The Dutch Data Protection Authority fined Uber €825 million over automated suspensions and deactivations that could cut off drivers’ income without adequate notice or meaningful human review. The case involved automated fraud flags, alleged unnecessary detours, uncompleted accepted trips, and low ratings.
Research answer

Create a landscape editorial hero image for this Studio Global article: What led the Dutch Data Protection Authority to fine Uber €825 million ($966 million)—the second-largest GDPR penalty ever, behind Meta’s €1. Article summary: The Dutch Data Protection Authority (AP) concluded that Uber used automated systems to suspend or deactivate drivers in 2020–22 without giving adequate notice or the safeguards GDPR requires when decisions significantly . Topic tags: general, government, news, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermar
Uber faces an €825 million penalty from the Dutch Data Protection Authority (AP) for using automated systems to suspend or deactivate drivers without adequately informing them or providing the safeguards required for high-impact automated decisions. The amount would make it the second-largest GDPR penalty on record, behind Ireland’s €1.2 billion fine against Meta in 2023. Uber says it will appeal, meaning the penalty may still change.
The AP’s finding concerned more than the use of algorithms to detect possible misconduct. Uber’s systems could trigger action against drivers in situations involving suspected fare fraud, allegedly unnecessary detours intended to inflate fares, accepted trips that drivers allegedly did not complete, and low customer ratings. Those actions could restrict or end a driver’s ability to earn through the platform.
Under GDPR rules on automated decision-making, a person generally cannot be subjected to a decision based solely on automated processing when it has a significant effect on them without appropriate protections. Those protections include meaningful human intervention, an opportunity to express the person’s view, and a way to contest the decision.
The regulator’s apparent conclusion was that Uber’s process did not provide those protections adequately. A notification after an algorithmic decision is not enough if the affected driver cannot understand what happened or obtain a genuine, independent reassessment.
The important distinction is between a human who can independently reconsider the evidence and a reviewer who simply confirms an automated result. In a related case, the Amsterdam Court of Appeal found that Uber’s claimed human reviews were merely symbolic and rejected reliance on a nominal “human in the loop.”
That earlier ruling helps explain the legal significance of the AP’s action. Human involvement must be capable of changing the outcome; it cannot be a procedural formality that leaves the algorithm’s decision effectively untouched. Drivers must also receive enough information about the decision to make a meaningful challenge.
The AP found that Uber did not adequately inform affected drivers that automated processes were being used to produce suspensions or deactivations, according to reporting based on the regulator’s decision. The information gap mattered because drivers could not properly assess why they had lost access or how to contest the underlying decision.
This creates two connected compliance problems:
The case therefore turns on both the outcome and the process behind it. A company may need to explain not only what action it took, but also how a person can obtain a real review when an automated system threatens their income.
The complaint originated in France, but the Dutch AP handled the cross-border case because Uber’s European headquarters are in the Netherlands. Under GDPR’s one-stop-shop framework, the supervisory authority in the country where a company has its main EU establishment generally takes the lead in cross-border matters, while other relevant authorities can participate.
The arrangement is designed to prevent a multinational company from facing entirely separate lead investigations in every EU country where its practices have effects. It also explains why a complaint filed by French drivers could result in a decision from the Dutch regulator.
Uber said it would appeal and described the decision and penalty as disproportionate. The company said it offers human reviews and a right to challenge suspensions. It also said suspected-fraud suspensions were temporary and denied that accounts were permanently deactivated solely through automation.
Uber further said that it no longer makes permanent deactivation decisions based only on automated systems. Those statements describe Uber’s position; the AP’s penalty concerns the practices examined for the relevant period, primarily 2020 through 2022.
The decision shows why algorithmic management is becoming a major privacy and employment issue in Europe. The systems at issue were not merely recommending advertisements or sorting routine customer data. They could determine whether a worker retained access to a platform that supplied income.
That raises a broader compliance lesson: a “human review” policy is unlikely to be sufficient if reviewers cannot independently examine the facts, hear the affected person’s explanation, and reverse an automated result. Companies using automated systems for worker onboarding, fraud detection, account restrictions, or deactivation need to consider transparency and contestability at the point where those systems affect a person’s livelihood.
The case also adds to Uber’s wider GDPR history in the Netherlands. In 2024, the Dutch authority separately fined Uber €290 million over transfers of European drivers’ personal data to the United States. Meta’s €1.2 billion penalty, meanwhile, concerned transfers of European Facebook users’ data to the U.S., rather than worker-management decisions.
For now, the €825 million amount remains subject to Uber’s appeal. But the underlying message is already clear: under GDPR, automated management cannot become a black box when its decisions can remove someone’s ability to work.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
The Dutch Data Protection Authority fined Uber €825 million over automated suspensions and deactivations that could cut off drivers’ income without adequate notice or meaningful human review.
The Dutch Data Protection Authority fined Uber €825 million over automated suspensions and deactivations that could cut off drivers’ income without adequate notice or meaningful human review. The case involved automated fraud flags, alleged unnecessary detours, uncompleted accepted trips, and low ratings.
The Dutch authority handled the cross border matter because Uber’s European headquarters are in the Netherlands, even though the complaint originated in France.