The Netherlands Fines Uber Over Algorithm-Only Account Deactivations

The Dutch data protection authority, the Autoriteit Persoonsgegevens, has fined Uber 825 million euros for deactivating driver accounts through an automated system with no meaningful human review, according to a document reported by Reuters and confirmed independently by Bloomberg and NL Times on August 21, 2026. The case covers incidents between 2020 and 2022, when Uber's fraud-detection software could suspend or permanently deactivate a driver's account, cutting off their income, without a person reviewing the decision first.

The investigation began after a complaint filed in France and was handled by the Dutch authority because Uber's European operations are based in the Netherlands, a mechanism GDPR calls the one-stop-shop rule for cross-border cases. Uber has said it strongly disagrees with the fine, argues its current process already includes human review and a driver dispute channel, and plans to appeal.

A Fine That Ranks Among Europe's Largest Ever

At 825 million euros, the penalty is the second-largest fine issued under GDPR since the regulation took effect in 2018, sitting behind only Ireland's 1.2 billion euro fine against Meta in 2023 for unlawfully transferring European user data to the United States, a decision Meta is still appealing. It is larger than Luxembourg's 746 million euro fine against Amazon in 2021, previously the second-biggest GDPR penalty on record.

CompanyFineYearViolation
Meta1.2 billion euros2023Unlawful EU-US data transfers
Uber825 million euros2026Automated driver account deactivation
Amazon746 million euros2021Advertising consent violations

The size of the fine signals how European regulators now price a specific, narrow failure: letting software make a consequential decision about a person's livelihood without a human able to meaningfully intervene. Unlike the Meta and Amazon cases, which involved broad data-handling practices across an entire user base, the Uber fine targets one automated process applied to a defined group of workers, and still reached nine figures.

The GDPR Rule Uber Fell Afoul Of

Article 22 of GDPR gives people the right not to be subject to a decision based solely on automated processing when that decision produces legal effects or similarly significantly affects them, unless a human reviews the outcome with real authority to change it. The Dutch authority found Uber violated both that right and the separate right to be informed, meaning drivers were not adequately told why their accounts were flagged or deactivated in the first place.

The distinction the regulator drew is not about whether software can flag a problem. It is about whether a human with genuine power to overturn the system's call reviewed it before the consequence landed. A dashboard a human glances at without real authority to reverse the decision does not satisfy the rule; the review has to be meaningful, not procedural.

What This Means for Any Company Automating Consequential Decisions

Uber is a ride-hailing platform, but the legal exposure this fine describes has nothing specific to gig work. Any European business that uses software to suspend a customer account, decline an insurance claim, flag a transaction as fraud, reject a loan application, or end a contractor relationship without a human able to meaningfully overturn the call sits on the same Article 22 ground Uber was fined for.

As AI features get folded into more back-office and customer-facing systems, the number of consequential decisions running through automated pipelines is rising faster than most companies' human-review processes are being redesigned to keep up. This fine gives every data protection officer a concrete reference point for board conversations: 825 million euros is what a regulator considers proportionate when a decision that ends someone's income runs through an algorithm with no real human check attached.