30 AOÛ 2026
GOVERNANCE

In the Netherlands, with the French CNIL's cooperation, Uber is fined €825M for letting an algorithm alone decide to deactivate drivers — the human control AppH refuses to strip from its own automations

On August 21, 2026, the Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, fined Uber €824.99 million — working with France's CNIL, which had received a complaint from 171 drivers back in 2020. Between 2018 and 2022, automated systems suspended or deactivated driver accounts on mere suspicion of fraud or ratings deemed too low, without genuine human review before the decision cut off someone's income. It's exactly the scenario AppH's architecture rules out by design: no real consequence without a human at the company clicking first.

On August 21, 2026, the AP — the Dutch counterpart to France's CNIL — announced a €824.99 million fine against Uber, the fourth the regulator has imposed on the company since 2018 (€600,000 in 2018, €10 million in 2023 for failing to inform drivers, €290 million in 2024 for data transfers outside the EU, and now this record sum). Between 2018 and 2022, Uber used software to monitor driver behavior, trips and ratings: a fraud suspicion flagged by the system was enough to automatically block an account, and persistently low ratings could lead to permanent exclusion from the platform — while deactivated, a driver couldn't accept rides, and so couldn't earn any income. The AP found that Uber should have built in genuine human intervention before these decisions took effect, under Article 22 of the GDPR, which protects individuals from a decision based solely on automated processing when it produces a legal or similarly significant effect.

The case originated in France: in 2020, 171 drivers turned to the Ligue des droits de l'Homme, which filed the complaint with the CNIL on their behalf. Because Uber's European headquarters sits in the Netherlands, the AP led the investigation under the GDPR's one-stop-shop mechanism — but the CNIL actively took part in the inspections, evidence review and drafting of the decision, and kept the complainants informed throughout. Large as it is, the fine falls well short of the legal ceiling: with roughly €44.5 billion in global 2025 revenue, Uber could have faced up to 4% of that revenue for an infringement this serious — about €1.78 billion, more than double what was actually imposed. Uber has said it will appeal, specifically disputing that permanent, rating-linked deactivations were automated, and maintaining that final fraud decisions already went through human review.

For AppH

  • The Dutch regulator puts a euro figure — backed by a real system running for four years — on exactly the risk AppH's architecture rules out by design: in neither the Fleet module nor Automations does a rule alone deactivate an account, block access, or trigger a consequence for someone's income — a human at the company has to click first.
  • GDPR Article 22, invoked here at this scale for the first time against a purely algorithmic decision, gives AppH a concrete legal argument — not just a best practice — to bring to any SMB client considering automating a decision that touches an employee, a supplier, or a customer without human sign-off before it executes.

Against / the honest limit

  • The Uber case involves an automated decision with a direct, significant effect on someone's income — a far heavier legal and human stake than most of what an AppH SMB client automates today (an invoice reminder, a low-stock alert). Claiming every Automations rule carries the same legal exposure as Uber's deactivation algorithm would overstate the comparison.
  • Uber is appealing and disputes part of the findings — specifically, that permanent ratings-based deactivations were automated, arguing human review already applied to final fraud decisions. The case isn't settled yet, and the sanctioned facts could still shift on appeal.

What stands out about this decision isn't the amount — €825 million is a lot, but it's still well short of what the GDPR would have allowed. What stands out is that Uber, a company with €44.5 billion in revenue and sizable legal and compliance teams, is defending itself by arguing over which decisions were actually automated and which already had a human behind them — four years after the fact, the company itself seems unable to draw that line precisely. That's exactly the problem an append-only audit trail and a mandatory "draft" status solve structurally: at AppH, the question "did a human approve this before it went out" is never a dispute reconstructed after the fact, because the answer is written into the system at the moment of the action itself, not pieced together four years later in front of a regulator. Accompanying an SMB owner means telling them plainly: the day a regulator — or a client, or an employee — asks who approved a decision and when, it's better to already have the answer written down than to have to rebuild it under pressure.

Vérifié par un humain d'AppH
← Previous article (older)Next article (newer) →

← Back to news

Want us to walk you through how this applies to a real case?

Talk to AppH

Get new posts by email

One email when we publish new analysis — never spam, unsubscribe in one click.