The Dutch data protection authority (AP) has fined Uber €825 million for violating the GDPR over the automated process the company used to ban drivers from its platform.
The fine, according to Reuters, is the second-largest ever issued in the EU under the General Data Protection Regulation, behind only the $1.2 billion fine imposed on Meta in 2023 for illegally transferring Facebook users’ data to the US.
Like Meta before it, Uber said it will appeal.
“We strongly disagree with this decision and the disproportionately high fine,” a company spokesperson said, adding that Uber takes driver rights seriously and that its current policies include both human review and the ability for drivers to challenge platform suspensions.
GDPR rules prohibit decisions made solely by algorithms when those decisions have a significant impact on people’s lives. In such cases, meaningful human review is required, along with the ability to contest the decision.
“The AP found that Uber violated drivers’ rights, specifically the right not to be subject to automated decision-making that has… significant consequences,” the ruling document states.
“Uber also violated the right to information,” the document adds, noting that the authority considered the matter serious enough to warrant the steep fine.
The case concerns incidents in Europe between 2020 and 2022 and began following a complaint filed in France. It was handled by the Dutch regulator because Uber’s European headquarters is located in the Netherlands.
Uber had temporarily suspended some drivers’ accounts on suspicion of fraud, such as taking unnecessary detours to inflate fares or accepting rides without intending to complete them.
Uber maintains it never permanently deactivated such accounts without prior human review.
Drivers with low customer ratings were sometimes permanently banned. Uber said it no longer makes final account-deactivation decisions solely through automated systems.





