Skip to content

Swiss Chinese Law Association — Geneva

SCLA | Swiss Chinese Law Association

Legal Observatory / AI and Data

Legal Update European Union Status unclear

Dutch Data Protection Authority Fines Uber EUR 824.99 Million for Unlawful Automated Decision-Making

The Dutch Data Protection Authority fined Uber EUR 824 990 000 for unlawful fully automated decision-making and failing to provide sufficient information on profiling under Articles 13 and 22 of the GDPR.

What Changed

  • The Dutch AP fined Uber EUR 824 990 000 for unlawful automated account deactivations of drivers and insufficient information on profiling under Articles 13 and 22 GDPR.
  • The enforcement action followed 171 French driver complaints submitted via LDH and CNIL, handled by the Dutch AP under the GDPR One-Stop-Shop mechanism for incidents between 2018 and 2022.
  • Uber has ceased the contested violations and appealed the fine, leaving the matter pending a final judicial decision.

The Dutch Data Protection Authority, the Autoriteit Persoonsgegevens (AP), has imposed an administrative fine of EUR 824 990 000 on Uber for failing to comply with the European Union's General Data Protection Regulation (GDPR). The regulatory decision impacts digital platforms and ride-hailing services using automated systems to manage service providers and workforce operations in the European Union.

The case originated from complaints submitted by 171 French Uber drivers through the Ligue des droits de l’Homme (LDH) to the French data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL). Because Uber maintains its European headquarters in the Netherlands, the investigation was handled by the Dutch AP under the GDPR One-Stop-Shop procedure. The regulatory review examined incidents occurring between 2018 and 2022.

The AP concluded that Uber breached Article 22 of the GDPR, which restricts fully automated individual decision-making, including profiling, where decisions produce legal effects or significantly affect individuals. The AP found that Uber subjected drivers to fully automated decisions based on fraud suspicions or low customer reviews. Uber's system automatically deactivated driver accounts temporarily or permanently in cases of persistent low ratings, directly resulting in lost driver income on the platform.

Furthermore, the authority ruled that Uber violated Article 13 of the GDPR by failing to provide drivers with sufficient information regarding automated decision-making and profiling processes when personal data was collected.

While the AP confirmed that Uber has stopped the violations, Uber has appealed the administrative fine. A final judicial decision on the matter has not yet been rendered.

Who May Be Affected

Platform technology companies, gig-economy workers, digital platform drivers, data protection officers, and regulatory compliance teams in the EU.

Cross-Border Context

The matter involved cross-border GDPR enforcement via the One-Stop-Shop mechanism, linking complaints from French drivers (CNIL) with Uber's European headquarters in the Netherlands (AP).

What to check next

  • Status and outcome of Uber's judicial appeal against the Dutch AP's administrative fine.
  • Subsequent guidance or case law regarding human intervention requirements in platform driver account deactivations under Article 22 GDPR.

This article provides general information and does not constitute legal advice. Consult the official text and obtain advice appropriate to your circumstances where needed.

Keep the issues that matter to you in view

Subscribe to SCLA updates and choose your interests.