Uber fined €825m for automated decisions: strong signal on GDPR Article 22
The Dutch DPA, with the CNIL, fined Uber nearly €825m for automated driver account deactivations/suspensions without adequate safeguards. Clear message: GDPR Article 22 applies concretely to high‑impact business algorithms.
On 24 August 2026, the Dutch DPA (AP), in cooperation with the CNIL, imposed a €824.99m fine on UBER B.V. and Uber Technologies Inc. for automated deactivation/suspension of driver accounts without adequate safeguards. Key takeaway: GDPR Article 22 is no longer theoretical; it applies concretely to high‑impact business algorithms. See CNIL, 24/08/2026; AP, 21/08/2026.
The case
- Organizations: Uber B.V. (Netherlands) and Uber Technologies Inc.
- Authorities: Autoriteit Persoonsgegevens (AP, NL) with cooperation from the CNIL (France).
- Date: 21–24 August 2026.
- Amount: €824,990,000.
- Allegations: automated individual decisions deactivating or suspending driver accounts; lack of meaningful human review and adequate information; insufficient redress channels.
- Legal basis: default prohibition on decisions based “solely” on automated processing producing legal or similarly significant effects (Article 22(1) GDPR), strict conditions for derogations (Article 22(2)), minimum safeguards (Article 22(3)), and transparency duties (Articles 13–15 GDPR).
- Official sources: CNIL press release “Décisions automatisées : sanction de près de 825 millions d’euros à l’encontre d’UBER” (24/08/2026); AP news “Uber krijgt boete van bijna 825 miljoen euro voor geautomatiseerd blokkeren van chauffeurs” (21/08/2026).
References:
- CNIL, 24/08/2026: https://www.cnil.fr/fr/decisions-automatisees-sanction-de-pres-de-825-millions-deuros-lencontre-duber
- AP, 21/08/2026: https://autoriteitpersoonsgegevens.nl/ (Actueel)
Legal reasoning
1) GDPR framework
Article 22(1) grants the right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal effects or similarly significant impacts. The only exceptions (Article 22(2)) are: contractual necessity (22(2)(a)), authorization by Union/Member State law with safeguards (22(2)(b)), and explicit consent (22(2)(c)). In all cases, Article 22(3) mandates safeguards: human intervention, the ability to express one’s point of view, and to contest the decision. Official text (EUR‑Lex, CELEX:32016R0679): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679.
2) EDPB interpretation
The “Automated individual decision‑making and Profiling” guidelines (WP251 rev.01, endorsed 25/05/2018) structure the analysis: what counts as a “decision”? what is “solely automated”? when is an effect “legal or similarly significant”? They clarify that non‑meaningful “human varnish” is not enough: if a person “strongly relies” on the algorithmic recommendation, Article 22(1) still applies. See EDPB WP251rev.01: https://www.edpb.europa.eu/documents/guideline/automated-decision-making-and-profiling_fr; and EDPB “DSA‑GDPR interplay” v1/2025, §22: https://www.edpb.europa.eu/system/files/2025-09/edpb_guidelines_202503_interplay-dsa-gdpr_v1_en.pdf.
3) CJEU contribution
On 7 December 2023, the CJEU held in OQ v Land Hessen (C‑634/21) that automated “scoring” can itself be a decision under Article 22(1) where a third party “relies decisively” on that score to enter/terminate a contract. The prohibition is a default rule and does not require the data subject to invoke it first. The case cemented the need for “meaningful” human review and effective safeguards. See: https://eur-lex.europa.eu/legal-content/EN/CASE/?uri=CELEX%3A62021CJ0634.
4) Applying it to Uber
According to the CNIL and AP, automated (de)activation of driver accounts produced major legal and economic effects (loss of platform access and thus income) without effective human oversight or compliant notice/redress. Authorities therefore applied: Article 22(1) (default prohibition); Article 22(2) (strict scrutiny of claimed exceptions); Article 22(3) (lack of concrete safeguards); and Articles 13–15 (specific information on logic and consequences of automated decision‑making). Sources: CNIL (24/08/2026); AP (21/08/2026); GDPR (EUR‑Lex).
What this changes in practice
- High‑impact automated “business decisions” (account suspensions, risk ratings, contract acceptance/termination, individualized pricing, KYC/AML filtering, fraud scoring, online account moderation/suspension) fall under Article 22(1) unless there is genuinely decisive human control.
- “Contractual necessity” (22(2)(a)) is interpreted strictly by the EDPB: it does not cover mere internal efficiency choices where less intrusive alternatives exist. You must evidence this (written analysis).
- Safeguards (22(3)) are not “cosmetic”: you must prove an accessible, competent human review channel with timelines, auditability of exchanges, and real ability to overturn the algorithm.
For NIS 2 and DORA sectors (banks, insurers, PSFs, essential/important entities), there is strong practical convergence: governance of decision models and robust logging become outcome‑oriented obligations, also useful for ILR (NIS 2) and CSSF (DORA). See ILR — NIS2 page: https://www.ilr.lu/secteurs-activites/niss/; CSSF — “ICT and cyber risk – for DORA entities”: https://www.cssf.lu/en/ict-and-cyber-risk-for-dora-entities/. To operationalize AI governance around decision points and human‑in‑the‑loop safeguards, embed these requirements in your model policies; for local alignment, consult DORA Luxembourg.
Common pitfalls
- Nominal “human in the loop”. A rubber‑stamp click, random post‑decision sampling, or scripted checks are not enough. The EDPB requires “meaningful” human involvement; the CJEU sanctions “determinative reliance” on a score. Document who decides, on what basis, and past reversals. Refs: EDPB WP251rev.01; CJEU C‑634/21.
- Incomplete information. Generic notices (“we use algorithms”) do not meet Article 13(2)(f)/14(2)(g): explain the underlying logic, its importance and envisaged consequences, and highlight the right to human intervention/contest. Ref: GDPR, Arts. 13–15 (EUR‑Lex).
- Misstating the 22(2)(a) exception. “Contractual necessity” does not follow from optimization alone. Prove no less intrusive alternative can perform the contract and that the purpose is inseparable from the automated decision (EDPB).
- No register of automated decisions. Many Article 30 records miss automated “decision points” and business rules. Result: you cannot evidence scope, bias tests, or effective redress. Build a dedicated inventory (processes, models, thresholds, training data, test sets, fairness metrics).
- Unmeasurable safeguards. “A human can be contacted” without SLAs or proof of reversals will be seen as window dressing. Set KPIs: median human response time; overturn rate; grounds for annulment; conversation logs; retention of decision logs (justified by Arts. 5(2)/24 and 22(3)).
Official sources
- CNIL — “Décisions automatisées : sanction de près de 825 millions d’euros à l’encontre d’UBER” (24 Aug 2026): https://www.cnil.fr/fr/decisions-automatisees-sanction-de-pres-de-825-millions-deuros-lencontre-duber
- Autoriteit Persoonsgegevens (AP, NL) — “Uber krijgt boete van bijna 825 miljoen euro voor geautomatiseerd blokkeren van chauffeurs” (21 Aug 2026) — Actueel: https://autoriteitpersoonsgegevens.nl/ (news listing)
- GDPR — Official text (EUR‑Lex), Article 22 and Recital 71: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
- EDPB — “Automated individual decision‑making and Profiling” (WP251 rev.01, endorsed 25/05/2018): https://www.edpb.europa.eu/documents/guideline/automated-decision-making-and-profiling_fr
- CJEU — OQ v Land Hessen (C‑634/21, 7 Dec 2023): EUR‑Lex/InfoCuria: https://eur-lex.europa.eu/legal-content/EN/CASE/?uri=CELEX%3A62021CJ0634
In sum, the Uber sanction cements the strict reading of Article 22: where a decision substantially affects individuals, “solely” automated processing is prohibited unless a narrowly proven exception applies and tangible safeguards exist. In Luxembourg, any organization using algorithms for access suspension, scoring, or individualized pricing should inventory its “decision points,” set up meaningful human intervention, and prove — through documentation and logs — that Article 22(3) safeguards work in practice.
Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →