What happened
On 8 October 2026 the Dutch Autoriteit Persoonsgegevens (AP) announced an administrative fine of EUR 824,990,000 against Uber for violating Article 22 GDPR (prohibition of fully automated individual decision-making) and Article 13 GDPR (failure to inform drivers about profiling). The case originated from complaints by 171 French Uber drivers lodged via CNIL and was handled by the AP under the GDPR One-Stop-Shop procedure. The AP found Uber automatically deactivated drivers' accounts on suspicions of fraud or persistently low customer reviews, causing income loss during deactivation, between 2018 and 2022. Uber has stopped the violations and has appealed; no final judicial decision yet.
Why it matters
This is one of the largest GDPR fines ever and squarely targets algorithmic (AI-driven) decision-making, not just data-handling — signalling that automated account/worker-management systems that make consequential decisions without meaningful human involvement constitute unlawful fully automated decision-making. It materially raises liability exposure for any deployer using AI agents/automation to make decisions affecting individuals in the EU.
Action needed
Audit any AI/automation used to take decisions with legal or similarly significant effects on individuals (account deactivation, sanctions, scoring, dismissal, fraud flags); ensure meaningful human review/contribution and comply with Art. 13-15 transparency duties; document the lawful basis before deploying automated decisioning in the EU.