In a landmark ruling that signals a tightening grip on Big Tech’s use of algorithmic management, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, or AP) has issued a staggering €824.9 million ($966 million) fine against Uber. The penalty, one of the largest ever levied under the European Union’s General Data Protection Regulation (GDPR), centers on the ride-hailing giant’s practice of automatically deactivating driver accounts without human oversight—a practice the regulator says robbed thousands of workers of their livelihoods.
This development marks a significant escalation in the ongoing legal and regulatory tug-of-war between Uber and European authorities, further cementing the Netherlands—where Uber maintains its European headquarters—as the epicenter of the battle for digital labor rights.
The Core Allegation: Algorithms Over Accountability
At the heart of the Dutch regulator’s case is the concept of "automated decision-making." Between 2018 and 2022, Uber utilized proprietary algorithms to monitor, assess, and, in many cases, terminate the accounts of drivers across the European Union.
According to the AP, these systems functioned as a "black box." Drivers whose accounts were flagged for suspected fraudulent activity or policy violations were often deactivated instantly. Crucially, these decisions were made entirely by software, with no meaningful human review to assess the context or accuracy of the data.
For the drivers affected, the consequences were immediate and catastrophic. Losing access to the Uber platform often meant an instantaneous loss of their sole source of income. Monique Verdier, deputy chair of the AP, underscored the human cost of this digital efficiency: "From one moment to the next, they no longer had any income through Uber. A computer should not make decisions on its own that have major consequences for you."
The regulator argued that by failing to provide human intervention, Uber effectively stripped its workforce of the right to contest decisions that profoundly altered their economic reality, a direct violation of the protections enshrined in Article 22 of the GDPR.
Chronology of a Regulatory Clash
The path to this nearly billion-euro penalty was paved by years of complaints and mounting evidence.
The Catalyst: The French Complaint (2020–2021)
The investigation was not initiated by the Dutch authority itself, but rather sparked by a grassroots movement. In 2020, 171 French drivers filed a complaint with the Ligue des Droits de l’Homme (Human Rights League) in France, alleging that Uber’s algorithmic deactivations were opaque, arbitrary, and unfair. Because Uber’s European operations are headquartered in the Netherlands, the French authorities referred the case to the AP, triggering a multi-year deep dive into the company’s internal data management practices.
A History of Friction
This is far from Uber’s first encounter with the AP. The company has been under the microscope for years:
- 2018: Uber was fined €600,000 for failing to report data breaches in a timely manner.
- 2023: The AP issued a €10 million fine after discovering that Uber had been keeping sensitive driver data, such as location and health information, for far longer than necessary.
- 2024: Prior to the current ruling, the AP hit Uber with a €290 million fine for illegally transferring the personal data of European drivers to the company’s headquarters in the United States, citing insufficient protections against foreign surveillance.
The progression from six-figure fines to hundreds of millions reflects a growing frustration among European regulators with Uber’s systemic approach to compliance.
Supporting Data and the Calculation of the Penalty
The €824.9 million fine is not an arbitrary figure; it represents a calculated application of the GDPR’s maximum penalty framework. Under EU law, regulators are empowered to fine companies up to 4% of their total global annual turnover for the most egregious violations of data privacy.

The AP concluded that Uber’s conduct constituted a "serious" and "deliberate" violation of the GDPR. By failing to ensure that automated decisions were subject to human scrutiny, the company bypassed the fundamental transparency and due process requirements of the law. The fine was calculated based on four percent of Uber’s worldwide annual turnover, the absolute ceiling allowed under the regulation, signaling that the Dutch authority views this breach as a top-tier violation.
Official Responses and the Road Ahead
As expected, the corporate response from Uber has been one of staunch resistance. Shortly after the fine was announced, an Uber spokesperson confirmed that the company has already filed an appeal.
In its preliminary statements, Uber has characterized the Dutch regulator’s decision as "flawed" and "extraordinary." The company maintains that its algorithmic processes are essential for maintaining safety and preventing fraud on the platform, and that its mechanisms for handling driver appeals are robust enough to satisfy the requirements of the law.
"We believe that our systems are compliant with the GDPR," the company stated, emphasizing that it will pursue all available legal avenues to have the fine overturned or significantly reduced. Legal analysts suggest that the appeals process could take years, potentially reaching the Court of Justice of the European Union (CJEU) if the matter remains unresolved in the lower courts.
Implications for the Gig Economy
The ruling carries profound implications that extend well beyond Uber. It serves as a warning to the entire gig economy—from food delivery platforms to freelance marketplaces—that "algorithmic management" is not a shield against labor and privacy regulations.
1. The Death of the "Black Box"
For years, tech platforms have relied on the complexity of their code to avoid accountability. The Dutch ruling suggests that if a company uses an algorithm to manage employees or contractors, it must ensure that there is a "human-in-the-loop" capable of reviewing, reversing, or explaining those decisions. Companies can no longer hide behind the excuse that "the computer decided."
2. Shifting Power Dynamics
This ruling bolsters the position of labor unions and human rights organizations across Europe. By successfully linking data protection law (GDPR) with the right to fair treatment in the workplace, the AP has provided a roadmap for other gig workers to challenge the algorithmic systems that govern their working conditions.
3. The "Brussels Effect"
While this case was decided in the Netherlands, the precedent is European-wide. The "Brussels Effect"—the tendency for EU regulations to set the global standard—means that tech companies may soon find themselves under similar pressure in other jurisdictions, including the United States, where lawmakers are increasingly looking to the EU’s framework as a blueprint for regulating artificial intelligence and the future of work.
Conclusion: A Turning Point for Tech Accountability
The €824.9 million fine is more than just a financial hit; it is a symbolic victory for the thousands of drivers who felt erased by the platforms they helped build. For Uber, the road ahead is fraught with legal challenges and the potential for long-term reputational damage.
As the case moves toward the appellate courts, the tech industry will be watching closely. If the ruling stands, it will signal the end of the "wild west" era of algorithmic management, forcing companies to balance their drive for efficiency with a newfound, legally binding responsibility to the human beings powering their platforms. In the digital age, the most expensive mistake a company can make may no longer be a technical glitch, but a failure to treat its workers with the transparency the law demands.







