On August 21, 2026, the Dutch data protection authority Autoriteit Persoonsgegevens (AP) imposed a fine of €824,990,000 on Uber B.V. and Uber Technologies Inc.
The case concerns fully automated individual decisions taken against platform drivers, in particular account deactivations triggered by fraud suspicions or low ratings, without any real human intervention. CNIL, which was involved in the case, published its statement on August 24.
This amount makes it the second-highest GDPR fine ever imposed, behind the €1.2 billion penalty issued to Meta in 2023. It represents approximately 1.85% of Uber’s global turnover (€44.5 billion in 2025), or nearly half of the legal ceiling of 4% provided for by the Regulation.
The AP's findings against Uber
The case dates back to 2020: 171 French drivers, supported by the Ligue des droits de l’Homme, had referred the matter to the CNIL after seeing their accounts suspended or permanently deactivated. Since Uber is established in the Netherlands, the AP became the lead supervisory authority under the one-stop-shop mechanism, with CNIL participating in the investigation (review of evidence, examination of the draft decision).
For the period from 2018 to 2022, the investigation established that Uber’s automated systems triggered:
- temporary account suspensions in cases of suspected fraud, notably suspicious “detours”;
- temporary or permanent deactivations based on customer ratings deemed too low.
In both cases, no human reviewed the situation before the sanction was applied, which had an immediate effect on the income of the drivers concerned.
The AP also found a breach of the transparency obligation: drivers were not sufficiently informed of the existence and logic of this automated processing.
The core issue: Article 22 of the GDPR
Article 22 of the GDPR sets out a clear principle: a person has the right not to be subject to a decision based solely on automated processing, where that decision produces legal effects concerning them or similarly significantly affects them. For the AP, cutting off a driver’s access to the platform, and therefore to their income, falls within this category.
AP Vice-President Monique Verdier expressed the principle as follows: a computer should not make on its own decisions that have major consequences for a person; such decisions must first be reviewed by a human being. The authority clarifies what it means by “human intervention”: a genuine power to overturn the algorithmic decision, actually exercised, and not merely a formal validation stamped onto a machine output.
The decision is particularly relevant as organizations increasingly automate their processes and deploy AI. The AP’s message is clear: human oversight is not a mere checkbox on a compliance checklist, but must be genuinely effective.
What happens next
Uber has announced that it will appeal, which suspends enforcement of the fine, likely for several years. The company disputes, among other things, that permanent deactivations were fully automated, states that fraud-related suspensions were generally brief, says that only 126 drivers were permanently deactivated in Europe in 2021, and claims that it has since changed its policies to incorporate human review and an appeals process.
The litigation will therefore largely turn on what counts, in practice, as genuine human intervention - a question that goes beyond Uber alone.
This case fits into a broader history of sanctions already imposed on Uber under the GDPR: €600,000 in 2018, €10 million in 2023 for failing to inform drivers, and €290 million in 2024 for transfers of data outside the EU, both of which are also being challenged. The total now exceeds €1 billion.
What organizations can learn from this
For any organization that automates decisions affecting individuals (customers, employees, contractors, drivers, job applicants), this decision clarifies several practical expectations beyond the transport-platform context.
Documenting a process is not enough: it must be possible to demonstrate, using operational evidence (intervention logs, rates of actually reviewed decisions, cases where the automated decision was overturned), that human intervention exists in practice.
The person responsible for validation must have the time, information, and authority needed to change or cancel the decision; a workload that allows only a superficial review does not constitute meaningful intervention within the meaning adopted by regulators.
It is also advisable to review the mapping of automated processing activities with significant impact (access to a service, income, employment, credit) in order to check their qualification under Article 22, and to provide data subjects with adequate information about the logic of the processing.
Finally, as automated decision-making systems and AI continue to expand, the gap between the defined policy and the system’s actual behavior becomes a key point of attention. A written compliance policy such as “a human validates the decision” only has value if the production system actually applies it.
The compliance gap is then between the procedure document and the actual behavior of the technical pipeline. A DPIA that describes a human review process, while the system automatically deactivates accounts without ever requesting such a review, does not reflect real practice.
In short
This €825 million fine illustrates the practical application of Article 22 of the GDPR to an automated decision-making case. It shows that formal human intervention, without any real power to change the decision, is not enough to satisfy the Regulation’s requirements, and that organizations automating high-impact decisions must be able to provide operational proof of compliance.
![[GDPR] Record fine: Uber sanctioned for automated decisions without human oversight](https://static.dastra.eu/content/2a257d8d-9985-452c-9f6a-35838ef4deb0/visuel-article-8-1000.webp)