The Dutch Data Protection Authority fined Uber €825 million ($964 million), the second-largest GDPR fine ever issued, for violating GDPR’s ban on fully automated decision-making. Between 2018 and 2022, Uber used automated software to suspend driver accounts, sometimes permanently, without human review to catch errors, and failed to tell drivers the decisions were automated
Because losing access to Uber can immediately prevent drivers from earning money through the platform, regulators deemed that the case should fall under Article 22 of the EU GDPR, which restricts automated-only decision-making when it comes to having significant effects on individuals.
Ultimately, it means this is now the second-largest GDPR fine ever to have been issued, falling short of Meta’s 2023 €1.2 billion fine.
Arti Raman, CEO, Portal26
“The uncomfortable truth in this case is that most companies couldn’t tell you, today, everywhere AI is making consequential decisions across their organization. Uber’s violation ran for four years before regulators caught it. That’s not just a governance failure, it’s a visibility failure: you can’t govern what you can’t see. Before you can prove a human was in the loop, or that a decision followed policy, you need to know which systems are touching hiring, credit, insurance, or someone’s livelihood in the first place. Most enterprises running AI today don’t have that map.”
Companies who operate in the EU should take note because the EU isn’t playing around. Thus these organizations need to shape up their business practices or they may be next on the hit list.
Related
This entry was posted on August 25, 2026 at 2:24 pm and is filed under Commentary with tags EU, Uber. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Uber gets hit with €825 million GDPR fine
The Dutch Data Protection Authority fined Uber €825 million ($964 million), the second-largest GDPR fine ever issued, for violating GDPR’s ban on fully automated decision-making. Between 2018 and 2022, Uber used automated software to suspend driver accounts, sometimes permanently, without human review to catch errors, and failed to tell drivers the decisions were automated
Because losing access to Uber can immediately prevent drivers from earning money through the platform, regulators deemed that the case should fall under Article 22 of the EU GDPR, which restricts automated-only decision-making when it comes to having significant effects on individuals.
Ultimately, it means this is now the second-largest GDPR fine ever to have been issued, falling short of Meta’s 2023 €1.2 billion fine.
Arti Raman, CEO, Portal26
“The uncomfortable truth in this case is that most companies couldn’t tell you, today, everywhere AI is making consequential decisions across their organization. Uber’s violation ran for four years before regulators caught it. That’s not just a governance failure, it’s a visibility failure: you can’t govern what you can’t see. Before you can prove a human was in the loop, or that a decision followed policy, you need to know which systems are touching hiring, credit, insurance, or someone’s livelihood in the first place. Most enterprises running AI today don’t have that map.”
Companies who operate in the EU should take note because the EU isn’t playing around. Thus these organizations need to shape up their business practices or they may be next on the hit list.
Share this:
Like this:
Related
This entry was posted on August 25, 2026 at 2:24 pm and is filed under Commentary with tags EU, Uber. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.