Technology

Uber’s €825 million fine: a warning for businesses using automated decision making

2 Sep 2026

On 21 August 2026, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) (“AP”), announced a fine of €824.99 million against Uber for making fully automated decisions about drivers. The automated decisions included temporary and permanent account deactivations, meaning drivers could lose access to their income from the Uber platform without meaningful human involvement in the decision-making process. The AP concluded that this infringed the GDPR’s restrictions on solely automated decision-making and that Uber had not provided sufficient information to drivers about the automated processes being used.

For businesses that are increasingly deploying AI and automation tools to manage workforces, customers and commercial operations, the case provides a reminder that automation must not come at the expense of legal compliance or appropriate governance.

What happened?

The AP reported that between 2018 and 2022, Uber used automated systems to monitor driver behaviour and customer ratings. Where the system detected suspected fraud, or customer ratings fell below certain thresholds, drivers’ accounts could be automatically deactivated. Some deactivations were temporary, while others were permanent.

The regulator found that these decisions were taken without meaningful human assessment and that the deactivations had significant consequences for affected drivers because they could prevent individuals from earning income through the platform. Uber has now stopped the infringements identified during its investigation and has appealed the fine.

What does the GDPR say about automated decision making?

Not all automated decision making is prohibited. But if systems make decisions that could seriously affect people, Article 22 GDPR requires organisations to check that the law allows it, explain to affected individuals clearly what is happening, and provide appropriate protections.

The UK Information Commissioner’s Office (ICO), the UK’s independent regulator for data protection and information rights, cites examples such as recruitment decisions, credit applications, insurance decisions and access to public services, all of which can have a significant impact on an individual’s financial position, employment opportunities or access to services.

Where organisations seek to rely on automated decision-making, they must carefully assess whether:

  • the automated decision could seriously affect the person concerned
  • there is a lawful reason for using the system in that way
  • individuals are adequately protected
  • individuals can understand what happened and challenge the decision and ask for human review

Importantly, simply inserting a nominal human review stage will not necessarily be sufficient. Regulators have consistently emphasised that any human involvement must be genuine, meaningful and capable of influencing the outcome.

Why businesses should pay attention

Many organisations now use AI and automation tools for processes such assessing job applicants, monitoring employee performance, detecting fraud and determining access to products or services.

Where automated systems can significantly affect individuals, businesses should carefully assess whether Article 22 GDPR may apply and whether sufficient human review mechanisms exist.

Businesses should ensure legal, compliance, procurement, HR and operational teams are aligned when deploying AI-enabled systems. Key questions include:

  • What decisions is the system making or influencing?
  • Can decisions be explained and justified?
  • Is meaningful human intervention available?
  • Are individuals given sufficient information about how decisions are reached?
  • Have appropriate risk assessments and DPIAs been undertaken?

A growing area of regulatory focus

GDPR fines can reach up to 4% of a company’s worldwide annual turnover. Uber’s global turnover was approximately €44.5 billion in 2025. The regulator described the infringements as serious and emphasised the significant consequences for affected drivers.

Whether or not the fine survives the appeal process, the decision reflects a broader regulatory trend. European regulators have repeatedly indicated that algorithmic decision-making, AI governance and workplace surveillance will remain enforcement priorities.

As organisations increasingly look to AI to improve efficiency and reduce costs, the case highlights that transparency, accountability and effective human oversight remain fundamental regulatory expectations.

What should businesses do now?

Organisations using AI or automated decision-making tools should take the opportunity to review existing practices. In particular, businesses should:

  • identify where automated decision-making is being used;
  • assess whether any decisions could fall within Article 22 GDPR;
  • ensure meaningful human oversight is built into decision-making processes;
  • review privacy notices and transparency information;
  • carry out or update DPIAs where appropriate;
  • audit supplier arrangements and contractual protections; and
  • establish clear governance structures for AI deployment.

The Uber decision serves as a reminder that efficiency gains cannot come at the expense of fundamental rights. As organisations continue to embed AI into core business functions, transparency, accountability and meaningful human oversight remain essential components of effective risk management.

 

Hans Schumann

Legal director
Commercial and Tech

Tessa Derkacz

Trainee Solicitor

 Download PDF
Share