EU GDPR enforcement

Uber's €825 Million GDPR Fine Confirms Article 22 Now Sets the Real Ceiling on Platform Automation

The Dutch DPA's record fine over automated driver deactivations shows GDPR's human-review rule, not the AI Act, is the binding constraint on algorithmic management.

Uber's Escalating Dutch GDPR Penalties People of Internet Research · EU €825M Fine for auto-deactivation Second-largest GDPR fine ever, iss… €1.1B+ Total Dutch fines on Uber Across four AP penalties from 2018… €290M 2024 data-transfer fine Prior Dutch DPA fine for unlawful … 2018–2022 Violation period Years the automated deactivation p… peopleofinternet.com
Uber's Escalating Dutch GDPR Penalties People of Internet Research · EU €825M Fine for auto-deactivation €1.1B+ Total Dutch fines on Uber €290M 2024 data-transfer fi… 2018–2022 Violation period peopleofinternet.com

Key Takeaways

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) fined Uber €824,990,000 on August 21, 2026 — the second-largest GDPR penalty ever issued, trailing only Ireland's €1.2 billion fine against Meta in 2023. The finding: between 2018 and 2022, Uber's systems automatically deactivated driver accounts — temporarily on suspicion of fraud, permanently when customer ratings dropped below a threshold — without a human reviewing the decision, and without adequately informing drivers this was happening. The AP ruled this breached Article 22 of the GDPR, which bars decisions with legal or similarly significant effects from being made "solely" by automated means. "A computer should not make decisions on its own that have major consequences for you," deputy AP chair Monique Verdier said in the regulator's statement.

The Case for the Fine

The strongest argument for this enforcement isn't abstract. Losing your ability to earn on a platform you depend on, based on a fraud flag or a rating algorithm you cannot see or contest, is exactly the kind of "significant effect" Article 22 was written to police. The complaint originated with 171 French drivers, organized through the Ligue des droits de l'Homme, several of whom described losing income for weeks with no appeal path that reached an actual person. This is not new territory for Dutch courts: an Amsterdam District Court already found in March 2021 that Ola's driver-deduction algorithm required human-comprehensible explanation under Article 22 in one of the first rulings anywhere on a GDPR right to explanation for automated decisions. Regulators had fair warning, and so did Uber. A fine of this scale — roughly 1.85% of Uber's €44.5 billion 2025 global revenue — is also not obviously disproportionate to a four-year violation affecting an unspecified but plainly large number of EU drivers' livelihoods.

Where the Fine Overreaches

The problem is not the underlying finding — it's the compounding. This is Uber's fourth AP penalty: €600,000 in 2018, €10 million in 2023, €290 million in July 2024 for unlawful US data transfers, and now €825 million. Dutch enforcement against a single company now totals over €1.1 billion, concentrated because Uber's EU headquarters sits in the Netherlands and the one-stop-shop mechanism routes cases there. That mechanism was designed to prevent forum-shopping and give companies one predictable regulator — not to let one authority stack sequential nine- and ten-figure fines against the same firm for related but legally distinct conduct. The AP itself estimates this single fine equals roughly 72% of all GDPR fines issued across the entire European Economic Area in 2025. When one national regulator's single decision can match three-quarters of a year's total EU enforcement, the concentration risk in the one-stop-shop design is doing more work than the underlying violation.

There is also a genuine hard case buried in the AP's finding that the ruling doesn't resolve cleanly. Uber says permanent deactivations already require human review and that drivers can appeal — its objection is to the AP's finding that fraud-suspicion suspensions, which are often reversed quickly, should be held to the same solely-automated standard as permanent terminations. Article 22 doesn't scale by severity or duration; a 48-hour automated fraud hold and a permanent account ban get identical legal treatment. That's defensible as a bright-line rule — it's much harder to build a compliance program around a discretionary "how severe is severe enough" test than a categorical one — but it does mean platforms have no calibrated way to move fast on genuine fraud signals without triggering the same liability as wrongful permanent bans.

What This Actually Changes

The practical effect lands on any platform running triage automation at scale — food delivery, freelance marketplaces, content moderation queues, ad-fraud detection — anywhere a system flags an account and a consequence follows before a person looks at the file. The compliant model isn't "no automation"; it's automation plus a real human checkpoint before the consequence lands, plus disclosure that the decision was automated in the first place. That's a staffing and latency cost, not a technology ban, and platforms operating in the EU should treat it as a fixed cost of doing business here now, not a one-off Uber problem.

Uber has filed an appeal, alongside ongoing appeals of both the 2023 and 2024 AP penalties — meaning none of the roughly €1.1 billion in cumulative fines is fully final. The Dutch courts, not the AP, will ultimately decide whether the automated-decision line the regulator drew survives judicial review, and whether the one-stop-shop mechanism can keep absorbing fines of this magnitude from a single authority without triggering pressure — from Uber or from Brussels — to rebalance how concentrated GDPR enforcement is allowed to get.

Sources & Citations

  1. EDPB — Dutch SA imposes €290M fine on Uber (2024 data transfer case)
  2. EUR-Lex — GDPR Regulation (EU) 2016/679, Article 22
  3. TechCrunch — Uber faces fine of nearly $1B over automated driver suspensions
  4. ppc.land — Dutch regulator fines Uber €825 million over automated driver blocking
  5. Pearl Cohen — Dutch DPA Fines Uber €825 Million for Fully Automated Deactivation