The Dutch Data Protection Authority fined Uber €825 million—about $966 million—for automated driver suspensions and deactivations during 2020–2022. The regulator treated account suspensions and bans as significant decisions because they could cut off drivers’ access to income, requiring transparency and meaningful h...
Research answer

Create a landscape editorial hero image for this Studio Global article: What did the Dutch Data Protection Authority’s €825 million (approximately $966 million) GDPR fine against Uber involve, including its findi. Article summary: The Dutch Data Protection Authority (AP) fined Uber €825 million—about $966 million—for GDPR violations arising from automated driver suspensions and deactivations between 2020 and 2022. It is the second-largest GDPR pen. Topic tags: general, news, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers
The Dutch Data Protection Authority (AP) has fined Uber €825 million—approximately $966 million—for GDPR violations linked to automated decisions affecting European drivers between 2020 and 2022. The regulator said Uber did not adequately inform drivers when automated systems influenced account suspensions or deactivations, nor provide sufficient human oversight. 12
Uber disputes parts of the decision and the size of the penalty and says it will appeal. 1
According to the AP’s decision, Uber used automated systems to temporarily suspend drivers suspected of fraud and to permanently deactivate some drivers based on low customer ratings. The systems could make or trigger these decisions without meaningful human review, while affected drivers were not adequately told how automated decision-making was being used. 145
The issue was not simply that Uber used software to detect potential fraud or assess service quality. The regulator’s concern was that automated processing could determine whether a driver continued to access the platform—and therefore whether that person could continue earning through it.
Examples of signals reportedly used in fraud detection included unusually long trips, which could suggest unnecessary detours, and accepting rides that a driver did not intend to take. 5
GDPR restricts decisions based solely on automated processing when they produce legal effects or otherwise significantly affect a person. The Dutch regulator describes this as a right to a human perspective in consequential decisions.
For platform drivers, losing access to Uber is more consequential than an ordinary account feature changing. A temporary suspension can interrupt income, while permanent deactivation can prevent a driver from working through the platform altogether. That livelihood impact is why the regulator treated the decisions as significant rather than routine operational actions. 45
Where an automated decision is permitted under GDPR, safeguards can include clear information about the process, the ability to request human intervention, and a meaningful opportunity to challenge the outcome.
The case began with complaints from French drivers. Former Uber driver Brahim Ben Ali gathered testimony from about 170 affected drivers, with assistance from the Swiss digital-rights group PersonalData.io. The available reporting refers to 171 French complainants. 413
The Dutch AP handled the investigation because Uber’s relevant European operations and GDPR supervisory arrangement were based in the Netherlands. That allowed the Dutch authority to act in a cross-border case involving drivers in another European country. 17
The episode also illustrates how individual complaints can expose the operation of large-scale algorithmic systems. Drivers sought information about decisions affecting their accounts, and the resulting regulatory inquiry examined not only the outcome of individual suspensions but also the structure of Uber’s automated decision-making process. 13
The €825 million sanction is reported as the second-largest penalty imposed under the EU’s GDPR, behind the €1.2 billion fine imposed on Meta. 12
It is also substantially larger than Uber’s earlier €290 million Dutch GDPR fine, which concerned transfers of European drivers’ personal data to the United States rather than automated account decisions.
| Case | Penalty | Main issue |
|---|---|---|
| Uber automated-driver-decision case | €825 million | Automated suspensions and deactivations without adequate information or human oversight 12 |
| Uber’s earlier Dutch GDPR case | €290 million | Transfers of European drivers’ data to the United States |
| Meta GDPR record fine | €1.2 billion | Transfer of Facebook users’ data to the United States 110 |
The fine itself is a regulatory sanction. It does not automatically compensate individual drivers for lost earnings.
Digital-rights advocates have viewed the ruling as possible groundwork for collective legal action seeking compensation from Uber. PersonalData.io said it was preparing a class action, according to reporting cited by Reuters. 13
That potential action would be separate from the AP’s fine. Drivers would still need to establish the basis and extent of any individual or collective compensation claim; the regulatory penalty alone does not create an automatic payout. 713
Uber said it strongly disagrees with the decision and considers the fine disproportionate. The company disputes some factual findings and the amount of the penalty and plans to appeal. 13
Uber also said the challenged policies were discontinued by 2021–2022. It maintains that its current procedures include human review and appeal routes, and has argued that most suspensions are brief and that permanent deactivations do not occur without human involvement. 17
Those are Uber’s stated positions, while the AP’s findings concern the historical practices examined in the decision. The appeal could therefore determine which findings and elements of the penalty ultimately stand.
The case pushes privacy enforcement beyond familiar questions about data collection and storage. It shows how GDPR can apply when personal data and automated profiling are used to control access to work, income, or a platform’s economic opportunities. 14
For technology and gig-economy companies, the practical lesson is that fraud detection, ratings systems, and account enforcement cannot be treated as consequence-free automation. Companies using such systems need to be able to explain how decisions are made, notify affected people, provide genuine human reconsideration, and offer an effective way to contest adverse outcomes.
The broader regulatory risk is clearest where software can make a worker temporarily unable—or permanently unable—to earn. In those situations, a nominal review process may not be enough: the human intervention must be capable of examining the decision and changing it when the evidence or circumstances warrant.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
The Dutch Data Protection Authority fined Uber €825 million—about $966 million—for automated driver suspensions and deactivations during 2020–2022.
The Dutch Data Protection Authority fined Uber €825 million—about $966 million—for automated driver suspensions and deactivations during 2020–2022. The regulator treated account suspensions and bans as significant decisions because they could cut off drivers’ access to income, requiring transparency and meaningful human review under GDPR.