Uber is facing an €825 million GDPR fine tied to a practice that likely sounds familiar to anyone who has ever been locked out of an account with no explanation: automatically suspending drivers based on algorithmic decisions, without a human ever reviewing the case. The penalty is one of the largest privacy fines in recent memory, and it puts a spotlight on a right that most internet users don't realize they have, the right not to be subject to purely automated decisions that carry real consequences.
What Uber Did: Algorithmic Suspensions Without Human Review
At the center of this case is Uber's system for deactivating drivers. According to regulators, drivers could be suspended, and in effect lose their income, based entirely on automated assessments of their activity, fraud signals, ratings, or other data points, without a person ever stepping in to confirm the decision was fair or even accurate. For a gig worker, a suspension isn't a minor inconvenience. It can mean an immediate loss of livelihood, often with little clarity about why it happened or how to appeal it.
This is not a story about a single rogue algorithm making a mistake. It's about a structural choice: building a system where machines make consequential decisions and humans are optional. That distinction matters enormously under European privacy law, and it's why the fine reached hundreds of millions of euros rather than a warning letter. Readers who want the full regulatory backstory, including how the penalty was calculated and what the Dutch authority found, can review the Dutch regulator's original GDPR fine against Uber for more detail on the case.
How GDPR's Article 22 Protects Against Automated Decisions
The legal foundation for this fine sits in Article 22 of the GDPR, a provision that gives individuals the right not to be subject to a decision based solely on automated processing when that decision produces legal effects or similarly significantly affects them. Losing access to your primary source of income clearly qualifies.
The rule doesn't ban automation outright. Companies can use algorithms to flag issues, score risk, or triage cases. What GDPR requires is that when a decision has serious consequences, a human has to be meaningfully involved, someone with the authority and information to actually override the machine, not just rubber-stamp its output. Regulators have increasingly treated "a person clicked approve" as insufficient if that person never had a real chance to investigate or reverse the outcome. Uber's case suggests that gap, between having a human in the loop on paper and having one in practice, is exactly where companies get into trouble.
Beyond Gig Work: Shadowbanning, Account Bans, and Data Deletion Requests
While this fine involves a rideshare company, the underlying issue extends well past gig work. Social media platforms use automated systems to shadowban accounts or remove content. Banks and payment processors use algorithms to freeze accounts over suspected fraud. Streaming services and marketplaces auto-ban users for flagged behavior. Even data deletion and access requests, core GDPR rights, are often processed by automated systems that can silently reject a legitimate request without any human review.
In each of these scenarios, the same tension applies: convenience and scale for the company, versus due process and transparency for the individual. Most users never think to ask whether a human reviewed the decision that affected them, largely because platforms rarely disclose it. Uber's fine signals that regulators are starting to treat that opacity as a compliance risk, not just a customer service annoyance.
What This Means For You
If you've ever been suspended, banned, or denied a request by an app or platform with no clear explanation, there's a good chance an algorithm made that call with minimal or no human oversight. Under GDPR, if you're in the EU or your data is processed by a company operating there, you generally have the right to ask for an explanation of automated decisions that significantly affect you, to contest the decision, and to request meaningful human review. Companies operating in this space are legally required to build in that safety valve, even if it's not obviously advertised.
This case also raises the practical value of being cautious about how much control you hand over to platforms that rely heavily on automated enforcement. Understanding your GDPR automated decision-making rights isn't just an abstract legal concept, it's a tool you can actually invoke when an app locks you out or an algorithm flags your account.
Key Takeaways
If you find yourself on the receiving end of an automated suspension, ban, or rejection, it's worth taking action rather than assuming the decision is final. Request a written explanation of how the decision was made and whether a human reviewed it. Cite your GDPR rights explicitly if the company is subject to EU law, and file a complaint with the relevant data protection authority if you don't get a satisfactory response. Keep records of your communications with the platform, since a documented pattern of automated, unreviewed decisions is exactly the kind of evidence that led to Uber's €825 million fine. As more of daily life gets filtered through algorithms, knowing these rights, and using them, is one of the clearest ways to push back when the machine gets it wrong.




