Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page
⚑ TL;DR
The Dutch Data Protection Authority has fined Uber €825 million β€” the second-largest GDPR penalty ever issued β€” for using an automated system to suspend and permanently deactivate driver accounts without meaningful human review. The case turns on GDPR Article 22, which bans purely automated decisions that significantly affect people, and it is a direct warning to any company using AI or rules-based systems to make consequential decisions about employees, contractors, or customers without a real human-in-the-loop process.

On August 21, 2026, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) announced an €825 million fine against Uber Technologies β€” roughly $966 million β€” for violating the European Union’s General Data Protection Regulation. It is the second-largest GDPR fine ever recorded, trailing only the €1.2 billion penalty levied against Meta earlier this year, and it lands squarely on a practice that a huge number of companies have quietly adopted over the past several years: using automated systems to make decisions about the people who work for or through their platform, without a documented, meaningful human review step.

The regulator found that Uber’s systems tracked driver behavior and customer ratings, then temporarily or permanently blocked driver accounts based on that data β€” cutting off drivers’ ability to earn β€” without human review and without clearly telling drivers that the decision had been made by an algorithm. Uber has said it will appeal, with a spokesperson calling the fine “disproportionate” and stating that current policies already include human review and a dispute process. Regardless of how the appeal plays out, the underlying legal theory the Dutch regulator used is not going away, and it applies well beyond ride-hailing.

The legal hook: GDPR Article 22

Article 22 of the GDPR gives individuals the right not to be subject to a decision based solely on automated processing β€” including profiling β€” when that decision produces legal effects or similarly significantly affects them. It is one of the oldest and most specific provisions in the regulation, but for years it was treated by many companies as a theoretical risk rather than an active enforcement priority. That has changed. Regulators across the EU have spent the past two years building enforcement muscle around algorithmic accountability, and the Uber case β€” which stems from a French complaint and covers incidents dating back to 2020–2022 β€” shows that regulators are willing to reach back several years and impose penalties large enough to change corporate behavior going forward.

The core violation is not that Uber used an algorithm to flag risky or low-rated drivers. Using data and models to detect patterns is not, by itself, illegal under GDPR. The violation is that the algorithm’s output translated directly into an account suspension or deactivation β€” a decision with real economic consequences β€” without a human genuinely reviewing the case before it took effect, and without the driver being told plainly that this was happening. The gap between “AI-assisted decision” and “AI-made decision” is exactly where GDPR draws its line, and it is a line a lot of automated workflows quietly cross.

Why this matters far beyond ride-hailing platforms

Any company that uses automated or AI-driven systems to make consequential decisions about people should read this case as a warning, not a curiosity about the gig economy. The same legal exposure applies to:

HR and workforce systems that use algorithmic scoring to flag employees for performance review, termination risk, or disciplinary action without a documented human sign-off. Credit and lending platforms that approve or decline applications, or set pricing, purely on model output. Customer risk and fraud systems that suspend or ban customer accounts based on automated fraud scores. Vendor and contractor management platforms that use performance algorithms to end relationships automatically. In every one of these categories, the same question the Dutch regulator asked about Uber applies: was there a real, meaningful human being in the loop before the decision took effect, and did the affected person know the decision was automated?

A pattern, not an isolated case

This fine does not exist in a vacuum. Regulators across the EU have been building toward more aggressive algorithmic-accountability enforcement for several years, and 2026 has already produced multiple headline fines β€” Meta’s €1.2 billion penalty being the most prominent before this one. The pattern that is emerging is consistent: regulators are prioritizing cases where automated systems make decisions with direct economic or reputational consequences for individuals, and where companies cannot produce clear documentation of human oversight. The size of these fines β€” routinely in the hundreds of millions to low billions of euros β€” signals that European regulators view algorithmic accountability as a top-tier enforcement priority, not a secondary compliance issue.

For any company operating in or serving EU markets, or handling EU residents’ data regardless of where the company is headquartered, this trend should be treated as an operating reality, not a distant regulatory risk. GDPR’s extraterritorial reach means a US-based SaaS company with European customers or contractors is exposed to exactly the same Article 22 analysis Uber faced.

πŸ’‘ Pro Tip: Run an internal audit of every automated system in your company that can suspend, deactivate, decline, downgrade, or otherwise take a materially negative action against an employee, contractor, vendor, or customer without a human clicking “approve” first. If you cannot produce a written description of the human review step β€” who does it, how long they spend, what they’re allowed to override β€” for each one, that system is a live GDPR exposure if it touches any EU-connected individual.

What “meaningful human review” actually requires

Regulators and courts interpreting Article 22 have been increasingly specific about what does not count as meaningful human review: a human who merely rubber-stamps an algorithm’s recommendation without the authority, time, or information to actually override it does not satisfy the requirement. Meaningful review generally requires that the human reviewer has genuine discretion to reach a different outcome, has access to the underlying facts (not just the algorithm’s score), and that the process is documented well enough to prove, after the fact, that real judgment was exercised. A review step that exists only on paper, or that is structurally designed to always agree with the algorithm, is unlikely to hold up under regulatory scrutiny.

Companies also need to satisfy the transparency half of Article 22: individuals have to be told, clearly and specifically, when a decision affecting them was made using automated processing, and they need a practical path to contest it. A buried clause in a 40-page terms-of-service document is not the standard regulators are applying in practice.

⚠️ Warning: This fine covers conduct from 2020–2022, meaning the exposure window for algorithmic-decision violations can stretch back years. Fixing your systems today does not eliminate liability for how they operated in the past. If your company has run automated account, employment, or credit decisions on EU-connected individuals for several years without documented human review, get legal counsel involved on both remediation and historical exposure β€” not remediation alone.

A practical compliance checklist

For any company running AI or rules-based decision systems that touch EU individuals, four steps move the needle fastest. First, inventory every automated system capable of a materially negative outcome for a person, and classify each one by whether it is fully automated, human-assisted, or human-decided. Second, for any fully automated system with real-world consequences, either build in a genuine human review step with documented discretion, or be prepared to defend the decision as falling outside Article 22’s scope β€” a narrow and risky argument. Third, update user-facing disclosures so that anyone subject to an automated decision is told plainly, at the time it happens, and given a real path to request human review. Fourth, retain records β€” not just of the algorithm’s output, but of the human reviewer’s reasoning β€” because in an investigation, the burden falls on the company to prove the review was real.

The bottom line

The Uber fine is a data point in a clear regulatory trend: as companies lean harder on AI and automation to manage people at scale, European regulators are responding with correspondingly larger enforcement actions, and they are willing to look back several years to find violations. The compliance bar here is not “don’t use algorithms” β€” it is “don’t let algorithms be the final word on decisions that materially affect people’s livelihoods, without a documented human able to say no.” Companies that treat that distinction seriously now will avoid becoming the next headline; companies that treat Article 22 as boilerplate legal text are building the same exposure Uber is now appealing.

Quick FAQ

Does GDPR Article 22 apply to US companies? Yes, if the company processes personal data of individuals in the EU β€” including employees, contractors, or customers β€” regardless of where the company itself is headquartered. GDPR’s extraterritorial reach is one of its defining features.

Is any use of AI in HR or account-management decisions automatically illegal? No. AI-assisted decisions where a human genuinely reviews the case and has real authority to reach a different outcome are generally compliant. The violation is decisions made solely by the algorithm, with no meaningful human involvement.

What should a company do first if it finds a gap? Stop the fully automated negative action (suspension, deactivation, decline) from taking effect without a documented human sign-off, then work backward to build the review process, disclosure language, and audit trail properly, ideally with legal counsel involved from the start.


Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading