The Dutch Data Protection Authority (AP) has fined Uber €825 million over automated driver-account deactivations. The decision, reported on 21 August and confirmed to Reuters by the regulator, concerns European incidents from 2018 to 2022. Uber says it will appeal, so the penalty is not final.
The amount is eye-catching. The operational lesson is more useful: when a system can remove someone’s ability to earn, work, obtain a service or access an opportunity, an organisation needs a real human-review route and a clear challenge process before it relies on automation.
What the AP’s Uber decision says
Reuters’ report says the AP fined Uber €825 million for deactivating driver accounts through automated systems without adequately informing drivers. Reuters reports that the regulator said some drivers lost access to income without warning or human involvement. The AP confirmed the decision to Reuters.
The case began with a French complaint and was handled by the Dutch authority because Uber’s European headquarters are in the Netherlands. Reuters reports that the regulator examined events from 2018 to 2022, including temporary suspensions linked to suspected fraud and some permanent deactivations connected with low customer ratings.
Uber disputes the decision and calls the fine disproportionate. It says its current policies include human reviews and a route for drivers to contest suspensions. The Associated Press account also reports that Uber plans to appeal. Treat the enforcement outcome as subject to that appeal.
Why Article 22 matters
GDPR Article 22 gives people the right not to be subject to a decision based solely on automated processing, including profiling, where it produces legal effects or similarly significantly affects them. The article sets limited exceptions. Where an exception applies, the controller must put suitable safeguards in place, including at least a right to obtain human intervention, express a view and contest the decision.
Article 22 is not a ban on software-assisted decisions. A fraud flag, risk score or workflow can still inform a person’s judgement. The risk rises when the system’s output becomes the decision in practice, especially where the outcome can cut off income, employment, insurance, credit, admission or essential access.
A human name in a workflow is not enough. A reviewer needs enough information, authority and time to assess the individual case and change the result. If the reviewer can only approve an algorithm’s recommendation, the control may be a rubber stamp.
Five controls to test now
- Map consequential decisions. List systems that suspend accounts, screen applicants, end contracts, set eligibility or restrict access. Record the data inputs and the practical impact of each outcome.
- Set an escalation threshold. Define which flags can trigger a temporary hold and which require a trained person to decide. Build the hold, review and decision steps into the workflow.
- Make the review meaningful. Give reviewers the case evidence, context and authority to reverse the result. Sample decisions to check that overrides happen where the facts justify them.
- Explain and challenge. Tell affected people what has happened, what information was used and how to request review. A challenge route needs an owner and a response standard.
- Keep the evidence. Retain the model version, inputs, reviewer identity, outcome and appeal result. That record supports audits, complaints and future changes.
Make it a management responsibility
This is a cross-functional control. Product and data teams need to describe how the system works; HR, operations or trust-and-safety teams need to run the review; legal and privacy teams need to assess the regulatory position; managers need to check the practice matches the design. Our guide to agentic AI covers the wider governance questions when systems can act across business tools.
Start with one high-impact workflow. Run five real or simulated cases through it, including an incorrect flag and a disputed result. If the reviewer cannot explain why the outcome changed or did not change, the control is not ready.
For a team-wide grounding in data-protection responsibilities, the free GDPR course gives staff a practical starting point. The immediate task for leaders is simpler: identify the decisions that materially affect people, then prove that the human safeguard works.
