Prefer to listen? Click play for AI narration

On 21 August 2026 the Dutch data protection authority, the Autoriteit Persoonsgegevens (AP), announced a fine of €824,990,000 on Uber. It is the second-largest GDPR fine ever issued, behind only Meta's €1.2 billion penalty in 2023. The offence was not a data breach or a shady data broker deal. It was a piece of software that switched drivers off without a human ever looking at the case.

If your business uses any tool that scores, flags, ranks or rejects people automatically, this decision is written about you too.

What Uber actually did wrong

Between 2018 and 2022, Uber ran software that tracked drivers' driving behaviour and customer ratings. When it detected a suspicion of fraud, or when ratings stayed too low, the driver's account was deactivated automatically, temporarily in the first case and permanently in the second. During a deactivation the driver lost all income from the platform. According to the AP, no human assessed these decisions.

The regulator found two violations. First, Uber breached the GDPR's prohibition on fully automated decision-making with significant effects (Article 22). Second, Uber did not give drivers enough information about the automated decision-making that governed their livelihood.

“A computer should not make decisions on its own that have major consequences for you. These decisions should have been looked at first by a human being.”

That is how AP deputy chair Monique Verdier put it in the announcement. It is a plain-language summary of Article 22, and a good sentence to pin above any team that builds or buys automated decision tools.

€825M
Fine on Uber, Dutch DPA, 21 Aug 2026
#2
Largest GDPR fine ever, after Meta's €1.2bn (2023)
171
French drivers whose complaint started the case
4 yrs
Period of infringement, 2018 to 2022

How a complaint from 171 drivers became a record fine

The case did not start in the Netherlands. In 2020, 171 French drivers, supported by the Ligue des droits de l'Homme, complained to the French regulator, the CNIL, about being cut off by an algorithm. Because Uber's European headquarters are in the Netherlands, the GDPR's one-stop-shop mechanism made the AP the lead authority. It investigated in close cooperation with the CNIL and aligned the final decision with other European supervisors.

Two practical lessons follow. Complaints from a few dozen people, or a single advocacy group, can escalate across borders. And once several regulators are aligned, the result is a coordinated fine rather than a national one. The amount is roughly 1.85% of Uber's 2025 global turnover of about €44.5 billion (our calculation from the AP's own figures), so nearly half of the 4% ceiling that applies to this type of breach.

Uber has stopped the practice and has appealed the fine. This is also the AP's fourth fine against the company, after €600,000 in 2018, €10 million in 2023 and €290 million in 2024, and Uber is contesting the last two as well. The final word may take years, but the message to the market is already clear.

What Article 22 GDPR actually requires

Article 22 gives people the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. Losing your income, being refused credit, or being screened out of a job are all significant effects. The rule has three moving parts:

Recent case law points the same way. In the SCHUFA case (C-634/21, December 2023) the EU Court of Justice held that producing a credit score can itself be an automated decision when a third party relies heavily on it. So even if a human signs the final decision, a score they cannot realistically depart from can trigger Article 22.

“We're not Uber” is the wrong reading

Uber's scale set the size of the fine. It did not create the obligation. The same duties apply to any business, and the exposure is wider than most owners assume:

Buying the tool from a vendor does not move the responsibility. If you decide to use it on your customers or staff, you are the controller and the duty to provide human review and an explanation sits with you. We covered a much smaller German case, a €492,000 fine over automated credit card rejections, in our earlier article on GDPR fines for AI mistakes. Uber shows the same logic at 1,700 times the price.

🧭
GDPRGard Tool
Not sure whether your tool triggers Article 22?

Answer a few questions in our GDPR decision tree to see which obligations apply to a specific use of automated processing or AI.

Open the decision tree →

Where the AI Act fits in

The AI Act's rules for high-risk systems, which include many hiring and worker-management tools, have been pushed back: the Digital AI Omnibus moved standalone high-risk obligations to 2 December 2027. It would be a mistake to read that as breathing room for automated decisions about people. Article 22 has applied since 2018 and the Uber decision shows regulators enforcing it at full strength today. The AI Act adds obligations later. It does not suspend the GDPR meanwhile. Our piece on the high-risk deadline and the GDPR overlap explains how the two fit together.

A practical checklist for this week

  1. List every automated decision. Include tools bought from vendors: hiring, fraud, credit, moderation, scoring, rating-based suspensions.
  2. Test for “solely automated”. For each one, ask whether a person with real authority reviews the outcome before it takes effect, and whether they ever overrule it. If they never do, treat it as automated.
  3. Pick a lawful route. Contract necessity, law, or explicit consent, and write down why. Be sceptical of “necessary for the contract” where a human could reasonably do the job.
  4. Build the safeguards. A route to request human review, a way for the person to state their case, and a clear, quick appeal.
  5. Explain the logic in plain words. Update your privacy notice and your access-request answers with what the system looks at, why, and what the consequences are. The EU Court of Justice has confirmed that people can demand an explanation of the procedure and principles applied, not just a formula.
  6. Run a DPIA. Systematic, large-scale evaluation of people through automated processing with significant effects is a listed trigger for a data protection impact assessment. See why AI features need a DPIA before launch.
  7. Keep a decision log. Record overturned decisions and complaints. It is the evidence a regulator will ask for first, and it shows the review is real.

If you operate a platform with gig or freelance workers, also check the EU Platform Work Directive, which adds its own limits on automated decisions in the workplace and has a national transposition deadline coming up at the end of 2026.

The bottom line

The Uber decision is a warning about accountability more than about size. Automation is allowed. Handing people's income, credit or job prospects to a system that no human can question or overrule is not. Regulators across Europe are now cooperating on exactly this kind of case, and complaints from a small group can be enough to set one off.

Book a free consultation with GDPRGard → and we will help you map which of your tools need a human in the loop.

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance — verify current obligations with your legal adviser.