On August 21, 2026, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, or AP) handed Uber a fine of €824,990,000, making it the second-highest GDPR penalty ever issued. The case centers on a narrow but consequential question: can a company let software decide, without human involvement, when to cut off someone's livelihood? For Uber drivers whose accounts were deactivated by automated systems, the answer from Dutch regulators is a firm no. This GDPR automated decision-making fine is a landmark test of how far companies can lean on algorithms to manage people.
What the Dutch DPA Found Uber Did Wrong
The AP's investigation concluded that Uber deactivated drivers through fully automated processes, meaning decisions with serious consequences (loss of income, loss of platform access) were made without meaningful human review. Under the General Data Protection Regulation, that kind of automated decision-making is only lawful under specific, narrow conditions. The AP determined Uber's practices did not meet them, and the size of the fine reflects both the scale of Uber's European operations and the severity of the violation. Two earlier reports on this story cover the penalty itself and the underlying practices in more detail; readers who want the full breakdown of the fine and how it was calculated can review the Dutch Regulator Hits Uber With $966M GDPR Fine coverage, as well as the companion report on the Dutch DPA Fines Uber €825M Over Driver GDPR Breach. This piece focuses instead on the privacy right at the heart of the case: the legal protection against being judged solely by a machine.
How GDPR's Article 22 Protects Against Fully Automated Decisions
The legal foundation for the AP's decision is Article 22 of the GDPR, which gives individuals the right not to be subject to a decision based solely on automated processing when that decision produces legal effects or similarly significantly affects them. Losing access to a platform that is someone's primary source of income clearly qualifies. Article 22 does not ban automation outright. Companies can use automated systems if they get explicit consent, if automation is necessary for a contract, or if it is authorized by law, and even then, people are entitled to obtain human intervention, express their point of view, and contest the outcome. The core requirement is that a human being with the authority to change the outcome must be able to review the case. A rubber-stamp review, where a person simply confirms whatever the algorithm decided, does not satisfy this standard. Regulators across Europe have increasingly focused on this distinction between genuine human oversight and cosmetic human involvement.
Why Automated Profiling Matters Beyond Gig Work
Uber's case involves drivers, but the same legal principle touches far more of daily life than ride-hailing. Automated scoring and decision systems now influence credit approvals, insurance pricing, hiring screens, fraud flags on financial accounts, and content moderation on major platforms. Any system that profiles a person and then triggers a consequential outcome, without a human meaningfully checking the result, risks running into the same Article 22 problem the AP identified. The fine signals to companies operating in the EU that automated pipelines built for efficiency still need a real human checkpoint when the stakes for individuals are high. It also gives ordinary users a clearer sense of what to look for: opaque, unexplained account suspensions or rejections that come with no path to a human reviewer are a red flag under EU privacy law.
What This Means For You
If you use platforms based in or operating within the EU, whether for work, lending, insurance, or anything else, you generally have the right to ask whether a decision affecting you was made by a human or a machine. You can request an explanation, ask for human review, and challenge the outcome. Companies are supposed to build these options into their processes, not treat them as optional extras. The Uber fine underscores that regulators are willing to impose severe financial penalties, not just warnings, when firms skip this step. That gives real weight to complaints filed with data protection authorities when a platform ignores or stonewalls a request for human review.
Key Takeaways
If you've been affected by an automated decision on any platform, request a full explanation in writing and specifically ask for human review, since this is a right under GDPR Article 22, not a courtesy. Keep records of any deactivation, rejection, or denial notices, including timestamps and the reasoning given, since these details matter if you later file a complaint with a data protection authority. If a company refuses to provide human review or a clear appeals path, you can escalate directly to your national data protection authority. Uber's €825 million penalty shows that this GDPR automated decision-making fine framework has real teeth, and it's a reminder that people, not just platforms, hold meaningful power to push back when algorithms make the final call.




