The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) announced on August 21, 2026 that it is fining Uber €824,990,000 for violating GDPR's ban on solely automated decisions with significant effects on individuals. Between 2018 and 2022, Uber's systems temporarily or permanently deactivated driver accounts — cutting off drivers' entire income from the platform — based on automated fraud-detection triggers or persistently low customer ratings, without a human reviewing the decision first. The AP also found Uber failed to adequately inform drivers that automated systems, rather than people, were making these calls. It is the second-highest GDPR fine ever issued, trailing only Meta's €1.2 billion penalty from 2023, according to the AP's press release.
The Case for the Fine
The strongest argument for this enforcement action is not abstract. Article 22 of the GDPR was written specifically to prevent the scenario the AP describes: a person's livelihood terminated by software, with no human in the loop to catch an error, weigh context, or hear an explanation before the consequence lands. Deputy AP chair Monique Verdier put it plainly: "A computer should not make decisions on its own that have major consequences for you. These decisions should have been looked at first by a human being," she said, as reported by TechCrunch. Drivers are not employees with the procedural protections that come with that status, and platform deactivation is often their only avenue of recourse before losing income entirely. A regulator that lets automated termination decisions go unreviewed for four years, across a workforce numbering in the hundreds of thousands, is not being unreasonably strict — it is applying a plain-text reading of a rule that has existed since 2018.
The case also did not originate from Dutch regulatory zeal. It traces back to 171 French drivers who complained to the Ligue des droits de l'Homme, which took the matter to France's CNIL; the AP became lead authority because Uber's EU headquarters sits in the Netherlands, under GDPR's one-stop-shop mechanism, as detailed by Pearl Cohen's legal analysis. That is the system working as designed: individual complaints, cross-border coordination, one authority resolving a pan-European pattern rather than 27 separate proceedings.
Why the Number, Not the Finding, Is the Problem
Where this enforcement action strains proportionality is the size of the penalty relative to the conduct at issue. Uber disputes the AP's characterization, telling reporters it "strongly disagree[s] with this decision and disproportionate fine," arguing that most suspensions are temporary holds pending review and that permanent deactivations do receive human sign-off — a factual dispute the company will now litigate on appeal, per TechCrunch's reporting. If that account is even partially accurate, the AP's finding of a blanket absence of human review may not survive appellate scrutiny intact — and a fine calculated near the top of GDPR's 4%-of-global-turnover ceiling should be reserved for violations where the facts are not seriously contested.
This is also the fourth AP fine against Uber since 2018 — following a €600,000 fine that year, €10 million in 2023, and €290 million in 2024 for unlawful data transfers to the US, per the AP's fine history. A pattern of repeat enforcement against one company raises a legitimate question: is the AP calibrating penalties to the specific harm in front of it, or anchoring upward each time to signal escalating severity? GDPR fines are meant to be "effective, proportionate and dissuasive" under Article 83 — not maximized for deterrent shock value against a company the regulator has already fined three times.
The Compliance Lesson Regardless of Appeal Outcome
Whatever happens on appeal, the compliance signal for every platform running algorithmic account-management, gig-work matching, or automated risk-scoring is unambiguous: a human must meaningfully review any automated decision that can cut off someone's income, and that review has to be documented, not nominal. Retrofitting human review after the fact, or asserting it happened without a paper trail, is precisely the gap the AP says it found. Platforms operating in the EU should treat this fine the way the industry treated the 2023 Meta transfer ruling — as the ceiling case that defines the floor of acceptable practice going forward, not as an isolated Dutch peculiarity.
The underlying principle — no solely automated termination of a person's livelihood without human review — is sound, proportionate regulation that any innovation-friendly framework should retain. The test now moves to the Dutch courts: whether an €825 million penalty against a single company, for conduct the company disputes and that predates 2022, survives as a proportionate application of that principle rather than a number set to make headlines.