The Dutch data protection authority has fined Uber nearly 825 million euros, approximately $962 million, for using fully automated software to deactivate drivers’ accounts without human review, in one of the largest GDPR enforcement actions in European Union history.
The Netherlands’ Autoriteit Persoonsgegevens, known as AP, announced the fine on Aug. 21 and said the company tracked driver behavior and customer reviews entirely through software between 2018 and 2022 without any human assessment involved in the decision process. When the software flagged suspected fraud or detected low customer reviews, drivers’ accounts were automatically deactivated on a temporary basis. In cases of persistently low reviews, accounts were permanently deactivated.
The deputy chair of the regulatory body described the deactivations as sudden and merciless, saying drivers went from one moment to the next without any income through Uber. She said a computer should not make decisions that have major consequences for a person without those decisions being reviewed by a human being first.
What GDPR requires
The fine is based on provisions of the European Union’s General Data Protection Regulation, which grants individuals the right not to be subject to decisions based solely on automated processing when those decisions significantly affect them. The deactivation system, as described by the AP, appears to have operated as precisely the kind of fully automated decision-making that GDPR is designed to restrict.
The law requires that companies using automated decision-making provide individuals with meaningful human review and the ability to contest decisions that materially affect their lives and livelihoods. Account deactivation that ends a driver’s income clearly meets that threshold, and the AP concluded the company’s system failed to provide any such review.
The scale of the impact
The deactivations occurred over a four-year period and affected Uber drivers across markets where the company operates, including in the Netherlands where the AP has jurisdiction over its European operations. The regulator said many drivers lost their incomes as a result of the automated system.
The 825 million euro figure is one of the largest GDPR fines issued against a technology company. The regulation allows for fines of up to 4 percent of a company’s global annual revenue, and penalties of this size reflect regulators’ increasing willingness to use the full weight of the law against major platforms.
Uber’s position
Uber did not immediately respond publicly to the fine announced on Aug. 21. The company has the ability to appeal through EU administrative and legal processes, which is standard practice for penalties of this magnitude.
The broader enforcement trend
European regulators have significantly increased GDPR enforcement over the past several years, with major fines issued against Meta, Google, Amazon and other large technology companies. The Uber case is notable because it specifically targets automated decision-making that affects workers rather than advertising practices or data transfers, expanding the practical scope of enforcement to the gig economy.
The AP said it worked with data protection authorities in other EU member states in bringing the case, reflecting the cross-border nature of the company’s operations and the regulation’s intent to protect individuals regardless of where a company is headquartered.

