A Record-Setting GDPR Penalty

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, or AP) has fined Uber €825 million for deactivating drivers' accounts through automated systems without properly informing them of the decision or giving them a meaningful way to contest it. The penalty ranks as the second-largest ever issued under the General Data Protection Regulation (GDPR), underscoring how seriously European regulators are treating the use of automated decision-making against workers and consumers.

Because Uber's European headquarters sits in the Netherlands, the AP acts as the lead supervisory authority for the company's privacy compliance across the entire European Union under the GDPR's "one-stop-shop" mechanism. That gives the Dutch watchdog outsized influence over how Uber, and by extension other gig-economy platforms operating similarly, must handle personal data tied to employment-style decisions.

Why Automated Decision-Making Triggered a GDPR Violation

At the center of the case is the GDPR's requirement that individuals be told when a decision affecting them is made by an automated system rather than a human, and that they be given the right to obtain human review, express their point of view, and contest the outcome. Uber's drivers reportedly had their accounts deactivated by automated fraud-detection or performance systems without receiving that transparency or recourse. For drivers who rely on the platform for their livelihood, a sudden, unexplained account suspension can mean an immediate loss of income with no clear path to appeal.

This isn't the first time Uber's data practices in the Netherlands have drawn regulatory scrutiny. Earlier action from the AP included a €10 million fine in February 2024 over failures to disclose how long driver data was retained, and a separate €290 million fine in August 2024 for transferring European drivers' personal data to the United States without adequate safeguards. Together, these cases paint a picture of a company that has repeatedly run into friction with the EU's data protection framework, particularly around transparency and cross-border data handling. Readers interested in the fuller regulatory breakdown of this latest case can review the details in our earlier coverage of the Dutch DPA's €825 million fine against Uber.

What This Means For You

Most people reading about this fine aren't Uber drivers, but the case still matters if you interact with any platform that uses automated systems to make consequential decisions about your account, your data, or your access to a service. Ride-hailing apps, delivery platforms, freelance marketplaces, and even banking or insurance apps increasingly rely on algorithms to flag accounts, deny service, or restrict access. This ruling reinforces that under GDPR, you generally have a right to know when a machine, not a person, made that call, and a right to push back.

If you ever find an account deactivated or a service denied without explanation, especially within the EU, it's worth asking the company directly whether the decision was automated and requesting the human review that GDPR guarantees. Companies operating in Europe are legally obligated to provide this information, even if it isn't offered upfront.

The size of this fine also signals to platforms of all kinds, not just Uber, that regulators are willing to impose penalties large enough to actually change corporate behavior. For everyday users, that translates into stronger leverage when disputing account suspensions, data retention practices, or unclear terms of service tied to algorithmic decision-making.

The Bigger Picture on Platform Accountability

This case fits into a broader trend of European regulators pushing back against opaque algorithmic systems that affect people's income and access to services. As gig-economy platforms and app-based services continue expanding their reliance on automation, expect more scrutiny not just of what data is collected, but of how decisions are made with that data and whether affected individuals are given a fair chance to respond.

Key Takeaways

  • The Dutch AP fined Uber €825 million for deactivating driver accounts via automated systems without proper notice or appeal rights, the second-largest GDPR penalty on record.
  • GDPR requires meaningful transparency and human review when automated decisions significantly affect someone, whether that's a driver, a customer, or an app user.
  • If a platform deactivates your account or denies access without explanation, ask whether an automated system was involved and request a human review.
  • This fine adds to a pattern of Dutch regulatory action against Uber, following earlier penalties over data retention and international data transfers, and signals growing enforcement pressure on platforms that rely heavily on automation.