Dutch regulators hit Uber with a record €825 million GDPR fine for silently deactivating driver accounts
Executive summary: The Dutch Data Protection Authority fined Uber €825 million for automatically suspending driver accounts without informing them, a breach of GDPR provisions on automated individual decision‑making. This is the largest GDPR fine to date, highlighting regulators’ willingness to penalise large tech firms for opaque algorithmic practices and potentially raising compliance costs across the ride‑hailing sector.
Who is involved: Uber Technologies Inc., the Dutch Data Protection Authority (AP), and the affected driver community in the Netherlands.
Likely next: Uber may lodge an appeal within the statutory period, and the decision could prompt similar investigations in other EU member states and spur stricter safeguards on automated account‑management systems.
The Dutch Data Protection Authority has imposed an €825 million fine on Uber after finding that the company’s automated system for suspending driver accounts breached GDPR Article 22, which requires transparency, human review, and meaningful recourse for decisions made solely by algorithms. The investigation revealed that Uber deactivated drivers — often without notice, explanation, or a genuine opportunity to contest the action — a practice the regulator labelled "silent deactivations." The penalty is the largest ever levied on a single company under the EU privacy regime and marks a decisive shift toward enforcing algorithmic accountability in the gig economy. By targeting the opaque automation that underpins platform workforce management, the ruling sets a precedent that extends beyond ride‑hailing to any service that uses automated decision‑making to control access to livelihoods. Companies must now demonstrate that their systems provide clear logic, human oversight, and effective appeal channels. Uber has announced it will appeal, a process that could take years, but the immediate impact is already rippling through the sector. Competing platforms such as Bolt, Deliveroo, and local taxi apps are auditing their own automated suspension and rating mechanisms to avoid similar sanctions. Meanwhile, European regulators are coordinating guidance on algorithmic transparency, suggesting a wave of enforcement actions that could raise compliance costs and reshape how gig platforms design their control systems.
Timeline
- — Uber soll wegen Verstoß gegen Datenschutzregeln in den Niederlanden 825 Millionen Euro Strafe zahlen (Der Spiegel — Wirtschaft)
Analysis — what this means
Sectors affected
- Ride‑hailing and mobility platforms
- Data‑privacy compliance services
Regulatory implications
- Record GDPR fine shows authorities can impose penalties up to 4% of global turnover for infringements.
Historical parallels
- Google fined €50 million by CNIL in 2019 for lack of transparency under GDPR.
- British Airways fined £20 million by ICO in 2020 for a data‑breach affecting passenger data.
- Marriott fined £18.4 million by ICO in 2020 for insufficient protection of guest‑data.
Key entities
Sources
Open the full interactive case file on Beyond →