Uber Faces One of Europe’s Biggest Privacy Penalties
Uber has been fined €825 million ($966 million) by the Dutch Data Protection Authority over the way its automated systems handled driver accounts, in one of the largest penalties ever issued under Europe’s General Data Protection Regulation.
The Dutch regulator, known as the AP, said Uber violated drivers’ rights by using automated systems to make decisions that could have a significant impact on their ability to work, while failing to provide sufficient information about those processes. The decision was dated August 17 and became public this week.
The penalty is the second-largest GDPR fine to date, behind the €1.2 billion penalty imposed on Meta in Ireland in 2023.
Uber has rejected the regulator’s findings and said it plans to appeal.
The case highlights a much broader question facing technology companies: how much power should algorithms have when their decisions can directly affect a person’s income?
What Triggered the Investigation?
The investigation began with complaints from Uber drivers in France and concerns events that took place between 2018 and 2022, with the relevant automated suspension practices including activity from 2020 to 2022.
The case was ultimately handled by Dutch authorities because Uber’s European headquarters are located in the Netherlands.
According to the Dutch regulator, Uber used automated systems to temporarily suspend drivers suspected of fraudulent activity.
Those systems could flag behavior such as allegedly taking unnecessary detours that increased fares or accepting trips without intending to complete them.
The company also used automated processes in connection with driver ratings, according to the regulator. In some cases, drivers with persistently low customer ratings were permanently deactivated.
For a technology platform, automatically identifying suspicious behavior can be an efficient way to manage millions of transactions.
But European privacy law places limits on what companies can delegate entirely to algorithms when the consequences for individuals are significant.
That distinction is at the heart of the Uber case.
Why GDPR Matters
Under the GDPR, individuals have protections against certain decisions made solely through automated processing when those decisions produce legal or similarly significant effects.
For an Uber driver, losing access to the platform is not simply a technical inconvenience.
For people who depend on the platform for their income, a suspension can immediately affect their ability to earn money.
The Dutch regulator concluded that Uber’s systems crossed that line and that affected drivers were not adequately informed about the automated decision-making involved.
The regulator’s decision therefore goes beyond a conventional privacy dispute.
It addresses the growing use of algorithms to make decisions about people’s employment, access to services and financial opportunities.
Uber Disputes the Regulator’s Findings
Uber strongly disagrees with the decision.
The company has said that the fine is disproportionate and that it will appeal.
Uber also disputes the regulator’s characterization of its permanent account deactivations.
The company maintains that it did not permanently deactivate drivers solely through automated systems without human involvement. Uber says its policies include human reviews and opportunities for drivers to challenge suspensions.
The company has also argued that the practices examined by the regulator are historical and that its current procedures provide greater human oversight.
That distinction will be important if the decision is challenged.
The issue is not simply whether software was involved.
Large technology platforms routinely use automated systems to detect fraud, suspicious behavior and violations of their rules.
The more difficult question is what happens after the algorithm makes its recommendation.
Does a qualified human genuinely review the evidence and have the authority to reverse the decision?
Or does the human simply approve what the software has already decided?
That distinction could become one of the most important technology-regulation questions of the coming years.
The Scale of the Fine Is Significant
The €825 million penalty is enormous even by the standards of European technology regulation.
The Dutch authority said the fine was calculated with reference to factors including the seriousness and scale of the violations and Uber’s turnover.
It is currently second only to the €1.2 billion GDPR fine against Meta.
But the size of the penalty should not be interpreted as meaning that every automated decision made by Uber was unlawful.
The regulator’s findings concern specific practices and a specific period.
Uber’s appeal could also challenge both the legal interpretation and the amount of the penalty.
Until the appeals process is complete, the regulator’s decision should therefore be described as a regulatory finding, rather than a final judicial determination.
A Warning for the Entire Gig Economy

The consequences of the case could extend far beyond Uber.
Food-delivery platforms, ride-hailing companies, online marketplaces and other gig-economy businesses increasingly rely on automated systems.
Algorithms can evaluate fraud risks, calculate ratings, identify suspicious behavior and determine whether an account should be investigated.
Automation is attractive because these platforms may have millions of users and workers.
Human beings cannot manually inspect every transaction.
But efficiency creates a new risk.
If an algorithm makes a mistake, the person affected may have little idea why the decision happened or how to challenge it.
That becomes particularly serious when the decision affects someone’s livelihood.
The Uber case could therefore become an important reference point for companies designing automated decision systems across Europe.
Europe Is Tightening Scrutiny of Big Tech
The decision also fits into a much broader European regulatory trend.
European authorities have increasingly challenged large technology companies over privacy, competition, data transfers and the use of automated systems.
Uber itself has faced previous enforcement action from Dutch regulators.
In 2024, the Dutch authority imposed a separate €290 million fine related to the transfer of European drivers’ personal data to the United States. Uber also challenged that decision.
The latest case shows that regulators are increasingly looking beyond where data is stored.
They are also examining how software uses that data to make decisions about real people.
That could become increasingly important as companies deploy more sophisticated artificial intelligence and automated decision-making tools.
The AI Question Behind the Uber Case
Although the Uber dispute is fundamentally a GDPR and algorithmic decision-making case, it also points toward a larger AI problem.
Companies are increasingly using automated systems to make decisions faster and at greater scale.
The technology can reduce costs and identify patterns humans might miss.
But automation also creates accountability problems.
When a person is denied a service, suspended from a platform or prevented from earning money, someone needs to be able to explain why the decision happened.
And if the decision was wrong, there must be a meaningful way to challenge it.
That principle is becoming increasingly important as AI moves from generating content to making operational decisions.
What Happens Next?
Uber is expected to appeal the Dutch regulator’s decision.
That means the €825 million penalty is unlikely to be the final chapter of the dispute.
The appeal could ultimately affect the size of the fine, the regulator’s interpretation of Uber’s systems or both.
For now, however, the message from European regulators is clear.
Automation does not remove responsibility.
A company cannot simply argue that a computer made the decision when that decision has serious consequences for a person’s livelihood.
The Bigger Story
The Uber case is ultimately about much more than one ride-hailing company.
It is about the rapidly changing relationship between people and algorithms.
Businesses increasingly depend on automated systems because they can process enormous amounts of information quickly.
But when those systems begin determining who can work, who can access a service or who is considered trustworthy, transparency and human oversight become much more important.
Truth Mode: this is not a case proving that algorithms are inherently dangerous, nor does the ruling mean that Uber has been prohibited from using automation.
The important point is narrower and more significant: European regulators have drawn a major line around automated decisions that can materially affect people’s lives.
And as AI becomes increasingly involved in decisions that once required human judgment, that line could become one of the most important boundaries in technology regulation.
For TheTechSpot, this is the real story: the future of technology may depend not only on what algorithms can decide, but on what society allows them to decide.