Skip to content

Uber faces fine of nearly $1B over automated driver suspensions

Uber faces fine of nearly $1B over automated driver suspensions, a penalty that puts renewed scrutiny on Uber GDPR compliance and the broader question of algorithmic accountability in gig economy platforms.

The Dutch Data Protection Authority has fined Uber 825 million euros, roughly 966 million dollars, for deactivating driver accounts through automated systems without adequate human review or proper notice to the people affected. The decision, dated August 17 and first reported after Reuters reviewed the document, ranks as the second largest penalty ever issued under Europe’s General Data Protection Regulation. Only the 1.2 billion euro fine Ireland’s regulator imposed on Meta in 2023, over the unlawful transfer of European Facebook users’ data to the United States, is larger.

The case centers on a straightforward but consequential principle written into GDPR: companies cannot let algorithms alone make decisions that significantly affect people’s lives. When automated systems are used for something as serious as suspending someone’s ability to earn a living, the law requires meaningful human involvement and a clear path for the affected person to challenge the outcome. The Dutch authority found that Uber fell short of that standard between 2018 and 2022, when its fraud detection systems flagged and suspended drivers, sometimes permanently, for behavior like taking unnecessary detours to inflate fares or accepting rides the system determined they never intended to complete. Regulators also found that ratings based deactivations, where drivers were cut off after their customer scores dropped below a set threshold, followed a similarly automated process with insufficient transparency about how the decision was actually made.

Because Uber’s European headquarters sits in Amsterdam, the Dutch regulator, known as the AP, took the lead role under the EU’s one stop shop enforcement framework, which allows a single national authority to handle cross border GDPR cases on behalf of the whole bloc. The fine was calculated against Uber’s global turnover of roughly 44.5 billion euros in 2025, a detail that helps explain why the number reached nine figures despite the underlying practices having been phased out years ago.

The origin of the case is as notable as the fine itself. It traces back to a French driver named Brahim Ben Ali, whose account was deactivated in 2019. According to reporting from TechCrunch, Ben Ali went on to collect testimonies from roughly 170 other Uber drivers who had similar experiences and eventually brought a formal complaint in the Netherlands, where jurisdiction over Uber’s European operations resides. He was supported in that effort by PersonalData.io, a Swiss nonprofit focused on digital rights, which helped drivers gather evidence about how the deactivation decisions were actually generated behind the scenes. The organization’s founder, Paul-Olivier Dehaye, described the underlying risk drivers face this way: a driver can complete a thousand trips with satisfied passengers, but a single serious complaint can trigger consequences that are wildly disproportionate to the incident itself. Dehaye also noted that this marks the third fine the Dutch regulator has levied against Uber, following an earlier 290 million euro penalty tied to the company’s handling of drivers’ personal data and a smaller 10 million euro fine over related issues.

Uber has rejected both the findings and the size of the penalty and plans to appeal. A company spokesperson said Uber strongly disagrees with the decision, calling the fine disproportionate, and pointed out that the specific practices under review had already been discontinued. According to the company, the temporary fraud waitlisting process referenced in the ruling ended in 2021, and ratings based deactivations stopped in 2022. Uber has also argued that only a relatively small number of drivers were actually affected and that its current account suspension policies already include human review and a formal process for drivers to dispute decisions.

That defense sits at the heart of a broader debate that extends well beyond this one case. As ride hailing, delivery and other platform based businesses have scaled globally, they’ve increasingly relied on automated systems to manage fraud detection, quality control and account status for workforces that can number in the millions. Those systems are efficient at scale in ways human review teams simply cannot match, but efficiency has costs when the person on the receiving end of an algorithmic decision has no meaningful way to understand why it happened or contest it. GDPR’s restrictions on fully automated decision making were written with exactly this kind of scenario in mind, and this ruling suggests European regulators are willing to enforce those restrictions aggressively even against practices a company says it has already abandoned.

The size of the penalty also reflects something about how GDPR fines are calculated more broadly. Because penalties can be pegged to a percentage of a company’s global annual turnover rather than a fixed cap, cases involving major multinational platforms can produce fines that dwarf anything seen in most other regulatory regimes. That structure is deliberate. Regulators in Brussels and national data protection authorities across the bloc have consistently argued that fines need to be large enough to genuinely change corporate behavior rather than simply being absorbed as a cost of doing business, and a penalty approaching a billion dollars sends a signal that’s hard to ignore even for a company the size of Uber.

For drivers, the ruling offers a degree of vindication, even if the practical benefit to any individual affected worker remains unclear while the case moves through Uber’s appeal. The Dutch authority’s findings validate what worker advocacy groups and digital rights organizations have argued for years, that platform companies have often treated automated account management as an internal operational matter rather than a decision with the same weight and due process expectations as, say, a termination decision made by a human manager. Whether that argument gains further traction depends heavily on how appellate courts in the Netherlands handle Uber’s challenge, and on whether other European regulators, or authorities outside the EU entirely, take note of the precedent and pursue similar cases against Uber or its competitors in the gig economy space.

For now, Uber’s appeal will likely take months if not longer to resolve, and the company continues to operate under its current suspension and dispute policies, which it maintains already meet the transparency and human review standards regulators are demanding. But the case adds to a growing list of enforcement actions that suggest the era of largely unchecked algorithmic management in the platform economy is giving way to a period of far closer regulatory attention, at least within the European Union’s borders. More on how platform companies are navigating GDPR enforcement is available on Techchora’s technology policy coverage, and the Dutch Data Protection Authority’s public statements on the case can be found on its official website.

Leave a Comment