France France CNIL GDPR enforcement Big Tech

Uber's €825 Million Fine Is Right on Human Review of Driver Deactivations, but Enforcement Needs Proportion

The Dutch DPA's €824.99M Uber penalty, built on French drivers' complaints, shows GDPR Article 22 can protect gig workers. Proportionality still matters.

The Uber GDPR Fine in Numbers People of Internet Research · France €825M Fine imposed Dutch AP penalty on Uber B.V. and … 170+ Drivers in original complaint Collective complaint filed with th… ~1.85% Share of global turnover Against a 4% statutory ceiling, pe… peopleofinternet.com
The Uber GDPR Fine in Numbers People of Internet Research · France €825M Fine imposed 170+ Drivers in original complai… ~1.85% Share of global turnover peopleofinternet.com

Key Takeaways

On 21 August 2026 the Dutch data protection authority (Autoriteit Persoonsgegevens, AP) fined Uber B.V. and Uber Technologies Inc. €824,990,000 for taking automated decisions about drivers and for failing to inform them adequately about profiling. The CNIL announced the sanction on 24 August, and the EDPB listed it among its news items on 8 October 2026. Uber has appealed, according to PPC Land's report on the decision.

The strongest case for the fine

The case for the regulators is serious, and it deserves a fair hearing. For a full-time driver, a deactivated account is not a product inconvenience. It ends their income. The CNIL says the Dutch authority found that Uber temporarily deactivated accounts over suspected fraud, and temporarily or permanently deactivated them over low customer ratings. The finding rested on the "absence totale d'intervention humaine", the total absence of human involvement in the decision.

GDPR Article 22(1) gives people the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Article 22(3) requires safeguards where the exceptions apply, including the right to obtain human intervention. Uber did not hide what it was doing. The question was whether a platform that decides alone whether someone can work can also decide alone whether the decision stands.

How a French complaint became a Dutch fine

The procedure matters as much as the penalty. The CNIL says the case began with a collective complaint it received in 2020 from the Ligue des droits de l'Homme, representing more than 170 Uber drivers. The complaint was supplemented in 2021 and covered information to individuals, data transfers outside the EU, and automated deactivations.

Because Uber's main EU establishment is in the Netherlands, the AP led the investigation under the GDPR's one-stop-shop mechanism. The CNIL says it worked closely with the AP on inspections, evidence analysis and review of the draft decision, and kept the complainants informed.

The mechanism did what it was designed to do. French workers complained at home, one regulator carried the case, and the platform faced one decision rather than 27 inconsistent ones. That consistency favours businesses as much as complainants. A company can plan around a single authority's reading of the law.

Where the analysis gets harder

The amount is the contested part. Reported figures put the fine at about 1.85% of Uber's roughly €44.5 billion 2025 global turnover, or about 46% of the 4% statutory ceiling, according to PPC Land. Some summaries wrongly call it the maximum penalty. It is not. The CNIL's own page does not say the fine is at the cap.

The same report puts the cumulative nominal total of Dutch penalties in this long-running matter at about €1.13 billion. That includes €10 million (11 December 2023, for failures to inform drivers) and €290 million (22 July 2024, for transfers of data outside the EU), both described by the CNIL. Uber is reported to be contesting those two earlier fines as well.

Proportionate enforcement does not mean light enforcement. It means a penalty scaled to the harm, the duration and the company's cooperation, and one a court can test. Three things stand out:

What this means for innovation

A pro-innovation position should not defend unreviewed algorithmic firing. Ratings-based deactivation is exactly the sort of automated decision where errors hit workers hardest, and where customer bias can pass into the system unnoticed. A narrow rule that says a human must be able to review, and the driver must be told how the system works, is easy to comply with and does not choke product development.

The risk lies elsewhere. Nine-figure penalties under a regulation that has produced little case law invite uncertainty about what "solely automated" means in practice. Does a human who rubber-stamps a flag count? Does a review after the fact count? Companies building AI-assisted moderation, fraud screening and hiring tools need answers they can engineer against. A fine this large, applied to a vague standard, pushes them toward either pulling products from Europe or adding token human sign-offs. Neither protects workers.

That is why the appeal matters. A court ruling that sets out what meaningful human intervention requires would give the sector more usable guidance than the fine itself. Regulators should also publish concrete examples of compliant review processes.

Bottom line

The AP and CNIL have shown that a complaint from a few hundred workers can move a one-stop-shop case to a decision against a global platform. The core finding is sound: people should not lose their income to a system no human has checked. The amount, the repeated stacking of penalties on one company, and the lack of clear operational rules will determine whether this enforcement raises standards or just raises legal costs. The outcome on appeal should be judged on whether it clarifies the law, not on the size of the number.

Sources & Citations

  1. CNIL: Décisions automatisées, sanction de près de 825 millions d'euros à l'encontre d'Uber
  2. EDPB news listing: Dutch DPA fines Uber EUR 824 990 000
  3. GDPR Article 22 text
  4. PPC Land: Dutch regulator fines Uber 825 million euros