On 21 August 2026, the Autoriteit Persoonsgegevens (AP), the Netherlands' data protection authority, imposed a final administrative penalty of €824,990,000 on Uber B.V. The fine arises from Uber's automated suspension and permanent termination of driver accounts based on fraud indicators and customer ratings, without human review, between 2018 and 2022. It is the second largest GDPR penalty on record.
GDPR Article 22(1) prohibits any data subject from being subjected to a decision based solely on automated processing that produces a legal or similarly significant effect, unless a qualifying exception under Article 22(2) applies. Uber's automated system classified drivers as fraud risks or low-rated and deactivated their accounts without a human decision-maker in the process. The AP found that Uber failed to satisfy any Article 22(2) exception. Uber also violated Article 22(3), which requires that the data subject be given the right to obtain human intervention, to express their view, and to contest the decision. The AP acted as lead supervisory authority under Article 56 GDPR following a complaint from 171 French drivers represented by the Ligue des droits de l'Homme to the French CNIL.
The decision applies directly to any operator using algorithmic systems to manage or terminate work relationships. Gig economy platforms, staffing services, and enterprises using AI-generated outputs to make HR decisions must ensure that a qualified human reviews each outcome before it takes effect. Individuals affected must receive a clear explanation of the criteria applied to their case. The fine's scale reflects that the conduct affected drivers across the EU over a four-year period.
Uber has stated it considers the fine disproportionate and an appeal is expected. The AP's enforcement theory, that purely automated account termination constitutes an Article 22(1) decision regardless of how the platform characterises the process, may be contested on scope. The question of what constitutes a 'solely automated' process when the underlying rules are designed by humans remains a live question in GDPR enforcement.
Licentium and its partner network advise employers, platforms, and AI deployers on GDPR Article 22 compliance. Work we undertake includes algorithmic impact assessments, human-in-the-loop process design, data subject rights procedure drafting, and regulatory response strategy.