BlackTree Security · Infrastructure · Automation · AI

The Algorithm Suspended the Driver. The Regulator Called It an €825 Million GDPR Violation.

The Dutch Data Protection Authority has imposed a €824.99 million GDPR fine on Uber over automated decisions that temporarily or permanently deactivated drivers. The number is extraordinary, but the operational lesson is simpler: if software can cut off a person’s income, meaningful human review cannot be a decorative appeal button added after the decision.

The enforcement action turns one of the GDPR’s most debated provisions into a control test that many organisations can apply immediately. A risk score is not merely analytics when it determines whether someone can work, transact, claim insurance, sell on a marketplace, or access an essential account. At that point, the design of the decision process matters as much as the model that produced the score.

The fine is about authority, not just the algorithm

On 21 August 2026, the Dutch authority, known as the AP, announced a fine of exactly €824,990,000 against Uber B.V. and Uber Technologies Inc. The French data protection authority, CNIL, said it had cooperated with the Dutch regulator throughout the investigation under the GDPR’s cross-border enforcement procedure.

The case began with a collective complaint filed with CNIL in 2020 by La Ligue des droits de l’Homme on behalf of more than 170 Uber drivers. The complaint, supplemented in 2021, covered transparency, international data transfers, and decisions that could temporarily or permanently disconnect drivers from the platform.

According to CNIL’s account of the decision, the AP found that account deactivations for suspected fraud and low customer ratings were automated individual decisions because human intervention was completely absent from the decision-making process. The practical consequence was direct: a blocked driver could no longer accept rides or generate revenue.

The regulator also said Uber failed to provide adequate information about the automated decision-making. Reporting by the Associated Press places the violations between 2018 and 2022. Reuters reported that the underlying decision was dated 17 August and that the announced penalty would be the second-largest GDPR fine on record, behind Ireland’s €1.2 billion Meta penalty in 2023.

Uber disputes the findings and intends to appeal. The company told the Associated Press that the authority examined historical policies discontinued years ago. Uber said it now uses human reviews, safeguards, and an appeal process, and it has separately disputed that permanent deactivations were fully automated. The fine should therefore be described as imposed and contested, not as a final payment or an uncontested finding.

Article 22 is a decision-architecture rule

Article 22 of the GDPR gives people the right not to be subject to a decision based solely on automated processing when that decision produces legal effects or similarly significant consequences. The regulation allows limited exceptions, but even then it requires safeguards that include the ability to obtain human intervention, express a point of view, and contest the decision.

That makes Article 22 less a ban on algorithms than a rule about where authority sits. Software may detect unusual behaviour, rank risk, or recommend action. The critical question is whether the system crosses the line from informing a human to deciding a person’s outcome.

Three stages need to be separated:

  • Signal: a model or rule flags suspected fraud, a poor rating, or another risk indicator.
  • Decision: the organisation suspends an account, rejects an application, withholds a payment, or imposes another material consequence.
  • Remedy: the affected person receives reasons, can submit relevant evidence, and has the case reconsidered by someone with authority to reverse the outcome.

Many systems contain a human somewhere but still fail this test in substance. A support agent who can repeat the model’s result but cannot inspect the evidence is not meaningful intervention. A reviewer who handles hundreds of cases per hour and is measured on agreement with the automated output may be a rubber stamp. An appeal after days or weeks of lost income may be important, but it does not automatically repair the absence of review before a severe decision took effect.

Fraud prevention is not a legal blank cheque

Fraud controls are necessary on large platforms. A service that connects strangers, moves money, and processes millions of transactions needs automated detection. The GDPR itself recognises fraud prevention as a legitimate context for profiling. But a legitimate purpose does not make every implementation lawful.

The key risk is false certainty. A fraud score is a probability assembled from imperfect signals. Route anomalies can have innocent explanations. A low rating can reflect service quality, bias, retaliation, or local conditions that the model does not understand. When a score becomes an immediate suspension, uncertainty is converted into economic harm without an independent check.

Security teams should recognise the parallel with automated containment. Endpoint and identity systems routinely isolate devices, revoke sessions, disable users, or block transactions. Fast action can prevent an incident from spreading, but the same mechanism can lock out an employee, interrupt a hospital workflow, or stop a customer from accessing funds. High-confidence automation still needs an escalation path proportional to the harm caused by a mistake.

The ruling reaches far beyond platform work

Uber is the defendant, but the control problem is common. The same architecture appears when a bank freezes an account, an insurer rejects a claim, an employer disciplines a worker, a marketplace removes a seller, a cloud provider terminates a tenant, or an identity platform marks a user as too risky to sign in.

It also matters for organisations deploying AI agents. An agent that recommends a decision remains within a narrower boundary. An agent that can execute the decision, notify the subject, close the case, and suppress reconsideration has been given institutional authority. That authority must be governed explicitly.

This is why the case connects with BlackTree’s earlier analysis, AI Agents Don’t Need More Intelligence. They Need Better Boundaries. The issue is not whether automation is sophisticated. It is whether the organisation has defined what the system may decide, what it may only recommend, and which outcomes require a human with the context and authority to intervene.

What organisations should test now

The fastest useful response is not another general AI policy. It is a decision inventory. List every process in which personal data feeds a score, rule, or model that can produce a material effect. Include fraud systems, access controls, trust and safety tooling, credit and insurance decisions, workforce management, customer support, and security automation.

For each process, map the full path from data to outcome:

  1. Identify the decision. State exactly what changes for the person, including temporary restrictions.
  2. Locate the human intervention. Determine whether it occurs before the outcome, after it, or not at all.
  3. Test authority. Confirm that the reviewer can inspect the relevant evidence, consider new information, and reverse the decision.
  4. Test independence. Measure whether reviewers routinely agree with the system because of targets, interface design, or lack of time.
  5. Explain the outcome. Give the affected person useful reasons and a practical route to challenge errors.
  6. Log the control. Preserve the inputs, model or rule version, decision, reviewer actions, appeal, and final outcome.
  7. Measure harm. Track false positives, time to restoration, reversals, repeat errors, and unequal effects across relevant groups.
  8. Provide a fail-safe. If the review control is unavailable or overwhelmed, reduce the scope of automation instead of allowing it to make unchecked consequential decisions.

The most revealing metric may be the reversal rate. A rate near zero can mean the automation is accurate, but it can also mean reviewers lack information or power. A high rate indicates the system is producing costly false positives. Either result deserves investigation.

The amount makes the governance failure visible

The €824.99 million figure will dominate attention, especially while Uber challenges it. The more durable lesson is the control boundary exposed by the case. An automated system did not merely generate an internal score. According to the regulator, it exercised the power to remove access to work and income without a human making the decision or giving drivers adequate information.

That is the point at which model governance becomes operational governance. If a machine can impose the consequence, the organisation must be able to show who remains accountable, where meaningful intervention occurs, how the affected person can be heard, and how an error is corrected before it becomes prolonged harm.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *