Netherlands Netherlands AP GDPR enforcement

Why the Netherlands' €825 Million Uber Fine Is a Proportionate Application of a Decade-Old Rule, Not Regulatory Overreach

The Dutch DPA fined Uber €825M for firing drivers by algorithm with no human review — a case that tests GDPR Article 22 without expanding it.

Uber's Dutch GDPR Fine, in Numbers People of Internet Research · Netherlands €825M Latest AP fine For fully automated driver account… 2nd highest Rank among GDPR fines Behind only Meta's €1.2B 2023 fine… €290M Prior AP fine, 2024 For unlawful driver data transfers… 4 AP fines against Uber since 2018 €600K (2018), €10M (2023), €290M (… peopleofinternet.com
Uber's Dutch GDPR Fine, in Numbers People of Internet Research · Netherlands €825M Latest AP fine 2nd highest Rank among GDPR fines €290M Prior AP fine, 2024 4 AP fines against Uber since 2018 peopleofinternet.com

Key Takeaways

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) announced on August 21, 2026 that it is fining Uber €824,990,000 for violating GDPR's ban on solely automated decisions with significant effects on individuals. Between 2018 and 2022, Uber's systems temporarily or permanently deactivated driver accounts — cutting off drivers' entire income from the platform — based on automated fraud-detection triggers or persistently low customer ratings, without a human reviewing the decision first. The AP also found Uber failed to adequately inform drivers that automated systems, rather than people, were making these calls. It is the second-highest GDPR fine ever issued, trailing only Meta's €1.2 billion penalty from 2023, according to the AP's press release.

The Case for the Fine

The strongest argument for this enforcement action is not abstract. Article 22 of the GDPR was written specifically to prevent the scenario the AP describes: a person's livelihood terminated by software, with no human in the loop to catch an error, weigh context, or hear an explanation before the consequence lands. Deputy AP chair Monique Verdier put it plainly: "A computer should not make decisions on its own that have major consequences for you. These decisions should have been looked at first by a human being," she said, as reported by TechCrunch. Drivers are not employees with the procedural protections that come with that status, and platform deactivation is often their only avenue of recourse before losing income entirely. A regulator that lets automated termination decisions go unreviewed for four years, across a workforce numbering in the hundreds of thousands, is not being unreasonably strict — it is applying a plain-text reading of a rule that has existed since 2018.

The case also did not originate from Dutch regulatory zeal. It traces back to 171 French drivers who complained to the Ligue des droits de l'Homme, which took the matter to France's CNIL; the AP became lead authority because Uber's EU headquarters sits in the Netherlands, under GDPR's one-stop-shop mechanism, as detailed by Pearl Cohen's legal analysis. That is the system working as designed: individual complaints, cross-border coordination, one authority resolving a pan-European pattern rather than 27 separate proceedings.

Why the Number, Not the Finding, Is the Problem

Where this enforcement action strains proportionality is the size of the penalty relative to the conduct at issue. Uber disputes the AP's characterization, telling reporters it "strongly disagree[s] with this decision and disproportionate fine," arguing that most suspensions are temporary holds pending review and that permanent deactivations do receive human sign-off — a factual dispute the company will now litigate on appeal, per TechCrunch's reporting. If that account is even partially accurate, the AP's finding of a blanket absence of human review may not survive appellate scrutiny intact — and a fine calculated near the top of GDPR's 4%-of-global-turnover ceiling should be reserved for violations where the facts are not seriously contested.

This is also the fourth AP fine against Uber since 2018 — following a €600,000 fine that year, €10 million in 2023, and €290 million in 2024 for unlawful data transfers to the US, per the AP's fine history. A pattern of repeat enforcement against one company raises a legitimate question: is the AP calibrating penalties to the specific harm in front of it, or anchoring upward each time to signal escalating severity? GDPR fines are meant to be "effective, proportionate and dissuasive" under Article 83 — not maximized for deterrent shock value against a company the regulator has already fined three times.

The Compliance Lesson Regardless of Appeal Outcome

Whatever happens on appeal, the compliance signal for every platform running algorithmic account-management, gig-work matching, or automated risk-scoring is unambiguous: a human must meaningfully review any automated decision that can cut off someone's income, and that review has to be documented, not nominal. Retrofitting human review after the fact, or asserting it happened without a paper trail, is precisely the gap the AP says it found. Platforms operating in the EU should treat this fine the way the industry treated the 2023 Meta transfer ruling — as the ceiling case that defines the floor of acceptable practice going forward, not as an isolated Dutch peculiarity.

The underlying principle — no solely automated termination of a person's livelihood without human review — is sound, proportionate regulation that any innovation-friendly framework should retain. The test now moves to the Dutch courts: whether an €825 million penalty against a single company, for conduct the company disputes and that predates 2022, survives as a proportionate application of that principle rather than a number set to make headlines.

Sources & Citations

  1. AP: Uber fined nearly €825 million for automated driver blocking
  2. AP: €290 million fine on Uber for data transfers to the US
  3. TechCrunch: Uber faces fine of nearly $1B over automated driver suspensions
  4. Pearl Cohen: Dutch DPA fines Uber €825M for fully automated deactivation