From the journal

Dutch DPA Fines Uber EUR 825 Million for Automated Driver Suspensions Under GDPR

On 21 August 2026, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) fined Uber Technologies Inc EUR 825 million for violating GDPR Article 22, finding that Uber's algorithmic system suspended driver accounts without any human review and failed to notify drivers of automated decisions. This is the second-largest GDPR penalty to date.

2 min read

On 21 August 2026, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, the AP) issued a fine of EUR 825 million against Uber Technologies Inc for violations of the General Data Protection Regulation. The AP acted as lead supervisory authority under the GDPR's one-stop-shop mechanism. Uber has appealed; the fine is subject to judicial review.

The AP grounded the fine in GDPR Article 22(1), which prohibits subjecting data subjects to decisions based solely on automated processing that produce legal or similarly significant effects without appropriate safeguards. The AP found that Uber's system permanently or indefinitely suspended driver accounts without any human reviewer ever examining whether the algorithmic output was correct. The AP also cited GDPR Articles 13(2)(f) and 14(2)(g), which require controllers to inform data subjects of the existence of automated decision-making, including meaningful information about the logic involved and its envisaged consequences.

Gig economy platforms, employers using algorithmic personnel management, and any business using AI to decide on or recommend termination, suspension, or restriction of access must assess their Article 22 compliance posture. Where automated processing can end a person's access to a platform or eliminate their income stream, Article 22(1) applies regardless of whether the decision is framed as a preliminary flag pending later human review. Controllers must confirm that privacy notices and layered disclosures identify automated decision-making and explain its logic under Articles 13(2)(f) and 14(2)(g).

Uber's appeal will test whether the AP's characterization of a no-human-review architecture as a per se Article 22(1) violation is confirmed at judicial level. If upheld, the EUR 825 million penalty would rank as the second-largest GDPR fine in the regulation's history. The outcome will clarify whether token human-in-the-loop steps, such as post-hoc review of completed suspensions, satisfy Article 22's safeguard requirement.

Licentium advises platforms, employers, and digital service providers on GDPR Article 22 compliance and algorithmic accountability. Work we undertake includes automated decision-making audits, Article 22 safeguard design, data protection impact assessments, DPO advisory, GDPR enforcement response strategy, and coordination with lead supervisory authorities across EU member states.

Source: Autoriteit Persoonsgegevens, Decision Against Uber Technologies, Inc. re GDPR Art. 22 and Art. 13(2)(f), 21 August 2026

More from the journal

See all
Illia Prokopiev

Foreign Ownership of a Delaware or Wyoming Entity: Federal Tax Classification, Information Reporting, Withholding, and State Duties

A non-U.S. person may own a Delaware or Wyoming LLC or a Delaware corporation, yet formation alone does not settle the federal tax result, the reporting burden, confidentiality, or the right to work in the country. This part takes the U.S. entity as chosen and examines classification, Form 5472 reporting, source and effectively connected income, partner and shareholder withholding, tax residence and immigration, duties beyond the formation state, real property and estate exposure, and treaty and home-country dependencies.

Illia Prokopiev

Structuring Cross-Border Digital-Asset Ventures (Part 2)

A cross-border digital-asset group must allocate protocol stewardship, token issuance, customer-facing regulated services, pooled investment, treasury, and founder functions before it selects any jurisdiction. The question presented is where each of those functions can lawfully sit across sixteen jurisdictions and the European Union and EEA overlay, as of 27 August 2026.

Illia Prokopiev

Function-First Entity Design for Cross-Border Digital-Asset Ventures

Cross-border digital-asset ventures often separate several legal roles. Those roles include the venture issuer, operating company, customer-facing licensee, token issuer, pooled vehicle, treasury body, and protocol administrator. The Question Presented is which roles eight jurisdictions can support as of 27 August 2026.