Uber Fined $966 Million Over Automated Driver Suspensions
Uber Fined €825 Million Over Automated Driver Suspensions Under GDPR
Based on an August 17 ruling examined by Reuters, a Dutch privacy watchdog has penalized Uber with a substantial €825 million ($966 million) sanction — marking the second-highest fine ever issued under European data protection regulations — due to its utilization of automated systems to deactivate driver accounts without providing proper notifications. The Dutch Data Protection Authority (AP) imposed this financial penalty, which remains just under the record-breaking €1.2 billion punishment that Ireland issued against Meta in 2023 for unlawfully transferring European Facebook users’ data to the United States. Uber has confirmed it plans to challenge the ruling in court.
The Tech TL;DR:
- The Penalty: Uber faces a €825 million ($966 million) fine from the Dutch Data Protection Authority under GDPR Article 22 regarding automated decision-making.
- The Root Cause: European regulators found that algorithms automatically suspended or permanently deactivated driver accounts for suspected fraud or low customer ratings without adequate human review or proper notice.
Algorithmic Management and GDPR Article 22 Violations
The regulatory action centers on Europe’s General Data Protection Regulation, specifically Article 22, which prohibits decisions made entirely by computer algorithms that carry significant consequences for individuals unless those individuals receive a meaningful chance for human review and a clear way to appeal. According to the decision reviewed by Reuters, the AP determined that Uber violated drivers’ rights by executing automated deactivations and suspensions between 2020 and 2022.
The investigation originally stemmed from a complaint filed in France. Because Uber’s European headquarters are located in the Netherlands, the Dutch authority assumed the role of lead supervisory authority under the GDPR’s one-stop-shop mechanism. Regulators concluded that the company’s automated systems flagged drivers suspected of taking unnecessary detours to inflate fares, or accepting ride requests with no intention of completing them. While Uber maintained that it never permanently deactivated driver accounts without involving a human reviewer, investigators found that drivers receiving consistently low customer ratings were sometimes permanently removed through automated processes alone, a practice the company states has since been discontinued.
Separating the Algorithmic Fine from Prior Data Transfer Penalties
Industry observers and investors have frequently conflated this ruling with earlier enforcement actions against the ride-hailing giant. This €966 million penalty is entirely distinct from the €290 million ($324 million) fine that the same Dutch authority imposed on Uber in August 2024. The 2024 penalty targeted the unlawful transfer of European taxi data to the United States between August 2021 and late 2023. Prior to that, the Dutch DPA issued a €600,000 fine in 2018 over an unreported data breach and a €10 million fine in 2023 over opaque data retention disclosures.
Unlike cross-border data transfer compliance, the ruling directly targets algorithmic management and the opacity of automated backend logic.
Corporate Response and Architectural Remediation
Uber has strongly pushed back against the ruling and its financial scale. “We strongly disagree with this decision and disproportionate fine,” an Uber spokesperson stated, adding that the company takes the rights of its drivers seriously and that its current operating procedures incorporate mandatory human reviews and formal appeal pathways.

{
"event_id": "mod_982341a",
"timestamp": "2026-08-21T15:28:00Z",
"entity_type": "driver_account",
"entity_id": "drv_77192",
"automated_flag": "suspected_detour_fraud",
"decision_status": "pending_human_review",
"escalation_route": "trust_and_safety_tier_2",
"appeal_enabled": true
}