Uber Faces $966 Million Penalty Over Algorithmic Driver Deactivations
Dutch regulators imposed one of Europe's largest GDPR fines after finding the platform removed drivers from its network without human oversight between 2018 and 2022

The Scale of the Sanction
Uber Technologies is contesting a €824.9 million ($966 million) penalty imposed by the Autoriteit Persoonsgegevens, the Dutch data protection authority. The fine stems from the company's use of fully automated decision-making systems that removed drivers from its platform between 2018 and 2022, according to the AP. The regulatory body calculated the penalty at four percent of Uber's worldwide annual revenue, the maximum threshold permitted under the General Data Protection Regulation.
The case marks the fourth time Dutch regulators have sanctioned Uber for data-handling practices, but this penalty dwarfs previous actions. In 2024, the AP issued a €290 million fine for improperly transferring European driver data to the United States. Earlier sanctions included a €10 million penalty in 2023 and a €600,000 fine in 2018.
How the Investigation Started
The enforcement action originated with 171 French drivers who flagged account deactivations to a local human rights organization. Because Uber's European headquarters sits in the Netherlands, jurisdiction transferred to the AP. The regulatory body's investigation focused on whether algorithmic systems made consequential employment decisions without meaningful human oversight, a practice the GDPR explicitly restricts.
"From one moment to the next, they no longer had any income through Uber," Monique Verdier, deputy chair of the AP, noted in describing the drivers' circumstances. The regulatory authority determined that the platform's automated systems deprived workers of their livelihood through decisions that lacked human intervention.
The Regulatory Framework at Stake
European data protection law imposes specific constraints on automated decision-making that produces legal effects or similarly significant consequences for individuals. Article 22 of the GDPR generally prohibits decisions based solely on automated processing when those decisions substantially affect people's rights. The regulation carves out narrow exceptions, but they typically require explicit consent or contractual necessity, alongside safeguards such as human review.
Platform labor sits at a complicated intersection of employment law, contract law, and data regulation across Europe. Gig economy companies often classify workers as independent contractors rather than employees, a distinction that has sparked litigation and regulatory scrutiny throughout the EU. Yet even when workers operate as contractors, data protection rules still govern how platforms collect, process, and act on their personal information.
At DailyTechWire, we've tracked how enforcement priorities around algorithmic management have intensified since 2020. Regulators in France, Spain, Italy, and the Netherlands have all opened investigations into how delivery and ride-hailing platforms use automated scoring, dispatch, and termination systems. The Uber case represents the most significant financial penalty to emerge from this wave of enforcement.
The Business Logic Behind Automation
Ride-hailing and delivery platforms manage networks that can span hundreds of thousands of drivers and couriers. Uber operates in more than 70 countries and processes millions of trips daily. Automated systems offer a way to monitor driver behavior, enforce community guidelines, detect fraud, and respond to customer complaints at scale.
Yet the efficiency gains from automation carry trade-offs. When an algorithm flags a driver's account for deactivation based on metrics such as cancellation rates, customer ratings, or suspected policy violations, the speed of that decision can cut off income before a worker has an opportunity to contest the underlying data or provide context. In markets where drivers depend on platform access for their primary income, an erroneous or poorly calibrated deactivation can have immediate financial consequences.
The tension between operational scale and individual due process has become a flashpoint in platform regulation. Policymakers and labor advocates argue that workers deserve transparency about the criteria used to evaluate their performance and a meaningful avenue to challenge adverse decisions. Platform companies counter that fraud, safety risks, and quality control require rapid, scalable enforcement mechanisms.
Uber's Pattern of Data Violations
The latest fine continues a pattern. The 2024 penalty for transatlantic data transfers arose after the European Court of Justice invalidated the Privacy Shield framework in 2020, leaving companies scrambling to find legal mechanisms for moving personal data between the EU and the United States. Uber's reliance on standard contractual clauses proved insufficient in the eyes of Dutch regulators, who found that the company had not adequately protected driver data from potential US government access.
The 2023 sanction involved allegations that Uber retained driver data longer than necessary and failed to provide adequate transparency about how it used that information. The 2018 fine, smaller in absolute terms but significant at the time, addressed a data breach that Uber did not disclose promptly to regulators or affected individuals.
Taken together, these enforcement actions suggest that Uber's compliance architecture has struggled to keep pace with the European regulatory environment. While the company has invested in privacy teams and legal infrastructure since the GDPR took effect in 2018, the recurring fines indicate persistent gaps between regulatory expectations and operational practice.
What Happens Next
Uber has filed an appeal, a standard procedural step that will send the case into the Dutch court system. Appeals can take years to resolve, and companies are not required to pay contested fines until the judicial process concludes. If the penalty survives appeal, it would rank among the largest GDPR fines ever imposed, trailing only the €1.2 billion sanction against Meta in 2023 for transatlantic data transfers.
The case could also influence how other platform companies design their driver management systems. If the penalty stands, it signals that data protection authorities view algorithmic deactivation as a high-risk processing activity that demands robust human oversight. That interpretation could prompt platforms to build review mechanisms into their workflows, adding operational costs but reducing regulatory exposure.
For drivers, the outcome may hinge less on the fine itself and more on whether Uber changes its deactivation procedures going forward. Financial penalties flow to government coffers, not to affected individuals. The GDPR does allow workers to pursue private damages claims, but those cases require separate litigation and can be difficult to win without clear evidence of harm.
The Broader Platform Labor Debate
The Uber penalty arrives as European institutions debate new rules specifically targeting platform work. The European Commission proposed a directive in 2021 that would create a legal presumption of employment for workers who meet certain criteria, such as algorithmic management of their tasks. That proposal remains under negotiation among member states, with significant disagreement about how to balance worker protections against the flexibility that defines gig economy business models.
Separately, the EU's Artificial Intelligence Act, which entered into force in 2024, classifies AI systems used for employment decisions as high-risk applications subject to transparency, accuracy, and human oversight requirements. As those rules phase in over the next several years, platforms will face additional compliance obligations around the algorithms that govern driver onboarding, dispatch, and termination.
The regulatory landscape is shifting in other major markets as well. California's Proposition 22, which classifies app-based drivers as contractors while granting limited benefits, faces ongoing legal challenges. Several cities in the United States have passed or proposed local ordinances requiring platforms to disclose deactivation reasons and provide appeal processes. In Southeast Asia, governments in Indonesia, Thailand, and the Philippines have begun exploring regulatory frameworks that address algorithmic transparency and worker grievance mechanisms.
These parallel developments suggest that the questions raised by the Dutch fine extend well beyond Uber's specific conduct. As automation becomes central to how platforms manage labor at scale, the rules governing when and how algorithms can make consequential decisions about people's livelihoods will shape the future structure of the gig economy.


