Uber hit with €825M Dutch fine over automated driver suspensions
What's the deal? The Dutch data protection authority has fined Uber €825mn, or about $966mn, for deactivating driver accounts through automated systems without properly informing them. It is the second-largest penalty ever issued under the General Data Protection Regulation (GDPR). Uber said it will appeal.
What the regulator says: GDPR bars decisions taken by algorithm alone where they significantly affect someone, requiring human involvement and a route to challenge them. For a driver, losing account access means losing the ability to work.
The authority, known as the AP, found that Uber "violated drivers' rights, specifically the right not to be subject to automated decision-making that has significant consequences," and had also "violated the right to be informed."
What Uber was doing: Uber temporarily suspended accounts of drivers its systems flagged for suspected fraud, such as taking detours to inflate fares or accepting trips they did not intend to complete. The AP said the software sometimes removed drivers with low customer ratings permanently. Uber disputes that, saying it has never automated a permanent deactivation.
Uber's response: "We strongly disagree with this decision and disproportionate fine," a spokesperson said. The company said its current policies include human review and a way to contest suspensions. It noted low customer ratings cost 126 drivers their accounts across Europe in 2021.
Where the case came from: The decision covers incidents in Europe between 2020 and 2022 and began with a complaint from drivers in France. The AP took the case because Uber's European headquarters sit in Amsterdam, making it the lead authority for Uber across the EU.
Why now? This is the fourth Dutch fine against Uber, and each has been larger than the last. The AP fined it €600,000 in 2018, €10mn in early 2024 over drivers' privacy rights, and €290mn over transfers of driver data to the United States. The new penalty is close to three times the size of that €290mn fine.
What could go wrong? Only Ireland's €1.2bn fine against Meta in 2023 has been larger under GDPR. Reuters noted that appeals running for years often shrink or overturn headline fines against large technology companies.
The signal: Both of the two largest GDPR penalties on record sit with regulators in small member states that host the European headquarters of large American companies. As firms lean on automated systems to manage workers, regulators are treating those decisions as consequential enough to carry record-breaking price tags.
Read more: The Next Web · Financial Times
Image credit: conceptphoto.info