AMSTERDAM — The Dutch data protection authority fined Uber 825 million euros, or about $966 million, on Sunday for the way it deactivates driver accounts, ruling that an automated process that cut off thousands of drivers violated European privacy law. The fine is the second-largest ever imposed under the European Union’s General Data Protection Regulation, behind only the record penalty against Meta in 2023.
The regulator’s finding goes to a question that is moving to the center of the technology industry: how much authority machines should have over people’s livelihoods. Uber, the regulator said, used an automated system to suspend driver accounts — for suspected fraud, identity problems or violations of its rules — without giving drivers sufficient warning and without adequate human review. The system’s decisions could end a driver’s income overnight, the authority argued, and European law requires that people be told why a decision affecting them was made, and that they have a meaningful way to challenge it. “Computers should not be the ones making decisions with such far-reaching consequences,” the regulator’s deputy chairman said in announcing the fine.
Uber disputed the finding, saying the automated deactivations were mostly temporary and that permanent account closures were reviewed by human teams before they took effect. The company said it would appeal, and it noted that the Dutch authority had already pursued it once before, fining Uber 290 million euros in 2024 for transferring driver data outside the EU. That fine is also under appeal.
The case is part of a pattern that has made the Dutch authority one of the most active enforcers of GDPR against the platform economy. Uber, whose European operations are headquartered in the Netherlands, has faced repeated scrutiny there; so have other companies that run gig-economy platforms. The regulator has argued that platforms cannot outsource their legal obligations to algorithms, and that the speed of automated decision-making does not excuse the absence of explanation and appeal.
Legal scholars said the ruling is notable for what it says about the boundaries of automated decision-making under Article 22 of the GDPR, which grants people the right not to be subject to decisions based solely on automated processing where those decisions produce legal or similarly significant effects. Deactivating a driver’s account is precisely such an effect, the Dutch authority argued, and its absence of adequate human involvement turned the process into a violation regardless of whether the underlying deactivations were correct.
For Uber, the fine arrives at an awkward moment. The company has been trying to reposition itself from a ride-hailing app into a platform for broader work, adding delivery, freight and business services, and it has emphasized the number of workers who earn through its apps. A record fine over the treatment of those workers cuts against that narrative, and the company’s appeal will be watched closely by the entire gig-economy sector, which uses similar automated systems for similar purposes.
The implications extend beyond ride-hailing. Every major platform that moderates accounts automatically — marketplaces, social networks, payment services — now has a European precedent to study. The Dutch ruling does not ban automated deactivation, but it requires that the process be explainable, that humans be meaningfully involved, and that drivers have a real path to challenge the outcome. Companies that built their trust-and-safety systems around speed and scale will now have to rebuild them around transparency and appeal.
Uber said it will fight the fine, and the appeal could take years. In the meantime, the practical question for the company is operational: how to redesign an account-safety system that processes millions of signals daily so that it satisfies European standards without losing the speed that keeps its platforms safe. The Dutch regulator has drawn the line, and the rest of the industry is reading it.
The ruling also lands against a backdrop of rising enforcement across Europe. The Dutch authority has been an aggressive interpreter of GDPR, and its decision is one of a series of penalties aimed at the algorithmic management of workers. In Italy, regulators have scrutinized the algorithms used by delivery platforms to allocate shifts; in Spain, courts have ruled that couriers must be treated as employees; in Germany, the labor ministry has published guidance on the rights of workers whose schedules are set by software. The common thread is a regulatory conviction that automation does not erase legal responsibility — someone must be answerable for what a machine decides.
For the ride-hailing industry specifically, the fine adds to a list of European costs that have reshaped how the companies operate. Uber and its rivals have adapted to EU rules by hiring employees in some markets, offering workers more protections in others, and redesigning the algorithms that govern their platforms. The Dutch decision pushes that adaptation into a new area: not just how drivers are paid and classified, but how their access to work itself is managed. A system that can cut off income must now justify itself to the people it affects, in terms they can understand and appeal.
The practical consequences will unfold over years. Uber’s appeal will test whether the Dutch authority’s interpretation of automated decision-making survives judicial review, and the answer will shape how every platform in Europe builds its trust-and-safety systems. Meanwhile, drivers who were deactivated without explanation have been given a legal finding that their treatment was unlawful, a status that could support compensation claims. The company said it would study the ruling’s details before responding further. Whatever the courts ultimately decide, the direction is set: in Europe, the machines that manage work are being put on trial, and the humans who wrote their rules are being held accountable.


