All news
Enforcement August 24, 2026 5 min

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

The Dutch authority fined Uber for suspending driver accounts on the basis of automated systems, without meaningful human involvement and without explaining what the suspicion rested on

TL;DR for the DPO

If a client's system suspends, rejects, downgrades or excludes someone without a person being able to genuinely review the decision, you are inside Article 22 — and the evidence that human involvement is meaningful has to be built beforehand, not afterwards. A flow where an operator clicks "confirm" on a recommendation they cannot overturn is not human involvement.

What happened

Between 2020 and 2022 Uber's systems suspended the accounts of European drivers suspected of fraud: routes the algorithms judged unnecessarily long, rides accepted and not performed. According to the Dutch authority some accounts were also permanently deactivated on the basis of low customer ratings, without human review. The company disputes this and maintains that permanent deactivations were not fully automated. The case started with a French complaint but was handled in the Netherlands, where Uber's European head office is.

The legal point is not the algorithm: it is who can overturn it

Article 22 does not prohibit automated systems. It restricts decisions based *solely* on automated processing that produce legal effects or similarly significantly affect someone. In those cases three things are needed together: human involvement that is meaningful — entrusted to someone with the authority and competence to change the outcome — the data subject's ability to express their point of view, and the ability to contest the decision. The authority also found a breach of the drivers' right to be informed about how the decision was made.

Why it reaches clients far smaller than Uber

  • Recruitment with automated CV filters: if a candidate is screened out by the system and nobody reviews the rejection, that is an automated decision with a significant effect.
  • Credit or reliability scoring computed by a supplier: the controller is still the one deciding, even when the score comes from outside.
  • Anti-fraud and anti-money-laundering systems that block an account or an order. The block is lawful; the absence of a human way out is not.
  • Automatic shift allocation, productivity scores, disciplinary suspensions suggested by software: at work, the significant-effect threshold is reached far sooner than people expect.

The document that is almost always missing

Not the privacy notice: the description of the logic of the decision, the criteria and the envisaged consequences, together with the evidence that human review exists and is able to change the outcome. Whoever writes it after the first complaint writes it under pressure, with the authority reading.

The figure, and what it says

Eight hundred and twenty-five million euro. It is the second-largest fine ever imposed under the GDPR: only Meta's 1.2 billion, decided in Ireland in 2023 over transfers to the United States, is higher. The same Dutch authority had already imposed 290 million on Uber in 2024, on a different matter. Uber has announced an appeal and calls the fine disproportionate, saying its current procedures provide for human review and a route to challenge suspensions.

Official source:Autoriteit Persoonsgegevens — statement of 21 August 2026

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min
Enforcement
80access requests refused

The client goes bankrupt, the vendor is left alone with the data — and becomes the controller

A retail chain goes bankrupt. Former employees need their own timesheets to document unpaid wages, but the only party holding them is the time-tracking software vendor, which replies that it may disclose nothing to anyone — "not even to the data subjects themselves" — because the contract with the controller has ended. The Norwegian authority decided the opposite: when you are the only one left deciding about the data, you are the controller.

Aug 21, 2026New 4 min