Uber has been fined almost €825 million by the Dutch Data Protection Authority (AP) in one of the largest GDPR penalties ever imposed, and this time the central issue is not a data breach or an international transfer.
It is automated decision-making.
The AP found that Uber used automated systems to temporarily deactivate drivers suspected of fraud and, in some cases, permanently deactivate drivers whose customer ratings remained too low. According to the regulator, these decisions were made without meaningful human intervention between 2018 and 2022.
For the drivers involved, the consequences were immediate. Once their accounts were blocked, they could no longer earn through the Uber platform.
The AP concluded that this breached the GDPR restrictions on solely automated decisions that have legal or similarly significant effects on individuals. It also found that Uber had failed to provide drivers with sufficient information about the automated decision-making taking place.
Uber strongly disputes the decision and has announced that it will appeal. The company says it takes decisions affecting drivers’ ability to earn seriously, that its current systems include human reviews and safeguards, and that drivers can challenge decisions they believe are wrong.
Whatever happens on appeal, the case has turned what can sometimes feel like one of the more technical provisions of GDPR into a very significant enforcement issue.
Automated decision making at the heart of the fine
Article 22 of the EU GDPR gives individuals the right not to be subject to decisions based solely on automated processing, including profiling, where those decisions produce legal effects or have a similarly significant impact on them.
That does not mean businesses cannot automate processes. The problem arises when the system moves beyond assisting a human and effectively becomes the decision-maker.
According to the AP, Uber used software to monitor drivers’ behaviour and customer reviews. Where the system identified suspected fraud, such as drivers allegedly taking unnecessary detours to increase fares, accounts could be temporarily deactivated. Persistent low ratings could also lead to permanent deactivation.
The regulator’s concern was that there was no meaningful human assessment before these significant decisions were made.
That distinction is important.
An algorithm flagging a transaction, customer, employee or supplier for a person to investigate is very different from an algorithm deciding the outcome itself. The greater the effect of the decision on the individual, the more important that distinction becomes.
Article 22 does contain exceptions allowing certain solely automated decisions, including where they are necessary for a contract, authorised by law or based on explicit consent. But these are subject to conditions and safeguards. Where applicable, those safeguards include the ability to obtain human intervention, express a point of view and challenge the decision.
For Uber’s drivers, being locked out of the platform meant losing their ability to earn through it. The AP regarded that as sufficiently serious for the GDPR’s automated decision-making protections to apply.
Is putting a human in the loop enough?
Perhaps the most important lesson from the case is what regulators mean by human intervention. Adding a nominal human review stage to an automated process does not necessarily solve the problem.
Meaningful human intervention requires someone to be capable of examining the information, questioning the automated recommendation and changing the outcome. A reviewer who simply approves whatever the system has produced is unlikely to provide much protection.
The European Data Protection Board has previously stressed that human intervention should be capable of addressing problems created by automated systems, rather than functioning as a superficial safeguard. For businesses rapidly introducing AI into their systems, this is particularly important.
A system might rank candidates for employment, identify customers as suspected fraudsters, determine whether someone qualifies for a financial product, flag employees as underperforming or restrict access to a service.
In all of these cases, businesses need to understand where automation ends and actual decision-making begins.
Transparency matters too
The AP did not only object to the way decisions were made. It also found that drivers had not been sufficiently informed about the automated decision-making affecting them.
This is another area where AI and automation can create GDPR problems.
If personal data is being used to make significant automated decisions, organisations cannot simply hide the process behind terms such as “proprietary algorithm” or “automated system”.
GDPR transparency requirements can require individuals to receive meaningful information about the logic involved, as well as the significance and expected consequences of the processing.
Recent EU case law has reinforced the importance of providing information that genuinely helps an individual understand how their data produced a particular outcome. That does not necessarily mean exposing source code or revealing every technical detail of a model. But an organisation should be able to explain, in understandable terms, what information is being used, how it influences the decision and what the consequences may be.
If a business cannot explain how an automated system reaches consequential decisions about people, that is itself a compliance warning sign.
From AI governance to GDPR enforcement
The timing of the Uber decision matters. Businesses are adopting AI and automated tools at extraordinary speed. Decisions that previously required a member of staff can increasingly be made, recommended or prioritised by software.
That can produce major benefits, but it also means automated decision-making is moving into areas where mistakes have serious consequences.
The Uber fine shows that organisations cannot treat GDPR compliance and AI governance as separate exercises.
Before deploying an automated system, businesses should know whether personal data is being used, what decisions the system contributes to and how significant those decisions are for the people affected.
They should also be able to answer, who actually makes the final decision? If the answer is “the system”, Article 22 should be considered carefully.
What should businesses do now?
The first step is understanding where automated decision-making already exists within the organisation. It may not always be labelled as AI. Fraud detection tools, recruitment systems, credit scoring, employee monitoring, customer risk scoring and automated account restrictions can all involve algorithmic decision-making.
Businesses should then identify which systems can produce outcomes with a significant effect on individuals.
From there, human oversight needs to be designed around the actual risk. Someone should have sufficient information, authority and time to question an automated recommendation rather than simply confirming it.
Transparency should also be reviewed. Privacy notices and other information provided to individuals need to reflect how automation is genuinely being used, including its significance and consequences where required.
Finally, organisations need an effective route for challenging decisions. A right to appeal means little if the appeal simply sends the same data back through the same automated process.
These controls also need evidence behind them. Businesses should be able to demonstrate how systems have been assessed, what safeguards were chosen, who is responsible for human review and how challenges are handled.
That documentation may become particularly important when responding to a complaint or regulatory investigation.
A significant warning, but an important UK distinction
For UK businesses, there is now an important difference between the EU GDPR rules involved in the Uber case and the UK GDPR.
Changes introduced by the Data (Use and Access) Act 2025, which took effect for automated decision-making from 5 February 2026, have made the UK regime more permissive. Significant solely automated decisions involving non-special category personal data can now be made in a wider range of circumstances, subject to a lawful basis and appropriate safeguards. Restrictions remain stronger where special category data is involved.
The safeguards remain important. UK organisations must provide information about significant automated decisions and enable individuals to make representations, obtain human intervention and contest decisions.
That means the lesson from Uber has not disappeared for UK businesses. The precise legal test may differ, but transparency, meaningful human involvement and the ability to challenge consequential decisions remain central to responsible automated decision-making.
Organisations operating in the EU, offering services to people there or otherwise falling within the scope of the EU GDPR must also consider the EU rules separately.
Article 22 just became much harder to ignore
At €825 million, the Uber penalty is reported to be the second-largest GDPR fine imposed to date, behind the €1.2 billion penalty issued to Meta in 2023. Uber’s appeal means the final outcome is far from settled.
But the wider compliance message is already difficult to miss. Automating a process does not automate away responsibility.
As businesses place more decisions in the hands of algorithms and AI systems, they need to know where those systems can materially affect people, whether genuine human oversight exists and whether affected individuals understand and can challenge what has happened.
For years, automated decision-making has been one of the less visible parts of GDPR compliance. After a fine approaching €825 million, Article 22 looks much less theoretical.
Read our guide, When data thinks: The intersection of GDPR and AI
Get it here →
