Executive assessment
On 2 September 2026, Stichting WIE International filed a Dutch collective action in the Amsterdam District Court against Uber B.V. and Uber Technologies Inc. on behalf of an estimated 241,000 current and former drivers who completed at least one Uber trip from 1 December 2020 onward in the Netherlands, Belgium, Germany, France, Poland, Romania or the United Kingdom.
The action alleges that Uber unlawfully used automated decision-making and profiling to set drivers’ pay and allocate rides, trained machine-learning systems on their personal data without a valid legal basis, and transferred driver data to the United States without required safeguards between 6 August 2021 and 27 November 2023; it seeks orders stopping the practices and deleting relevant data, declarations of unlawfulness, compensation and profit-based relief, although these remain pleaded allegations rather than judicial findings.
The proceeding is best understood as a challenge to an integrated decision system rather than a single claim about fare levels. The pleaded theory connects collection of driver data, construction of behavioural profiles, automated distribution and pricing of work, reuse of records for model development, disclosure and transfer practices, and the remedies sought for those operations. Treating those components separately is essential because each has a different legal test, evidentiary burden, temporal reach, and remedy.
The strongest common questions are:
- which entity determined purposes and means;
- which categories of data entered each system;
- what purposes and lawful bases were communicated;
- how work offers and pay figures were generated;
- whether any human review was real;
- what transfer mechanism applied during each period; and
- whether the controller maintained the documentation required by accountability, privacy-by-design, and impact-assessment duties.
Under EU GDPR Article 22, software influence is not enough: the contested decision must be based solely on automated processing and must produce legal or similarly significant effects. United Kingdom claims require a separate period-specific analysis because the current UK GDPR no longer reproduces the former EU rule unchanged. Article 82 likewise does not turn every infringement into a damages award. Each compensatory claim requires damage and a causal link, even though EU law permits compensation for genuine non-material harm without a seriousness threshold. The class may therefore obtain declaratory, transparency, or injunctive relief on a broader basis than monetary relief.
The action’s wider importance lies in its procedural design. Dutch collective-redress rules can aggregate system-level data-protection issues, but they do not erase limits arising from foreign class participation, claim-period changes, different contracting entities, driver-specific exposure, or the compensatory character of Article 82. A successful case-management plan will probably need system-and-time cohorts rather than one undifferentiated class.
New EU rules reinforce the direction of travel without automatically deciding the pleaded GDPR claims. The Platform Work Directive contains dedicated controls on automated monitoring and decision systems for people performing platform work and must be transposed by 2 December 2026. The AI Act lists specified worker-management and task-allocation uses among Annex III high-risk use cases, but Regulation (EU) 2026/1744 postponed the core Chapter III high-risk requirements for Annex III systems to 2 December 2027. Temporal application, national transposition, system classification, and private-enforcement consequences must be analysed provision by provision.
What the case is actually about
One factual chain, several legal acts
A platform-mediated trip is not one act of processing. It is a sequence: account and identity data are created; location, availability, acceptance, cancellation, rating, safety, and trip records are captured; features and profiles are derived; models or rules rank possible matches; a work opportunity and proposed remuneration are presented; later observations feed monitoring, fraud, quality, pricing, and development processes; and data may be shared among group entities and service providers. A pleading that labels the whole sequence “algorithmic management” still must identify the legal act challenged at each point.
That decomposition matters. Lawful collection for dispatch does not automatically authorize development of every later model. A transparent and lawful model-training purpose does not answer whether an individual work-allocation decision falls under Article 22. An Article 15 access failure does not prove discriminatory pay. An unlawful transfer does not establish that a domestic allocation result was inaccurate. Conversely, the same record may support several duties at once: a profile may be personal data, a factor in an automated decision, part of the information needed for an intelligible explanation, and an item transferred to another recipient.
Allegations, proof, and neutral characterisation
The official register extract proposes a group of natural persons who completed at least one trip through the Uber Driver app from 1 December 2020—or another date fixed by the court—in the Netherlands, Belgium, Germany, France, Poland, Romania, or the United Kingdom. It alleges unlawful automated remuneration and ride allocation, incompatible or insufficiently transparent use of driver data for machine-learning development, and transfers to the United States from 6 August 2021 to 27 November 2023. It seeks cessation and destruction orders, declarations, damages, and relief pleaded under Articles 6:104 and 6:212 of the Dutch Civil Code. Those are allegations and requested remedies, not findings. The merits will turn on the actual system record, including versions, data lineage, decision logs, governance materials, transfer documentation, and driver-specific examples.
Procedural architecture: WAMCA, GDPR representation, and cross-border scope
Collective standing is an issue in its own right
The Dutch Act on Resolution of Mass Damages in Collective Action (WAMCA) permits a qualifying representative organisation to seek declaratory, injunctive, and monetary relief under Article 3:305a of the Dutch Civil Code and the collective-proceeding provisions of the Code of Civil Procedure. Admissibility is not a formality. The court examines similarity of interests, governance, representativeness, funding and control, absence of profit distribution to founders or directors, and a sufficient connection with the Netherlands. Competing proceedings may be coordinated and an exclusive representative designated before the merits are resolved.
Article 80 of the GDPR supplies a separate representation framework. With a mandate, a qualifying not-for-profit body may exercise specified data-subject rights; Member States may also permit certain actions without individual mandates. In Meta Platforms Ireland v Verbraucherzentrale, the Court of Justice confirmed that a consumer association can bring a representative action without naming every affected person where the alleged processing is liable to affect the rights of identifiable data subjects. That ruling supports system-level enforcement, but it does not displace national admissibility rules or eliminate proof of the substantive right.
A headline population is not automatically a judgment class
A stated affected population and the group legally bound by a Dutch collective judgment are not necessarily identical. Under the WAMCA structure, persons domiciled or resident in the Netherlands are ordinarily addressed through an opt-out mechanism after the class is defined, whereas persons outside the Netherlands ordinarily require an affirmative opt-in unless the court orders a different mechanism permitted by the statute. Notices, language, identification, and reliable contact information become material case-management questions for a class distributed across many states.
Foreign participation also interacts with jurisdiction, applicable law, and enforcement. Domicile of an Amsterdam-based defendant provides a strong jurisdictional anchor for claims against that entity, and Article 79 GDPR preserves access to the courts where a controller or processor has an establishment. Claims against other group entities require their own analysis, including whether they are controllers, joint controllers, recipients, or processors and whether jurisdiction over closely connected claims is available. A corporate group and a single product name are not, without more, a single legal defendant.
Cohorts should follow systems and law, not geography alone
The proposed period begins on 1 December 2020, or another date fixed by the court, and crosses material legal and technical changes: the end of the Brexit transition on 31 December 2020; changes in United States transfer mechanisms following Schrems II, the 2021 standard contractual clauses, and the 10 July 2023 EU–US Data Privacy Framework; the 5 February 2026 commencement of the United Kingdom’s new automated-decision regime under the Data (Use and Access) Act 2025; and successive versions of allocation, pricing, safety, and fraud systems. A driver’s country is therefore only one dimension.
Lawfulness, fairness, and purpose limitation
Algorithmic processing is not unlawful by category
The GDPR regulates purposes, means, and effects; it does not prohibit platforms from using statistical or machine-learning systems as such. For each operation, the controller must identify a lawful basis under Article 6 and comply with the principles in Article 5, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability. A controller that relies on contractual necessity must show that the processing is objectively necessary for the core service, not merely useful to its chosen commercial design. A controller relying on legitimate interests must identify a legitimate interest, establish necessity, and balance that interest against the rights and reasonable expectations of drivers.
Consent is usually a fragile basis in a platform-work setting where refusal may impair access to income and terms are presented on a take-it-or-leave-it basis. That does not make all consent invalid, but it places pressure on whether it was freely given, specific, informed, and withdrawable without detriment. The controller’s actual conduct must match the basis and purpose communicated at the relevant time; a litigation-stage reformulation cannot cure an earlier transparency or purpose defect.
Development use requires its own purpose analysis
Operational trip data may be valuable for improving allocation, estimating arrival times, detecting fraud, forecasting demand, or personalising offers. Value is not a lawful basis. Where development was not part of the original specified purpose, the controller must assess compatibility under Article 6(4) or identify a new lawful basis and provide updated information. The analysis includes the relationship between purposes, collection context, the nature of the data, possible consequences for drivers, and safeguards such as separation, aggregation, access controls, retention limits, and testing for bias or leakage.
Training data are not outside the GDPR merely because they have been transformed into features or used to fit model parameters. The decisive question is whether information relates to an identified or identifiable person. The EDPB’s Opinion 28/2024 treats anonymity of AI models as a case-specific assessment and addresses how unlawful training data can affect subsequent deployment. A model need not be assumed to contain personal data in every case, but neither can the controller assume that weights are anonymous without evidence addressing extraction, memorisation, singling out, and reasonably likely means of identification.
Fairness is broader than statistical accuracy
A model can be statistically accurate yet process data unfairly. Fairness examines, among other things, whether drivers were misled about how their conduct would be used; whether design exploits information asymmetry or vulnerability; whether proxies produce unjustified disparate effects; whether feedback loops penalise earlier system-induced behaviour; and whether drivers can understand and challenge consequential results. The GDPR is not a general equal-pay code, so a differential outcome is not automatically a data-protection infringement. A discrimination theory needs evidence linking a protected or unjustified factor to the result and the applicable equality or labour-law rule.
Automated work allocation and remuneration: EU Article 22 and UK divergence
Four gates control an EU Article 22 claim
EU GDPR Article 22(1) applies only where there is (1) a decision, (2) based solely on automated processing, including profiling, (3) concerning the data subject, and (4) producing legal effects or similarly significantly affecting that person. Each gate requires evidence. The CJEU’s SCHUFA judgment confirms that “decision” is interpreted functionally: a score may itself qualify where a third party gives it a determining role in whether a contract is established, performed, or terminated. The reasoning prevents controllers from avoiding Article 22 by distributing a decisive process across entities or nominal steps.
“Solely automated” turns on meaningful intervention
A process does not escape Article 22 because a human appears somewhere on an organisation chart. Human intervention must be capable of changing the result, informed by the relevant data, and exercised with real authority rather than as a routine endorsement. Review after the driver has already lost an opportunity may be a safeguard for contesting a decision, but it may not mean that the original decision was not solely automated. Conversely, a genuinely discretionary dispatcher or reviewer who evaluates the case before the result is made may take the process outside Article 22(1), while leaving other GDPR duties intact.
The driver’s own act of accepting or declining an offered trip is also not automatically the human intervention contemplated by Article 22. The legal focus is the controller’s decision that generated the terms and access offered to that driver. Yet driver choice can matter to significance and causation: a non-binding suggestion among many comparable options may affect a person less than an offer architecture that effectively determines earning opportunities.
Significance may be cumulative, but cannot be presumed
Work allocation, remuneration, and account access are capable of materially affecting livelihood, especially when decisions recur at scale and shape the opportunities available during working time. That makes Article 22 a serious theory. Still, not every proposed fare or ranking event necessarily reaches the statutory threshold. The class must connect the decision type to effects of sufficient legal, economic, or practical weight. Repetition and cumulative effect are relevant, but the GDPR does not provide a simple rule that many individually trivial outputs always become one significant decision.
Exceptions do not end the inquiry
If EU GDPR Article 22(1) applies, the controller must identify an exception under Article 22(2): necessity for entering or performing a contract, authorisation by Union or Member State law, or explicit consent. Contract necessity is narrower than operational convenience. Where point (a) or (c) applies, Article 22(3) requires safeguards that include at least the right to obtain human intervention, express a point of view, and contest the decision. Where point (b) applies, the authorising law must itself lay down suitable measures to safeguard the data subject’s rights, freedoms, and legitimate interests. Special-category data add the restrictions in Article 22(4). Transparency, fairness, accuracy, and security remain applicable in all events.
United Kingdom law requires a separate time split
For decisions taken before 5 February 2026, the former UK GDPR Article 22 framework remained materially aligned with the EU provision. Section 80 and Schedule 6 of the Data (Use and Access) Act 2025 replaced that framework for later decisions with Articles 22A–22D. The current UK regime generally permits solely automated significant decisions involving non-special-category data where the processing has a lawful basis, while requiring information, representations, human intervention, and contest rights. Decisions based wholly or partly on special-category data remain more restricted. The transitional saving preserves the former rule for earlier decisions. UK claims therefore require separate cohorts by decision date, data category, lawful basis, and safeguards; current UK access responses also apply a reasonable-and-proportionate-search standard.
Access, explanation, and evidence asymmetry
Article 15 is an access right, not unlimited discovery
EU GDPR Article 15 gives a data subject access to personal data and specified contextual information, including purposes, categories, recipients, retention, sources, and—where applicable—the existence of automated decision-making with meaningful information about the logic involved and the significance and envisaged consequences. In CRIF, the CJEU held that a “copy” must be a faithful and intelligible reproduction; extracts from documents or databases may be required when necessary to make the personal data intelligible. The right does not ordinarily compel disclosure of every internal document or source code unrelated to the requester’s personal data.
Dun & Bradstreet Austria sharpened the explanation duty. The information must enable the person to understand the procedure and principles actually applied to their data to reach the particular result. A generic list of possible variables or a mathematically opaque formula is unlikely to suffice. At the same time, the judgment does not create an automatic right to a model repository. Where the controller invokes trade secrets or third-party rights, it may need to place the protected material before the competent supervisory authority or court, which determines the extent of disclosure after balancing the rights and interests involved; those interests do not justify a blanket refusal.
The case needs decision-level exemplars
System diagrams and policy documents can establish common architecture, but Article 15 and Article 22 disputes become concrete through exemplars: the data available at the time, features used, system version, output, threshold or ranking effect, human actions, notice supplied, challenge route, and subsequent consequence. A representative set of driver-level decision packets would allow the court to test whether explanations match actual processing and whether differences across products or periods require subclasses.
International transfers: a period-by-period inquiry
Transfer law follows the route and date
A disclosure or remote access by an entity in a third country can be a restricted transfer even when data remain hosted in Europe. The claimant must identify exporter, importer, categories, purpose, and period. The controller must identify the Chapter V mechanism and show compliance with the rest of the GDPR. Group membership is not a transfer mechanism, and a valid transfer instrument does not cure an incompatible purpose or excessive dataset.
After Schrems II invalidated the EU–US Privacy Shield in July 2020, exporters relying on standard contractual clauses had to assess the law and practices of the destination country and implement supplementary measures where necessary. The Commission adopted modernised clauses in June 2021 with transition arrangements. From 10 July 2023, transfers to a participating, certified United States organisation could rely on the EU–US Data Privacy Framework adequacy decision for the covered data and purposes. These periods cannot be collapsed into a single proposition that every transatlantic transfer was either lawful or unlawful.
United Kingdom drivers require a separate legal map
EU law applied in the United Kingdom through the Brexit transition, which ended on 31 December 2020. Thereafter, UK GDPR and the Data Protection Act 2018 govern much UK domestic processing, while EU GDPR may still apply where its territorial criteria are met. The Commission’s 2021 adequacy decision for the United Kingdom was extended by Implementing Decision (EU) 2025/2574 until 27 December 2031. UK-origin transfers and any processing outside that adequacy route remain subject to the United Kingdom rules in force at the relevant time, including amendments made by the Data (Use and Access) Act 2025. A Dutch proceeding can adjudicate claims within its jurisdiction, but the substantive rule, controller, and transfer character must be determined for each period rather than inferred from a driver’s present location.
Erasure, rectification, and the model problem
Deleting records is not the same as deleting a system
Article 17 can require erasure where data are no longer necessary, consent is withdrawn without another basis, an objection prevails, or processing was unlawful, subject to exceptions such as legal obligations and establishment, exercise, or defence of legal claims. Relief should distinguish raw trip records, account fields, derived profiles, feature stores, training datasets, logs, backups, model outputs, and model parameters. Each has a different relationship to the individual and a different feasibility and legal analysis.
A court should not assume either that model weights are always personal data or that model “unlearning” is never required. Evidence should address whether a person can be singled out, whether training examples can be extracted or inferred, what retraining or unlearning would achieve, the effect on other persons and system integrity, and whether less intrusive measures can provide effective compliance. Injunctive relief must be specific enough to enforce and proportionate to the proven infringement.
Remedies: why liability and money may diverge
Article 82 is compensatory
The CJEU’s damages jurisprudence is consistent on the core structure: Article 82 requires an infringement, material or non-material damage, and a causal link. There is no additional EU-law seriousness threshold for non-material damage, but damage cannot be presumed from the infringement alone. Compensation must be full and effective, yet it is not punitive and is not calculated by the gravity of the breach as if it were an administrative fine. National procedural rules govern proof and quantification subject to equivalence and effectiveness.
That structure is especially important in a mass action. A common finding that notices were defective or a transfer instrument was missing can establish infringement for a cohort. It does not prove that each driver lost income, suffered distress, lost control of data in a compensable way, or experienced the same duration and intensity of harm. The court may use presumptions or standardised evidence where national law permits and the inference is sound, but it cannot eliminate the EU-law elements.
Pay loss needs a counterfactual
A claim that an allocation or remuneration model reduced earnings requires a credible counterfactual: what opportunity or payment would the driver probably have received absent the unlawful processing? Gross differences across drivers do not answer that question because location, time, demand, vehicle, acceptance patterns, trip characteristics, and lawful product rules may explain variation. The strongest proof would combine system logs, causal or quasi-experimental analysis, controlled comparisons, and driver records, with sensitivity tests for lawful alternative designs.
Profit-based relief is not Article 82 compensation
Article 82 does not convert controller revenue or avoided compliance cost into data-subject damage. The two Dutch-law routes pleaded in the register extract must be kept distinct. Article 6:104 of the Dutch Civil Code is a discretionary method of estimating damages by reference to all or part of the profit obtained through a breach of contract or tort; it is not a free-standing disgorgement cause of action. Article 6:212 supplies a separate unjust-enrichment basis and requires its own elements. Either route may present questions of liability, loss or impoverishment, causal connection, reasonableness, and apportionment. A court might grant cessation or correction without awarding a platform-wide profit measure.
Declaratory and corrective relief may travel further
Declarations about controllership, transparency, purpose, safeguard design, or transfer periods can resolve common issues even where monetary claims later require individualisation. Carefully framed orders may require improved notices, decision-level explanations, retention limits, renewed lawful-basis assessments, effective human review, data-access workflows, transfer safeguards, or independent auditing. The order should identify the relevant system and period and avoid mandating a particular technical design where several compliant designs are possible.
The AI Act and Platform Work Directive
Regulatory overlap is functional, not automatic
The AI Act lists specified AI systems used for employment and worker management—including certain task-allocation, monitoring, evaluation, and decisions affecting the terms or continuation of work—among the Annex III high-risk use cases, subject to the Regulation’s definitions and exclusions. Regulation (EU) 2026/1744 postponed Chapter III, Sections 1–3, for Annex III systems—including classification and the core requirements on risk management, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy, and robustness—to 2 December 2027. Other provisions, including post-market monitoring, complaints, and individual explanations, follow their own text and application dates and must be analysed separately.
The Platform Work Directive addresses automated monitoring and decision systems more directly in the platform-work context and extends key algorithmic-management protections to persons performing platform work, not only those ultimately classified as employees. It restricts specified categories of processing, requires information, impact assessment, human oversight, and review of significant decisions, and protects workers and representatives. EU Member States must transpose the Directive by 2 December 2026. It does not apply in the United Kingdom as a matter of EU law, and before transposition the precise domestic rights and horizontal enforceability require national-law analysis.
Neither instrument retroactively proves the GDPR case
Later, more specific regulation can illuminate the risks lawmakers considered important, but it does not retroactively change the elements of a GDPR claim. Nor does non-compliance with a new regulatory duty automatically establish Article 82 damage. The instruments should be used as separate legal layers: first determine the law applicable to the challenged operation and date; then assess whether the same evidence supports duties under multiple regimes and whether national law supplies a private remedy.
Conclusions
The Amsterdam proceeding tests whether collective redress can convert the internal architecture of a platform’s decision systems into justiciable common issues. EU GDPR doctrine supports meaningful scrutiny: a decisive automated output cannot be insulated by formal steps; data access must be intelligible and specific enough to understand the result; development use requires a lawful and transparent purpose; and international transfers must be justified for the route and period in question. United Kingdom claims require separate application of the domestic text in force when the relevant decision or processing occurred.
The same doctrine limits overstatement. EU Article 22 is not a general fairness review of every algorithm, Article 15 is not unlimited source-code discovery, erasure does not automatically require destruction of an entire model, and Article 82 does not award money for a breach alone. The proceeding’s most plausible shape is therefore asymmetric: broad architecture findings and corrective relief, narrower automated-decision findings tied to defined legal periods and decision types, and compensation only for cohorts or individuals who can prove damage and causation.
For platforms, the practical lesson is to govern the entire decision stack: data lineage, purpose, model development, deployment, human oversight, explanation, transfer, retention, and remedy. For claimant organisations, the lesson is to plead and prove system versions, legal periods, and causal pathways rather than rely on the scale of the proposed class. For courts, modular adjudication offers a route to effective enforcement without turning collective procedure into a presumption of uniform liability or harm.
