The Dutch Data Protection Authority (AP) has announced a proposed €825 million fine against Uber, the second-largest penalty issued under the EU’s General Data Protection Regulation (GDPR) to date, trailing only Meta’s €1.2 billion fine in 2023 for cross-border data violations. Uber has stated it will appeal the decision.

The case traces back to a 2019 complaint by a former Uber driver in France whose account was deactivated by the platform. Together with 170 fellow drivers, he gathered evidence alleging that Uber relied entirely on automated algorithms to handle driver complaints and account suspensions, then submitted the complaint through a civil society group to a French human rights organization. Because Uber’s European headquarters is in the Netherlands, the investigation was ultimately led by Dutch regulators.
According to the AP, between 2018 and 2022 Uber’s systems tracked drivers’ routes in real time and monitored passenger ratings, then automatically flagged suspected fraud—such as taking unnecessary detours to inflate fares—and deactivated accounts without human review. Drivers with persistently low ratings could face permanent deactivation, effectively cutting off their income.

The regulator concluded that Uber violated GDPR provisions that prohibit decisions with significant consequences for individuals being made solely by automation, and that require meaningful human involvement and a clear path to challenge the outcome. The AP also found that Uber failed to adequately inform drivers that such automated decision-making was being used, breaching their right to transparency under Articles 13 and 14 of the GDPR. The fine was calculated as a proportion of Uber’s 2025 global turnover.
Uber disputes the findings, arguing that most suspensions were temporary, that no permanent deactivations occurred without human review, and that drivers could appeal. The company contends the penalty is excessive and disproportionate. Uber has also noted that the practices at issue were discontinued years ago—its temporary fraud “waitlisting” process ended in 2021 and ratings-based deactivations in 2022.
This is not Uber’s first GDPR run-in in Europe. In 2023 it was fined €10 million over insufficient transparency in its privacy notices, and in 2024 it received a €290 million penalty for transferring sensitive EU driver data to the U.S. without adequate safeguards.
The €825 million penalty sends a strong signal that EU regulators are tightening oversight of algorithmic management in the gig economy. Platforms cannot replace human judgment with fully automated systems when decisions materially affect people’s livelihoods; they must ensure workers are informed about how such decisions are made and have accessible avenues for review and redress.
Leave a comment