Uber B.V. – €824,990,000 Fine (Netherlands, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Uber B.V. was fined nearly 825 million euros for using software that automatically deactivated drivers' accounts based on their performance without human review. This decision is important because it highlights the risks of relying solely on automated systems for significant actions that affect people's livelihoods. Drivers who were deactivated could not earn income during this process, which raises serious concerns about fairness and transparency.
What happened
Uber used software to automatically deactivate drivers' accounts based on their behavior and customer ratings without human assessment.
Who was affected
Drivers working for Uber who had their accounts deactivated due to automated decision-making were affected.
What the authority found
The Dutch Data Protection Authority ruled that Uber violated GDPR by making significant decisions about drivers' accounts based solely on automated processing without meaningful human involvement.
Why this matters
This ruling emphasizes the need for companies to ensure human oversight in automated decision-making processes. It serves as a warning for businesses using similar systems to review their practices and improve transparency with their workers.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Entities Involved
Uber B.V. and Uber Technologies Inc., the controllers, used software between 2018 and 2022 to monitor drivers’ behaviour and customer ratings. Where the system detected suspected fraud or low customer ratings, drivers’ accounts could be automatically temporarily or permanently deactivated without human assessment. During the deactivation, affected drivers could no longer generate income through Uber. The proceedings followed complaints by 171 French drivers represented by the Ligue des droits de l’Homme. Since the controllers’ main European establishment was in the Netherlands, the Dutch DPA investigated the matter as lead supervisory authority in cooperation with the French DPA and other concerned authorities. The DPA held that the controllers violated Article 22 GDPR by subjecting drivers to decisions based solely on automated processing which significantly affected them. The account deactivations were made automatically, without meaningful human involvement, and prevented affected drivers from working through Uber and earning income via the platform. The DPA also found that the controllers had not sufficiently informed drivers about the automated decision-making. The press release does not specify the exact GDPR transparency provision infringed. The DPA imposed a fine of €824,99 m. The infringing practices had already ended by the time of the decision. The controller announced that it would challenge the fine.
Related Enforcement Actions (2)
Other enforcement actions involving Uber B.V. in NL
Fine
€825.0M
Details
Fine Date
21 August 2026
Authority
Autoriteit Persoonsgegevens
Fine Amount
€824,990,000
GDPRhub ID
gdprhub-10219About this data
Cite as: Cookie Fines. Uber B.V. - Netherlands (2026). Retrieved from cookiefines.eu
Last updated: