Subjects
Jurisdictions

EU/Netherlands: Uber Fined for GDPR breach

Uber has been fined EUR825 million by the Dutch data protection authority for a breach of the automated decision-making rules under Article 22 of the EU GDPR, the second largest penalty ever issued under these regulations.

The Breach Activity

Uber had been using fully automated decision-making technology (ADT) to suspend or deactivate drivers’ accounts, without any human oversight. 

These decisions were likely to have significant effects on drivers’ finances.

GDPR Rules

Article 22 gives data subjects the “right not to be subject to a decision based solely on automated processing”, where those decisions may have “significant” effects.  This clearly includes automated decisions without human review.

“Significant” decisions are those likely to have serious real-world impact on an individual’s finances, health or social standing, which would include many employment related decisions.

Exceptions to the basic rule include decisions necessary for entering into, or performance of, a contract of where the data subject has given explicit informed consent. However, even in these cases the data controller must have in place measures to protect the subject’s rights, freedoms and legitimate interests. This includes rights to contest decisions made without human review.             

Breaches can result in fines up to 4% of global turnover.

The Employment Context

The Uber decision relates to the gig-economy, but the impact is much wider.  According to research by Visionary Analytics in 2025, 25% of European employers are using ADT to make decisions previously made by managers. This will only increase. Usages are seen in hiring, performance measuring and selections for both promotion and redundancy pooling.  

Steps to Ensure Compliance
  • Data Protection Impact Assessments (DPIA): Conducting DPIA’s are mandatory where ADT means there is a high risk to the rights and freedoms of individuals.  Nevertheless, conducting a DPIA is good practice in any event, particularly when the mandatory threshold is unclear. The assessment will help identify and minimise data privacy and compliance risks.
  • Ensure that human involvement in automated decision-making is meaningful and carried out by a person with the authority and competence to change outcomes. They must be sufficiently informed of ADT risks to detect anomalies and automation bias and be able to interrupt and override the decision.
  • Have processes in place that allow data subjects to understand and contest high impact decisions, including the ability to require human review.
  • Publish clear, accessible transparency statements explaining how the ADT will be used, which decisions will be affected, and how individuals can request a review.       

This is a high-level general update only. Legal advice should be obtained on specific circumstances.


Scroll to Top