The Dutch Data Protection Authority (Dutch DPA, AP) has decided to impose a fine of 825 million euros on the ride-hailing platform Uber for failing to fully comply with manual review and notification obligations when suspending or deactivating some driver accounts using an automated system.
According to a report by Reuters on August 21 citing the regulatory decision of the AP on August 17, from 2020 to 2022, Uber utilized an automated system to identify drivers suspected of fraud, such as those the system believed to be taking longer routes to increase fares, accepting trips but not completing them, and temporarily suspending certain drivers. Some low-rated drivers may even face permanent deactivation.
The AP deemed that Uber’s actions contravened the provisions of the European Union’s General Data Protection Regulation (GDPR) regarding automated decision-making and decided to fine the company 825 million euros (approximately 966 million dollars). If this fine is upheld, it will be the second-highest fine in GDPR history, only behind the 1.2 billion euro fine imposed on Meta by Irish regulators in 2023.
GDPR regulations prohibit decisions that have a significant impact on people’s lives being made solely by computer algorithms and require meaningful human review and challenge mechanisms for such decisions.
The Dutch Data Protection Authority (AP) confirmed this decision but has not provided further comments at this time.
Uber has stated that they will appeal this decision.
A company spokesperson said that Uber “strongly disagrees with this decision and the disproportionate fine” and emphasized that the company values driver rights. Current policies include manual review and allowing drivers to challenge suspension decisions.
—
