Policy & Geopolitics
Automated Decisions Just Cost Uber €1.13B in Total
The Dutch DPA fined Uber €825M for deactivating drivers without human review — the third fine from one 2020 complaint, now €1.13B cumulative.
The Dutch Data Protection Authority fined Uber €824,990,000 — roughly $966 million — for deactivating driver accounts through automated systems with no human in the decision, the second-largest penalty ever issued under the GDPR. The French CNIL, which co-ran the case, confirmed the amount and the reasoning in its statement on the automated-decisions penalty: deactivations for suspected fraud and for low customer ratings “constitute automated individual decisions due to the complete absence of human intervention in the decision-making process.”
Add up what one complaint has now cost. The CNIL notes the same 2020 collective filing — brought by La Ligue des droits de l’Homme on behalf of more than 170 drivers — produced a €10 million fine in December 2023 for failing to inform drivers, a €290 million fine in July 2024 over data transfers, and now €825 million. That is roughly €1.13 billion in cumulative penalties traceable to a single complaint about how an automated system treated a few hundred people. The escalation curve, not the headline number, is what belongs in a governance review.
Scale it against the business and the figure stops looking abstract. Uber reported $52.0 billion of 2025 revenue in its annual report on Form 10-K, so the $966 million penalty equals about 1.9% of a full year’s revenue — material, but well inside the 4% ceiling the regulation permits. The room left above the fine is the part a compliance team should read as a warning rather than a reprieve.
The violation was procedure, not prediction
Read the finding carefully and it says nothing about model quality. The regulator did not rule that Uber’s fraud signals were inaccurate or its ratings unfair. It ruled that decisions with major consequences for individuals were made with no human involved and without adequate notice. Deputy chair Monique Verdier put it bluntly in TechCrunch’s account of the decision: “A computer should not make decisions on its own that have such major consequences.”
Uber disputes the factual predicate, saying most suspensions are brief, no permanent deactivation occurs without human review, and drivers can appeal; it will file an appeal, and AP’s report notes the company says the authority examined “historic policies that were discontinued years ago.” The violations were dated 2018 to 2022. That is the detail operators should sit with: conduct retired four years ago produced a nine-figure penalty in 2026, because enforcement runs on the regulator’s clock, not the product roadmap’s.
The bill for shipping an agent without a human gate
Every team now wiring agents into systems that suspend accounts, deny claims, flag transactions, or gate access is building the same legal object Uber built — an automated individual decision under Article 22 of the GDPR, which restricts decisions based solely on automated processing that produce legal or similarly significant effects. The 2026 twist is that agents make these decisions faster, in more places, and with far worse documentation than a rules engine did in 2019.
Three controls follow directly from the finding, and none require slowing a product down. Log the human intervention, not just the outcome: the violation was the absence of intervention, so an audit trail showing who reviewed what, when, is the evidence that decides the case. Distinguish reversible from consequential actions in code, and route only the consequential ones through review — the approval-gating pattern this paper set out when Claude gained write access to workspace email. And write the notice before launch, since Uber’s first fine, the €10 million one, was for failure to inform.
The jurisdictional mechanics matter as much as the controls. The Dutch authority led because Uber’s main European establishment is in Amsterdam, running the case through the GDPR’s one-stop-shop cooperation procedure with the CNIL examining the draft decision. A complaint filed by French drivers therefore produced a Dutch penalty covering conduct across the bloc. For any company running one automated decision system across multiple European markets, that is the shape of the exposure: a single design choice, one lead regulator, and a fine sized against global turnover rather than local revenue.
The counterpoint deserves airing, because it is not frivolous. Writing in his linked commentary on the decision, John Gruber argued the ruling risks making it unlawful for Uber to police drivers who scam customers, and that blaming “a computer” is like blaming a time clock for a firing. The counter-argument, from PersonalData.io founder Paul-Olivier Dehaye in the same TechCrunch piece, is that Uber is free to punish scammers using humans — it must then accept the responsibility that comes with deciding. Both readings agree on the operational point: the cost of automation here is the cost of a reviewer, and the fine prices what skipping one is worth.
What would change the verdict is the appeal. A Dutch court reducing or vacating the penalty would weaken the deterrent considerably, and Dehaye’s plan to launch a class action for driver compensation could push total exposure well past the fine itself. Until then, the enforceable rule is simple and it sits alongside today’s lead on how buyers are actually spending on frontier models: capability is cheap, and the human in the loop is now a line item with a known price, as the archive argued when the UK AI Safety Institute pushed agent evaluation toward governance.
Sources
- CNIL — Automated decisions: UBER fined nearly EUR 825 million
- TechCrunch — Uber faces fine of nearly $1B over automated driver suspensions
- AP News — Uber fined nearly $1 billion by Dutch regulators over account suspensions
- GDPR Article 22 — automated individual decision-making, including profiling
- Daring Fireball — commentary questioning the Dutch regulator’s reasoning
- SEC EDGAR — Uber Technologies annual report on Form 10-K for 2025
- EUR-Lex — consolidated text of the General Data Protection Regulation