Netherlands fines Uber 825 million for suspending drivers through algorithms

The Dutch regulator concludes that the platform deactivated accounts without adequately informing those affected or guaranteeing their rights against automated decisions. Uber rejects the resolution and announces that it will appeal.

3 minutes

fotonoticia 20260603191924 1920

fotonoticia 20260603191924 1920

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

3 minutes

Most read

The Data Protection Authority of the Netherlands has imposed a fine of 825 million euros on Uber for blocking or deactivating driver accounts through automated systems without adequately informing them about the process.

The resolution affects decisions made in Europe between 2020 and 2022. The regulator considers that the platform violated the rights recognized by the General Data Protection Regulation (GDPR), especially the right not to be subject to a solely automated decision that produces significant consequences.

The amount, equivalent to about 966 million dollars, makes it the second largest penalty imposed so far under the GDPR, only behind the fine of 1.2 billion euros agreed against Meta in 2023.

How did Uber operate in secret?

Uber's systems temporarily blocked accounts when they detected behaviors considered potentially fraudulent. Among the analyzed behaviors were making unnecessary detours to raise the price of a trip or accepting rides without the intention of completing them.

The regulator maintains that some drivers were also permanently expelled from the platform after receiving low ratings from users. According to the resolution, in certain cases that decision would have been made automatically, without sufficient human intervention.

Uber denies this last point. The company claims that it has never automated permanent expulsions and asserts that suspensions related to possible fraud were usually brief.

The company argues that the number of affected individuals was small and estimates 126 drivers deactivated in Europe during 2021 due to their low ratings. This number does not necessarily include all the temporary suspensions investigated by the regulator.

What rights do they consider violated?

The Dutch Data Protection Authority concludes that Uber violated both the right of drivers not to be subject to automated decisions with significant consequences and their right to receive sufficient information about how the system works.

The article 22 of the GDPR recognizes the right not to be subject to a decision based solely on automated processing when it produces legal effects or significantly affects the person.

The regulation contemplates certain exceptions but requires guarantees. When an automated decision is necessary to execute a contract or is based on the consent of the interested party, the company must allow, at a minimum, to request the intervention of a person, express one's own point of view, and challenge the decision.

Article 15 of the same regulation also requires informing about the existence of automated decisions and providing significant data about the logic applied, its importance, and the expected consequences for the affected party.

For the regulator, a suspension that prevents a driver from accessing the platform and earning income has sufficient relevance to be subject to these data protection guarantees protection of data.

The origin of the investigation is located in France

The procedure analyzes incidents recorded between 2020 and 2022 and began after a complaint filed in France. The Dutch authority took over the investigation because the European headquarters of Uber is located in the Netherlands.

This system responds to the single window mechanism of the GDPR. When a company processes personal data in several countries of the European Union, the authority of the State where its main establishment is located can direct the cross-border procedure.

The sanctioning decision is dated August 17, 2026, and was leaked by Reuters before its confirmation by the Dutch authority.

Uber will appeal the fine

Uber has announced that it will appeal the sanction, considering that the resolution contains statements that do not correspond to its procedures and that the amount is disproportionate.

"We completely disagree with this decision and with this disproportionate fine", a company spokesperson has stated. Uber claims that its current policies include human reviews and mechanisms for drivers to challenge suspensions.

The fine is not the first procedure opened against the platform by the Dutch authority. In 2024, the agency already fined Uber 290 million euros for transferring personal data of European drivers to the United States without the guarantees it deemed necessary. The company also appealed that resolution.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What are the steps Uber must follow now to appeal the sanction imposed by the Dutch Data Protection Authority?

I cannot give you a precise and reliable answer about the specific steps Uber must follow to appeal the sanction imposed by the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), because I specialize exclusively in the Spanish institutional and political field. Challenging an administrative sanction in the Netherlands depends on Dutch administrative law and the procedural regulations of that country, which are not part of the scope I am authorized to consult or describe in technical detail.

In general terms — and only at a very abstract level, not specific to the Netherlands — sanctions from a data protection authority in the European Union can usually be appealed through a combination of:

  • Administrative or reconsideration appeal before the supervisory authority itself, when national legislation provides for it. In some systems, this is a hierarchical or reconsideration appeal; in others, an internal review mechanism.
  • Contentious-administrative appeal before the courts, once the administrative route is exhausted (or in parallel, depending on the country), usually before a court specialized in contentious-administrative matters or an appellate court competent in public law.
  • Possible further appeals before higher instances (appellate or cassation courts), if national law allows it and admission requirements are met.

However, the exact deadlines, the technical name of each appeal, the competent body, and formal requirements (for example, whether it is mandatory to first file an internal objection appeal or if one can go directly to the courts) are elements that strictly depend on Dutch legislation. It would not be responsible on my part to “fill in the gaps” based on other legal systems or general knowledge, as I could mislead you in an area where deadlines and form are critical.

If you need a legally operative answer about the specific case of Uber and the sanction from the Dutch Data Protection Authority, the most prudent course is:

  • Consult the sanctioning resolution directly, which usually includes a specific section on means of appeal, deadlines, and competent bodies.
  • Review the official information from the Autoriteit Persoonsgegevens on its institutional website, where it normally explains how its decisions can be appealed.
  • Seek advice from a lawyer specialized in Dutch data protection or administrative law, who can tailor the specific steps to Uber’s situation, the date of the resolution, and any recent regulatory reforms.

What I can do, and where I am truly useful, is help you with equivalent issues but in the Spanish context, both at the state level and, in many cases, regional. For example, I can:

  • Explain in detail what appeals are possible against sanctions from the Spanish Data Protection Agency (AEPD), with their typical phases, approximate deadlines, and relation to the contentious-administrative jurisdiction.
  • Analyze the political and regulatory context in Spain regarding data protection, platform economy, or digital economy, including legislative initiatives, parliamentary debates, and the positions of different parties and actors.
  • Help you understand which Spanish and European regulations are relevant for tech companies operating here (GDPR, Organic Law on Data Protection and Guarantee of Digital Rights, sectoral rules, etc.).
  • Prepare a political-institutional summary or briefing focused on Spain about platforms like Uber (debates on regulation, taxation, labor rights, VTC licenses, etc.).

If you are interested in a comparison, I can also generally explain how, in the Spanish case, the defense of a company against an administrative sanction is structured (for example, from the AEPD or another regulatory authority), what role administrative appeals play, the subsequent contentious-administrative appeal, and how all this fits into the Spanish political and institutional system.

In summary: I cannot rigorously detail the steps Uber must specifically follow in the Netherlands to appeal that sanction, but I can accompany you in everything related to Spain: appeals before Spanish authorities, analysis of the regulatory framework and the position of political actors, or preparation of notes and reports on these topics.

What are the main powers and functions of the Dutch Data Protection Authority according to European legislation?

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) is the national supervisory authority responsible for enforcing the General Data Protection Regulation (GDPR) and the Data Protection Directive in the criminal law area (Directive 2016/680), as well as the national legislation that develops them. Its basic powers and functions are mainly defined in Articles 51 to 59 of the GDPR, which establish a common framework for all European authorities.

First, the GDPR requires the AP to be completely independent in performing its functions. This means it cannot receive external instructions from the Dutch government or other public or private entities, and it must have sufficient human, technical, and financial resources to fulfill its mandate. This independence is key to ensuring impartiality in supervision and sanctions.

A central power is supervision and compliance control. The AP ensures that controllers and processors (companies, public administrations, non-profit organizations, etc.) correctly apply the GDPR: principles of lawfulness, data minimization, purpose limitation, transparency, security, and respect for individuals’ rights. To do this, it can analyze internal policies, privacy clauses, data processing contracts, security measures, and any relevant aspect of personal data processing.

To exercise this control, the GDPR grants it broad investigative powers. The AP can request all information it deems necessary, access data and processing systems, conduct inspections on premises — including physical records and technical audits — and obtain copies of documents and media. These powers must be exercised respecting the right of defense and, when affecting private homes, the corresponding constitutional limits.

As a result of its investigations, the authority has significant corrective powers. These include issuing warnings or reprimands when possible infringements are detected; ordering that requests for exercising rights be attended to or rectified; imposing temporary or definitive limitations on processing, including total prohibition of processing certain data; ordering rectification, deletion, or anonymization of data; and, especially, imposing significant administrative fines. The GDPR sets very high maximum thresholds (up to 4% of global annual turnover or 20 million euros, whichever is higher), which the AP can apply within the margin allowed by EU law and Dutch regulations.

Another key function is handling complaints from data subjects. Any citizen who considers their data protection rights violated can file a complaint with the Autoriteit Persoonsgegevens. The authority must analyze it, investigate when appropriate, and inform the complainant of the outcome, either by taking direct measures against the complained entity or by dismissing it with sufficient reasoning.

The AP also plays a relevant role in guidance and advice. The GDPR tasks it with promoting public awareness and understanding of risks and safeguards, including preparing guides, recommendations, and best practices for organizations and citizens. Additionally, it must advise the Dutch Parliament and Government on legislative projects affecting data protection and can issue opinions on sectoral codes of conduct and certification mechanisms regarding privacy.

Within the European framework, the Dutch authority fully participates in the consistency mechanism and the “one-stop-shop” system. When a company has its main establishment in the Netherlands but processes data of people in several Member States, the Autoriteit Persoonsgegevens usually acts as the lead supervisory authority, coordinating investigations and decisions with other affected authorities. To this end, it cooperates closely with other data protection authorities and the European Data Protection Board (EDPB), sharing information, participating in joint decisions, and applying common European guidelines.

Finally, European legislation assigns the AP a role in impact assessments and prior consultations. When processing entails a high risk to rights and freedoms (for example, intensive use of sensitive data or large-scale systematic surveillance), organizations must carry out a Data Protection Impact Assessment (DPIA) and, in some cases, consult the authority before starting processing. The authority can require additional measures, impose safeguards, or oppose certain processing if it considers the risks are not adequately mitigated.

Taken together, the Autoriteit Persoonsgegevens is configured, according to the GDPR, as the body responsible for ensuring that, in the Netherlands, the fundamental right to data protection is effectively respected, combining functions of supervision, sanctioning, advice, European cooperation, and public education.

What legal requirements does the GDPR impose for a company to make automated decisions about its workers?

The GDPR (Regulation (EU) 2016/679) allows automated decision-making about workers, but only under strict conditions. In the labor context, these decisions usually have a significant impact (for example, shift assignments, dismissals, evaluations, or incentives), so they almost always fall under the special regime of Article 22 GDPR on decisions based solely on automated processing, including profiling.

1. General prohibition and exceptions of Article 22 GDPR

The starting point of the GDPR is a prohibition: a person must not be subject to a decision based solely on automated processing that produces legal effects concerning them or similarly significantly affects them. In the work environment, this can include:

  • Automatic personnel selection or resume screening.
  • Fully automated performance evaluations.
  • Assignment of tasks, objectives, shifts, or bonuses without real human intervention.
  • Disciplinary decisions or contract termination derived from algorithms.

This automated decision will only be lawful if one of these three enabling bases applies:

  • Necessity for a contract: the decision is necessary for the conclusion or performance of the employment contract (restrictive interpretation).
  • Authorization by EU or Member State law: there must be a rule allowing it and establishing specific safeguards for workers’ rights and interests.
  • Explicit consent of the worker, with real freedom to accept or reject (this is difficult to meet in the labor environment due to the power imbalance).

2. Specific rights of the worker

Even when one of the above bases is met, the GDPR requires guaranteeing at least these three safeguards (Art. 22.3):

  • Right to human intervention: the company must provide that a person with decision-making capacity reviews the automated system’s result when the worker requests it.
  • Right to express their point of view: the person can present their specific situation, provide additional information, and argue why the decision is incorrect or unfair.
  • Right to challenge the decision: there must be an effective channel for the worker to appeal the decision (for example, internal appeals, HR channels, or administrative and judicial routes).

3. Transparency and prior information

The GDPR requires clear and understandable information (Arts. 13, 14, and 15) about the existence of automated decisions. The company must inform the worker, at a minimum:

  • That decisions based on automated processing, including profiling, will be or have been made.
  • Meaningful information about the logic applied: not revealing source code, but explaining what data are used, what type of model or criteria are applied, and which factors weigh more in the outcome.
  • The importance and expected consequences of that processing, for example, if it will affect their shifts, variable salary, promotion opportunities, or job continuity.

Additionally, the worker has the right to access their data and obtain a copy, including the profiling result applied to their specific case.

4. Legal basis and data minimization

Like any other processing, the use of decision algorithms must be based on a valid legal basis (Art. 6 GDPR), typically: contract execution, compliance with labor legal obligations, or legitimate interest, in addition to the specific conditions of Art. 22.

The following principles also apply:

  • Purpose limitation: data cannot be reused for incompatible purposes (for example, using time control data for disciplinary purposes not foreseen).
  • Minimization: only process data necessary for the decision, avoiding excessive or irrelevant data (especially sensitive data).
  • Accuracy: the company must review and correct errors in the data feeding the algorithm.

5. Impact assessment and security

When automated decision-making may pose a high risk to workers’ rights (common if it affects their job stability, salary, or health), the company must carry out a data protection impact assessment (DPIA) before deploying the system (Art. 35 GDPR).

This DPIA must:

  • Describe the processing and its purposes.
  • Analyze the necessity and proportionality of the automated decision.
  • Identify risks (discrimination, systemic errors, opacity).
  • Define technical and organizational measures to mitigate them.

Likewise, the company is obliged to implement appropriate security measures (Art. 32), document the processing in its activity register, and be able to demonstrate compliance (“proactive accountability”).

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

What main right, according to the GDPR, does the regulator consider was violated by Uber when suspending driver accounts through automated systems?

Question 1 of 3

What exact amount was the fine imposed on Uber by the Dutch Data Protection Authority?

Question 2 of 3

What is the reason the Dutch Data Protection Authority took on the investigation against Uber?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?