← All posts / Policy

Uber Fined €825 Million for Letting Algorithms Fire Drivers

The Dutch data regulator hit Uber with the second-largest GDPR fine in history for deactivating driver accounts by algorithm alone — a landmark moment for AI governance and worker rights.

Uber Fined €825 Million for Letting Algorithms Fire Drivers

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, or AP) has fined Uber €825 million ($966 million) for using automated systems to deactivate driver accounts without adequate human review — the second-largest penalty ever issued under Europe’s GDPR, surpassed only by the €1.2 billion fine Ireland’s regulator imposed on Meta in 2023 over transatlantic data transfers.

The decision, dated August 17 and confirmed publicly on Friday, August 21, 2026, is the most consequential enforcement action to date against “robo-firing” — the practice of letting software algorithms terminate people’s livelihoods without a human ever looking at the case.

What Uber’s algorithms did

The case concerns incidents across Europe between 2018 and 2022, originating from a complaint filed by French Uber drivers. It landed with the Dutch regulator because Uber’s European headquarters are located in the Netherlands.

According to the AP, Uber’s systems automatically suspended drivers suspected of fraud — including cases where the platform’s software concluded a driver had taken unnecessary detours to inflate fares or had accepted trips without intending to complete them. More seriously, the agency found that drivers with low customer ratings were sometimes permanently deactivated by computer alone, with no meaningful human involvement in the decision.

GDPR Article 22 bans decisions made solely by automated processing when they have significant effects on people’s lives — employment being the canonical example. The law requires meaningful human review and a genuine avenue to challenge the decision. The AP found Uber failed on both counts: drivers were cut off “without warning or human involvement.”

“Uber has committed serious infringements,” said Monique Verdier, deputy chair of the Dutch DPA. “From one moment to the next they no longer had any income … A computer should not make decisions on its own that have (such) major consequences.”

Uber’s defense — and the numbers dispute

Uber says it will appeal. “We strongly disagree with this decision and disproportionate fine,” a company spokesperson said, insisting that Uber takes drivers’ rights seriously and that its current policies include human review and processes for drivers to dispute suspensions.

The company disputes the regulator’s characterization on a key point: Uber claims it never automated permanent deactivation decisions and that fraud-related suspensions were usually brief, with permanent removals requiring human sign-off. To argue the fine is disproportionate, Uber also points to scale: only 126 drivers in Europe were deactivated due to low customer ratings in 2021, which the company calls a small fraction of its driver base.

The regulator calculated the fine as a fraction of Uber’s 2025 annual turnover — the standard GDPR methodology that ties penalties to global revenue, which is precisely what makes this enforcement regime so feared by platform companies.

Why this matters far beyond Uber

This fine lands at the intersection of three of the most important debates in AI right now.

First, it’s a template for regulating automated decision-making. As AI agents increasingly make or recommend consequential decisions — hiring, lending, insurance, account bans, gig-work deactivations — regulators need enforcement precedents that show the line between acceptable automation and unlawful robo-decision. The €825 million figure makes clear that “the algorithm decided” is not a legal defense when someone’s income is on the line.

Second, it escalates the US-EU regulatory conflict. European regulators have now imposed billions of euros in penalties on American tech companies under privacy, competition, and digital-markets rules — the EU fined Google €890 million for anti-competitive actions just last month. Meta, Google, Apple, and Amazon all face multiple fines, though headline amounts are often reduced or reversed after years of appeals. President Donald Trump has publicly criticized these fines, and in April a US State Department official called them the “biggest single source of friction” in US-EU economic relations. An appeal from Uber could take years.

Third, it empowers workers and civil society. The case only exists because of a years-long effort by drivers and the Swiss digital-rights group PersonalData.IO, which helped French drivers demand access to data about the algorithmic decisions affecting their work — a GDPR right that seeded the eventual Dutch investigation. The group’s founder, Paul-Olivier Dehaye, says it is now preparing a class action suit against Uber seeking compensation for drivers, meaning the financial exposure may not end with the fine itself.

The bigger picture: human-in-the-loop becomes law

For AI practitioners, the message is blunt. The same week the industry races to deploy autonomous agents that can take actions on users’ behalf, Europe’s regulators have just put a nine-figure price tag on the failure mode everyone in the field knows well: an automated system making an irreversible, high-stakes decision about a person with no human in the loop and no meaningful appeal path.

The pattern is not unique to Uber. Delivery riders, content creators, marketplace sellers, and gig workers across the platform economy routinely report account terminations triggered by fraud-detection or quality-scoring systems that are opaque by design. What makes this case a landmark is that a regulator finally quantified the harm at a scale companies cannot ignore — nearly a billion dollars for the governance gap around one category of automated decision.

Expect two follow-on effects. Other national data protection authorities will likely dust off their own Article 22 enforcement files against platforms operating in their markets. And compliance teams across the tech industry will be scrambling to audit which of their automated systems touch employment-like decisions — and whether their “human review” is genuinely substantive or merely a rubber stamp, which courts and regulators have repeatedly warned does not satisfy the law.

Uber’s appeal will run for years, and the final number may shrink. But the principle is now etched into enforcement history: when an algorithm can take away someone’s livelihood, a human must be meaningfully accountable — and the cost of forgetting that is measured in hundreds of millions of euros.