Uber B.V. – €824,990,000 Fine (Netherlands, 2026)

€824,990,000Autoriteit Persoonsgegevens21 August 2026Netherlands
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Uber B.V. was fined nearly 825 million euros for using software that automatically deactivated drivers' accounts based on their performance without human review. This decision is important because it highlights the risks of relying solely on automated systems for significant actions that affect people's livelihoods. Drivers who were deactivated could not earn income during this process, which raises serious concerns about fairness and transparency.

What happened

Uber used software to automatically deactivate drivers' accounts based on their behavior and customer ratings without human assessment.

Who was affected

Drivers working for Uber who had their accounts deactivated due to automated decision-making were affected.

What the authority found

The Dutch Data Protection Authority ruled that Uber violated GDPR by making significant decisions about drivers' accounts based solely on automated processing without meaningful human involvement.

Why this matters

This ruling emphasizes the need for companies to ensure human oversight in automated decision-making processes. It serves as a warning for businesses using similar systems to review their practices and improve transparency with their workers.

GDPR Articles Cited

AI-verified

Art. 22(GDPR)
View original scraped data
Art. 22(GDPR)

Original data from scraper before AI verification against source document.

Entities Involved

Uber B.V.
Uber Technologies Inc.
Source verified 27 August 2026
amount discrepancy
Full Legal Summary
Detailed

Uber B.V. and Uber Technologies Inc., the controllers, used software between 2018 and 2022 to monitor drivers’ behaviour and customer ratings. Where the system detected suspected fraud or low customer ratings, drivers’ accounts could be automatically temporarily or permanently deactivated without human assessment. During the deactivation, affected drivers could no longer generate income through Uber. The proceedings followed complaints by 171 French drivers represented by the Ligue des droits de l’Homme. Since the controllers’ main European establishment was in the Netherlands, the Dutch DPA investigated the matter as lead supervisory authority in cooperation with the French DPA and other concerned authorities. The DPA held that the controllers violated Article 22 GDPR by subjecting drivers to decisions based solely on automated processing which significantly affected them. The account deactivations were made automatically, without meaningful human involvement, and prevented affected drivers from working through Uber and earning income via the platform. The DPA also found that the controllers had not sufficiently informed drivers about the automated decision-making. The press release does not specify the exact GDPR transparency provision infringed. The DPA imposed a fine of €824,99 m. The infringing practices had already ended by the time of the decision. The controller announced that it would challenge the fine.

Details

Fine Date

21 August 2026

Authority

Autoriteit Persoonsgegevens

Fine Amount

€824,990,000

GDPRhub ID

gdprhub-10219

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Uber B.V. - Netherlands (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: