The Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, fined Uber €824.99 million on August 21, 2026 — the second-largest GDPR penalty ever issued, trailing only Meta's €1.2 billion fine from 2023. The AP found that between 2018 and 2022, Uber ran systems that flagged suspected fraud or persistently low customer ratings and then temporarily or permanently deactivated the associated driver accounts without meaningful human review, cutting off drivers' income with no real avenue to contest the decision before it took effect.
What the AP Actually Found
The legal hook is Article 22 of the GDPR, which bars decisions "based solely on automated processing" that "significantly affect" a person unless strict safeguards — including a right to human review — are in place. AP deputy chair Monique Verdier put the finding bluntly: "A computer should not make decisions on its own that have such serious consequences for people." The regulator also found Uber failed to adequately inform drivers that automated systems, rather than people, were making these calls. The case began when a suspended French driver, joined by roughly 170 others, complained to the French rights group Ligue des droits de l'Homme, which routed the matter to France's CNIL. Under GDPR's one-stop-shop mechanism, jurisdiction passed to the AP because Uber's EU headquarters sits in Amsterdam — meaning one national regulator now sets automated-decision-making policy for Uber's driver relationships across the entire bloc.
Uber says the finding mischaracterizes its current practices, that most suspensions are temporary, that permanent deactivations already require human sign-off, and that drivers can appeal. A spokesperson called the fine itself "disproportionate" and confirmed Uber will appeal — a process that, based on Uber's prior GDPR fight with the AP, can run up to four years with the fine suspended throughout.
The Case for the AP's Position
Before arguing the other side, it's worth stating plainly why this enforcement action has real merit. Platform work carries an acute power asymmetry: a driver's entire livelihood can be switched off by a rating algorithm with no manager to appeal to and no paycheck arriving the next day while the dispute is sorted out. That is precisely the harm Article 22 was written for — decisions with serious life consequences shouldn't be made by a black box with no human accountable for the outcome. Gig platforms have also historically resisted transparency about how their ranking and deactivation systems work, which is what let this pattern run for four years before regulators caught up. On the facts as the AP describes them, the underlying conduct — fully automated firing, effectively — is exactly the kind of governance gap that both the EU's 2024 Platform Work Directive and the AI Act's human-oversight requirements for high-risk systems are separately trying to close. The AP got there first with the tool it had.
Where Proportionality Breaks Down
That said, using GDPR as the enforcement vehicle for what is fundamentally a labor-governance problem creates real distortions. Article 22 was drafted for informational harms — wrongly denied loans, unfair insurance pricing — not engineered as an employment-termination statute, and stretching it to cover deactivation decisions means the penalty scales off global turnover rather than any assessment of actual driver harm, which is how a workforce-management dispute produces a nine-figure fine. This is now Uber's fourth AP penalty since 2018 — after €600,000, €10 million, and €290 million for a separate 2024 US-data-transfer finding — pushing cumulative Dutch exposure past €1.1 billion, almost all of it still under appeal and therefore unpaid and legally unsettled. A four-year suspended-fine cycle is a poor substitute for a clear compliance standard: Uber says it already added human review before this decision was even announced, which suggests the real dispute is now about evidentiary proof of past conduct, not current risk to drivers.
A Precedent Beyond Uber
The knock-on effects reach past this one company. Digital-rights group PersonalData.io, whose founder Paul-Olivier Dehaye is launching a driver-compensation vehicle called StartClaims, is already positioning the ruling as a template for algorithmic-management claims against other platforms. That is a legitimate use of a real precedent — but it also means one DPA's reading of a privacy article is now shaping labor exposure for an entire sector, ahead of the AI Act's human-oversight rules actually coming into force. The EU has purpose-built instruments in flight for exactly this problem; regulators should finish building those rather than routing gig-labor policy through the fine that happens to be biggest. Proportionate, well-targeted rules on algorithmic deactivation — clear notice, a guaranteed human appeal, and interim income continuity during disputes — would fix the actual harm without turning every enforcement action into a bet-the-company privacy verdict.