The Dutch Data Protection Authority has issued an €825 million fine against Uber for violating GDPR regulations by using automated algorithms to deactivate driver accounts without adequate human oversight between 2018 and 2022. Uber has denied wrongdoing and announced plans to appeal.
- The Dutch Data Protection Authority fined Uber €825 million ($966 million) for GDPR violations.
- Uber deactivated drivers' accounts using automated algorithms between 2018 and 2022 without human intervention.
- This penalty marks the second-largest GDPR fine in EU history, following Meta's €1.2 billion penalty in 2023.
- Uber announced it will appeal the decision, stating the findings relate to discontinued historical policies.
Amsterdam: In a landmark regulatory enforcement under the European Union's General Data Protection Regulation (GDPR), the Dutch Data Protection Authority (Autoriteit Persoonsgegevens - AP) has imposed a massive €825 million fine (approximately $966 million / ₹8,100 crore) on global mobility platform Uber. The penalty represents the second-largest GDPR sanction ever issued in the European Union, surpassed only by the €1.2 billion fine levied against Meta in 2023. Readers tracking international technology policy and corporate compliance can follow real-time reporting on our global business and technology news desk.
The Core Violation: Automated Suspensions and Lack of Human Review
The Dutch privacy watchdog concluded that between 2018 and 2022, Uber deployed automated algorithmic systems and software to track driving patterns, ride routes, and customer review scores, automatically suspending or permanently deactivating driver accounts suspected of fraud, such as taking indirect routes to inflate fares. The regulator found that these punitive measures were executed entirely through automated processes without mandatory human review or prior warning, directly stripping drivers of their primary source of income.
GDPR Legal Framework on Automated Decision-Making
Under statutory provisions of the EU GDPR, commercial entities are strictly prohibited from subjecting individuals to decisions based solely on automated processing—including profiling—that produce legal effects or significantly impair their livelihood. The Dutch regulator noted the following core compliance failures:
- Absence of Meaningful Human Oversight: Account terminations and temporary blocks were executed automatically by software routines rather than reviewed by human compliance officers.
- Lack of Transparency: Uber failed to adequately inform affected drivers about the specific algorithmic logic, criteria, or evidence leading to their suspensions.
- Impaired Right to Contest: Drivers were denied immediate, effective mechanisms to challenge automated deactivation decisions before suffering financial disruption.
Cross-Border Enforcement and Origin of Complaints
The investigation originated from complaints filed by 171 French drivers represented by the human rights advocacy group Ligue des droits de l'Homme (LDH) with France's privacy regulator (CNIL). Because Uber's European corporate headquarters is based in Amsterdam, the Dutch AP assumed lead supervisory jurisdiction under the GDPR's 'one-stop-shop' cross-border mechanism in coordination with other European privacy authorities.
Uber's Stance and Forthcoming Appeal
Uber strongly rejected the ruling and described the €825 million sanction as disproportionate, confirming it will file a formal legal appeal in the Dutch courts. An Uber spokesperson stated that the investigation examined historical operational policies that have since been discontinued. The company maintained that its current protocols include human oversight, robust safeguards, and structured dispute resolution channels for all account suspensions.
Comments (0)
Leave a Comment
No comments yet. Be the first to comment!