Technology

Dutch Regulator Fines Uber €825 Million Over Automated Driver Suspensions

Martin HollowayPublished 4d ago5 min readBased on 9 sources
Reading level
Dutch Regulator Fines Uber €825 Million Over Automated Driver Suspensions
Photo by Dllu / CC BY-SA 4.0

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has fined Uber €825 million (approximately $966 million) for using automated decision-making to suspend drivers' accounts without adequate human oversight. It is the second-largest penalty issued under the EU's General Data Protection Regulation (GDPR) to date. The regulator's investigation centered on complaints that Uber deactivated driver accounts through automated processes without sufficient warning or meaningful human review. Reuters

GDPR is the EU's overarching privacy and data protection law. Among its provisions is Article 22, which restricts solely automated decision-making that has legal or similarly significant effects on individuals. In other words, if an algorithm makes a decision that materially affects someone, such as taking away their income, a human needs to be meaningfully involved.

Dutch DPA deputy chair Monique Verdier characterized the violations as "serious infringements" and stated that "a computer should not make decisions on its own that have such major consequences." The fine follows the regulator's finding that some Uber drivers were permanently deactivated without human review, a claim Uber disputes. TechCrunch

Uber has pushed back on multiple fronts. The company argued that most driver suspensions are brief, that no permanent deactivations occur without human review, and that drivers retain the ability to appeal. Uber confirmed it will appeal the fine.

The case traces back to Brahim Ben Ali, a former Uber driver in France whose account was deactivated in 2019. Ben Ali collected testimonies from 170 other Uber drivers and filed his complaint in the Netherlands, where Uber's European headquarters are located. He was assisted by PersonalData.io, a Swiss nonprofit focused on digital rights, which helped drivers collect data about how deactivation decisions were made. Paul-Olivier Dehaye, the founder of PersonalData.io, said he now plans to launch a class action suit through which affected drivers can seek compensation. TechCrunch

Dehaye is also starting a new company called StartClaims to support litigation and regulatory action, first against Uber, then expanding into other gig economy cases and adjacent areas such as adtech. That detail matters because it signals a shift from individual regulatory complaints toward structured, scalable litigation infrastructure built around GDPR enforcement.

This is the third fine the Dutch DPA has levied on Uber. The regulator previously imposed a €290 million fine on Uber Technologies Inc. and Uber B.V. for transferring drivers' personal data to the United States without adequate safeguards, and a separate €10 million fine for violating privacy rules. The cumulative total across the three actions now exceeds €1.1 billion. Autoriteit Persoonsgegevens

For platforms operating at the scale of Uber's driver network, where thousands of account decisions are made daily, the tension between operational efficiency through automation and the regulatory requirement for meaningful human involvement is not abstract. The Dutch DPA's position, as articulated by Verdier, sets a clear enforcement expectation: when the consequence is loss of livelihood, an automated system cannot be the final arbiter.

Uber's counterargument, that permanent deactivations do involve human review and that drivers can appeal, raises the question of what constitutes "meaningful" human oversight under the regulation. A human rubber-stamping an algorithmic recommendation may not satisfy the standard, and the Dutch DPA's enforcement suggests regulators are prepared to draw that line firmly. The dispute over whether permanent deactivations occurred without human review, which Uber contests, is likely to be central to the appeal.

The broader context here is that automated decision-making in employment and gig-economy contexts has been a regulatory flashpoint across the EU, and the Dutch DPA has now established itself as one of the most aggressive enforcers in this domain. For engineering and product teams building automated moderation, suspension, or risk-scoring systems that affect users in the EU, the message is direct: the design of human-in-the-loop processes, the documentation of those processes, and the ability to demonstrate meaningful intervention are all now squarely within regulatory scope.

Dehaye's StartClaims initiative adds another dimension. If class action litigation under GDPR becomes a repeatable mechanism, the cost calculus for automated decision systems changes. Fines from regulators are no longer the only financial risk. The prospect of compensation claims from affected individuals, structured at scale, would make the compliance arithmetic considerably harder.

Uber's appeal will likely take months, if not longer. In the meantime, the fine stands as the second-largest GDPR penalty on record, and the enforcement logic behind it, that automated decisions with major consequences on individuals require genuine human oversight, is now firmly in the regulatory mainstream.