Dutch Data Protection Authority, in Cooperation with the CNIL, Fines Uber €824,990,000 for Automated Decisions Concerning Drivers

Kişisel Verilerin Korunması Hukuku, Data Protection Law

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens), acting in cooperation with the Commission Nationale de l’Informatique et des Libertés (“CNIL”) imposed an administrative fine of €824,990,000 on UBER B.V. and UBER TECHNOLOGIES INC. (“Uber”) for taking automated individual decisions concerning drivers using its platform. The decision was announced by the CNIL on August 24, 2026.

Uber consists of UBER B.V., a Dutch company located in Amsterdam, and UBER TECHNOLOGIES INC., a US company with its registered office in San Francisco, and operates a platform connecting private hire vehicle (“PHV”) drivers with users.

The decision originated from a collective complaint filed with the CNIL in 2020 by the association La Ligue des droits de l’Homme, representing more than 170 drivers on the Uber platform. The complaint, supplemented in 2021, concerned, among other matters, the information provided to individuals, transfers of personal data outside the European Union, and automated decisions to temporarily and/or permanently deactivate drivers’ accounts.

Within the scope of the decision, the following key points were highlighted:

  • The decision is the third fine imposed on Uber in connection with the same complaint, following a €10 million fine imposed on December 11, 2023 for failure to inform drivers and a €290 million fine imposed on July 22, 2024 for transfers of personal data outside the European Union.
  • Under the cooperation procedures established by the GDPR, the Dutch Data Protection Authority was competent to conduct the investigation, as Uber’s main establishment is in the Netherlands. The CNIL cooperated closely with its Dutch counterpart throughout the procedure, including during the inspections, the analysis of the evidence obtained, and the examination of the draft decision under the one-stop-shop mechanism.
  • The Dutch Data Protection Authority considered that the deactivation of drivers’ accounts in cases of suspected fraud (temporary deactivation) and in cases of low customer ratings (temporary and permanent deactivation) constituted automated individual decisions, due to the complete absence of human intervention in the decision-making process.
  • The authority emphasized that these decisions significantly affect drivers, who are no longer able to carry out rides and generate income once their accounts have been blocked.

The CNIL informed the complainants of the decision in accordance with the GDPR.

You can access the Decision here.

 

Kind regards,

Zumbul Attorneys-at-Law

info@zumbul.av.tr

 

All information and documents on our website have been prepared by Zumbul Attorneys at Law for general informational purposes only, in accordance with the Attorneyship Law, other relevant legislation and the Professional Rules of Attorneyship of the Union of Turkish Bar Associations. These publications are not intended for advertising or commercial purposes. The information and documents provided are of a general nature and under no circumstances, do they guarantee or warrant that the content is complete, accurate, up-to-date, or reliable. You should not rely on the information and documents on this website without first consulting a lawyer or expert. The links included in our website’s publications are sourced from publicly available materials and are provided solely for the convenience of visitors in accessing additional information. These links do not constitute any form of recommendation or endorsement of the linked persons, institutions or organizations. The information on this website does not in any way constitute legal advice or establish an attorney-client relationship with visitors to the site. All content on this website is the property of by Zumbul Attorneys at Law, and no content may be copied, reproduced, or used without prior written permission.