What Uber Did Wrong Under GDPR

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has fined Uber €825 million, roughly $966 million, making it one of the largest penalties ever issued under the General Data Protection Regulation. The fine centers on Uber's use of automated systems to suspend or deactivate driver accounts. Under GDPR, individuals have the right to understand how automated decisions affecting them are made and to challenge those decisions with a human reviewer. Regulators found that Uber's process for cutting off drivers, sometimes with significant financial consequences, did not give affected drivers adequate transparency or a meaningful way to contest the outcome.

This is not Uber's first run-in with Dutch regulators. In 2024, the same authority fined Uber €290 million for transferring the personal data of EU-based drivers to servers in the United States without proper safeguards. That case involved Standard Contractual Clauses, the legal mechanism companies use to justify moving European data overseas. Uber reportedly stopped using those clauses after August 2021, leaving driver data insufficiently protected during international transfers. Together, the two penalties paint a picture of a company that has repeatedly struggled to align its internal data practices with GDPR's core requirements around transparency, consent, and cross-border transfers.

How GDPR Enforcement Actually Works

GDPR is enforced by national data protection authorities in each EU member state, not by a single centralized European regulator. Because Uber's European operations are headquartered in the Netherlands, the Dutch authority took the lead on this case, similar to how Ireland's Data Protection Commission handled a separate €1.2 billion fine against Meta in 2023 for privacy violations tied to data transfers, a penalty Meta has appealed.

This structure means the authority overseeing a company depends on where that company's main EU establishment is located, and enforcement actions can take years to conclude. Regulators investigate complaints, request documentation, and issue fines that companies frequently appeal, extending the process further. For readers trying to understand how these investigations unfold and what powers regulators actually hold, the CNIL explainer offers a useful look at how one of Europe's most active data protection authorities operates, since the same fundamental enforcement principles apply across EU member states, including the Netherlands.

What This Means for Your Personal Data

The scale of Uber's fine, now totaling over €1.1 billion across two enforcement actions, reflects how seriously EU regulators treat automated decision-making and data transfer violations. But the size of a fine doesn't undo the impact on the people whose data was mishandled in the first place. Drivers who had their accounts automatically suspended without clear explanation or recourse experienced real financial harm, and no penalty paid to a regulator directly compensates them for that.

This case is a reminder that GDPR exists because companies, even large, well-resourced ones, don't always get data handling right on their own. Automated systems can make consequential decisions about people's livelihoods with little transparency unless regulators step in. If a company as prominent as Uber can rack up hundreds of millions in penalties for these practices, it's a signal that users should not assume any platform is automatically respecting their data rights simply because it operates in the EU.

Steps Users Can Take to Limit Exposure

While regulators handle enforcement, individuals still have practical steps they can take. Review the privacy settings and data permissions on apps you use regularly, including rideshare and gig platforms, and limit what data you share when possible. If you believe an automated decision has affected you unfairly, GDPR gives you the right to request human review and to ask a company to explain the logic behind that decision. You can also file a complaint directly with your national data protection authority if a company is unresponsive.

Keeping personal data minimal wherever you can, using strong account security, and staying informed about how platforms handle cross-border data transfers all reduce your exposure to the kind of issues that led to Uber's fines.

The Bigger Picture

Uber's €825 million penalty over driver data underscores a broader truth about GDPR fine enforcement: privacy protections only work when regulators actively hold companies accountable, and users benefit from understanding those protections themselves rather than assuming corporate goodwill will fill the gap. As more automated systems shape everyday decisions, from account suspensions to service eligibility, staying informed about your rights under GDPR is one of the most effective tools you have. Take time to review how the platforms you rely on handle your data, and don't hesitate to exercise your right to question automated decisions that affect you directly.