Compliance

Uber Fined Nearly €825 Million Over Automated Driver Deactivations

Uber Fined Nearly €825 Million Over Automated Driver Deactivations

On August 21, 2026, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) announced a €824.99 million fine against Uber. The AP found that, between 2018 and 2022, Uber deactivated certain driver accounts through fully automated means. The decisions significantly affected drivers’ access to work and income, while Uber failed to provide the drivers with sufficient information. Uber has announced that it will appeal.

Based on the materials currently available, the AP’s grounds for the fine principally concern whether account deactivation constituted a fully automated decision governed by Article 22 of the GDPR and whether the information provided to drivers made it difficult for them to understand and challenge the decisions. The AP has not yet published the full decision, so its detailed findings, assessment of the evidence and method for calculating the fine remain to be seen.

I. Facts of the Case

The case arose from complaints by 171 French Uber drivers. The French human rights organization Ligue des droits de l’Homme (LDH) filed the complaints on the drivers’ behalf with the French Data Protection Authority (Commission nationale de l’informatique et des libertés, CNIL). Because Uber’s main establishment in Europe is located in the Netherlands, the AP led the investigation under the GDPR’s one-stop-shop mechanism and cooperated with the CNIL during the investigation. The AP also coordinated its enforcement decision with other European data protection authorities.

According to the AP’s announcement, Uber used software to monitor drivers’ conduct on the road and customer ratings. When the system suspected fraud, it automatically deactivated an account temporarily—for example, where it determined that a driver had increased a fare by taking an unnecessary detour or had accepted a trip without intending to complete it. The AP also found that the system automatically and permanently deactivated the accounts of drivers whose customer ratings remained low. Once their accounts were deactivated, drivers could no longer accept trips or earn income through the Uber platform.

Uber disputes the AP’s factual finding concerning permanent deactivations. The company states that temporary deactivations triggered by suspected fraud were generally brief, that all permanent deactivations were subject to human review, and that it never permanently deactivated an account through automated means. Uber also states that 126 drivers in Europe were deactivated for low customer ratings in 2021 and that the number of affected drivers was limited.

II. The AP’s Grounds for the Fine

According to the AP’s announcement, the fine rests on two grounds: fully automated decision-making and insufficient information.

1. Account Deactivation Was an Automated Decision with Significant Effects

Article 22(1) of the GDPR provides that a person has the right not to be subject to a decision based solely on automated processing that produces legal effects concerning them or similarly significantly affects them. The AP considered that Uber’s system directly determined whether drivers could continue using the platform. Because account deactivation prevented drivers from earning income through Uber for the relevant period, it had a significant effect on them.

The AP further found that the deactivation decisions in suspected-fraud and low-rating scenarios were made without human judgment. In the announcement, AP Vice-Chair Monique Verdier stated that affected drivers could lose their platform income without warning and that decisions with such serious consequences should first be reviewed by a person. Based on the announcement currently available, the AP characterized the process as fully automated decision-making prohibited by the GDPR.

Article 22(2) of the GDPR provides exceptions for automated decisions that are necessary for entering into or performing a contract, authorized by law, or based on the individual’s explicit consent. Processing based on contractual necessity or explicit consent must also provide safeguards such as human intervention, an opportunity for the individual to express their point of view, and a way to contest the decision. The AP’s announcement does not state whether Uber invoked any of these exceptions or how the authority assessed them.

2. Drivers Were Not Given Sufficient Information About the Decisions

The AP also found that Uber did not adequately inform drivers about its use of automated decision-making. MLex’s report on the decision indicates that the authority considered the reasons given for deactivation insufficient, making it difficult for drivers to understand and challenge the decisions.

Under the relevant conditions, Articles 13, 14 and 15 of the GDPR require controllers to disclose the existence of automated decision-making, provide meaningful information about the logic involved, and explain the significance and envisaged consequences of the processing. The AP’s announcement summarizes the issue as a failure to provide drivers with sufficient information. It neither identifies the specific provisions on which the information-related finding was based nor discloses the notices Uber provided to drivers.

Information duties and human involvement address distinct issues. Human involvement determines whether a decision remains fully automated; disclosure determines whether drivers can understand the basis of a decision, verify the relevant facts, and exercise their right to object. Even where a company provides an appeal channel, the practical value of that appeal is weakened if the individual is not told the specific reasons and relevant data.

The AP states that the amount of the fine was based on Uber’s 2025 global turnover and calculated in accordance with the European data protection authorities’ fining guidelines. Uber considers the fine grossly disproportionate, citing the discontinuation of the relevant policies, the limited number of affected drivers, and the human review and appeal opportunities included in its current process.

III. Kaamel Analysis: Regulatory Attention Is Shifting from “Whether a Person Is Involved” to “Whether Review Is Effective”

The Guidelines on Automated Individual Decision-Making require companies not to circumvent Article 22 of the GDPR through merely formal human involvement. A reviewer must have the authority and competence to change the decision and must examine the input and output data relevant to the individual case. This case indicates that regulatory scrutiny is increasingly focused on reviewers’ authority, the timing of review, and records of actual operations.

Human judgment before a final decision and appellate review after a decision has been made serve different legal functions. If a person independently reviews the system’s output, considers other relevant facts, and makes the final determination before an account deactivation takes effect, the decision may no longer be “based solely on automated processing.” A post-decision appeal is a remedial mechanism; its availability does not automatically change the automated nature of the original decision. Companies therefore need to specify whether the system generates a risk alert, a recommended action, or a directly effective decision, and record the stage at which a person intervenes.

Reviewers must also have substantive decision-making authority. The effectiveness of human involvement may depend on whether the system interface presents both the triggering signals and contrary evidence, and whether reviewers receive appropriate training, have sufficient time, and can reverse a deactivation. A person who routinely confirms the system’s conclusion or can only refer an appeal to another team is unlikely to demonstrate that they independently assessed the individual case.

A company’s explanations, reviews, and records must also form a continuous chain of evidence. Notices should enable drivers to understand the principal factual basis and applicable rules for a deactivation. Reviewers should be able to access the relevant data, hear the driver’s account, and explain why the decision was upheld or reversed. System logs and case records should allow the automated output, human judgment, and final outcome to be reconstructed. Regulators can then assess whether the company’s human involvement is consistent in its policies and actual operations.

Directive (EU) 2024/2831 of the European Parliament and of the Council of 23 October 2024 on improving working conditions in platform work (the “Platform Work Directive”) further specifies the requirements applicable to platform work. Member States must transpose the Directive into national law by December 2, 2026. Article 10 requires decisions to restrict, suspend or terminate a platform worker’s account, among other decisions, to be taken by a human being; persons entrusted with oversight must also have the competence and authority to override automated decisions. Article 11 requires the platform to state the reasons for its decision and, in principle, to provide a sufficiently precise and adequately substantiated written reply within two weeks after receiving a request for review.

Until the AP publishes its full decision, the scope of this case will continue to depend on the specific process identified by the authority, the evidence submitted by Uber, and the outcome of the appeal. Companies can begin by examining four facts along the decision chain: whether a system output takes direct effect; when a person intervenes; whether that person can access complete information and change the outcome; and whether affected individuals receive specific reasons and effective review. These facts will determine whether “human involvement” can be regarded as an effective control under regulatory scrutiny.

References

Start Your Compliance Journey !

Contact security and privacy veterans at Kaamel

https://kaamel.com
info@kaamel.com
340 E Middlefield Rd, Mountain View, CA 94043
AICPA Drata
© 2024 Kaamel Inc. All rights reserved.