← All posts / Policy

€825 Million: Dutch Regulator Fines Uber a Near-Record GDPR Penalty for Letting Algorithms Fire Drivers

The Dutch DPA's €824.99M fine — the second-largest GDPR penalty ever — punishes Uber for fully automated account deactivations that cut off drivers' income with no human review from 2018 to 2022, and it sets a compliance bar every platform running algorithmic decisions now has to clear.

€825 Million: Dutch Regulator Fines Uber a Near-Record GDPR Penalty for Letting Algorithms Fire Drivers

The largest penalty ever imposed for automated decision-making landed on August 21, 2026, and it landed on one of the most algorithmically managed companies on earth. The Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, fined Uber €824,990,000 (about $966 million) for deactivating drivers’ accounts through fully automated systems without adequate human review or transparency — the second-largest GDPR fine in history, behind only Ireland’s €1.2 billion penalty against Meta in 2023.

The decision matters far beyond ride-hailing. It is the most expensive confirmation yet of a principle that every company deploying AI agents and algorithmic management is now being forced to internalize: when a machine’s output strips someone of their livelihood, a human has to be meaningfully in the loop — and the people affected have to be told it’s happening.

What Uber’s systems did

Between 2018 and 2022, according to the AP’s findings, Uber ran software that continuously tracked drivers’ driving behavior and customer ratings. The logic was blunt:

  • When the software flagged a suspicion of fraud, the driver’s account was automatically deactivated — temporarily at first.
  • When customer reviews were judged too low, accounts were automatically deactivated, temporarily for a first flag and permanently where low ratings persisted.
  • No person assessed the outcome at any stage. Income through the platform stopped the moment the system acted.

The AP held that this violated Article 22 of the GDPR, which prohibits decisions based solely on automated processing that significantly affect individuals — unless narrow exceptions apply and safeguards, including the right to human intervention, are provided. Uber qualified on neither count. The regulator additionally found that Uber did not sufficiently inform drivers that automated decision-making was running at all. A deactivation notice, the reasoning goes, is not an explanation; Articles 13 and 14 require disclosing the logic involved and the significance and envisaged consequences of the processing.

Monique Verdier, deputy chair of the AP, did not mince words in the authority’s statement: “Uber has committed serious infringements. Drivers were deactivated without pardon. From one moment to the next, they no longer had any income through Uber. That’s forbidden. A computer should not make decisions on its own that have major consequences for you. These decisions should have been looked at first by a human being.”

How a French complaint became a Dutch record fine

The case’s procedural path is a blueprint for how cross-border algorithmic enforcement now works in Europe. In 2020, the Ligue des droits de l’Hombe (LDH), a French human rights organization, filed a collective complaint with France’s CNIL on behalf of more than 170 Uber drivers, later supplemented in 2021. The complaint covered three issues: inadequate information provided to individuals, transfers of personal data outside the EU, and automated decisions to temporarily or permanently disconnect drivers.

Because Uber’s European headquarters sit in Amsterdam, the GDPR’s one-stop-shop mechanism handed the file to the Dutch AP as lead supervisory authority. The CNIL cooperated closely throughout — during the checks, the analysis of evidence, and the examination of the draft decision — and the AP aligned the fine with other European supervisors before imposing it.

This is the same complaint pathway that produced Uber’s two previous European penalties: €10 million in December 2023 for failing to inform drivers (retention terms and obstructed access requests), and €290 million in July 2024 for transferring driver data to the United States. The August 2026 decision resolves the third and final pillar of the LDH complaint. The AP has now fined Uber four times in total — €600,000 in 2018, €10 million in 2023, €290 million in 2024, and €824.99 million now — a nominal sum of more than €1.12 billion against a single company.

Reading the numbers

The fine’s scale is best understood against three reference points.

Against Uber’s revenue. GDPR fines are capped at 4% of worldwide annual turnover. The AP put Uber’s 2025 global turnover at roughly €44.5 billion, setting the theoretical ceiling near €1.78 billion. The penalty lands at about 1.85% of turnover — under half of what the regulator could have imposed, which suggests the AP calibrated the amount to survive appeal rather than to maximize headlines.

Against all of Europe. According to the European Data Protection Board’s annual report published April 9, 2026, every data protection authority across the EEA issued a combined €1,145,760,374 in GDPR fines during the whole of 2025. This single Uber decision is worth roughly 72% of that entire year’s total across 30 countries. The AP itself accounted for €353.4 million of 2025’s total across 42 enforcement actions — a regulator that fines rarely but heavily, by deliberate posture.

Against the enforcement reality. Uber has filed an appeal, calling the amount disproportionate and telling the Associated Press the regulator examined “historic policies that were discontinued years ago.” The company says its current process routes permanent deactivations through a human and gives drivers a way to contest them. A May 2026 analysis found nearly 40% of the €7.1 billion in announced GDPR penalties have been either struck down or are still being fought — including OpenAI’s overturned €15 million Rome penalty and Amazon’s returned €746 million Luxembourg fine. Treat €824.99 million as an opening position, not a bank transfer. Uber is simultaneously contesting the 2023 and 2024 fines, leaving three of the four Dutch decisions against it open at once.

Why this is really a story about AI agents

The legal ground under this decision is shifting in two directions at once, and both matter for anyone shipping automated systems.

The Digital Omnibus would rewrite Article 22. The European Commission’s Digital Omnibus proposal, published November 19, 2025, would transform Article 22 from an individual’s right into a list of conditions under which automated processing is permitted — and states plainly that offering a human alternative does not stop a controller from deciding by machine alone. Had that text been law between 2018 and 2022, the AP would have been arguing a different case. Whether that reform survives contact with the European Parliament is now one of the most consequential open questions in AI governance.

The Platform Work Directive adds a second layer. EU member states must transpose the platform work directive into national law by December 2, 2026. It regulates algorithmic management directly — not through data protection principles but as labor law. Sweden’s implementation inquiry, led by Supreme Court justice Jonas Malmberg, proposes that platform employers negotiate with relevant trade unions before introducing or changing automated monitoring or decision systems, hand over data protection impact assessments, and evaluate in writing at least every two years how automated decisions affect the people subject to them.

And the test the AP applied travels well beyond ride-hailing. Nothing in its reasoning depends on transport or on whether a system is marketed as AI. What matters is whether an automated output lands a significant consequence on an identifiable person. Credit refusals, fraud blocks, automated account suspensions, eligibility screening, and revoked access all sit inside that frame — and regulators are converging on it. Austria’s authority reached the same conclusion about automated credit scoring in September 2025, and in November a German administrative court ordered Schufa to show how it derives individual scores.

The AP’s own draft guidance on “meaningful human intervention,” opened for consultation in March 2025, offers the sharpest compliance test: the person reviewing an automated outcome must have the standing to reverse it — and must actually reverse it when the file warrants. A reviewer who has never once said no is not oversight.

The bottom line

For the AI industry, the Uber fine is the clearest statement yet that the agent era’s defining legal risk is not model capability but decision governance. As companies race to deploy autonomous agents that can take real-world actions — suspending accounts, blocking payments, screening applicants — European regulators have now priced the failure mode at nearly a billion euros. The companies that treat human-in-the-loop as an architectural requirement rather than a bolt-on afterthought will be the ones that don’t read about themselves in the next enforcement press release.

Uber has stopped the violations, according to the AP. The appeal will take years. The principle, though, is already in force — and every algorithmic system operating in Europe is now measured against it.