A record-adjacent fine, and a narrow legal theory behind it
On August 21, 2026, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) announced a €824,990,000 fine against Uber B.V. and Uber Technologies Inc. — the second-largest penalty ever issued under the GDPR, trailing only Ireland's €1.2 billion fine against Meta in 2023. The AP acted as lead supervisory authority because Uber's European headquarters sit in the Netherlands, but it did so in cooperation with France's CNIL under the GDPR's one-stop-shop mechanism, since the underlying complaint originated in France.
The legal theory is narrow and specific: Article 22 of the GDPR gives individuals the right not to be subject to decisions "based solely on automated processing" that produce legal or similarly significant effects on them, unless a specific exception applies and safeguards — including a right to human intervention — are provided. The AP found that between 2018 and 2022, Uber used automated systems to temporarily suspend driver accounts on suspicion of fraud and to permanently deactivate accounts tied to persistently low customer ratings, without genuine human review before those decisions took effect. As the AP's deputy chair, Monique Verdier, put it in the regulator's announcement: "A computer should not make decisions on its own that have major consequences for you."
Where the complaint came from
The case traces to 2020, when France's Ligue des droits de l'Homme filed a complaint with the CNIL on behalf of more than 170 Uber drivers, supplemented in 2021. Because Uber's main EU establishment is in the Netherlands, the CNIL referred the matter to the AP, which conducted the investigation while the CNIL continued to cooperate through the fact-finding and the review of the AP's draft decision. This is not Uber's first Dutch GDPR penalty tied to the same driver complaints: the AP fined Uber €10 million in December 2023 for failing to adequately inform drivers about automated decision-making, and €290 million in July 2024 after finding Uber transferred European drivers' personal data — including location data, identity documents, and payment details — to US servers without valid transfer safeguards once it stopped relying on Standard Contractual Clauses in August 2021.
The steelman: platform "black-box" firing is a real due-process problem
The strongest case for this enforcement action is straightforward. Losing access to a ride-hailing platform is not a trivial inconvenience for a driver who depends on it for a livelihood — it is closer to a termination decision, and Article 22 exists precisely because automated systems making high-stakes calls at scale, with no meaningful human in the loop, can encode errors and biases that no individual driver has the power to contest. Regulators are right that a rating-based or fraud-flag algorithm that permanently cuts off someone's income deserves a real appeals process, not a rubber-stamped review that exists on paper only. The GDPR's drafters anticipated exactly this scenario — automated e-recruiting and account-termination decisions are the textbook examples cited in the regulation's own recitals — and a platform operating across 27 member states with millions of workers is a reasonable place to test whether that protection is enforceable.
Why the remedy still looks disproportionate to the conduct
Even granting that framing, the size and structure of this fine sit uneasily with the goal of getting companies to build better-governed automated systems. Uber disputes the AP's characterization directly, saying its current policy already requires human review before permanent deactivation and gives drivers a mechanism to contest suspensions — meaning the conduct being fined is largely historical, tied to a system Uber says it has since changed. A €825 million penalty for a five-year-old process design, assessed years after the underlying practice was reportedly altered, does more to signal regulatory muscle than to correct an ongoing harm. That distinction matters for how other platforms respond: the lesson many will take is not "add meaningful human review to consequential automated decisions," but "minimize the auditable trail of automation entirely," or worse, keep fraud-detection systems glacially slow to avoid the appearance of an unreviewed automated decision. Fraud and rating-manipulation detection at Uber's scale — millions of trips daily — is not a task human reviewers can meaningfully replicate without automated flagging doing the first pass; the real regulatory question is what "meaningful human review" requires downstream of that flag, and neither the GDPR text nor this enforcement action offers platforms a clear, calibrated standard for that question.
What comes next
Uber has said it will appeal, and the amount alone guarantees years of litigation before any money changes hands. For the broader tech-policy landscape, this is a marker that European regulators are willing to use Article 22 aggressively against algorithmic management in the gig economy — a signal that will land as much in Brussels' ongoing platform-work directive debates as in Uber's balance sheet. The proportionate path forward is for the European Data Protection Board to issue clearer guidance on what "meaningful human intervention" actually requires in high-volume automated-decision contexts, so that platforms building good-faith fraud and safety systems have a compliance target that isn't just a nine-figure fine assessed after the fact.