The Netherlands’ Data Protection Authority fined Uber €825 million ($966 million) on August 17 for suspending and deactivating driver accounts through automated systems without adequate human review or notice. This penalty is the second-largest ever under the EU’s General Data Protection Regulation (GDPR), following Ireland’s €1.2 billion fine against Meta in 2023. The violations occurred between 2018 and 2022, according to medianama.com.
The investigation focused on two automated systems Uber used: a fraud-detection tool that flagged behaviors such as unnecessary detours or accepting trips without intent to complete them, and a ratings-based system that could permanently remove drivers with low customer scores. Both systems suspended or terminated accounts without prior human review, violating drivers’ rights. Uber informed regulators it ended the fraud-related suspension process in 2021 and stopped ratings-based deactivations in 2022, per medianama.com.
The fine highlights the EU’s enforcement of GDPR’s safeguards against automated decision-making with significant consequences. Losing access to an Uber account means drivers lose income, making human oversight critical. The penalty ranks just behind Meta’s 2023 fine, underscoring regulatory scrutiny of tech companies’ automated systems. The case originated from complaints by French drivers but was handled by Dutch authorities since Uber’s European headquarters are in the Netherlands, medianama.com reported.
The €825 million fine was announced on August 17 by the Netherlands’ Data Protection Authority, marking a major enforcement action under GDPR. Uber’s automated suspension systems operated from 2018 until their discontinuation in 2021 and 2022, respectively, according to medianama.com.