On 21 August 2026, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, the AP) issued a fine of EUR 825 million against Uber Technologies Inc for violations of the General Data Protection Regulation. The AP acted as lead supervisory authority under the GDPR's one-stop-shop mechanism. Uber has appealed; the fine is subject to judicial review.
The AP grounded the fine in GDPR Article 22(1), which prohibits subjecting data subjects to decisions based solely on automated processing that produce legal or similarly significant effects without appropriate safeguards. The AP found that Uber's system permanently or indefinitely suspended driver accounts without any human reviewer ever examining whether the algorithmic output was correct. The AP also cited GDPR Articles 13(2)(f) and 14(2)(g), which require controllers to inform data subjects of the existence of automated decision-making, including meaningful information about the logic involved and its envisaged consequences.
Gig economy platforms, employers using algorithmic personnel management, and any business using AI to decide on or recommend termination, suspension, or restriction of access must assess their Article 22 compliance posture. Where automated processing can end a person's access to a platform or eliminate their income stream, Article 22(1) applies regardless of whether the decision is framed as a preliminary flag pending later human review. Controllers must confirm that privacy notices and layered disclosures identify automated decision-making and explain its logic under Articles 13(2)(f) and 14(2)(g).
Uber's appeal will test whether the AP's characterization of a no-human-review architecture as a per se Article 22(1) violation is confirmed at judicial level. If upheld, the EUR 825 million penalty would rank as the second-largest GDPR fine in the regulation's history. The outcome will clarify whether token human-in-the-loop steps, such as post-hoc review of completed suspensions, satisfy Article 22's safeguard requirement.
Licentium advises platforms, employers, and digital service providers on GDPR Article 22 compliance and algorithmic accountability. Work we undertake includes automated decision-making audits, Article 22 safeguard design, data protection impact assessments, DPO advisory, GDPR enforcement response strategy, and coordination with lead supervisory authorities across EU member states.