In 2019, Brahim Ben Ali lost his Uber account. He was driving in France, and after thousands of rides, an automated system decided his livelihood was over. Last week, the Dutch data protection authority did the math on how many other drivers got the same kind of treatment and dropped a fine on Uber for a staggering €825 million.

That is the equivalent of roughly $960 million — the second-largest penalty ever handed out under Europe’s GDPR, behind only the €1.2 billion fine regulators hit Meta with in 2023. And it all comes down to one deceptively simple principle that anyone working in tech should be paying attention to: a computer should not get to make a life-changing decision about you on its own.
What Uber Actually Did
The Dutch Data Protection Authority, known as the AP, wrapped up an investigation into complaints that Uber was deactivating driver accounts through automated systems — sometimes permanently — without enough warning and without genuine human oversight. In its statement, deputy chair Monique Verdier said the company had committed “serious infringements.” Her line cut through all the jargon: “A computer should not make decisions on its own that have such major consequences.”
Uber disagrees, and it will appeal. The company argues that most suspensions are brief, that nobody is permanently deactivated without human review, and that drivers have a way to appeal. The regulator counters that some drivers were permanently cut off without a human anywhere in the chain. Those two very different versions of reality are now heading to a courtroom.
The Rule Underneath the Headline
This case is not really about one ride-hailing company. It is the enforcement arm of the GDPR’s Article 22, which says people have a right not to be subjected to decisions based solely on automated processing when those decisions significantly affect them — and that when such systems are used, there has to be meaningful human involvement and a way to challenge the result.
In plain language: if an algorithm decides whether you keep your job, your account, or your income, then a human needs to be genuinely in the loop, and you need a door to knock on when it goes wrong. It is the same principle that sits underneath the automated decisions we are all quietly building into government systems, banking apps, and corporate workflows.
The Human Story Behind the Fine
The complaint that started all of this is its own quiet epic. Ben Ali, after his own deactivation in 2019, collected testimonies from more than 170 other Uber drivers and brought the matter to the Netherlands, where Uber’s European headquarters sits. A Swiss digital-rights nonprofit called PersonalData.io helped the drivers pull the data showing how these deactivation decisions were actually made — the first step toward proving they were automated.
Paul-Olivier Dehaye, the nonprofit’s founder, put words to a fear every gig worker recognizes. A driver can “complete a thousand journeys with satisfied passengers,” he said, “but if just one person reports a very serious problem, the consequences can be enormous.” One complaint. One automated flag. A thousand good rides count for nothing against the threshold.
Here is a detail I find striking: this is the third fine the Dutch regulator has leveled at Uber. There was €290 million back in 2024 over how Uber handled European drivers’ personal data, plus a smaller €10 million penalty for related issues. Dehaye says all of them trace back to complaints from the same determined group of drivers — and he is now building a company called StartClaims to push similar cases across the wider gig economy. It is a reminder that when a system stays broken, the people it harms eventually get organized.
The Other Side of the Coin
The strongest pushback I found came from John Gruber at Daring Fireball. His argument is worth taking seriously: of course Uber should use automation to police drivers who pull scams or leave riders stranded. Saying a computer suspended someone is a bit like saying “the time clock” fired a habitually late employee. Managers set the policies; the devices just measure compliance.
He isn’t wrong that we shouldn’t romanticize the human manager either. A person can be just as arbitrary and a lot slower. And I’ve written before about how trusting algorithms blindly creates its own failure modes — like how Discord’s AI moderation wrongly banned 8,000 people in the name of safety. Automation errs in one direction; humans err in another. The question is never whether to have a decision-maker. It is who answers for it.
Dehaye’s response to Gruber lands for me. Uber is free to use humans to punish drivers who genuinely scam, he said — but then it has to take responsibility for that decision “like being an employer, not being a marketplace.” The moment you rely on automation to decide who gets to work, you have accepted a duty of care that travels with it.
This Isn’t Academic Where I Work
I manage an ICT division in the Philippines, and we roll out automated systems constantly — approval flows, compliance checks, anomaly flags, workflow automation. I have watched the same pattern the Dutch regulator flagged play out in miniature: we get the automation working beautifully, and only later do we ask where the human override lives.
The Philippines is also a gig-economy country. Hundreds of thousands of people — ride-hailing drivers, food-courier riders, vehicle and scooter renters — depend on platforms like Grab for their daily income. When I land in this crowd, I think about a delivery rider I know who lives or dies by the daily rating. In a market like ours, the “algorithm as boss” is not a European abstraction. It is the app sitting on a rider’s phone quietly deciding whether tomorrow exists.
Somewhere along the way, I stopped treating an automated decision as the finished product. It is only half of one. The other half is the human appeal path — the safety valve, the person who can actually reverse a bad call before the damage becomes permanent. That has to be designed in from day one, not bolted on after a regulator counts the wrong suspensions. It is like chess: you move well when you have already thought about the response to your own mistake, not just the winning move.
What Every Team Building Automated Decisions Should Steal From This
This is not a story about one company for me. It is a checklist for anyone shipping automated decisions at any scale:
- Assume the machine will be wrong sometimes — because it will. Design the correction path before you design the automation, not after.
- A “false positive” is never just a number. To the person on the other side, it is a lost day’s income, a lost account, a lost livelihood. Count the human cost in your product review, not just the error rate.
- Meaningful human review means the human can actually overturn the machine, not rubber-stamp it after the damage is done.
- Document the appeal process. If you cannot explain to an outsider how someone contests an automated decision, you do not actually have one.
None of this is anti-automation. I am as enthusiastic about well-built systems as anyone — and I have written about why voluntary, self-imposed limits are not a real safety system. The gap here is the same one that shows up when even frontier AI labs document almost nothing about how they would rein in their own systems. It is a lot easier to claim a human is in the loop than to build a loop a human can actually reach.
The Data-Rights Wave Underneath
There is also a broader current worth naming. The Uber fine lands in the same season as a wave of rulings that treat people’s data and their working conditions as things companies owe a duty toward — not just value to be extracted. We have seen it in the data-consent fights over everything from Samsung’s “consent or delete” health-data ultimatum to the quiet expansion of automated scoring in banking and government. The regulators are telling one story: the more consequential the automated decision, the more accountability it carries.
That accountability gap is exactly why we are using AI more than ever while trusting it less than ever. We adopt the efficiency; we flinch at the verdicts. The Uber case is the market finally putting a price on the part we keep flinching about.
The Bottom Line
Uber will appeal, and the fine may shrink or shift through the courts. That is fine — the number was never really the story.
The story is that a major privacy enforcer has now said, loudly and on the record, that a computer should not hold that much power over a person’s working life without a human answerable for it. That principle is bigger than Uber and bigger than the gig economy. It is headed for every organization quietly automating decisions about the people they serve — including the government work where I sit.
The lesson I am carrying back to my own team is simple and a little uncomfortable. When an algorithm makes a call that changes someone’s life, someone has to be able to say “that was wrong, and I am fixing it.” If you do not have that person, the algorithm is not running your process. It is running your people. And one day, the bill for that comes due.