Uber fined €825 million for suspending drivers through algorithms without human review
Uber has been fined €825 million by the Netherlands' Data Protection Authority for using automated systems to suspend and deactivate driver accounts without adequate human review, violating GDPR.
Intelligence analysis by Gemini 2.5 Flash

The Dutch regulator imposed a massive fine on Uber for algorithmic management practices between 2018 and 2022, where drivers were suspended or terminated based on fraud detection or low ratings without human oversight. This decision, the second-largest GDPR penalty, underscores strict enforcement against gig-economy platforms.
Imagine a big taxi app that uses a computer program to decide if a driver can keep working. If the computer thinks a driver is doing something wrong, or if their customer ratings drop too low, it might automatically stop them from driving, like taking away their job, without a person even looking at it first. A country in Europe said this isn't fair and made the app pay a huge fine because people should have a chance to explain themselves before a computer makes such a big decision about their work.
Analysis
The Netherlands' Data Protection Authority (AP) has levied a substantial fine of €825 million against Uber, marking a significant enforcement action under the EU's General Data Protection Regulation (GDPR). This penalty, which ranks as the second-largest ever issued under GDPR, specifically addresses Uber's practices of suspending and deactivating driver accounts through automated systems without sufficient human review or prior notice. The violations, occurring between 2018 and 2022, involved a fraud-detection tool and a ratings-based system that could permanently remove drivers, directly impacting their livelihoods.
€825 Million
The core of the AP's finding was that Uber violated drivers' rights by subjecting them to automated decision-making with significant consequences, failing to adequately inform them about these processes. The investigation pinpointed two primary algorithmic systems: one designed for fraud detection, flagging behaviors like unnecessary detours, and another that deactivated drivers based on low customer ratings. In both scenarios, account suspensions or terminations were executed without any human intervention, a practice the AP deemed a serious breach of GDPR's safeguards against automated decisions that have a substantial impact on individuals. Uber has stated it ended the fraud-related suspension process in 2021 and ratings-based deactivations in 2022, but the fine covers past violations.
Dutch Authority
The decision by the Dutch authority to handle this case, despite initial complaints from French drivers, stems from Uber's European headquarters being located in the Netherlands. This is not the first time the AP has taken action against Uber; previous fines include €600,000 in 2018 for an unreported data breach, €10 million in 2023 for unclear data retention, and €290 million in 2024 for transferring European drivers' personal data to the United States without adequate safeguards. This latest fine, however, specifically targets algorithmic management and the communication of suspension decisions, distinguishing it from previous data storage or transfer-related penalties. Uber has expressed strong disagreement with the decision and the fine's magnitude, announcing its intention to appeal.
Indian Parallel
The implications of this European ruling resonate significantly in India, where a GDPR-style law protecting gig workers from automated decision-making is currently absent. Despite this, the issue of arbitrary account deactivation by algorithms, without human explanation, is a common grievance among Uber and Ola drivers in India. Unlike the EU's data protection fines, India's response has primarily manifested through state labor laws and judicial interventions. Rajasthan introduced a gig-worker welfare law in 2023, and Karnataka's 2025 Platform-Based Gig Workers Act mandates aggregators to provide written reasons for deactivation and establish internal dispute-resolution committees. This Karnataka provision is currently facing a constitutional challenge, with petitioners arguing that algorithmic decisions affecting livelihoods require the same due process as human decisions, highlighting the ongoing legal and policy debates in the Indian gig economy.
Key points
- Uber was fined €825 million by the Netherlands' Data Protection Authority for violating GDPR by using automated systems to suspend drivers.
- The violations involved fraud-detection and ratings-based systems that deactivated accounts without human review or adequate notice between 2018 and 2022.
- This is the second-largest GDPR fine ever, signaling strict enforcement against gig-economy platforms for algorithmic management practices.
- In India, similar issues of arbitrary algorithmic deactivation are common, leading to state-level gig-worker welfare laws and ongoing constitutional challenges.
- Uber claims it has since implemented human review and dispute processes, but plans to appeal the decision, calling the fine disproportionate.
Uber's stated current policies, which include human review and a dispute process for drivers, suggest a potential shift towards more equitable algorithmic management. This could lead to improved working conditions and greater transparency for gig workers, fostering a more trust-based relationship between platforms and their drivers.
Uber's strong disagreement with the fine and its intention to appeal indicate a prolonged legal battle, which could delay the full implementation of robust human oversight in algorithmic decision-making. In India, the constitutional challenge against new gig worker protection laws suggests continued uncertainty and potential setbacks for drivers seeking due process against automated deactivations.



