Dutch regulator fines Uber €824.99m over automated driver deactivations
The Dutch data protection authority fined Uber €824.99m for using fully automated decisions to suspend and deactivate drivers between 2018–2022, citing GDPR Article 22.

The Dutch data protection authority has fined Uber €824.99 million for using fully automated decision‑making to suspend and deactivate driver accounts without meaningful human review, the regulator announced on August 30.
The Autoriteit Persoonsgegevens (AP) said its investigation found that between 2018 and 2022 Uber’s systems blocked and deactivated drivers on the basis of automated processing and that drivers did not have a real opportunity to obtain human intervention or to contest those decisions. The regulator concluded this breached Article 22 of the GDPR, which limits the use of solely automated decisions that produce legal or similarly significant effects for individuals.
The AP’s ruling orders Uber to stop the practice of fully automated blocking and to put in place effective human review for livelihood‑impacting decisions. The regulator published its decision alongside a summary of findings explaining that the automated processes at issue affected drivers’ ability to access work and therefore triggered heightened protections under EU data‑protection law.
Legal and policy observers say the size of the penalty — one of the largest under the GDPR — signals immediate legal risk for any platform operator or employer that relies on unreviewed algorithms to remove people from work. The AP tied its analysis directly to Article 22, and the decision arrives as Brussels prepares platform‑work rules that will increase scrutiny of algorithmic management and require greater transparency around automated decision‑making for gig economy platforms.
For HR and operations teams that use automated tools to enforce policy, the message is straightfoward: decisions that deprive workers of access to assignments or income can trigger data‑protection safeguards. Organisations that automate sanctions or deactivation should review whether their systems provide meaningful human oversight, clear avenues for appeal and documentation showing that decisions are not solely the product of automated profiling.
The AP did not publish the precise technical details of the algorithms, training data or the internal thresholds used to trigger driver deactivations, and the regulator’s public summary does not list the specific steps Uber must take to implement compliant human review. Nor does the decision reproduce the internal logs or models the authority examined. That opacity leaves open questions about how platforms should demonstrate the effectiveness of any human‑in‑the‑loop processes and what counts as "meaningful" review in practice.
Uber has previously defended its risk‑scoring and enforcement systems as necessary to protect riders and drivers, but the AP’s ruling places the burden on platforms to show how automation is balanced with individual rights. The regulator’s decision also illustrates how national DPAs are prepared to deploy the GDPR against algorithmic management that directly affects livelihoods, rather than confining enforcement to traditional privacy harms.
This ruling will reverberate beyond ride‑hailing. HR leaders, compliance teams and tech suppliers that design access‑control or sanctioning systems should expect more detailed scrutiny from regulators and likely demands for demonstrable human oversight from both authorities and courts. As the EU’s platform‑work framework crystallises, companies operating algorithmic management systems will need to document governance, oversight and redress mechanisms — and be prepared to defend them before regulators tasked with protecting workers’ rights under data‑protection law.