The Dutch data protection authority, the Autoriteit Persoonsgegevens (AP), announced on 21 August 2026 that it has imposed a fine of 824,990,000 euros on Uber after finding that the company used fully automated decision-making to deactivate drivers' accounts. The amount is extraordinary. The more important compliance lesson is not the size of the fine. It is what the case tells organisations about the governance of automated decisions.

According to the AP, Uber used automated systems to temporarily deactivate driver accounts where fraud was suspected and, in cases involving persistently low customer ratings, to deactivate accounts permanently. The findings concern practices operated between 2018 and 2022. The AP found that there was no human assessment before those decisions were taken. For the drivers affected, deactivation meant losing the ability to earn income through the platform. The AP therefore concluded that the decisions significantly affected the drivers and breached the GDPR rules on solely automated decision-making. The regulator also found that Uber had not adequately informed drivers about the automated decision-making involved.

Uber disagrees with the decision and has announced that it will challenge the fine. The company's stated position is that the AP examined historic policies discontinued years ago, and that its current process involves human review before deactivation together with a route for drivers to challenge a suspension. The case is therefore not legally settled. But the compliance questions it raises should already be familiar to organisations deploying increasingly automated systems.

Why is Article 22 GDPR an operational requirement rather than a disclosure exercise?

Article 22 GDPR provides that an individual has the right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal effects concerning them or similarly significantly affects them.

There are exceptions. Solely automated decisions may, subject to the requirements of Article 22, be permitted where they are necessary for entering into or performing a contract, authorised by Union or Member State law, or based on the individual's explicit consent. Where the contractual necessity or consent exceptions are relied upon, suitable safeguards must include at least the ability to obtain human intervention, to express a point of view, and to contest the decision.

This means Article 22 cannot be treated simply as a disclosure requirement. It requires organisations to understand how decisions are actually made. Consider the operational questions that sit behind the law. Is a decision being made solely by an automated system? What role, if any, does a human perform before the decision takes effect? How significant is the decision for the individual? What permits the organisation to automate the decision? Can the individual understand what happened, and can they challenge it? Who reviews that challenge, and does that person have enough information and authority to change the decision? Can the organisation demonstrate that this process works?

These are governance and control-design questions, not drafting questions.

What does meaningful human intervention actually require?

One of the easiest mistakes in automated decision-making governance is to assume that the presence of a human somewhere in the workflow automatically creates human oversight. It does not.

A person who mechanically approves a system recommendation without meaningful assessment may contribute very little to the decision. A reviewer who cannot understand why the system reached its conclusion may struggle to challenge it. A reviewer who technically has an override button but is discouraged from using it may have little practical authority. And a review mechanism available only after the significant consequence has occurred is different from human involvement in the decision itself.

Effective human intervention therefore has to be designed as a control. That means defining who intervenes, at what stage, and what information they receive. It means stating what they are expected to assess, what constitutes a reason to override the automated recommendation, and what authority they hold. It means recording how the review was conducted, how the affected person can express their position or contest the result, and how repeated errors, overrides and complaints are analysed.

The governance objective should not be to prove that a human appeared somewhere in the workflow. It should be to demonstrate that the human can meaningfully affect the decision.

Is every automated decision an AI system?

The Uber decision also provides an important reminder as organisations focus heavily on the EU AI Act. Not every automated decision-making system is necessarily an AI system.

Article 22 GDPR predates the current generative AI boom by years. Yet many of the governance questions now being discussed in AI programmes are closely related to issues privacy professionals have dealt with for much longer: transparency, profiling, significant decisions, explainability, contestability, accountability and human intervention.

This matters when organisations design their governance structures. An AI inventory alone will not necessarily identify every automated decision that creates material risk. Conversely, not every automated processing activity will fall within Article 22.

Organisations need to understand the actual decision architecture. What technology is being used? What personal data is involved? Does the system make a decision or merely support one? How determinative is its recommendation? What consequence follows? Which regulatory regimes apply? The classification should follow the facts rather than the label placed on the technology.

How does the Platform Work Directive change the picture?

For digital labour platforms specifically, the regulatory direction is clearer still. Directive (EU) 2024/2831 on improving working conditions in platform work requires Member States to establish rules on automated monitoring and automated decision-making systems.

Among other things, Article 10(2) requires digital labour platforms to devote sufficient human resources to oversight, with the persons charged with that function holding the necessary competence, training and authority to override automated decisions. It goes further for particularly consequential decisions: Article 10(5) provides that a decision to restrict, suspend or terminate the contractual relationship or the account of a person performing platform work, or any other decision of equivalent detriment, is to be taken by a human being. Article 11 adds rights of explanation, together with access to a contact person at the platform holding the competence and authority to discuss and clarify the decision.

Member States must transpose the Directive by 2 December 2026 under Article 29(1).

The Uber decision therefore sits within a wider regulatory movement towards more explicit governance of algorithmic decision-making. The GDPR, the Platform Work Directive and, where applicable, the EU AI Act should not be viewed as isolated compliance exercises. They increasingly form part of an interconnected governance environment.

What this means for your organisation

  • Article 22 GDPR is a control-design obligation, not a privacy notice paragraph. Adding wording about automated decision-making to a policy does not change how the decision is actually taken.
  • Human presence in a workflow is not the same as human oversight. Where a reviewer lacks the information, the time, or the practical authority to reach a different conclusion, the decision may still be solely automated in substance.
  • An AI inventory alone will not surface every consequential automated decision. Rule-based scoring, thresholds and eligibility logic can significantly affect individuals without meeting any definition of an AI system.
  • Digital labour platforms face a second, more explicit regime from 2 December 2026. Article 10(5) of the Platform Work Directive requires a human being to take decisions that restrict, suspend or terminate an account.
  • The Uber decision is under challenge and is not legally settled. The governance questions it raises apply regardless of how the appeal is resolved.

What you should do now

  1. Identify where consequential automated decisions actually occur, and map each decision from beginning to end, including the data involved.
  2. Determine for each one whether the system makes the decision or supports a human decision-maker, and how determinative its recommendation is in practice.
  3. Assess the consequence for the individual, and establish which legal and regulatory requirements apply to that decision.
  4. Define when human intervention is required and design that intervention as a control, with documented responsibility, escalation routes, and the information the reviewer receives.
  5. Create mechanisms for explanation, challenge and review where required, and retain evidence that the control operates in practice.
  6. Monitor the decision after deployment: how frequently decisions are challenged, how often humans override them, whether certain groups are disproportionately affected, whether reviewers consistently accept system recommendations, whether complaints identify recurring weaknesses, and whether the system or its underlying logic has changed since the original assessment.

The bigger lesson

The Uber decision is important because it illustrates something broader about technology governance. Regulatory compliance does not end when an organisation identifies the applicable legal requirement. The requirement has to travel through the organisation: from regulation to obligation, from obligation to control, from control to implementation, from implementation to evidence, and from evidence to ongoing monitoring.

Article 22 may tell an organisation when solely automated decision-making creates a legal problem. Governance determines whether the organisation can identify that problem before a regulator does.

The 824,990,000 euro figure will dominate the headlines. The more useful question for organisations is much simpler: if a system makes or materially influences an important decision about a person, can you explain exactly how that decision is governed? If the answer is unclear, the automated decision-making programme probably needs another look.

How Priventia helps

Priventia treats an automated decision as a chain rather than a policy statement: the provision that applies, the obligation it produces, the control that carries it, the evidence that the control operated, and the monitoring position that follows. The Compliance Intelligence Assessment resolves which provisions apply to your organisation in its jurisdictions, roles and activities, and the Controls Library links the resulting obligations to the human intervention, explanation and contestability controls that support them.

Sources

  • Autoriteit Persoonsgegevens, "Uber fined nearly 825 million euros for automated driver blocking", announced 21 August 2026.
  • Regulation (EU) 2016/679 (GDPR), Article 22.
  • Directive (EU) 2024/2831 on improving working conditions in platform work, Articles 10(2), 10(5), 11 and 29(1).