Uber is facing one of the largest monetary penalties issued under GDPR, with the Dutch data protection authority set to slap the business with a €825m (£706m) fine over its use of automated systems to deactivate driver accounts.
The Autoriteit Persoonsgegevens (AP) found that the company had deactivated driver accounts without adequately informing them, according to a document seen by the FT.
The fine is the second largest under GDPR; Meta was whacked by a €1.2bn penalty by Ireland’s Data Protection Commission in 2023. It is appealing the ruling. Meanwhile, Amazon’s 2021 €746m (£644m) GDPR fine – at the time the second highest penalty ever issued – was kicked out by a Luxembourg court earlier this year.
Uber has branded the fine “disproportionate” and said it will appeal against the decision. It added that the AP had examined “historic policies that were discontinued years ago”.
In a statement, the company behind the ride-hailing app said: “We take decisions that affect drivers’ ability to earn extremely seriously and we’re fully committed to fair treatment. This includes human reviews, robust safeguards and the opportunity for drivers to appeal our decisions if they believe we made a mistake.”
The penalty has yet to be formally announced but has been confirmed by the AP, which is the lead regulator for Uber as its European headquarters are located in Amsterdam.
In the document, the AP said Uber “violated drivers’ rights; specifically, the right not to be subject to automated decision-making that has legal consequences or otherwise significant consequences for the drivers. Uber has also violated the right to be fully informed about such automated decision-making”.
The penalty follows a €290m Dutch fine against Uber two years ago for transferring personal data of European taxi drivers to the US and failing to appropriately safeguard the data with regard to these transfers. Meanwhile, in 2018, it was clobbered with fines of more than £900,000 by UK and Dutch regulators for showing “complete disregard” for the personal information of both customers and drivers following a 2016 hack attack which the company covered up for over a year.
The head of the Computer & Communications Industry Association Europe Daniel Friedlaender criticised the latest penalty as “truly colossal” and stressed that GDPR enforcement “should never be turned into punishment for punishment’s sake”.
Related stories
Court shoots down €746m ‘flawed’ Amazon GDPR fine
Meta rocked by EU data transfer block and €1.2bn fine
Uber drivers threaten legal action over data roadblock
Tesco dumps Uber in fresh Clubcard Reward shake-up
Uber fined £900,000 over ‘complete disregard’ for data
Uber hires two privacy chiefs in wake of mass breach


Be the first to comment on "Uber slams ‘disproportionate’ €825m Dutch GDPR fine"