On 24 August 2026 the Dutch Data Protection Authority fined Uber €825 million — about $964 million — for breaching the GDPR.
The finding is not about a breach or a leak. It is about who, or what, made a decision.
What Uber did
It used automated software to suspend driver accounts, sometimes permanently, without human review to catch mistakes. And it did not tell drivers that automated decision-making was being applied to them.
The violations run from 2018 to 2022.
The right being enforced
GDPR restricts decisions made solely by automated processing where they produce legal or similarly significant effects on a person. Losing the account you drive for is comfortably inside that.
The obligation is not that software cannot be involved. It is that a person must be able to obtain human intervention, express a view and contest the outcome — and must be told the processing is happening in the first place. On the regulator's finding, Uber failed on both halves: no human in the loop, and no notice.
That distinction matters for anyone building with models right now. The rule was never "do not automate". It is that an automated decision about a person needs a door back to a human, and the person has to know the door exists.
Uber's answer
The company disagrees and will appeal. It says it takes driver welfare seriously and is fully committed to fair treatment, including human reviews, robust safeguards and the opportunity for drivers to appeal — and that the policies at issue were discontinued years ago.
Both things can be true. A company can have fixed a practice and still be fined for the years it ran, which is how enforcement of a four-year-old violation necessarily works.
The fourth fine, and the trajectory
This is the fourth penalty the same Dutch authority has issued against Uber. In 2024 it fined the company €290 million over transfers of European driver data to the United States.
€290 million then. €825 million now. Roughly 2.8 times larger, from the same regulator, against the same company, two years apart.
That is the same curve we traced through TikTok's COPPA settlement, where a $5.7 million penalty in 2019 became $400 million in 2026 and through Google's €890 million DMA fine. Regulators across two continents have arrived at the same conclusion in the same year: the previous numbers were too small to change behaviour.
Why this one is different from the others
Because it is not about data moving somewhere it should not, or a market being tilted. It is about an algorithm making a decision that ended someone's income, with nobody obliged to look at it.
That is the first of these fines that reads as a direct precedent for AI systems now being deployed into hiring, lending, insurance and moderation. None of the reasoning depends on the software being sophisticated. It depends on there being a consequential decision, no human, and no notice.
India's DPDP obligations arrive in November 2026 without an equivalent automated-decision right in the same form, which makes the European position the one to watch if you build for both markets.
What is not established
- How many drivers were affected. Not specified in the reporting.
- Whether the fine survives appeal. Uber has said it will contest it.
- What the automated system actually did — the technical basis for suspensions has not been described publicly.
- Whether the current process satisfies the regulator. Uber says the policies were discontinued; the authority has not said the replacement is compliant.