Uber Fined Nearly $1 Billion by Dutch Regulators for GDPR Violations in Driver Account Suspensions
Uber has been fined 825 million euros ($964 million) by Dutch regulators for violating GDPR through its automated suspension of driver accounts without human review.

Dutch data protection authorities have levied a substantial fine of 825 million euros (approximately $964 million) against Uber, citing violations of the European Union's General Data Protection Regulation (GDPR). The penalty stems from the ride-hailing giant's practice of using automated software to suspend driver accounts, sometimes permanently, without adequate human oversight to verify the decisions or correct potential errors.
The Dutch Data Protection Authority stated that Uber failed to comply with data privacy rules by relying solely on automated decision-making processes, which are restricted under GDPR. Furthermore, the authority found that Uber did not adequately inform drivers about its use of these automated systems and the implications for their accounts. These violations reportedly occurred between 2018 and 2022.
In response to the fine, Uber has indicated its disagreement with the decision and announced its intention to appeal. A company spokesperson stated that the regulators examined outdated policies that have since been discontinued. Uber emphasized its commitment to fair treatment of drivers, highlighting that decisions impacting their ability to earn are taken seriously and involve human reviews, safeguards, and appeal processes for drivers who believe a mistake was made.
This is not the first time Uber has faced penalties from Dutch regulators. The company has been fined by the authority on four previous occasions. The most significant prior fine, amounting to 290 million euros ($324 million) in 2024, was imposed for allegedly transferring personal data of European drivers to the United States without ensuring adequate data protection measures.
The GDPR, enacted in 2018, grants individuals significant rights over their personal data and imposes strict obligations on organizations that process it. Key provisions include requirements for lawful processing, transparency, data minimization, and limitations on automated decision-making, particularly when it has significant legal or similar effects on individuals.
This substantial fine underscores the increasing regulatory scrutiny faced by technology companies regarding their use of artificial intelligence and automated systems. Regulators are paying close attention to how these technologies are deployed, especially when they impact individuals' livelihoods or fundamental rights. The case highlights the critical need for robust human oversight and transparent communication when implementing automated decision-making processes.
Uber's appeal will likely focus on demonstrating that its current practices comply with GDPR and that the historical policies cited by the Dutch authority are no longer in effect. The outcome of this appeal could set important precedents for how automated decision-making is regulated within the EU, particularly for large platform companies that rely heavily on algorithmic processes.