Click to open contact form.
Your Global Partners in the Business of Innovation

Dutch Data Protection Authority Fines Uber €825 Million for Fully Automated Deactivation of Drivers

Client Updates / August 31, 2026

Written by: Haim RaviaDotan Hammer

On August 21, 2026, the Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, imposed a fine of €824,990,000 – the second highest GDPR fine ever – on Uber for making fully automated decisions about drivers. Where Uber’s software detected a suspicion of fraud, or where customer reviews were too low, the accounts of the drivers concerned were automatically deactivated — temporarily in the case of fraud suspicion, and permanently in the case of persistently low customer ratings. Drivers lost their income through Uber for the duration of the deactivation. The conduct occurred between 2018 and 2022, and Uber has since stopped the violations.

The AP found that Uber breached the GDPR’s prohibition on fully automated decision-making, and separately that Uber did not sufficiently inform drivers about the automated decision-making. The decisive point was the absence of any human assessment: Uber used software to track drivers’ driving behavior and customer reviews, and the deactivation followed automatically from what that software detected, with no human being interposed before a decision with significant consequences for the driver took effect.

Monique Verdier, deputy chair of the AP, said: “Uber has committed serious infringements. Drivers were deactivated without pardon. From one moment to the next, they no longer had any income through Uber. That’s forbidden. A computer should not make decisions on its own that have major consequences for you. These decisions should have been looked at first by a human being.”

The investigation originated outside the Netherlands. It began after 171 French drivers reported the practice to the Ligue des droits de l’Homme, a French human rights organization, which lodged a complaint on their behalf with the French regulator, the CNIL. Because Uber’s European headquarters are in the Netherlands, the matter passed to the AP as lead supervisory authority under the GDPR’s one-stop-shop mechanism; the AP investigated in close cooperation with the CNIL and aligned its fine decision with other European regulators.

The AP noted that all European privacy regulators calculate fines in the same way, subject to a maximum of 4% of a company’s worldwide annual turnover; Uber’s global turnover in 2025 was approximately €44.5 billion. This is the fourth fine the AP has imposed on Uber, following fines of €600,000 in 2018, €10 million in 2023 and €290 million in 2024 — the latter two of which Uber is still contesting.

Click here to read the Dutch Data Protection Authority’s announcement of the fine

MEDIA HIGHLIGHTS