Dutch DPA Fines Uber EUR 825 Million for Automated Driver Deactivations Under GDPR Article 22
Independently fact-checked against primary sources (last audited August 27, 2026). · 5 primary sources cited on this page. How we verify our legal content

Dutch DPA Fines Uber EUR 825 Million for Automated Driver Deactivations Under GDPR Article 22
The Dutch Data Protection Authority fined Uber B.V. and Uber Technologies Inc. EUR 824,990,000 on August 21, 2026, ruling that Uber violated GDPR Article 22 by deactivating driver accounts through fully automated decisions with no human review, cutting off drivers' income without warning.
Information last verified on August 27, 2026. This is a developing story; we update it as the record changes.
Jurisdiction scope: This article addresses the Dutch Data Protection Authority's GDPR Article 22 decision against Uber and the cooperation of France's CNIL under the EU one-stop-shop mechanism. It does not address US, UK, or other non-EU privacy regimes. For the broader rules this decision sits inside, see the Netherlands' GDPR framework.
What Happened
On August 21, 2026, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, or AP) announced a fine of EUR 824,990,000 against Uber B.V. and Uber Technologies Inc. for violating Article 22 of the GDPR, which restricts decisions based solely on automated processing that significantly affect a person. The AP found that Uber used software to track drivers' driving behavior and customer ratings, and that when the software flagged a suspected fraud case or persistently low ratings, it automatically deactivated the driver's account, temporarily for suspected fraud and temporarily or permanently for low ratings, with no human reviewing the decision first. The conduct ran from 2018 to 2022. The AP also found that Uber failed to adequately inform drivers that these deactivation decisions were fully automated, a separate transparency finding under the GDPR.
"Uber has committed serious infringements. Drivers were deactivated without pardon. From one moment to the next, they no longer had any income through Uber. That's forbidden. A computer should not make decisions on its own that have major consequences for you. These decisions should have been looked at first by a human being."
Monique Verdier, deputy chair of the Dutch AP, August 21, 2026
CNIL, France's data protection authority, described the practical effect in its own release: "These decisions significantly affect drivers who, if their account is blocked, can no longer make rides and generate revenue." A driver whose account is deactivated cannot accept trips on the platform, so the loss of income is immediate rather than something the driver can appeal before it takes effect.
The case began with a collective complaint that the French human rights organization La Ligue des droits de l'Homme (LDH) filed with CNIL in 2020 on behalf of more than 170 French drivers, supplemented in 2021. According to CNIL, the complaint covered several issues, including the information Uber provided to individuals, the transfer of driver data outside the European Union, and the automated deactivation decisions the AP has now ruled on. For the procedure itself, see how a CNIL complaint proceeds in France. Because Uber's European headquarters, Uber B.V., is established in the Netherlands, the AP took over the investigation under the GDPR's cooperation rules, working closely with CNIL throughout.
There is a three-day gap between the two regulators' own dates for this story. The AP's release is dated, and states it was last edited on, August 21, 2026. CNIL's release describing the same decision is dated August 24, 2026. The underlying decision and the fine belong to the AP as lead authority; CNIL's page is the concerned authority's own published account of that decision, not a separate or later ruling.
What the Law Actually Says
GDPR Article 22 gives a person the right not to be subject to a decision "based solely on automated processing, including profiling," if that decision produces legal effects or similarly significantly affects them. The right does not apply if the decision is necessary for a contract, authorized by law with safeguards, or based on explicit consent. Where the exception is contract necessity or explicit consent, Article 22(3) still requires the controller to give the person at least the right to obtain human intervention, to state their view, and to contest the decision. Where the exception is a law authorizing the processing, that law itself has to lay down the suitable safeguards.
The AP's finding turned on the "solely automated" element. CNIL summarized the AP's reasoning as resting on "the complete absence of human intervention in the decision-making process." In practice, that means a system flagging a risk score or a low rating is not itself the problem; the problem is letting that flag deactivate an account without a person reviewing the specific case before the consequence lands. Deputy chair Monique Verdier framed the standard the same way: decisions with major consequences for a person "should have been looked at first by a human being."
The GDPR's cooperation procedure, often called the one-stop-shop mechanism, explains why a Dutch regulator decided a case built on complaints from French drivers. Under the GDPR, a company is generally investigated and sanctioned by the supervisory authority of the EU country where its main establishment sits, here the Netherlands, rather than by every country where its users or complainants are located. CNIL, as the authority that originally received the complaint, remained a "concerned authority": it cooperated with the AP during the investigation, the review of evidence, and the examination of the AP's draft decision before the AP issued it. The AP also said it aligned the fine with other European supervisory authorities before finalizing it. Drivers or others in the Netherlands who want to raise a similar concern directly can look at how a complaint reaches the Dutch data protection authority.
The AP also noted that GDPR fines are generally capped at 4% of a company's worldwide annual turnover, and put Uber's global 2025 turnover at approximately EUR 44.5 billion, the frame regulators use to explain how a fine of this size is calculated.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
This decision is not really about Uber's fraud-detection or ratings software as technology. It is about a design choice: letting that software's output trigger a consequential decision without a human step in between. That distinction is the entire test under GDPR Article 22, and it is a test that any platform running algorithmic account management, not just ride-hailing, has to satisfy if its users are in the EU.
The size of the fine, and the fact that it is the third the AP has issued against Uber from the same complaint in under three years, points to a pattern rather than an isolated failure: a EUR 10 million transparency fine in 2023, a EUR 290 million data-transfer fine in 2024, and now an approximately EUR 825 million automated-decision fine in 2026. Regulators reading a single company's file this way, issue by issue, is itself notable for other platforms with similar architecture.
The underlying harm the AP describes, a driver losing all income from a platform "from one moment to the next" with no person having looked at their specific case, sits close to what dismissal law is designed to prevent in an ordinary employment relationship. Gig-platform drivers are typically classified as independent contractors rather than employees, which is part of why account deactivation is governed by data protection law rather than how Dutch law treats ending a work relationship; the practical effect on income can look similar even though the legal frameworks differ. The same tension, automated monitoring of a workforce colliding with rules written for human oversight, is why France's separate rules on monitoring employees have become their own area of regulatory attention, distinct from this consumer-facing GDPR case but drawing on the same underlying concern about unreviewed algorithmic control over a person's ability to work.
What Happens Next
According to the AP, Uber has announced that it will challenge the EUR 824,990,000 fine. The AP's English-language release renders this as filing an appeal; its Dutch-language release uses the term bezwaar, which in Dutch administrative procedure is an objection lodged with the regulator that issued the fine, before any appeal to a court. The AP also states that Uber is contesting the 2023 and 2024 fines and that those procedures are still ongoing. None of the three fines is final while a challenge is pending, and this article does not predict how any of them will be resolved. The AP says Uber has now ended the violations.
Uber disputes the decision. A company spokesperson told Reuters that Uber strongly disagrees with the decision and considers the fine disproportionate, and Uber has said its current policies include human review of account suspensions and a route for drivers to contest them. The AP has not published the underlying fine decision document as of August 27, 2026, so its full reasoning is not yet available for review.
How This Affects You
This decision applies EU and Dutch law to a company established in the Netherlands; it does not create new rights for people outside the EU, and it is not legal advice for any individual driver's situation. For drivers and platform workers inside the EU, the ruling is a concrete example of what "meaningful human involvement" means under GDPR Article 22 in practice: a flag from an automated system is not enough on its own to end someone's access to work through a platform. Anyone who believes a similar fully automated decision affected them can look at how a complaint reaches the relevant national data protection authority in their own EU country.
This is general legal information, not legal advice. It covers the Netherlands, France, and EU-wide GDPR procedure, and reflects sources verified on August 27, 2026. Laws change and this story is developing; consult a lawyer licensed in your jurisdiction about your specific situation.
Related articles
- the Netherlands' GDPR framework
- filing a complaint with the Dutch data authority
- France's rules on monitoring employees
Last updated: 2026-08-27. This is a developing story; details verified as of 2026-08-27.
Frequently Asked Questions
What did the Dutch Data Protection Authority fine Uber for?
The AP fined Uber B.V. and Uber Technologies Inc. EUR 824,990,000 on August 21, 2026, for violating GDPR Article 22 by deactivating driver accounts through fully automated decisions, with no human review, when its software flagged suspected fraud or persistently low customer ratings.
How much is the fine and in what currency?
The fine is EUR 824,990,000 (about EUR 825 million), announced by the Dutch AP on August 21, 2026.
Why did a Dutch regulator decide a case brought by French drivers?
Under the GDPR's one-stop-shop mechanism, a company is generally investigated by the supervisory authority where its EU main establishment is located. Uber's European headquarters, Uber B.V., is in Amsterdam, so the Dutch AP served as lead authority while France's CNIL, which received the original complaint, cooperated throughout as a concerned authority.
What does GDPR Article 22 actually require?
Article 22 gives a person the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them, unless a narrow exception applies. Where the exception is contract necessity or explicit consent, Article 22(3) still requires the controller to allow the person to obtain human intervention, state their view, and contest the decision. Where a law authorizes the processing instead, that law has to supply the safeguards.
Is this the first fine the Dutch AP has issued against Uber?
No. The AP describes this as its fourth fine against Uber overall, after a EUR 600,000 fine in 2018, and as the third fine arising from the same 2020/2021 driver complaint, following EUR 10 million in December 2023 for failing to inform drivers and EUR 290 million in July 2024 for unlawful international data transfers.
Has Uber appealed the fine?
According to the AP, Uber has announced that it will challenge the EUR 824,990,000 fine. The AP's English release calls this filing an appeal, while its Dutch release uses the term bezwaar, an objection lodged with the regulator itself before any court appeal. Uber is also still contesting the 2023 and 2024 fines, so none of the three amounts is final. Uber has publicly said it strongly disagrees with the decision and considers the fine disproportionate.
Why are the AP and CNIL announcement dates different?
The AP's own release, the source of the decision, is dated and was last edited on August 21, 2026. CNIL's release describing the same AP decision, published by the cooperating French authority, is dated August 24, 2026, three days later.
What happened to drivers whose accounts were automatically deactivated?
The AP found that affected drivers lost the ability to accept rides, and therefore income, the moment the automated system deactivated their account, without a human reviewing their individual case first.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Autoriteit Persoonsgegevens, Uber fined nearly 825 million euros for automated driver blocking (English release, 21 August 2026)(autoriteitpersoonsgegevens.nl).gov
- Autoriteit Persoonsgegevens, Uber krijgt boete van bijna 825 miljoen euro voor geautomatiseerd blokkeren van chauffeurs (original Dutch-language release, 21 August 2026)(autoriteitpersoonsgegevens.nl).gov
- CNIL, Automated decisions: Uber fined nearly EUR 825 million (24 August 2026)(cnil.fr).gov
- Regulation (EU) 2016/679 (GDPR), Article 22, official consolidated text on EUR-Lex(eur-lex.europa.eu).gov
- Autoriteit Persoonsgegevens, Algorithms and AI theme page (supervisory framework for automated decision-making)(autoriteitpersoonsgegevens.nl).gov