Dutch regulator hits Uber with near-billion-euro GDPR penalty
The Dutch Data Protection Authority has imposed a record €824.9 million fine on Uber for using fully automated systems to deactivate driver accounts across Europe between 2018 and 2022 without human review. The Autoriteit Persoonsgegevens said the practice breached the EU General Data Protection Regulation by making significant decisions about livelihoods through automated processing alone.
The penalty, announced on 22 August 2026, equates to about $966 million and is the largest GDPR fine ever issued to Uber. The AP calculated it at the statutory maximum of four percent of the company's worldwide annual turnover.
Uber's European headquarters are in the Netherlands, giving the AP jurisdiction under the EU one-stop-shop mechanism. The regulator said the automated deactivations deprived drivers of income with no meaningful human oversight, a core requirement under GDPR for decisions with legal or similarly significant effects. The authority said the scale and duration of the practice justified the maximum penalty.
Automated deactivations at the core
According to the AP, Uber's system was able to suspend or permanently deactivate driver accounts automatically based on algorithmic assessments. The authority found that between 2018 and 2022 drivers were cut off from the platform without a human being involved in the decision, and often without adequate explanation or effective recourse.
Monique Verdier, deputy chair of the AP, said: 'From one moment to the next, they no longer had any income through Uber.' She added: 'A computer should not make decisions on its own that have major consequences for you.'
The regulator stressed that GDPR allows automated decision-making only under strict conditions, including a right to human intervention and safeguards for data subjects. The AP concluded Uber failed to meet those standards on a systemic basis and did not provide the transparency and contestability required by Article 22.
The decision highlights growing regulatory scrutiny of algorithmic management in the gig economy, where account access directly determines a worker's ability to earn. The AP said the lack of human review meant drivers could not understand why they were deactivated or challenge the outcome effectively.
How the case reached the AP
The investigation began after 171 French drivers reported the deactivations to a local human rights organization. The complaints described sudden loss of access to the app and income, with limited ability to challenge the outcome or obtain a clear reason.
Because Uber's EU base is in the Netherlands, the case was transferred to the AP under the one-stop-shop mechanism. The Dutch authority opened a formal inquiry and ultimately issued the fine after finding evidence of repeated automated deactivations without human review across multiple markets.
The AP said the complaints were representative of a wider pattern rather than isolated incidents, and that the automated process was applied consistently to driver accounts during the four-year period.
A pattern of fines
This is not the first time the AP has sanctioned Uber. The regulator previously fined the company three times.
In 2018 the AP imposed €600,000, about $701,000, for GDPR breaches. In 2023 it issued a €10 million penalty, around $11.6 million. The biggest previous hit came in 2024, when Uber was fined €290 million, roughly $339 million, for improperly transferring personal data of European drivers to the United States.
The new €824.9 million penalty dwarfs those earlier sanctions and reflects the AP's view that automated livelihood decisions represent a more serious harm than data transfer issues. The regulator said the fine was necessary to deter similar conduct by large platforms.
What happens next
Uber said it has already filed an appeal against the decision. The company has not yet issued a detailed public response beyond confirming the appeal.
The case adds pressure on platforms that rely heavily on algorithmic management of gig workers. Regulators across Europe have been scrutinizing automated account controls, deactivation practices and transparency obligations under GDPR and the Digital Services Act.
For drivers, the ruling underscores the legal requirement for human oversight when automated systems can end access to work. For Uber, the fine, if upheld, would be a major financial and reputational hit and could prompt a review of how driver deactivations are handled across its European markets.