From the journal

Dutch DPA Fines Uber €824.99 Million for GDPR Article 22 Violation, August 2026

On 21 August 2026, the Autoriteit Persoonsgegevens imposed a fine of €824,990,000 on Uber B.V. for fully automated deactivation of drivers' accounts in breach of GDPR Article 22, which prohibits automated individual decision-making that produces legal or similarly significant effects on data subjects without a qualifying exception. The penalty is the second largest GDPR fine on record, behind the €1.2 billion fine imposed on Meta by the Irish DPA in 2023.

2 min read

On 21 August 2026, the Autoriteit Persoonsgegevens (AP), the Netherlands' data protection authority, imposed a final administrative penalty of €824,990,000 on Uber B.V. The fine arises from Uber's automated suspension and permanent termination of driver accounts based on fraud indicators and customer ratings, without human review, between 2018 and 2022. It is the second largest GDPR penalty on record.

GDPR Article 22(1) prohibits any data subject from being subjected to a decision based solely on automated processing that produces a legal or similarly significant effect, unless a qualifying exception under Article 22(2) applies. Uber's automated system classified drivers as fraud risks or low-rated and deactivated their accounts without a human decision-maker in the process. The AP found that Uber failed to satisfy any Article 22(2) exception. Uber also violated Article 22(3), which requires that the data subject be given the right to obtain human intervention, to express their view, and to contest the decision. The AP acted as lead supervisory authority under Article 56 GDPR following a complaint from 171 French drivers represented by the Ligue des droits de l'Homme to the French CNIL.

The decision applies directly to any operator using algorithmic systems to manage or terminate work relationships. Gig economy platforms, staffing services, and enterprises using AI-generated outputs to make HR decisions must ensure that a qualified human reviews each outcome before it takes effect. Individuals affected must receive a clear explanation of the criteria applied to their case. The fine's scale reflects that the conduct affected drivers across the EU over a four-year period.

Uber has stated it considers the fine disproportionate and an appeal is expected. The AP's enforcement theory, that purely automated account termination constitutes an Article 22(1) decision regardless of how the platform characterises the process, may be contested on scope. The question of what constitutes a 'solely automated' process when the underlying rules are designed by humans remains a live question in GDPR enforcement.

Licentium and its partner network advise employers, platforms, and AI deployers on GDPR Article 22 compliance. Work we undertake includes algorithmic impact assessments, human-in-the-loop process design, data subject rights procedure drafting, and regulatory response strategy.

Source: Autoriteit Persoonsgegevens, Uber fined nearly 825 million euros for automated driver blocking, 21 August 2026

More from the journal

See all

European Commission Designates ChatGPT a Very Large Online Search Engine Under DSA

On 31 August 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine and Reddit and Roblox as Very Large Online Platforms under the Digital Services Act. OpenAI reported 159.1 million average monthly active recipients in the EU for the six months ending 31 March 2026, exceeding the 45 million designation threshold by more than three times. Designated services must meet enhanced DSA obligations within four months of notification.

MAS Consults on Legislative Implementation of Singapore Stablecoin Regime, 1 September 2026

On 1 September 2026, the Monetary Authority of Singapore published a consultation paper setting out draft amendments to the Payment Services Act 2019 to convert its 2023 stablecoin policy into enforceable statute. Key proposals require 100% reserve backing in high-quality liquid assets, prohibit interest payments on MAS-regulated stablecoins, and restrict the 'MAS-regulated stablecoin' label to licensed issuers only. The consultation closes on 16 October 2026.

EU Cyber Resilience Act Reporting Obligations Take Effect 11 September 2026

The EU Cyber Resilience Act's incident and vulnerability reporting requirements take effect on 11 September 2026, more than fourteen months before the Act's full compliance date of December 2027. Manufacturers of products with digital elements placed on the EU market must notify national CSIRTs and ENISA of actively exploited vulnerabilities within 24 hours and of severe security incidents within 72 hours, with a final report due no later than 14 days after a corrective measure is available.