A €825 million fine issued to Uber by the Dutch Data Protection Authority is the second-largest in General Data Protection Regulation (GDPR) history, behind only the €1.2 billion penalty issued to Meta in 2023. Uber has drawn the GDPR fine due to alleged driver suspensions by an automated system, without notice issued to the impacted parties or any human review of these decisions.
Though the description of the case might suggest an AI was involved, the window actually ran from 2018 to 2022 prior to the world-changing initial public release of ChatGPT. The automated system flagged drivers when they took actions that were suspected of being potentially fraudulent, such as going off of an expected route, and had the ability to suspend accounts without human oversight.
Uber contests GDPR fine as disproportionate
The GDPR fine, which equates to about USD 966 million, was calculated based on Uber’s 2025 annual turnover and issued by the Dutch regulator on August 17. Uber called the fine “disproportionate” and indicated it would appeal; the process can take a very long time, as indicated by the record-setting Meta GDPR fine that remains under appeal some three years later.
The regulator predicates the GDPR fine on the fact that the sudden driver suspensions left some app users without income, a decision that it says should not be left up to an automated system alone. The GDPR has specific language in Article 22 about the use of automated algorithms to make decisions that could have “significant” impact on a person’s life, requiring them to both have some form of human review involved in the process and to properly inform the impacted party and provide them with a means to challenge the decision. None of these things appeared to happen in this case. The Dutch regulator contends that enough low review scores from customers could alone be sufficient to trigger driver suspensions.
Uber claims that it did have a human review process in place, however, and decisions were handed off to it if they involved a permanent account ban. It is challenging the GDPR fine on this basis, as well as the fact that the regulator listed only 126 driver suspensions attributed to the automated process. Uber contends that the fine amount is disproportionate given the relatively small amount of impacted individuals, and further claims that some of these suspensions were only temporary and brief.
Arti Raman, CEO of Portal26, notes that while the driver suspensions did not involve a modern AI system, this is exactly the type of issue that can be expected from emerging agentic systems that are increasingly trusted to handle day-to-day aspects of running a business on their own:
“The uncomfortable truth in this case is that most companies couldn’t tell you, today, everywhere AI is making consequential decisions across their organization. Uber’s violation ran for four years before regulators caught it. That’s not just a governance failure, it’s a visibility failure: you can’t govern what you can’t see. Before you can prove a human was in the loop, or that a decision followed policy, you need to know which systems are touching hiring, credit, insurance, or someone’s livelihood in the first place. Most enterprises running AI today don’t have that map.”
Swiss nonprofit helped to organize complaints about driver suspensions
Complaints about driver suspensions began to come in from France in 2018. In 2019, one impacted driver collected testimonies from 170 others with the assistance of a Swiss nonprofit called PersonalData.io, which also intervened in collecting data about how the suspension decisions were made.
Though the intent of the software was to identify and weed out bad drivers, who have been caught engaging in various forms of fraud and platform manipulation, Uber reportedly stopped using the automated flagging system in 2022. Scammy drivers sometimes pull the classic taxi trick of simply taking a needlessly long route to inflate fares, but some of these methods are specific to the Uber platform. For example, drivers would sometimes spoof their location to claim to have picked a passenger up and completed a trip when they did not. Others attempt to bait customers into canceling via various means, such as a frightening profile picture, so that they can pocket a small cancellation fee with no work.
GDPR fines have become a point of international contention under the second Trump administration, which has attacked those levied against US-based companies and indicated that they are among the biggest barriers to improved economic relations with the EU. The fine totals have reached billions of dollars collectively since the GDPR went into effect in 2018 and have disproportionately touched major US-based tech firms that operate in the bloc. However, numerous of these fines have been reduced or even eliminated after lengthy appeals processes that can take up to several years to resolve (as is the case with Meta’s present record-holding GDPR fine).
The Dutch data privacy regulator has been one of the more active entities in the bloc, and has been particularly active against Uber (which keeps its EU headquarters in the Netherlands). This is its third fine of the market-leading ridesharing app, with two prior fines involving driver data privacy that totalled €290 million and €10 million respectively. The regulator has issued few other GDPR fines of this size, save for a €30.5 million judgement against Clearview AI in 2024 for collection of facial data. Other tech platforms it has fined include TikTok and Booking.com, though for substantially smaller amounts.

