The regulator focused on temporary suspensions triggered by suspected fraud and certain temporary or permanent deactivations linked to customer ratings. According to the Dutch authority, these decisions could prevent drivers from working and earning income, yet were made without meaningful human intervention.
The case brings GDPR Article 22 back into focus. European data protection law restricts certain decisions based solely on automated processing when they produce legal effects or similarly significant consequences for individuals.
The lesson for U.S. companies operating in Europe is broader than Uber: adding a nominal “human in the loop” is not enough. Human review must be meaningful, independent, and capable of changing the outcome.
The decision also follows the Court of Justice of the European Union’s 2023 SCHUFA judgment, which held that an automated score can itself qualify as an automated decision where it plays a determining role in the final result.
Uber disputes the decision and has announced an appeal.
From a French Driver Complaint to an €824.99 Million Fine
The case began with a collective complaint filed in France in 2020 by the Ligue des droits de l’Homme on behalf of more than 170 Uber drivers and supplemented in 2021.
The complaint covered several data protection issues, including transparency, international data transfers, and automated account deactivations.
Because Uber’s main European establishment is in the Netherlands, the Dutch Data Protection Authority handled the cross-border GDPR investigation under the EU’s one-stop-shop mechanism, in cooperation with the French CNIL and other European supervisory authorities.
The same complaint has produced three major enforcement actions:
- a €10 million fine concerning transparency and driver privacy rights;
- a €290 million fine concerning transfers of driver data to the United States;
- and the August 2026 €824.99 million fine concerning automated individual decision-making.
For U.S. businesses, the sequence is important. GDPR exposure is not limited to data breaches or international transfers. The way an algorithm makes decisions about people can itself become a major enforcement issue.
The Core Question: Can Software Effectively Remove Someone’s Ability to Work?
The Uber case is easy to understand at an operational level.
A driver opens the app and discovers that the account has been suspended or deactivated.
In some cases, the trigger is suspected fraud. In others, low customer ratings may contribute to temporary or permanent deactivation.
According to the Dutch regulator, some of those decisions were made automatically without meaningful human involvement.
The consequence was significant: a blocked driver could no longer use the Uber platform to take rides and generate income.
That is where GDPR Article 22 becomes relevant.
What GDPR Article 22 Actually Says
Article 22 gives individuals the right not to be subject to certain decisions based solely on automated processing, including profiling, where the decision produces legal effects or similarly significantly affects them.
The rule is not an absolute ban on automation.
Article 22 contains exceptions, including where automated decision-making is necessary for entering into or performing a contract, is authorized by EU or Member State law, or is based on the individual’s explicit consent.
Depending on the applicable exception, the controller may also need to provide safeguards such as the right to obtain human intervention, express a point of view, and challenge the decision.
The practical issue is therefore not simply whether software was involved.
The question is whether the software effectively made the consequential decision.
“Human in the Loop” Cannot Be a Compliance Label
This is the most important operational lesson from the Uber enforcement action.
Companies increasingly describe automated systems as having a “human in the loop.”
That phrase has little legal value if the human cannot genuinely reconsider the outcome.
According to the Dutch authority’s position in the Uber case, human involvement must be effective.
A reviewer should be able to assess the individual case, exercise independent judgment, and change the outcome produced by the automated system.
A process in which an employee merely rubber-stamps an algorithmic recommendation may therefore remain vulnerable under Article 22.
For legal and compliance teams, that requires testing the real workflow:
- What information does the reviewer receive?
- Can the reviewer question the algorithmic flag?
- Does the reviewer have authority to restore the account?
- Can the affected individual explain their position?
- Can an appeal genuinely result in a different decision?
- Is the review documented?
The location of the human matters less than the authority of the human.
SCHUFA: A Human at the End of the Process May Not Be Enough
The Uber case fits into the broader approach taken by the Court of Justice of the European Union in its December 7, 2023 SCHUFA judgment, Case C-634/21.
SCHUFA generated automated probability scores assessing an individual’s ability to meet future payment obligations. Those scores were supplied to third parties such as lenders.
The CJEU held that the automated score itself could qualify as an automated individual decision under Article 22 when the recipient gives that score a determining role in deciding whether to establish, perform, or terminate a contractual relationship.
That reasoning is highly relevant to modern AI and algorithmic systems.
A company cannot necessarily avoid Article 22 simply by placing a human after the algorithm.
If the automated output effectively controls the result, the decision may already be automated in substance.
The compliance question becomes:
Is the algorithm informing human judgment, or is the human merely formalizing a decision the algorithm has already made?
Why the Uber Case Matters Beyond Ride-Hailing
The same issue appears in many corporate workflows.
A fraud engine may block a customer.
A recruiting system may automatically eliminate an applicant.
A marketplace may suspend a seller.
A financial institution may rely on automated scoring to deny a transaction or service.
An insurer may automate eligibility or claims-related decisions.
In each case, legal teams operating in Europe should ask:
- Is an identifiable individual subject to a decision?
- Is the decision based solely, or effectively in a determining way, on automated processing?
- Does it create a legal or similarly significant effect?
- Does an Article 22 exception apply?
- Are the required safeguards meaningful?
- Can the company prove that a human can genuinely override the automated result?
Article 22 Is an AI Governance Rule Even Though It Predates Generative AI
One of the most important lessons is historical.
GDPR Article 22 predates the current generative AI boom.
The Uber case therefore demonstrates that companies do not need to deploy a frontier generative AI model to create “AI governance” risk.
Traditional scoring systems, fraud engines, ranking models, and algorithmic management tools may be enough.
For U.S. companies operating in Europe, this matters because many automated workflows were designed years before current AI governance programs existed.
The compliance review should therefore extend beyond newly purchased AI tools.
Legacy automation may be just as important.
What Legal Teams Should Audit Now
Companies should map automated decision-making processes that affect customers, employees, contractors, applicants, sellers, and other individuals.
For each process, legal teams should identify:
- the decision being made;
- the data used;
- the significance of the outcome;
- whether the system acts automatically;
- whether a human reviews the decision;
- what authority that human actually has;
- how individuals are informed;
- how they can challenge the result;
- and what evidence proves that the review process is real.
This is not only a privacy notice exercise.
It is workflow governance.
Final Analysis
The €824.99 million Uber fine does not mean European law prohibits automation.
It means consequential automation requires legal design.
A company may use algorithms to identify risk, prioritize cases, detect fraud, or support decision-making.
The problem arises when the automated system effectively becomes the final decision-maker while the human reviewer exists only on paper.
That is the broader message of both Uber and SCHUFA.
“Human in the loop” is not a compliance badge.
It must describe a real allocation of decision-making power.
For every automated workflow, the most useful governance question may therefore be the simplest one:
If the system is wrong, who has the authority to say no to the algorithm?
Uber has challenged the regulator’s conclusions and announced an appeal, so the legal dispute is not over.
Why was Uber fined €824.99 million?
The Dutch Data Protection Authority found that certain automated driver suspensions and deactivations significantly affected drivers without sufficient human involvement and that drivers were not adequately informed about the automated decision-making.
What does GDPR Article 22 regulate?
Article 22 restricts certain decisions based solely on automated processing, including profiling, where those decisions produce legal effects or similarly significant effects on individuals.
Does GDPR Article 22 prohibit all automated decisions?
No. The GDPR provides specific exceptions, but safeguards may apply depending on the circumstances.
What counts as meaningful human intervention?
Meaningful intervention requires a human reviewer who can genuinely assess the individual case, exercise independent judgment, and change the automated outcome.
What did the SCHUFA judgment establish?
The CJEU held that an automated score can itself qualify as an automated decision where the score plays a determining role in the decision ultimately made by another organization.
Why should U.S. companies care?
U.S. companies operating in Europe may use automated fraud, HR, marketplace, credit, insurance, or platform-enforcement systems that affect individuals protected by the GDPR. Those workflows may require Article 22 analysis even when the underlying technology is not generative AI.
