On 21 August 2026 the Dutch data protection authority, the Autoriteit Persoonsgegevens (AP), announced a fine of €824,990,000 on Uber. It is the second-largest GDPR fine ever issued, behind only Meta's €1.2 billion penalty in 2023. The offence was not a data breach or a shady data broker deal. It was a piece of software that switched drivers off without a human ever looking at the case.
If your business uses any tool that scores, flags, ranks or rejects people automatically, this decision is written about you too.
What Uber actually did wrong
Between 2018 and 2022, Uber ran software that tracked drivers' driving behaviour and customer ratings. When it detected a suspicion of fraud, or when ratings stayed too low, the driver's account was deactivated automatically, temporarily in the first case and permanently in the second. During a deactivation the driver lost all income from the platform. According to the AP, no human assessed these decisions.
The regulator found two violations. First, Uber breached the GDPR's prohibition on fully automated decision-making with significant effects (Article 22). Second, Uber did not give drivers enough information about the automated decision-making that governed their livelihood.
“A computer should not make decisions on its own that have major consequences for you. These decisions should have been looked at first by a human being.”
That is how AP deputy chair Monique Verdier put it in the announcement. It is a plain-language summary of Article 22, and a good sentence to pin above any team that builds or buys automated decision tools.
How a complaint from 171 drivers became a record fine
The case did not start in the Netherlands. In 2020, 171 French drivers, supported by the Ligue des droits de l'Homme, complained to the French regulator, the CNIL, about being cut off by an algorithm. Because Uber's European headquarters are in the Netherlands, the GDPR's one-stop-shop mechanism made the AP the lead authority. It investigated in close cooperation with the CNIL and aligned the final decision with other European supervisors.
Two practical lessons follow. Complaints from a few dozen people, or a single advocacy group, can escalate across borders. And once several regulators are aligned, the result is a coordinated fine rather than a national one. The amount is roughly 1.85% of Uber's 2025 global turnover of about €44.5 billion (our calculation from the AP's own figures), so nearly half of the 4% ceiling that applies to this type of breach.
Uber has stopped the practice and has appealed the fine. This is also the AP's fourth fine against the company, after €600,000 in 2018, €10 million in 2023 and €290 million in 2024, and Uber is contesting the last two as well. The final word may take years, but the message to the market is already clear.
What Article 22 GDPR actually requires
Article 22 gives people the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. Losing your income, being refused credit, or being screened out of a job are all significant effects. The rule has three moving parts:
- “Solely automated” means no meaningful human involvement. A person who simply clicks “approve” on whatever the system suggests does not count. The European guidelines on automated decision-making say the human must have real authority and the ability to change the outcome.
- Exceptions are narrow. Automated decisions are allowed only where necessary for a contract, authorised by law, or based on explicit consent. Even then you must offer safeguards: human intervention, the chance to express a view, and the right to contest the decision.
- Transparency comes on top. Articles 13 to 15 require “meaningful information about the logic involved” and the consequences. Uber was penalised for this separately.
Recent case law points the same way. In the SCHUFA case (C-634/21, December 2023) the EU Court of Justice held that producing a credit score can itself be an automated decision when a third party relies heavily on it. So even if a human signs the final decision, a score they cannot realistically depart from can trigger Article 22.
“We're not Uber” is the wrong reading
Uber's scale set the size of the fine. It did not create the obligation. The same duties apply to any business, and the exposure is wider than most owners assume:
- Hiring tools that auto-reject CVs or rank candidates by an AI score.
- Fraud and risk engines that block orders, freeze accounts or refuse refunds without review.
- Marketplace and gig platforms that suspend sellers, hosts or freelancers based on ratings or flags.
- Credit, insurance and subscription tools that decline or reprice customers automatically.
- Employee monitoring that feeds performance scores into discipline or pay.
Buying the tool from a vendor does not move the responsibility. If you decide to use it on your customers or staff, you are the controller and the duty to provide human review and an explanation sits with you. We covered a much smaller German case, a €492,000 fine over automated credit card rejections, in our earlier article on GDPR fines for AI mistakes. Uber shows the same logic at 1,700 times the price.
Answer a few questions in our GDPR decision tree to see which obligations apply to a specific use of automated processing or AI.
Where the AI Act fits in
The AI Act's rules for high-risk systems, which include many hiring and worker-management tools, have been pushed back: the Digital AI Omnibus moved standalone high-risk obligations to 2 December 2027. It would be a mistake to read that as breathing room for automated decisions about people. Article 22 has applied since 2018 and the Uber decision shows regulators enforcing it at full strength today. The AI Act adds obligations later. It does not suspend the GDPR meanwhile. Our piece on the high-risk deadline and the GDPR overlap explains how the two fit together.
A practical checklist for this week
- List every automated decision. Include tools bought from vendors: hiring, fraud, credit, moderation, scoring, rating-based suspensions.
- Test for “solely automated”. For each one, ask whether a person with real authority reviews the outcome before it takes effect, and whether they ever overrule it. If they never do, treat it as automated.
- Pick a lawful route. Contract necessity, law, or explicit consent, and write down why. Be sceptical of “necessary for the contract” where a human could reasonably do the job.
- Build the safeguards. A route to request human review, a way for the person to state their case, and a clear, quick appeal.
- Explain the logic in plain words. Update your privacy notice and your access-request answers with what the system looks at, why, and what the consequences are. The EU Court of Justice has confirmed that people can demand an explanation of the procedure and principles applied, not just a formula.
- Run a DPIA. Systematic, large-scale evaluation of people through automated processing with significant effects is a listed trigger for a data protection impact assessment. See why AI features need a DPIA before launch.
- Keep a decision log. Record overturned decisions and complaints. It is the evidence a regulator will ask for first, and it shows the review is real.
If you operate a platform with gig or freelance workers, also check the EU Platform Work Directive, which adds its own limits on automated decisions in the workplace and has a national transposition deadline coming up at the end of 2026.
The bottom line
The Uber decision is a warning about accountability more than about size. Automation is allowed. Handing people's income, credit or job prospects to a system that no human can question or overrule is not. Regulators across Europe are now cooperating on exactly this kind of case, and complaints from a small group can be enough to set one off.
Book a free consultation with GDPRGard → and we will help you map which of your tools need a human in the loop.
Sources
- Autoriteit Persoonsgegevens: Uber fined nearly 825 million euros for automated driver blocking (21 Aug 2026)
- Ashurst: Data Bytes 68, EMEA Data Privacy Update, September 2026
- Dastra: €825 million fine, Uber sanctioned for automated decision-making
- LexisNexis: Dutch DPA fines Uber for automated driver deactivation; CNIL co-operation under one-stop-shop
Also read:
- Forget the AI Act — GDPR is already fining companies for AI mistakes
- The high-risk deadline moved. The GDPR overlap didn't.
- Why every SaaS company needs a DPIA before launching AI features