Uber Fined 825 Million Euros for Letting Software Decide
The Dutch data protection authority says Uber suspended and deactivated drivers through automated systems without proper human review. It is the second-largest GDPR fine ever issued.
The Netherlands’ data protection authority has fined Uber 825 million euros, about 966 million dollars, over the way it suspended and deactivated driver accounts between 2018 and 2022. The regulator found that Uber used software to flag drivers for suspected fraud or consistently low ratings and acted on those flags without adequate human review, and without telling drivers properly what was happening. It is the second-largest penalty ever issued under the EU’s GDPR privacy law, behind only Ireland’s 1.2 billion euro fine against Meta in 2023.
The legal hook is a specific and often overlooked part of GDPR: Article 22, which says you have a right not to be subject to a decision based solely on automated processing where that decision significantly affects you. Losing access to the app is not a minor inconvenience for a driver, it is the end of their income, which is precisely the kind of consequence the rule was written for. Deputy chair Monique Verdier put it plainly: a computer should not make decisions on its own that have such major consequences. Uber says it will appeal, calls the fine disproportionate, and disputes the finding, arguing that permanent deactivations are not made without human review and that its current process includes appeals.
What’s actually going on here: notice that nothing in this case involves a large language model or anything most people would call AI. It is scoring software and rules, the kind that has been running quietly inside companies for a decade. That is what makes the ruling worth paying attention to now: it sets the price for automated decisions about people at the moment when companies are rushing to hand far more consequential decisions to far more capable systems. The other detail regulators keep circling is what counts as human review. Having a person somewhere in the process is not enough if that person is rubber-stamping a queue of machine-generated verdicts without the time or authority to overturn one. Expect the EU AI Act, which layers additional obligations on high-risk uses like employment decisions, to be read alongside cases like this rather than instead of them.
What this means for you: if a company in the EU makes a decision about you that has real consequences, a rejected loan, a closed account, a filtered job application, you can ask whether it was made automatically, ask for a human to look at it, and contest it. Most people never do, largely because most people do not know the right exists. If you run a business that uses any kind of scoring or automated filtering on customers, contractors or applicants, the two questions this case turns on are worth asking of your own setup: can an affected person find out a machine decided, and is the human in your loop actually able to say no?
Sources
Source: https://techcrunch.com/2026/08/23/uber-faces-fine-of-nearly-1b-over-automated-driver-suspensions/
X Shuts Down Nitter, and the Open Web Gets a Little Smaller
X sent legal letters to the open-source project that let people read posts without an account. The main instance went dark on August 25, taking a common research and archiving route with it.