Dutch Regulator Fines Uber €825 Million for Firing Drivers by Algorithm

Europe's largest-ever GDPR fine was handed to Uber after the Dutch data protection watchdog found that an automated system suspended driver accounts, sometimes permanently, with no human ever checking whether the decision was right.

ThreatVectr Newsdesk· 3 min read
Aerial 16:9 top-down view of an anonymous city grid at dusk, with faint concentric signal-ring overlays radiating from a single city block, cool blue and amber
Share

Key points

  • The Dutch Data Protection Authority (AP) fined Uber €825 million (roughly $964 million) for breaching the EU's GDPR privacy law.
  • Uber's automated software suspended driver accounts, including permanent bans, without any human reviewing the decisions for errors.
  • The fine is believed to be the largest single GDPR penalty ever issued against one company.
  • The AP, based in the Netherlands, has jurisdiction because Uber's European headquarters is registered there.

Uber drivers in Europe lost their livelihoods to a machine. No manager reviewed the call. No appeal landed in a human inbox. According to the Dutch Data Protection Authority (AP), that process broke EU law, and the company now faces an €825 million bill to prove it.

The AP announced the fine on Friday. GDPR, which stands for the General Data Protection Regulation, is the European Union's main privacy law. It sets strict rules on how companies can use personal data to make decisions that seriously affect people, including employment decisions. One of those rules says people have the right to a meaningful human review before an automated system ends their livelihood.

What did Uber actually do wrong?

Uber used automated software to flag and suspend driver accounts. In some cases the suspensions were permanent. The AP found that no human being checked those decisions to see whether the software had made a mistake.

For a driver, a suspended account means no income. An algorithm deciding that, with no human backstop, is exactly what GDPR's rules on automated decision-making are designed to prevent.

The AP's jurisdiction here is straightforward: Uber's European headquarters sits in the Netherlands, making the AP the lead supervisory authority for GDPR purposes across the EU.

How big is this fine?

Detail Figure
Fine amount (euros) €825 million
Fine amount (US dollars, approx.) $964 million
Regulator Dutch Data Protection Authority (AP)
Legal basis EU GDPR
Uber's European HQ Netherlands

At roughly $964 million, this is widely considered the largest single GDPR fine on record. For context, Meta was fined €1.2 billion by Irish regulators in 2023 for a different GDPR violation, but that case involved cross-border data transfers rather than automated decision-making.

Uber has not yet said publicly whether it will appeal.

What should drivers, or anyone flagged by an algorithm, watch for?

If you are an Uber driver and your account has been restricted or suspended, you have rights under GDPR to request that a human being review the automated decision. You can also ask Uber for a copy of the personal data it used to reach that decision, a process called a subject access request.

More broadly, if any company tells you that an automated system made a decision affecting your employment, finances or services, EU law gives you the right to contest it and to ask for human intervention. That right exists whether or not the company volunteers the information.

This story was first reported by SecurityWeek. The AP is expected to publish its full decision in the coming weeks.

© 2026 Threat Vectr