preloader

· · digital-privacy gdpr compliance ai netherlands europe data-protection

Uber Got Fined 825 Million Euros Because No Human Reviewed What the Algorithm Decided

Source: Autoriteit Persoonsgegevens

An algorithm flagged a driver, and that was the whole process. No person reviewed the flag before the account was suspended, or in many cases permanently removed.

What the Dutch regulator found

The Autoriteit Persoonsgegevens fined Uber 824,990,000 euros on 21 August 2026 for violating the GDPR’s ban on fully automated decision-making. Between 2018 and 2022, Uber ran systems that tracked driving behaviour and passenger ratings, and when those systems flagged a suspicion of fraud or a rating that fell below a set threshold, the driver’s account was deactivated automatically, first temporarily, then permanently if the pattern persisted. The regulator also found that Uber failed to give drivers adequate information about the fact that these decisions were automated at all. The case reached the Dutch authority because Uber’s European headquarters sit in the Netherlands, but the complaint originated with 171 French drivers who reported the practice to a human rights organisation, which is a reminder that GDPR enforcement in one member state routinely follows harm caused across several others.

Why this fine is bigger than it looks

At nearly 825 million euros, this is the second-largest GDPR penalty ever issued, behind only the 1.2 billion euro fine against Meta in 2023. Uber has confirmed it is appealing, but the size of the number is not really the story. The finding is that a company built and ran a consequential automated decision pipeline, one that ended people’s ability to earn a living, without the human-in-the-loop review that Article 22 requires and without telling the people affected how the system worked. That is not an edge case anymore. It is close to the default architecture of any modern platform using AI or rules-based scoring to flag fraud, moderate content, approve or deny transactions, or manage a workforce.

The part that should worry other companies

Plenty of European businesses now run automated fraud detection, risk scoring, content moderation, or eligibility systems built the same way Uber’s was: a model or ruleset makes the call, and the consequential action happens automatically because adding a human reviewer to every flag felt too slow or too expensive. Article 22 does not ban automation. It requires that decisions with legal or similarly significant effects on a person get a genuine human review path, real transparency about how the system works, and a way to contest the outcome. A rubber-stamp reviewer who never overrides the model does not satisfy that requirement, and regulators are now demonstrably willing to test it with fines in the hundreds of millions.

If your platform makes automated decisions that affect users, customers, or staff, whether that is fraud scoring, account suspension, credit decisioning, or AI-driven moderation, now is the time to check whether a real human review step exists, whether your disclosures actually explain the logic involved, and whether your audit trail could survive a regulator asking to see it. Contact Excello Digital to review how your automated systems are built and documented before a regulator does it for you.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!