What businesses can learn from Uber’s €825m GDPR fine about automated decisions, AI governance, human oversight and workplace decision systems today.

01

What happened

On 21 August 2026, the Dutch Data Protection Authority announced a fine of nearly €825 million against Uber. The regulator said that, between 2018 and 2022, automated systems could temporarily or permanently deactivate driver accounts following suspected fraud or persistently low customer ratings.

According to the regulator, affected drivers were not adequately informed about the automated decision-making and meaningful human assessment was missing in relevant cases. Losing access to an account could prevent a driver from earning through the platform.

Uber disputes parts of the findings. It says its current processes include human review, safeguards and a route for drivers to challenge suspensions. The company has announced that it will appeal, so the regulator's decision should not be presented as the final outcome of the dispute.

02

This is a GDPR case

Uber was not fined under the EU AI Act. The enforcement action was taken under the GDPR, particularly its rules on solely automated decision-making with legal or similarly significant effects.

Article 22 does not ban every automated decision. Exceptions can apply, but safeguards may be required. These can include the right to obtain human intervention, express a point of view and challenge the decision.

The business question is practical: if software can materially affect someone's work, income, account or access to a service, can your team explain the decision and correct it when the system is wrong?

03

The wider AI governance lesson

AI compliance is not only about ChatGPT. Systems that score, rank, monitor, recommend or make decisions about people can create much greater regulatory risk than everyday generative AI use.

A system does not need to make the final decision by itself to deserve governance attention. Its recommendation may still shape what a manager, recruiter or fraud team does next.

  • Candidate screening and CV ranking.
  • Employee performance scoring and productivity monitoring.
  • Fraud alerts, disciplinary flags and account restrictions.
  • Shift or task allocation based on behaviour or personal characteristics.
  • Promotion, termination or access recommendations.
04

When the AI Act could apply

This case was not decided under the AI Act, but it shows why employment and workforce systems receive special attention under the Regulation.

Annex III point 4 can classify certain AI systems as high-risk where they are used for recruitment, candidate selection, work-related decisions, promotion or termination, task allocation, or monitoring and evaluating performance and behaviour. The wording expressly includes work-related contractual relationships involving people providing services through platforms.

That does not mean Uber's particular system was necessarily an AI system or a high-risk AI system. An Uber-style decision system could fall within these rules only if it meets the AI Act definition of an AI system and the relevant high-risk criteria.

Following Regulation (EU) 2026/1744, the main Chapter III requirements for Annex III high-risk AI systems apply from 2 December 2027.

05

Human oversight must be real

For high-risk AI systems, Article 14 requires effective human oversight. The reviewer needs enough competence, training and authority to understand the system's limits, question its output and recognise over-reliance on automation.

Where appropriate, that person must be able to disregard, override or reverse the output. A human clicking ‘approve’ is not necessarily meaningful oversight if they routinely accept the recommendation without understanding or challenging it.

06

The Platform Work Directive adds another layer

Member States must transpose Directive (EU) 2024/2831 by 2 December 2026. It contains specific rules on algorithmic management and automated decision-making by digital labour platforms.

In particular, decisions to restrict, suspend or terminate a person's platform account or contractual relationship must be taken by a human being. This is a separate legal framework, but it makes the governance lesson especially relevant for platform businesses.

07

Could this happen in your business?

Ask one question: does software in your business influence a decision about a person? That might be a candidate rejected after CV ranking, an employee flagged for poor performance, a worker given fewer shifts because of a score, a customer refused access to a service, or a contractor suspended after a fraud alert.

If the answer is yes, establish:

  1. What system is making or influencing the decision.
  2. What personal data it uses.
  3. Whether the system qualifies as AI.
  4. Whether the use could be high-risk under the AI Act.
  5. Who reviews important decisions.
  6. Whether that reviewer has genuine authority to disagree.
  7. What information is given to the affected person.
  8. How errors and decisions can be challenged.
  9. What records show how the decision was reached.
08

Blanche perspective

The takeaway is not that every business needs a complex compliance programme. It is that decisions about people deserve a closer look than routine productivity uses of AI.

Using AI or automated systems to make decisions about people? Blanche can help you identify what systems you use, where the risks sit and what controls need to be in place.

S

Sources

Primary and authoritative sources used for this Insight.

  1. Dutch Data Protection Authority: Uber automated decision-making fine, 21 August 2026
  2. GDPR, Article 22: automated individual decision-making
  3. Regulation (EU) 2024/1689, consolidated text of 27 July 2026
  4. European Commission AI Act Service Desk: Article 14 human oversight
  5. Regulation (EU) 2026/1744: revised high-risk application date
  6. Directive (EU) 2024/2831 on platform work
  7. Reuters: Uber response and announced appeal
Share this Insight