window How long Uber's prior GDPR appeal … peopleofinternet.com
Uber's Dutch GDPR Exposure People of Internet Research · Netherlands €824.99M Latest fine amount 2018-2022 Automated deactivation per… €290M Prior Dutch fine, 2024 Up to 4 years Appeal suspension window peopleofinternet.com

Key Takeaways

The Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, fined Uber €824.99 million on August 21, 2026 — the second-largest GDPR penalty ever issued, trailing only Meta's €1.2 billion fine from 2023. The AP found that between 2018 and 2022, Uber ran systems that flagged suspected fraud or persistently low customer ratings and then temporarily or permanently deactivated the associated driver accounts without meaningful human review, cutting off drivers' income with no real avenue to contest the decision before it took effect.

What the AP Actually Found

The legal hook is Article 22 of the GDPR, which bars decisions "based solely on automated processing" that "significantly affect" a person unless strict safeguards — including a right to human review — are in place. AP deputy chair Monique Verdier put the finding bluntly: "A computer should not make decisions on its own that have such serious consequences for people." The regulator also found Uber failed to adequately inform drivers that automated systems, rather than people, were making these calls. The case began when a suspended French driver, joined by roughly 170 others, complained to the French rights group Ligue des droits de l'Homme, which routed the matter to France's CNIL. Under GDPR's one-stop-shop mechanism, jurisdiction passed to the AP because Uber's EU headquarters sits in Amsterdam — meaning one national regulator now sets automated-decision-making policy for Uber's driver relationships across the entire bloc.

Uber says the finding mischaracterizes its current practices, that most suspensions are temporary, that permanent deactivations already require human sign-off, and that drivers can appeal. A spokesperson called the fine itself "disproportionate" and confirmed Uber will appeal — a process that, based on Uber's prior GDPR fight with the AP, can run up to four years with the fine suspended throughout.

The Case for the AP's Position

Before arguing the other side, it's worth stating plainly why this enforcement action has real merit. Platform work carries an acute power asymmetry: a driver's entire livelihood can be switched off by a rating algorithm with no manager to appeal to and no paycheck arriving the next day while the dispute is sorted out. That is precisely the harm Article 22 was written for — decisions with serious life consequences shouldn't be made by a black box with no human accountable for the outcome. Gig platforms have also historically resisted transparency about how their ranking and deactivation systems work, which is what let this pattern run for four years before regulators caught up. On the facts as the AP describes them, the underlying conduct — fully automated firing, effectively — is exactly the kind of governance gap that both the EU's 2024 Platform Work Directive and the AI Act's human-oversight requirements for high-risk systems are separately trying to close. The AP got there first with the tool it had.

Where Proportionality Breaks Down

That said, using GDPR as the enforcement vehicle for what is fundamentally a labor-governance problem creates real distortions. Article 22 was drafted for informational harms — wrongly denied loans, unfair insurance pricing — not engineered as an employment-termination statute, and stretching it to cover deactivation decisions means the penalty scales off global turnover rather than any assessment of actual driver harm, which is how a workforce-management dispute produces a nine-figure fine. This is now Uber's fourth AP penalty since 2018 — after €600,000, €10 million, and €290 million for a separate 2024 US-data-transfer finding — pushing cumulative Dutch exposure past €1.1 billion, almost all of it still under appeal and therefore unpaid and legally unsettled. A four-year suspended-fine cycle is a poor substitute for a clear compliance standard: Uber says it already added human review before this decision was even announced, which suggests the real dispute is now about evidentiary proof of past conduct, not current risk to drivers.

A Precedent Beyond Uber

The knock-on effects reach past this one company. Digital-rights group PersonalData.io, whose founder Paul-Olivier Dehaye is launching a driver-compensation vehicle called StartClaims, is already positioning the ruling as a template for algorithmic-management claims against other platforms. That is a legitimate use of a real precedent — but it also means one DPA's reading of a privacy article is now shaping labor exposure for an entire sector, ahead of the AI Act's human-oversight rules actually coming into force. The EU has purpose-built instruments in flight for exactly this problem; regulators should finish building those rather than routing gig-labor policy through the fine that happens to be biggest. Proportionate, well-targeted rules on algorithmic deactivation — clear notice, a guaranteed human appeal, and interim income continuity during disputes — would fix the actual harm without turning every enforcement action into a bet-the-company privacy verdict.

Sources & Citations

  1. Autoriteit Persoonsgegevens — Uber fine announcement
  2. European Data Protection Board — 2024 €290M Uber fine
  3. GDPR Article 22 text
  4. TechCrunch — Uber faces fine of nearly $1B
  5. SecurityWeek — Uber to appeal €290M GDPR fine