Uber is fined €825 million ($about $966 million) by the Dutch Data Protection Authority for deactivating driver accounts using automated systems. The regulator says the approach violates the EU General Data Protection Regulation (GDPR), because decisions that significantly affect people are made solely by software without sufficient warning or meaningful human involvement and review.
Multiple outlets report that the fine is based on GDPR requirements that individuals should not be subject to a decision based only on automated processing when it has major consequences. Sources describe how Uber’s systems suspend or deactivate drivers after alerts or assessments, including cases involving suspected fraud or other conduct. The regulator says affected drivers do not receive adequate information and that a computer system should not make such major decisions on its own.
Outlet coverage also notes dispute and context. Several reports say Uber plans to appeal, and they refer to the size of the penalty as among the largest GDPR fines issued so far. Some reporting highlights Uber’s argument that deactivations are typically brief and may involve human review in some situations, while the Dutch authority maintains that serious infringements occurred.