Security2 distinct publishers3 min readPublished
The Dutch regulator did not rule that Uber's deactivations were wrong, only that no person reviewed them. That reading reaches every fraud score and abuse pipeline with EU users.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Two trigger conditions did the work here, and both are ordinary plumbing: software watching driving behaviour that raised a fraud suspicion, and a customer rating that fell under a threshold [4]. The first took an account off temporarily; persistent low ratings took it off for good, and the driver's earnings through the platform stopped while the account was down [3]. Nothing in the regulator's description requires the model to have been wrong. The GDPR's limit attaches to fully automated decisions that can significantly affect a person's life, and taking away the ability to earn sits inside that [18], so the absence of a human assessment is itself the finding [5].
That makes the defensible artefact a record rather than a policy. Uber disagrees with both the decision and the amount and is appealing [8]. Its position is that the authority examined historic policies discontinued years ago, and that it has human reviews, robust safeguards and an appeal route for drivers who believe it made a mistake [9]. The AP's own statement says the violations have now stopped [7]. Those two readings can both hold only if the human step arrived after the conduct window closed, and securityaffairs notes the appeal will have to establish whether the protections existed during 2018 to 2022 or came later [10]. A present-tense appeals process is not evidence about a 2019 deactivation. Proving the point after the fact means producing dated evidence, decision by decision, that a person looked and had the authority to reverse the call. The transparency finding is the cheap half to remedy; the review requirement is the half that shows up in headcount.
The size is worth reading against this regulator's own history with the company. The prior record was 290 million euros in 2024, over European driver data sent to the United States without adequate protection [12], which Uber also appealed at the time [13]. The new penalty is roughly 2.8 times that [15], and the two together put about 1.1 billion euros in front of a single national authority [16].
The transferable part is the shape, not the industry. A score crosses a line, an account changes state, and nobody in the loop is asked to agree [4]. Fraud holds and abuse enforcement are usually built that way, and the AP did not have to argue that any individual outcome was unfair to reach a penalty [5]. For anyone running that pattern on EU data subjects, the question on the table is not model accuracy but whether a review step exists, who staffs it, and whether its output is logged well enough to survive a regulator reading it four years later.
Ranked by verification strength, evidence, and original report placement.
The Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, imposed a fine of 824,990,000 euros on Uber because it ruled Uber made fully automated decisions about drivers.
The Dutch Data Protection Authority said it is imposing a fine of 825 million euros ($964 million) because Uber violated the EU's GDPR.
On suspicion of fraud or customer reviews that were too low, drivers' accounts were automatically temporarily deactivated, and in case of persistent low customer reviews permanently deactivated; as a result their income via Uber was lost during the deactivation.
Uber used software to track drivers' driving behaviour and customer reviews; if the software detected a suspicion of fraud or reviews were too low, the accounts concerned were automatically deactivated with no human assessment. This occurred between 2018 and 2022.
The AP found that Uber violated the prohibition on fully automated decision-making under the GDPR.
The AP also found that Uber did not sufficiently inform drivers about the automated decision-making.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Regulator statement quoted directly and corroborated by two outlets
The core facts trace to the AP's own published statement, quoted at length by one source and summarised consistently by the other, with the exact penalty figure, both findings, the conduct window and Uber's on-the-record response all present. What is missing is documentary detail on affected driver volumes and any appeal filing, and the analytical extensions about the appeal and about gig-economy spillover are single-outlet assertions.
One confirmed deployment and one enforcement action, no measured spillover
There is firm evidence of real-world deployment on both sides of the story: Uber ran automated deactivation in production for roughly five years, and the regulator has actually issued and published a penalty. But the cluster contains no counts of affected drivers, no evidence of other regulators following, and no evidence of any other platform changing its automated-enforcement design, so uptake of the ruling as a broader compliance norm is unmeasured.
Documented fine, over-extended reach
The penalty, findings and Uber's response are precisely evidenced, so the headline number is not inflated. The framing that this reading reaches every fraud score and abuse pipeline with EU users goes beyond what the sources show: the ruling concerns one company's discontinued practice, is under appeal and therefore not final, and no other enforcement action or platform change is cited. That gap between a single non-final national decision and a universal design mandate is the overstatement.
Regulator deterrence signalling versus Uber's historic-policy defence
Both principal voices in the cluster have visible stakes: the AP's published statement carries deterrent framing for a fourth fine against the same company, while Uber's statement is structured to move the conduct into the past and foreground safeguards whose timing the regulator disputes. The two reporting outlets are security and privacy trade publications whose audience interest favours enforcement stories, and one adds an explicit industry-wide moral. No sponsorship, funding or commercial relationship is disclosed in the sources, so this reflects positional rather than financial incentive.
High on the enforcement facts, low on consequences
Two independent publishers agree on every material number and finding, and the primary regulator statement is quoted, so confidence in what happened is high. Confidence in what follows is much lower: the appeal is unresolved, the affected population is unquantified, and the industry-wide implication is unverified, so the aggregate sits well below ceiling.
product
amber's 7mn-euro bet: the AI cost centre has moved upstream of the model1 distinct publisher
leadership
Robotaxis Are Taking Mid-Teens Share in Three Metros. Headcount Will Not Show It.1 distinct publisher
product
Canva's forecast cut turns model routing into a product line item1 distinct publisher
product
Uber's first European robotaxi still has a driver in it, and that is the whole story1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026
1 article · August 24, 2026