Uber fined nearly $1 billion by Dutch regulators over automated suspensions of driver accounts

In one of the most substantial penalties for violating European Union privacy rules to date, Dutch data protection officials have ordered ride-hailing giant Uber to pay a record-breaking €825 million ($964 million) fine for breaches of the bloc’s landmark General Data Protection Regulation (GDPR). The Dutch Data Protection Authority (DPA) announced the penalty Friday, detailing that the violation stems from Uber’s use of fully automated decision-making software to suspend and even permanently deactivate driver accounts between 2018 and 2022, with no mandatory human oversight to catch algorithmic errors. Under GDPR’s strict provisions, entirely automated processes that have significant negative impacts on individuals are explicitly prohibited. The regulator also added that Uber failed to meet its transparency requirements, neglecting to properly inform drivers that their account status decisions were being made entirely by algorithm with no human input before suspension. This penalty marks the fourth time the Dutch DPA has levied a fine against Uber, and it is far larger than the previous largest penalty issued to the company by the same regulator: a €290 million ($324 million) fine handed down in 2024 over unauthorized, inadequately protected transfers of European drivers’ personal data to servers in the United States. In response to the new ruling, Uber immediately pushed back against the decision, saying it disagrees with both the finding of violation and the size of the fine, and confirming it plans to file an official appeal against the penalty. In a formal written statement, the company emphasized that the policies under investigation were discontinued years ago. “We take decisions that affect drivers’ ability to earn extremely seriously and we’re fully committed to fair treatment,” the statement read. “This includes human reviews, robust safeguards, and the opportunity for drivers to appeal our decisions if they believe we made a mistake.” The massive penalty has drawn broad attention to ongoing enforcement of GDPR rules, particularly around algorithmic decision-making that impacts gig workers, who have increasingly raised concerns about opaque automated systems that can suddenly cut off their income with no avenue for immediate review.