Skip to content

Regulatory Pulse

Dutch DPA fines Uber €824.99 million over automated driver blocking

The Dutch DPA imposed €824.99 million for unlawful automated driver deactivation and inadequate profiling information. Uber has appealed; no final judicial decision has been issued.

Netherlands / European Union
Automated decision-making, profiling and AI governance
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Official enforcement development · Reviewed 10 October 2026 · 7 min read

The 60-second summary

The Dutch DPA imposed €824.99 million for unlawful automated driver deactivation and inadequate profiling information. Uber has appealed; no final judicial decision has been issued. The official summary reports Article 22 and Article 13 infringements involving fully automated driver-account deactivation. The case concerned events between 2018 and 2022 and complaints by 171 drivers. The regulator says the violations have stopped. Uber has appealed, and judicial review is pending.

Timeline that matters

  1. Decision date not specified in the reviewed official summary

  2. EDPB national summary published 8 October 2026

What changed

The official summary reports Article 22 and Article 13 infringements involving fully automated driver-account deactivation.The case concerned events between 2018 and 2022 and complaints by 171 drivers.The regulator says the violations have stopped. Uber has appealed, and judicial review is pending.

Who should care

AI and automated-decision product ownersPrivacy and legal teamsFraud and platform operationsHuman-review and customer-service teams

Why this matters for global organisations.

Automation that removes access to work or services needs a documented legal assessment, meaningful human intervention and usable explanations. A review button alone does not demonstrate that an accountable person can reconsider the outcome.

13 actions to start now

  1. Inventory automated decisions affecting employment, earnings or access to services.
  2. Map inputs, thresholds, fraud signals and customer ratings.
  3. Assess which decisions have legal or similarly significant effects.
  4. Identify any applicable exception and required safeguards with counsel.
  5. Test whether human reviewers have authority, time and information to change outcomes.
  6. Prevent automatic blocking from bypassing required review.
  7. Explain decision logic, significance and likely consequences in accessible notices.
  8. Provide accessible routes to challenge decisions and supply additional context.
  9. Train reviewers to recognise bad signals and discriminatory proxies.
  10. Log the decision, supporting data, reviewer reasoning and outcome.
  11. Refresh the DPIA for materially significant automated workflows.
  12. Test false positives, error correction and appeal turnaround.
  13. Assign an accountable owner and periodically audit production outcomes.

Evidence worth retaining

  • Automated-decision inventory
  • Article 22 assessment and DPIA
  • Model and rules documentation
  • Human-review procedures and training
  • Notices and user-testing evidence
  • Decision and challenge logs
  • Fairness and false-positive test reports

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Is a decision solely automated in substance?
  • Is there a valid exception for this use and are safeguards effective?
  • What level of human involvement is meaningful?
  • What must affected individuals be told about logic and consequences?
  • How should pending judicial review affect reliance on the regulator’s interpretation?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.