Uber Hit With $964M GDPR Fine Over Automated Driver Account Suspensions
The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has fined Uber 825 million euros (approximately $964 million) for violating the EU's General Data Protection Regulation (GDPR) through its use of fully automated decision-making to suspend driver accounts between 2018 and 2022. Dutch regulators found that Uber relied on algorithmic systems to flag and deactivate drivers, sometimes permanently, without providing meaningful human review of those decisions. Under Article 22 of the GDPR, individuals have the right not to be subject to a decision based solely on automated processing when it produces legal or similarly significant effects.
Beyond the automated suspension issue, the authority also determined that Uber failed to adequately inform drivers about the automated decision-making processes affecting their accounts, a breach of GDPR transparency requirements. Uber has stated it disagrees with the ruling and intends to appeal, noting that the policies under scrutiny were discontinued years ago. "We take decisions that affect drivers' ability to earn extremely seriously and we're fully committed to fair treatment," the company said, emphasizing its current appeal mechanisms and human review processes.
This marks the fourth fine the Dutch DPA has levied against Uber, with the largest prior penalty of 290 million euros ($324 million) imposed in 2024 for transferring European driver data to U.S. servers without adequate safeguards. The case underscores the growing regulatory scrutiny facing companies deploying automated decision-making systems that materially affect users, particularly under Europe's strict data protection framework. Organizations operating in the EU should audit their AI-driven account management workflows and review their data transfer mechanisms to avoid similar exposure. Users concerned about how their personal data flows across borders can run a DNS leak test to verify whether their connections are routed through protected channels, and conduct a broader privacy checkup to identify exposure points in their own digital footprint.