The Dutch Data Protection Authority has imposed a €825 million fine on Uber, the second-largest penalty ever handed down under Europe's General Data Protection Regulation, over the ridesharing company's use of automated systems to deactivate driver accounts without adequate transparency or human review. The decision, issued on August 17 and reviewed by Reuters, centres on Uber's practices between 2020 and 2022 across Europe, which were first flagged in a complaint from France. Because Uber's European headquarters are located in the Netherlands, the Dutch regulator took jurisdiction of the case.

The fine underscores growing regulatory scrutiny across Europe regarding algorithmic decision-making that affects individuals' livelihoods. Under GDPR rules, automated decisions with significant consequences for people require meaningful human intervention and the ability for affected individuals to challenge the outcome. The authority concluded that Uber violated drivers' fundamental rights by making suspension decisions through algorithms without ensuring transparent communication about how those decisions were reached or providing adequate channels for dispute.

Uber's suspension practices during the period in question involved multiple scenarios. Temporary suspensions were often triggered when the company's systems detected suspected fraudulent behaviour, such as drivers taking unnecessarily circuitous routes to inflate fares or accepting trips with no apparent intent to complete them. Additionally, drivers with persistently low customer ratings faced the risk of permanent account deactivation, a consequence that could severely damage their ability to earn income on the platform. The Dutch regulator determined that these automated deactivations constituted a violation of drivers' rights to information and protection against purely algorithmic decision-making.

Uber has signalled its intention to appeal the decision, arguing that it strongly disagrees with both the ruling and the quantum of the penalty. The company's spokesperson countered that Uber takes drivers' rights seriously and highlighted that its current policies incorporate human review mechanisms and provide drivers with opportunities to dispute platform suspensions. This defence suggests that Uber may have modified its systems since the 2020-2022 period under investigation, though the regulator's finding indicates those protections were insufficient during the years in question.

The fine places Uber in notable company within the history of GDPR enforcement. Only one penalty has exceeded it: Ireland's €1.2 billion fine against Meta in 2023 for unlawfully transferring European Facebook users' personal data to the United States. Meta is currently appealing that decision, and similarly, Uber's appeal will likely extend this legal battle over data protection standards for years. These escalating penalties reflect regulators' determination to enforce GDPR provisions even against tech giants with significant market power.

The case carries implications well beyond Uber itself. Platform-based work has become increasingly important across Southeast Asia and Europe, with millions of drivers, delivery personnel, and freelancers depending on algorithmic systems for income access. The Dutch regulator's decision signals that companies cannot outsource accountability to algorithms when people's livelihoods hang in the balance. This precedent may influence how other ride-hailing and gig economy platforms throughout Europe and beyond design their account management procedures.

For Malaysian stakeholders, this development warrants attention given the region's expanding gig economy sector and the absence of comprehensive algorithmic accountability frameworks similar to GDPR. Malaysian regulators and policymakers may eventually face similar questions about how domestic platforms should balance fraud prevention with fairness to workers. The Dutch case demonstrates that treating algorithmic decisions as neutral technical outputs, rather than consequential business decisions, exposes companies to substantial regulatory and legal risk.

The decision also highlights the distinction between temporary and permanent account suspensions in regulatory assessment. The regulator acknowledged that Uber did not permanently deactivate accounts suspected of fraud without some form of human input, but the authority remained concerned about the initial automated trigger mechanisms and the insufficient communication to drivers about why suspensions occurred and how they could challenge them. This nuance suggests that regulators are not necessarily opposed to AI-assisted decision-making, but rather demand transparency and meaningful human oversight at critical junctures.

Uber's assertion that it no longer relies solely on automated systems for permanent deactivations indicates the company has adjusted its practices in response to regulatory pressure, even before this formal decision. However, the fine addresses historical violations, and the appeal process will determine whether the penalty's size reflects appropriate deterrence or regulatory overreach. The outcome will likely shape how tech platforms across multiple jurisdictions approach algorithmic governance in the coming years, particularly regarding worker protection and algorithmic transparency.