The Dutch data protection authority has fined Uber €825 million for the way in which the platform used automated systems to suspend drivers’ accounts — the case highlights that the automation of business decisions is becoming an increasingly significant regulatory risk in Europe.
According to the Autoriteit Persoonsgegevens, between 2018 and 2022 Uber made decisions regarding some of its European drivers entirely automatically. The systems were able to temporarily block accounts where fraud was suspected and, according to the regulator, also permanently deactivate them due to low customer ratings. Drivers were reportedly not provided with sufficient information about how the mechanism worked, nor were they given adequate opportunities for human intervention.
The fine is the second-highest ever imposed under the GDPR, after the €1.2 billion fine imposed on Meta in 2023. Uber has announced it will appeal. The company claims the penalty is disproportionate and that permanent account deletion did not occur without human review. Current procedures are also designed to allow drivers to challenge suspensions.
The dispute has implications that extend beyond ride-hailing platforms. The GDPR restricts the ability of algorithms alone to make decisions that significantly affect individuals. In certain cases, safeguards are required, including the possibility of human intervention and the right to challenge decisions.
For companies, this means that the automation of HR processes, fraud detection, credit assessment or contractor management is no longer merely a technological project. The way in which human oversight, decision justification and appeal procedures are designed can have a direct impact on a company’s financial risk. The Uber case may further encourage European regulators to scrutinise more closely systems that automatically determine people’s access to work and income.
