Uber's $964 Million GDPR Fine Over Driver Account Suspensions
Dutch regulators fine Uber $964M for automated driver account suspensions without human review.
Dutch data protection authorities have slapped Uber with a fine approaching $1 billion, saying the ride-hailing company used automated software to suspend driver accounts, sometimes permanently, without any human review to catch mistakes. The penalty, announced Friday by the Dutch Data Protection Authority, stems from violations of the European Union's General Data Protection Regulation, which bans fully automated decision-making.
The Fine and Its Basis
The Dutch Data Protection Authority is imposing a fine of 825 million euros, equivalent to $964 million, on Uber. The authority said the company violated GDPR by using automated systems to suspend driver accounts, sometimes permanently, with no human oversight to check for errors. The violations occurred from 2018 to 2022, according to the agency.
Beyond the automated suspensions, the authority also said Uber failed to inform drivers about its automatic decision-making processes. The EU's data privacy rules specifically prohibit decisions made solely by automated means without human review.
Uber's Response and Appeal
Uber said it disagrees with the decision and the fine, and it plans to appeal. The company issued a written statement in response to the penalty.
“The (Data Protection Authority) examined historic policies that were discontinued years ago. We take decisions that affect drivers’ ability to earn extremely seriously and we’re fully committed to fair treatment. This includes human reviews, robust safeguards, and the opportunity for drivers to appeal our decisions if they believe we made a mistake,”
— Uber, in a written statement
A Pattern of Penalties
This is not the first time the Dutch Data Protection Authority has fined Uber. In fact, it marks the fourth time the authority has imposed a fine on the company. The largest previous penalty came in 2024, when Uber was hit with a 290 million euro ($324 million) fine for allegedly transferring personal details of European drivers to the United States without adequate protection.
The latest fine dwarfs that previous record, signaling the regulator's increasing scrutiny of Uber's data handling practices.
What This Means for Drivers
For drivers, this fine highlights the importance of transparency and human oversight in automated systems that affect their livelihoods. The Dutch regulator's action underscores that algorithmic decision-making must be fair and accountable, especially when it can lead to account suspensions that prevent drivers from earning.
Uber's commitment to human reviews and driver appeal rights, as stated in its response, may address some concerns, but the company's appeal means the matter is far from settled.
Broader Implications for Tech Companies
This case serves as a reminder to all technology companies operating in the EU that GDPR compliance is not optional. The regulation's prohibition on fully automated decision-making applies to a wide range of industries, from ride-hailing to finance to hiring.
Companies using algorithms to make decisions about individuals must ensure they have human review mechanisms in place and that they are transparent about their automated processes.
Regulatory Landscape in Europe
The Dutch Data Protection Authority's actions come amid a broader European push to enforce data privacy and algorithmic accountability. The EU has been increasingly active in fining companies for GDPR violations, with several high-profile cases in recent years.
TikTok recently reached a $400 million settlement with the US Justice Department over children's privacy, and Apollo Global faced data breach scrutiny. These cases highlight the global attention on data protection.
What to Watch For
Uber's appeal will be closely watched, as it could set a precedent for how automated decision-making is treated under GDPR. If the fine stands, it would be one of the largest GDPR penalties ever issued, reinforcing the strict requirements for human oversight in algorithmic systems.
For now, Uber drivers and the broader tech industry are left waiting to see how this case unfolds.
Sources
- SecurityWeek Original source
- transferring personal details of European drivers Also reporting
- Personal Information Exposed in Apollo Global Data Breach Also reporting
- TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy Also reporting
Continue Reading
AI Coding Piles Up Remediation Debt
Enterprises face growing open-source vulnerability backlogs as AI tools accelerate code output.
August .NET Update Breaks WPF Printing
Printing and PDF export fail in some WPF apps after August 2026 .NET updates; Microsoft offers a risky workaround.
Keycloak flaw lets unauthorized password resets
CVE-2026-18963 allows full account takeover via reset flow; patches out.