Uber has been hit with a record €825 million ($966 million) fine by the Dutch data protection authority (AP) for using automated systems to deactivate driver accounts without providing sufficient information about the process. The regulator found that the ride-hailing giant violated GDPR requirements by failing to explain how its algorithms made suspension decisions and by not giving drivers a meaningful opportunity to challenge those decisions.
The fine, announced in a decision dated August 17, is the second-largest GDPR penalty ever imposed, surpassed only by the €1.2 billion fine against Meta in 2023. The AP's investigation focused on Uber's use of automated tools to identify and suspend drivers suspected of fraud or other policy violations, determining that the company's procedures lacked transparency and due process.
Under GDPR, companies must provide "meaningful information about the logic involved" in automated decision-making and allow individuals to obtain human intervention. The AP concluded Uber fell short on both counts. The company has signaled it will appeal the decision, arguing that its systems are designed to protect passengers and that drivers are given clear explanations for suspensions.
This case is part of a broader trend of European regulators imposing hefty penalties on major US technology firms. In recent years, regulators have fined Apple, Google, and Meta billions of euros for violations ranging from antitrust practices to data privacy breaches. The Digital Markets Act and GDPR have given authorities powerful tools to enforce rules against companies violating European standards.