Amsterdam: In a landmark regulatory enforcement under the European Union's General Data Protection Regulation (GDPR), the Dutch Data Protection Authority (Autoriteit Persoonsgegevens - AP) has imposed a massive €825 million fine (approximately $966 million / ₹8,100 crore) on global mobility platform Uber. The penalty represents the second-largest GDPR sanction ever issued in the European Union, surpassed only by the €1.2 billion fine levied against Meta in 2023. Readers tracking international technology policy and corporate compliance can follow real-time reporting on our global business and technology news desk.

The Core Violation: Automated Suspensions and Lack of Human Review

The Dutch privacy watchdog concluded that between 2018 and 2022, Uber deployed automated algorithmic systems and software to track driving patterns, ride routes, and customer review scores, automatically suspending or permanently deactivating driver accounts suspected of fraud, such as taking indirect routes to inflate fares. The regulator found that these punitive measures were executed entirely through automated processes without mandatory human review or prior warning, directly stripping drivers of their primary source of income.

GDPR Legal Framework on Automated Decision-Making

Under statutory provisions of the EU GDPR, commercial entities are strictly prohibited from subjecting individuals to decisions based solely on automated processing—including profiling—that produce legal effects or significantly impair their livelihood. The Dutch regulator noted the following core compliance failures:

  • Absence of Meaningful Human Oversight: Account terminations and temporary blocks were executed automatically by software routines rather than reviewed by human compliance officers.
  • Lack of Transparency: Uber failed to adequately inform affected drivers about the specific algorithmic logic, criteria, or evidence leading to their suspensions.
  • Impaired Right to Contest: Drivers were denied immediate, effective mechanisms to challenge automated deactivation decisions before suffering financial disruption.

Cross-Border Enforcement and Origin of Complaints

The investigation originated from complaints filed by 171 French drivers represented by the human rights advocacy group Ligue des droits de l'Homme (LDH) with France's privacy regulator (CNIL). Because Uber's European corporate headquarters is based in Amsterdam, the Dutch AP assumed lead supervisory jurisdiction under the GDPR's 'one-stop-shop' cross-border mechanism in coordination with other European privacy authorities.

Uber's Stance and Forthcoming Appeal

Uber strongly rejected the ruling and described the €825 million sanction as disproportionate, confirming it will file a formal legal appeal in the Dutch courts. An Uber spokesperson stated that the investigation examined historical operational policies that have since been discontinued. The company maintained that its current protocols include human oversight, robust safeguards, and structured dispute resolution channels for all account suspensions.