Dutch Regulator Fines Uber Over Automated Suspensions
The Dutch Data Protection Authority fined Uber EUR 825 million on August 21 for deactivating driver accounts through automated systems without adequately informing drivers, Reuters reports. The regulator characterized the conduct as serious GDPR infringements involving decisions with major livelihood consequences. Uber disputes the decision and the size of the penalty and has said it will appeal, according to Reuters.
The Dutch Data Protection Authority has fined Uber EUR 825 million for deactivating driver accounts through automated systems without adequately informing them, Reuters reported on August 21. The regulator's decision, dated August 17, would make the penalty the second-largest issued under the European Union's General Data Protection Regulation, according to Reuters.
Dutch regulator deputy chair Monique Verdier said Uber had committed "serious infringements" by deactivating accounts without warning or human involvement. Verdier said drivers could lose their income from one moment to the next and added: "A computer should not make decisions on its own that have (such) major consequences."
Uber said it would appeal. An Uber spokesperson told Reuters: "We strongly disagree with this decision and disproportionate fine," adding that the company's policies include human reviews and opportunities for drivers to challenge suspensions.
What the regulator found
According to NL Times, which cited the regulator's decision and Reuters, Uber's automated systems temporarily suspended multiple European drivers suspected of fraud between 2020 and 2022. The report said that some drivers with low customer ratings were permanently suspended.
The case followed a complaint by drivers in France. The Dutch authority led the investigation because Uber's European headquarters is in the Netherlands, NL Times reported. Reporting by MLex also identifies cooperation between Dutch and French privacy watchdogs in the case.
GDPR prohibits decisions made solely through automated processing when they have significant effects on an individual, including employment-related consequences. Reuters reported that the Dutch authority found both an infringement of drivers' right not to be subject to consequential automated decision-making and an infringement of their right to information.
Implications for automated decision systems
The case concerns automated account enforcement. It places a high-profile enforcement action around a familiar operational pattern: automated fraud, trust-and-safety, or ranking systems can restrict access to work, services, or income.
For teams deploying such systems, comparable regulatory scrutiny typically turns on more than predictive accuracy. Meaningful human review, clear notice, an accessible appeal path, and records that explain how a decision was reached are recurring controls where an automated outcome can materially affect a person. The reported dispute also illustrates why separating temporary automated safeguards from permanent adverse decisions is consequential in system design and governance.
Uber told Reuters that it no longer makes permanent deactivation decisions solely through automated systems. The appeal means the EUR 825 million penalty remains contested. Reuters noted that headline penalties imposed on large technology companies under European rules are frequently challenged and can be reduced or overturned after extended appeals.
Only Meta's EUR 1.2 billion 2023 Irish GDPR penalty, concerning data transfers to the United States, exceeds the Uber penalty, Reuters reported.
Key Points
- 1Dutch regulators imposed a EUR 825 million GDPR penalty after finding Uber used automated driver deactivations without adequate information or human involvement.
- 2The case applies GDPR protections to platform-work decisions, where automated fraud and rating controls can materially affect a driver's income.
- 3Comparable high-impact automated systems commonly require explainability, notice, appeal mechanisms, and meaningful human review alongside model performance controls.
Scoring Rationale
This is one of the largest GDPR penalties to date and directly concerns automated decisions affecting workers' livelihoods. It is highly relevant to teams building trust, fraud, ranking, and enforcement systems that can deny users access to income or essential services.
Sources
Public references used for this report.
Practice with real Ride-Hailing data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Ride-Hailing problems
