Uber set for €825mn Dutch fine over automating driver suspensions
Uber is set to be fined €825mn by the Dutch data watchdog over its use of automated systems to deactivate driver accounts, in one of the largest penalties issued under Europe’s privacy rules.
The Dutch Data Protection Authority found that the ride-hailing group had deactivated driver accounts through automated systems without adequately informing them, according to a document seen by the FT.
The fine is the second largest under Europe’s General Data Protection Regulation (GDPR), which allows regulators to fine companies for mishandling Europeans’ personal data.
Meta was hit in 2023 by a €1.2bn fine for privacy violations by Ireland’s Data Protection Commission. The US group is appealing the penalty.
Uber called the fine “disproportionate” on Friday and said it will appeal against the decision. It added that Dutch regulators had examined “historic policies that were discontinued years ago”.
“We take decisions that affect drivers’ ability to earn extremely seriously and we’re fully committed to fair treatment. This includes human reviews, robust safeguards and the opportunity for drivers to appeal our decisions if they believe we made a mistake,” Uber said.
The penalty is not yet formally announced but was confirmed by the Dutch Data Protection Authority on Friday. The Dutch regulator handled the investigation because Uber’s European headquarters are located in Amsterdam. The fine was first reported by Reuters.
In the document, the Dutch regulator said Uber “violated drivers’ rights — specifically, the right not to be subject to automated decision-making that has legal consequences or otherwise significant consequences for the drivers. Uber has also violated the right to be fully informed about such automated decision-making.”
The penalty follows a €290mn Dutch fine against Uber two years ago for transferring personal data of European taxi drivers to the US and failing to appropriately safeguard the data with regard to these transfers.
Daniel Friedlaender, head of the Computer & Communications Industry Association Europe, whose members include many Big Tech groups, said the fine was “truly colossal” and stressed that GDPR enforcement “should never be turned into punishment for punishment’s sake”.