Uber Drivers Faced €825M in Unreviewed Account Bans, Dutch Regulator Says
The Dutch data watchdog fined Uber €825 million for letting software suspend and deactivate driver accounts without human review or adequate notice.
For years, Uber drivers in Europe could lose their accounts — and their income — without a single human being reviewing the decision. Software flagged suspected fraud or persistently low ratings, and the account was suspended or shut down. Now the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) has priced that practice at €825 million, the second-largest fine ever issued under the EU's General Data Protection Regulation (GDPR).
The Reuters report on the decision, released publicly on 21 August 2026, describes a system in which Uber allowed automated software — with no human involvement — to decide when a driver stopped earning on the platform. Drivers suspected of fraud, or those whose customer ratings fell below an acceptable threshold, could find their accounts suspended automatically. Persistently low ratings led to permanent deactivation. The regulator found that this closed loop breached GDPR's Article 22, which restricts decisions based solely on automated processing when they have significant effects on individuals, and that Uber separately failed to adequately inform drivers about how the system worked.
Monique Verdier, the AP's Deputy Chair, put the regulator's position bluntly: "Uber committed serious violations. Drivers were deactivated without warning. A computer should not make decisions on its own that have major consequences for you. These decisions should first have been reviewed by a human."
What the policy says
The AP's decision, adopted on 17 August 2026, targets two distinct GDPR obligations. First, Article 22 prohibits decisions that produce legal or similarly significant effects on a person when those decisions are based solely on automated processing. The AP concluded that Uber's fraud-flagging and ratings-based deactivation systems crossed this threshold: a driver's account could be suspended or permanently terminated with no employee at any stage reviewing the decision before it took effect. Second, GDPR's transparency rules require companies to inform data subjects that automated decision-making is being applied to them, explain the logic involved, and describe the anticipated consequences. The AP found Uber did not sufficiently do this.
The violations are said to have occurred between 2018 and 2022, according to Xinhua and the detailed reconstruction of the decision published by PPC Land, which notes the exact fine was €824,990,000. Uber has said the practices covered by the decision were discontinued years ago — the fraud "waitlisting" process ended in 2021 and ratings-based deactivations in 2022, according to Yahoo Finance. But the fine addresses the period when they were active.
What it means in practice
The penalty is the second-largest GDPR fine on record. It follows a series of escalating sanctions from the same regulator: roughly €600,000 in 2018, €10 million in early 2024 over driver privacy rights, and €290 million in August 2024 for transferring European drivers' personal data to the United States without adequate safeguards, as Anadolu Agency and other outlets have catalogued. The trajectory is unambiguous: the AP has made Uber's treatment of driver data a recurring enforcement priority, and the fines keep growing.
Uber's European headquarters is in Amsterdam, which makes the Dutch AP the lead data protection regulator for EU-wide cases involving the company's drivers. The case originated from complaints by French Uber drivers filed around 2020–2022, as ABC News and Yahoo Finance report. Uber has said it disagrees with the decision and the fine, calling it disproportionate, and will file an appeal. A spokesperson told The Straits Times and other outlets: "We disagree with this decision and the fine, which we believe is disproportionate, and we will file an appeal."
Who this affects
For Uber drivers in Europe — the immediate subjects of the case — the decision confirms that algorithmic account terminations demand human review and clear explanation. The AP's logic rests on a simple principle: access to income is a significant interest, and a machine should not unilaterally sever it. The ruling does not, however, spell out a specific number of affected drivers or a compensation mechanism. It is a penalty on the company, not a direct payout to drivers.
For operators of ride-hailing platforms beyond Europe, the case is a loud signal. Uber, Bolt, inDrive and other companies operating in African markets including Nigeria, Ghana, Kenya and South Africa use similar rating and fraud-detection systems. Drivers across the continent routinely report account blocking, opaque "fraud" flags, and rating-related deactivations with limited recourse. The Dutch decision does not bind Nigerian regulators, but it establishes a concrete regulatory benchmark — and a very large number — for what such practices can cost a platform when they cross the line into fully automated decision-making.
For Nigerian policymakers and digital rights advocates, the decision offers a reference point. Nigeria's Data Protection Act (NDPA) 2023, enforced by the Nigeria Data Protection Commission (NDPC), incorporates GDPR-influenced principles on automated decision-making and data subjects' rights. No NDPC enforcement action of comparable scale has yet targeted ride-hailing platforms, but the Dutch case supplies advocacy groups and driver associations with a template: automated account actions that affect income, without meaningful human review or clear explanations, are precisely the harms modern data protection law was designed to address.
The decision also folds into a broader global regulatory conversation about AI and algorithmic management. The EU's AI Act, various national frameworks, and an emerging body of precedent are converging on the idea that automated systems making consequential decisions about people require transparency, safeguards, and avenues for human intervention. The AP's €825 million penalty is among the strongest statements yet that platform workers are not exempt from that principle.
What the decision does not settle
Several questions remain open. The most consequential is legal: Uber is appealing, and the outcome will be watched closely. A March 2021 ruling by the District Court of Amsterdam, in a case brought by Uber drivers, found that Uber's contract termination procedure did not constitute automated decision-making under Article 22 — though the court did order Uber to provide more information to affected drivers. The AP's new decision represents the regulator's view that specific practices crossed the threshold the court declined to reach. Whether an appellate body agrees will determine whether this fine stands as a precedent or a contested outlier.
There is also the question of what compliance actually looks like. The AP has not published detailed guidance on how many human reviewers a platform must employ, what standard of review satisfies Article 22, or how much explanation drivers must receive before a suspension takes effect. The decision says software cannot decide alone; it does not say what a compliant human-in-the-loop process must include. Platforms operating at Uber's scale — millions of drivers, constant fraud flags, ratings updating in real time — will need to design processes that are both legally defensible and operationally practical, and no regulator has yet specified that design.
Finally, the extraterritorial ripple effects are speculative. Uber has said the practices were discontinued years ago, and the company will presumably argue that any current system already includes human review. But the commercial risk extends beyond Europe. If regulators in other jurisdictions — including those in African markets with GDPR-influenced data laws — begin to treat algorithmic driver management as a data protection issue rather than merely a labour or contract issue, the cost structure of platform operations shifts. That is what makes this fine significant beyond the headline number: it recategorises a core platform practice as a serious regulatory violation.
What to watch next: Uber's appeal, which will determine whether the €825 million figure survives, and whether the AP follows up with more specific guidance on what compliant human review requires. For African observers, the more immediate signal is whether the Nigeria Data Protection Commission or other regional regulators reference this case in their own enforcement priorities or guidance on automated decision-making. The Dutch regulator has drawn a line; whether other jurisdictions follow is the next question.