Uber Faces €825 Million Fine Over Automated Driver Deactivations in French-Dutch GDPR Case
Key Takeaways
- €824.99 Million Fine: The Dutch Data Protection Authority fined Uber for using fully automated systems to deactivate drivers without human assessment.
- Automated Driver Deactivations: Suspected fraud and low customer ratings could trigger temporary deactivation, while persistently low ratings could result in permanent removal.
- Significant Impact on Drivers: The AP found that the decisions significantly affected drivers because deactivation prevented them from accepting rides and earning income through Uber.
- Cross-Border GDPR Investigation: The case originated with complaints from 171 French drivers and was handled by the Dutch regulator in cooperation with France’s CNIL under the GDPR’s one-stop-shop mechanism.
- Uber Appeals: Uber has stopped the practices identified by the regulator and has appealed the €824.99 million fine.
Deep Dive
Uber’s software could cut a driver off from the platform for suspected fraud or poor customer ratings. What it did not necessarily do first was ask a person. That has now cost the company €824.99 million.
The Dutch Data Protection Authority, or AP, and French CNIL fined Uber after finding that the company used fully automated systems to temporarily or permanently deactivate drivers’ accounts between 2018 and 2022. Drivers suspected of fraud could be temporarily removed from the platform. Low customer ratings could also trigger temporary deactivation, while persistently low ratings could result in permanent removal.
According to the regulator, those decisions were made without human assessment. For a driver, deactivation was not an abstract change in account status. Once blocked, the driver could no longer accept rides or earn money through Uber. The AP concluded that this made the decisions significant enough to fall under the General Data Protection Regulation’s restrictions on decisions based solely on automated processing.
“Uber has committed serious infringements,” AP Deputy Chair Monique Verdier said. “From one moment to the next, they no longer had any income through Uber.”
The regulator also found that Uber failed to give drivers sufficient information about the automated decision-making involved. Uber has since stopped the practices identified in the case, according to the AP. The company has appealed the fine.
The Case Began in France
The investigation grew out of complaints from 171 French Uber drivers who reported their concerns to the Ligue des droits de l’Homme, a French human rights organization. The group filed a collective complaint with France’s privacy regulator, the CNIL, in 2020 and supplemented it the following year.
The complaint went beyond automated deactivation. It also raised questions about the information Uber provided to drivers and the transfer of personal data outside the European Union.
Because Uber’s main European establishment is in the Netherlands, the Dutch regulator took the lead under the GDPR’s one-stop-shop system. The CNIL said it worked closely with the AP throughout the investigation, including on evidence gathering and the review of the draft decision.
The automated-decision case centered on software Uber used to monitor driver behavior and customer reviews. When the system detected suspected fraud or ratings that fell below required levels, an account could be deactivated automatically.
The AP’s objection was not simply that software played a role. It was that, in the regulator’s view, software made the decision itself.
That matters under the GDPR. European privacy law places limits on decisions made solely through automated processing when those decisions produce legal effects or otherwise significantly affect an individual. The regulator concluded that cutting off a driver’s ability to earn income through the platform met that standard.
Uber’s Fourth Dutch Privacy Fine
The penalty is the fourth the AP has imposed on Uber. The regulator fined the company €600,000 in 2018. In 2023, it imposed a €10 million fine over failures to provide drivers with adequate information. A year later, it fined Uber €290 million over transfers of personal data outside the European Union.
Uber is challenging the 2023 and 2024 penalties, according to the AP, and those proceedings remain ongoing. The latest fine is considerably larger. European privacy regulators can impose penalties of up to 4% of a company’s worldwide annual turnover for the most serious GDPR violations. The AP said Uber generated approximately €44.5 billion in global revenue in 2025.
The size of the penalty will draw attention, but the more durable part of the decision may be what the regulator says about human involvement.
Companies have spent years inserting automated systems into decisions once made by people, particularly where large numbers of workers, customers or transactions are involved. The efficiency is obvious. The governance question becomes harder when the software is no longer sorting information for a person to consider, but deciding whether someone keeps access to work.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

