• About
  • Privacy Poilicy
  • Disclaimer
  • Contact
CoinInsight
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
CoinInsight
No Result
View All Result
Home Regulation

A computer cut off their income. Now Uber faces an €825m GDPR fine

Coininsight by Coininsight
August 25, 2026
in Regulation
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Uber has been fined almost €825 million by the Dutch Data Protection Authority (AP) in one of the largest GDPR penalties ever imposed, and this time the central issue is not a data breach or an international transfer.

It is automated decision-making.

Related articles

NIST Is Offering a New AI Evaluation Framework, Not Another Compliance Checklist

August 24, 2026

5 key strategies for compliance leaders

August 23, 2026

The AP found that Uber used automated systems to temporarily deactivate drivers suspected of fraud and, in some cases, permanently deactivate drivers whose customer ratings remained too low. According to the regulator, these decisions were made without meaningful human intervention between 2018 and 2022.

For the drivers involved, the consequences were immediate. Once their accounts were blocked, they could no longer earn through the Uber platform.

The AP concluded that this breached the GDPR restrictions on solely automated decisions that have legal or similarly significant effects on individuals. It also found that Uber had failed to provide drivers with sufficient information about the automated decision-making taking place.

Uber strongly disputes the decision and has announced that it will appeal. The company says it takes decisions affecting drivers’ ability to earn seriously, that its current systems include human reviews and safeguards, and that drivers can challenge decisions they believe are wrong.

Whatever happens on appeal, the case has turned what can sometimes feel like one of the more technical provisions of GDPR into a very significant enforcement issue.

Automated decision making at the heart of the fine

Article 22 of the EU GDPR gives individuals the right not to be subject to decisions based solely on automated processing, including profiling, where those decisions produce legal effects or have a similarly significant impact on them.

That does not mean businesses cannot automate processes. The problem arises when the system moves beyond assisting a human and effectively becomes the decision-maker.

According to the AP, Uber used software to monitor drivers’ behaviour and customer reviews. Where the system identified suspected fraud, such as drivers allegedly taking unnecessary detours to increase fares, accounts could be temporarily deactivated. Persistent low ratings could also lead to permanent deactivation.

The regulator’s concern was that there was no meaningful human assessment before these significant decisions were made.

That distinction is important.

An algorithm flagging a transaction, customer, employee or supplier for a person to investigate is very different from an algorithm deciding the outcome itself. The greater the effect of the decision on the individual, the more important that distinction becomes.

Article 22 does contain exceptions allowing certain solely automated decisions, including where they are necessary for a contract, authorised by law or based on explicit consent. But these are subject to conditions and safeguards. Where applicable, those safeguards include the ability to obtain human intervention, express a point of view and challenge the decision. 

For Uber’s drivers, being locked out of the platform meant losing their ability to earn through it. The AP regarded that as sufficiently serious for the GDPR’s automated decision-making protections to apply.

Is putting a human in the loop enough?

Perhaps the most important lesson from the case is what regulators mean by human intervention. Adding a nominal human review stage to an automated process does not necessarily solve the problem.

Meaningful human intervention requires someone to be capable of examining the information, questioning the automated recommendation and changing the outcome. A reviewer who simply approves whatever the system has produced is unlikely to provide much protection.

The European Data Protection Board has previously stressed that human intervention should be capable of addressing problems created by automated systems, rather than functioning as a superficial safeguard. For businesses rapidly introducing AI into their systems, this is particularly important.

A system might rank candidates for employment, identify customers as suspected fraudsters, determine whether someone qualifies for a financial product, flag employees as underperforming or restrict access to a service.

In all of these cases, businesses need to understand where automation ends and actual decision-making begins.

Transparency matters too

The AP did not only object to the way decisions were made. It also found that drivers had not been sufficiently informed about the automated decision-making affecting them.

This is another area where AI and automation can create GDPR problems.

If personal data is being used to make significant automated decisions, organisations cannot simply hide the process behind terms such as “proprietary algorithm” or “automated system”.

GDPR transparency requirements can require individuals to receive meaningful information about the logic involved, as well as the significance and expected consequences of the processing.

Recent EU case law has reinforced the importance of providing information that genuinely helps an individual understand how their data produced a particular outcome. That does not necessarily mean exposing source code or revealing every technical detail of a model. But an organisation should be able to explain, in understandable terms, what information is being used, how it influences the decision and what the consequences may be.

If a business cannot explain how an automated system reaches consequential decisions about people, that is itself a compliance warning sign.

From AI governance to GDPR enforcement

The timing of the Uber decision matters. Businesses are adopting AI and automated tools at extraordinary speed. Decisions that previously required a member of staff can increasingly be made, recommended or prioritised by software.

That can produce major benefits, but it also means automated decision-making is moving into areas where mistakes have serious consequences.

The Uber fine shows that organisations cannot treat GDPR compliance and AI governance as separate exercises.

Before deploying an automated system, businesses should know whether personal data is being used, what decisions the system contributes to and how significant those decisions are for the people affected.

They should also be able to answer, who actually makes the final decision? If the answer is “the system”, Article 22 should be considered carefully.

What should businesses do now?

The first step is understanding where automated decision-making already exists within the organisation. It may not always be labelled as AI. Fraud detection tools, recruitment systems, credit scoring, employee monitoring, customer risk scoring and automated account restrictions can all involve algorithmic decision-making.

Businesses should then identify which systems can produce outcomes with a significant effect on individuals.

From there, human oversight needs to be designed around the actual risk. Someone should have sufficient information, authority and time to question an automated recommendation rather than simply confirming it.

Transparency should also be reviewed. Privacy notices and other information provided to individuals need to reflect how automation is genuinely being used, including its significance and consequences where required.

Finally, organisations need an effective route for challenging decisions. A right to appeal means little if the appeal simply sends the same data back through the same automated process.

These controls also need evidence behind them. Businesses should be able to demonstrate how systems have been assessed, what safeguards were chosen, who is responsible for human review and how challenges are handled.

That documentation may become particularly important when responding to a complaint or regulatory investigation.

A significant warning, but an important UK distinction

For UK businesses, there is now an important difference between the EU GDPR rules involved in the Uber case and the UK GDPR.

Changes introduced by the Data (Use and Access) Act 2025, which took effect for automated decision-making from 5 February 2026, have made the UK regime more permissive. Significant solely automated decisions involving non-special category personal data can now be made in a wider range of circumstances, subject to a lawful basis and appropriate safeguards. Restrictions remain stronger where special category data is involved. 

The safeguards remain important. UK organisations must provide information about significant automated decisions and enable individuals to make representations, obtain human intervention and contest decisions. 

That means the lesson from Uber has not disappeared for UK businesses. The precise legal test may differ, but transparency, meaningful human involvement and the ability to challenge consequential decisions remain central to responsible automated decision-making.

Organisations operating in the EU, offering services to people there or otherwise falling within the scope of the EU GDPR must also consider the EU rules separately.

Article 22 just became much harder to ignore

At €825 million, the Uber penalty is reported to be the second-largest GDPR fine imposed to date, behind the €1.2 billion penalty issued to Meta in 2023. Uber’s appeal means the final outcome is far from settled.

But the wider compliance message is already difficult to miss. Automating a process does not automate away responsibility.

As businesses place more decisions in the hands of algorithms and AI systems, they need to know where those systems can materially affect people, whether genuine human oversight exists and whether affected individuals understand and can challenge what has happened.

For years, automated decision-making has been one of the less visible parts of GDPR compliance. After a fine approaching €825 million, Article 22 looks much less theoretical.

Read our guide, When data thinks: The intersection of GDPR and AI

Get it here →

Share76Tweet47

Related Posts

NIST Is Offering a New AI Evaluation Framework, Not Another Compliance Checklist

by Coininsight
August 24, 2026
0

NIST’s new draft framework for evaluating AI systems, TEVV-Athlon, should provide a useful reframe for leaders who rely on checklist-style...

5 key strategies for compliance leaders

by Coininsight
August 23, 2026
0

As organizations begin planning for 2027, compliance leaders are balancing growing expectations with limited resources. AI governance, evolving regulations, and...

What’s new in Astute, August 2026 update (v3.5.9)

by Coininsight
August 23, 2026
0

This month’s release focuses on Instructor Led Training. We’ve improved how completed classes appear to learners, made class and course...

Harassment and Inclusion Training: Better Together

by Coininsight
August 22, 2026
0

One HR leader shared a situation with me that I’ve thought about ever since.  A manager wasn’t generating complaints. He...

GRC News Roundup: Speeki, Napier AI, Descartes & More

by Coininsight
August 21, 2026
0

GRC technology is one of the fastest-growing segments in enterprise software, and compliance professions are rapidly evolving. Here’s the latest...

Load More
  • Trending
  • Comments
  • Latest
What’s Actually Going On With Ripple’s Blockchain?

What’s Actually Going On With Ripple’s Blockchain?

January 12, 2026
MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

July 24, 2025
Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

November 26, 2025
Easy methods to Host a Storj Node – Setup, Earnings & Experiences

Easy methods to Host a Storj Node – Setup, Earnings & Experiences

March 11, 2025
Kuwait bans Bitcoin mining over power issues and authorized violations

Kuwait bans Bitcoin mining over power issues and authorized violations

2
The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

2
Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

1
Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

1

Gemini Wants Apex’s Crypto Prediction Flow. But Apex Already Has Kalshi

August 25, 2026

The Long(er) road to Devcon

August 25, 2026

A computer cut off their income. Now Uber faces an €825m GDPR fine

August 25, 2026

Cypher Tank Returns To Lugano, Expanding Its Bet On Bitcoin Founders

August 25, 2026

CoinInight

Welcome to CoinInsight.co.uk – your trusted source for all things cryptocurrency! We are passionate about educating and informing our audience on the rapidly evolving world of digital assets, blockchain technology, and the future of finance.

Categories

  • Bitcoin
  • Blockchain
  • Crypto Mining
  • Ethereum
  • Future of Crypto
  • Market
  • Regulation
  • Ripple

Recent News

Gemini Wants Apex’s Crypto Prediction Flow. But Apex Already Has Kalshi

August 25, 2026

The Long(er) road to Devcon

August 25, 2026
  • About
  • Privacy Poilicy
  • Disclaimer
  • Contact

© 2025- https://coininsight.co.uk/ - All Rights Reserved

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining

© 2025- https://coininsight.co.uk/ - All Rights Reserved

Social Media Auto Publish Powered By : XYZScripts.com
Verified by MonsterInsights