Uber hit with €825M GDPR fine over automated driver deactivations
The Dutch Data Protection Authority has fined Uber €825 million for using fully automated algorithms to suspend or block driver accounts without sufficient human oversight or transparency. The ruling highlights increasing regulatory scrutiny on the use of automated decision-making systems in managing distributed workforces, citing violations of GDPR requirements.
Key Takeaways
- The €824,990,000 penalty is the second-largest GDPR fine ever issued, representing 1.85% of Uber’s 2025 global turnover.
- Regulators found Uber breached transparency requirements by failing to inform drivers that algorithms were responsible for account deactivations.
- The investigation originated from a complaint by 171 French drivers represented by the Ligue des droits de l’Homme.
- Uber plans to appeal the decision, arguing that permanent deactivations always involve human review and that the fine is disproportionate.
Why It Matters
This ruling signals that European regulators are now using existing data protection laws to police the algorithmic management of distributed workforces. For any platform using scoring systems or automated thresholds to manage users, the decision establishes that 'meaningful human review' must be a substantive process rather than a post-hoc rubber stamp. This enforcement action aligns with the emerging EU Platform Work Directive, which seeks to limit automated deactivations across the gig economy. As Uber appeals the findings, the industry should watch for how courts define the specific boundary between an algorithmic recommendation and a final human decision.
Additional Context
Uber's €825 million penalty from the Dutch Data Protection Authority is the largest GDPR fine ever issued by a Dutch regulator and ranks among the top enforcement actions across the EU. The case originated from a complaint filed by Ligue des droits de l'Homme, a French human rights organization, which brought the matter to CNIL before it was referred to the Dutch authority because Uber's European headquarters are in Amsterdam. This cross-border referral mechanism under GDPR's one-stop-shop provision has been used in several high-profile cases, but the Uber decision marks the first time it has produced a fine of this magnitude against a platform company for automated workforce management specifically.
The enforcement action arrives as the EU Platform Work Directive moves toward implementation. The European Parliament and Council reached provisional agreement on the directive in February 2024, establishing a legal presumption of employment for platform workers and explicitly restricting automated decisions affecting working conditions. Member states have until December 2026 to transpose the directive into national law. Uber has consistently opposed the directive's presumption clause, and the company spent €1.75 million on EU lobbying in 2024 alone, according to Corporate Europe Observatory's analysis of transparency register filings. The Dutch fine and the directive together create a dual regulatory pincer: GDPR enforcement punishes past automated decisions while the EU AI Act compliance deadlines will prospectively restrict them.
From a technical and compliance standpoint, the ruling draws a line that platform engineering teams must now operationalize. The Dutch authority found that Uber's systems lacked what it called "meaningful human intervention," a standard that Monique Verdier, vice chair of the Dutch Data Protection Authority, described as requiring a person with authority and competence to genuinely review the algorithm's output before any consequential action is taken. This echoes guidance the European Data Protection Board issued in its February 2025 recommendations on automated decision-making under Article 22, which clarified that a human reviewer must have the ability to override the system's conclusion, not merely confirm it. For streaming and platform companies that use , content scoring, or account management systems, the Uber case establishes that logging a human sign-off without genuine review capacity will not satisfy GDPR requirements.
Read full article at ioplus.nl
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source