Uber Hit With $966 Million Fine in the Netherlands Over Automated Driver Dismissals
The Dutch Data Protection Authority (DPA) has imposed a $966 million fine on Uber, accusing the ride-hailing giant of using automated systems to suspend or deactivate some drivers' accounts without adequately informing them or providing appropriate human oversight.
This fine marks the second-largest penalty ever issued under the European Union's General Data Protection Regulation (GDPR), placing Uber squarely in the crosshairs of one of the largest regulatory sanctions levied against a U.S. tech company in Europe.
Algorithmic Decision-Making Under Scrutiny
The Dutch DPA stated that Uber violated drivers' rights by relying on automated systems to make decisions that significantly impacted their ability to work on the platform, without providing sufficient transparency regarding how these decisions were reached.
Under European data protection rules, individuals cannot be subjected to decisions based exclusively on algorithms if those decisions carry legal or significant personal impacts. Companies are required to ensure genuine human review and grant individuals the right to contest such decisions.
The case dates back to practices Uber employed across Europe between 2020 and 2022. The investigation was triggered by a complaint filed by drivers in France but was subsequently transferred to the Dutch authority, as Uber’s European headquarters is located in the Netherlands.
Fraud Detection vs. Driver Rights
Uber utilized automated systems to suspend the accounts of drivers suspected of violations or fraud. Flagged cases included drivers deemed to have taken excessively long routes to inflate fares or those who accepted ride requests without the intention of completing them.
The Dutch authority also noted that some drivers who received low customer ratings had their accounts permanently deactivated through these automated systems. However, Uber denied relying solely on automation for permanent account deactivations.
Uber's Response and Appeal
Uber strongly opposed the decision, calling the fine "disproportionate" and confirming its intention to appeal. The company asserted that its current policies involve human review of such decisions and afford drivers the opportunity to appeal account suspensions.
Defending its practices, Uber highlighted that the investigated actions stem from legacy policies that were discontinued years ago. The company maintained that it now handles decisions affecting drivers' earning capabilities with a high degree of care. Furthermore, Uber argued that the scope of affected drivers was limited, noting that only 126 drivers in Europe had their accounts deactivated in 2021 due to low customer ratings—a point it cited as evidence that the fine is exaggerated.
Mounting Regulatory Pressure in Europe
This penalty arrives amid heightened scrutiny by European regulators over how major tech firms utilize data and algorithms, particularly when automated systems directly affect individuals' rights or employment capabilities.
The new fine dwarfs a previous $338 million penalty imposed on Uber by Dutch authorities for transferring European drivers' personal data to the U.S. in violation of data protection rules.
Uber’s latest penalty ranks as the second-largest GDPR fine to date, trailing only the roughly $1.40 billion fine levied against Meta by Irish regulators in 2023 for illegally transferring European Facebook users' data to the U.S.
The case underscores the escalating regulatory pressure on U.S. tech companies operating in Europe, as authorities increasingly deploy massive fines against corporations that deploy personal data or algorithmic systems without implementing required safeguards for users and gig workers.
