Phone us
A recent €825 million GDPR fine against Uber has put automated decision making firmly in the spotlight. This article looks at what the case means for organisations using algorithms and AI to make decisions about people, and why meaningful human oversight, transparency and governance remain essential.

Automated decision making is becoming embedded in everyday business. Algorithms can identify suspected fraud, assess creditworthiness, screen job applicants, evaluate employee performance, prioritise customers, calculate risk scores and determine whether users should retain access to online services.

For organisations, the attraction is clear. Automation can process large volumes of information quickly and consistently, reduce costs and allow decisions to be made at a scale that would be difficult to achieve manually.

However, a recent €824.99 million GDPR fine against Uber demonstrates what can happen when automated systems move beyond supporting human decisions and effectively start making significant decisions about people themselves.

On 21 August 2026, the Dutch Data Protection Authority announced that it had fined Uber almost €825 million after concluding that the company had used fully automated processes to temporarily or permanently deactivate drivers’ accounts. The decisions included suspensions relating to suspected fraud and low customer ratings. Because drivers could no longer accept journeys or generate income through Uber while their accounts were deactivated, the regulator considered the decisions to have a significant effect on the individuals concerned.

The case provides a timely warning for organisations increasingly looking to artificial intelligence, algorithms and automated systems to make operational decisions. The lesson is not that automated decision making should be avoided. It is that organisations need to understand when automation has moved from assisting a human to replacing them, what consequences those decisions have for individuals and whether the governance surrounding that process is sufficient.

What Happened in the Uber Case?

The case originated from a collective complaint submitted to the French data protection regulator, the CNIL, in 2020 on behalf of more than 170 Uber drivers. Because Uber’s main European establishment is in the Netherlands, the Dutch Data Protection Authority led the investigation under the GDPR’s one-stop-shop mechanism, with the CNIL participating in the process.

The investigation considered, among other issues, decisions that resulted in drivers being disconnected from the Uber platform. According to regulators, Uber used automated systems to identify suspected fraudulent behaviour and monitor customer ratings. In certain circumstances, this could result in a driver’s account being temporarily deactivated. Persistently low customer ratings could also result in temporary or permanent deactivation.

The Dutch authority concluded that these decisions were being made without human intervention during the period it investigated. That distinction was crucial. Losing access to an Uber account is not comparable to an algorithm deciding which advert somebody sees or which product appears first in a recommendation list. For a driver reliant on the platform for their income, account deactivation can have an immediate and significant financial impact.

The regulator therefore concluded that Uber had breached GDPR rules governing solely automated individual decision making. It also found that drivers had not been sufficiently informed about the automated nature of the decisions.

Uber strongly disputes the findings and has said it will appeal the decision. The company has argued that its policies include human review, safeguards and opportunities for drivers to challenge suspensions, and that the regulator was examining historical practices which have since been discontinued. The fine should therefore be understood as a regulatory decision that Uber is contesting, rather than the final outcome of the legal dispute.

The Problem Is Not Automation Itself

Automated decision making is sometimes discussed as though data protection law is fundamentally opposed to organisations using algorithms. It is not.

Automation can provide substantial benefits. Decisions can be processed more quickly, large datasets can be analysed consistently, fraudulent activity can be identified sooner and employees can be freed from repetitive administrative work.

The concern arises when an automated system makes a decision about a person that can materially affect their life, finances, employment, opportunities or legal rights, particularly where the person has limited understanding of how that decision was reached or little ability to challenge it.

An algorithm may produce the decision, but the organisation remains responsible for deciding:

  • Who designed or selected the system
  • What information it uses
  • What thresholds trigger action
  • Whether the information is sufficiently accurate
  • Whether bias has been considered
  • Whether a human should review the result
  • How individuals are informed
  • What happens when the system gets something wrong

Automation does not remove organisational accountability. In some circumstances, it makes that accountability more important.

What Counts as a Significant Automated Decision?

Under the EU GDPR, Article 22 provides specific protections around decisions based solely on automated processing, including profiling, where those decisions produce legal effects or similarly significantly affect an individual.

The key concepts are solely automated and significant.

A process may involve sophisticated automation without necessarily falling within these rules if a human genuinely evaluates the information and makes the ultimate decision.

Equally, an automated decision does not automatically become a high-risk Article 22 decision simply because a computer made it. Its impact on the individual matters.

Regulatory guidance has traditionally identified automated credit refusals and recruitment decisions as examples where the consequences can be sufficiently significant. The Uber case provides another useful example. If an automated system determines that an individual should lose access to the platform through which they earn their income, the consequences are clearly different from an automated recommendation with little practical impact.

Organisations should therefore examine not only how automated a process is, but what actually happens to the person at the end of it.

Putting a Human in the Process Is Not Necessarily Enough

One of the most important governance lessons surrounding automated decision making concerns the meaning of human oversight.

It can be tempting to assume that adding a human approval stage automatically means a decision is no longer automated. Regulatory guidance makes clear that meaningful human involvement requires considerably more than this.

The ICO has said that where automation is used to support decisions, the human decision maker should actively assess the recommendation rather than simply approving it routinely. They should have the competence and authority to disagree with the system, consider other relevant information and genuinely influence the outcome.

Consider an automated fraud system that assigns a customer a high-risk score and recommends closing their account. If an employee simply sees the recommendation, clicks “approve” and closes the account without examining the underlying evidence, it may be difficult to argue that the human meaningfully made the decision.

Similarly, if staff are technically permitted to overturn an algorithm but organisational culture, performance targets or system design discourage them from doing so, human oversight may exist on paper while being largely ineffective in practice.

The more useful question is not simply whether a human is involved, but what that review actually involves.

Automated Fraud Decisions Deserve Particular Attention

The Uber case is especially relevant to organisations using automation for fraud prevention.

Fraud detection increasingly relies on automated systems because of the sheer quantity of transactions and activity organisations need to monitor. Systems can identify unusual payment patterns, device changes, suspicious login behaviour, identity inconsistencies, transaction velocity, unusual locations and other indicators far more quickly than individual analysts.

However, a fraud indicator is not necessarily proof of fraud. False positives can occur. A legitimate customer may travel unexpectedly. A person’s spending behaviour may change. A new device may be genuine.

The consequences of an automated response therefore matter. Using automation to flag an account for investigation presents a different risk from allowing the same system automatically to suspend the account, reject a payment, terminate a relationship or accuse somebody of fraudulent behaviour.

Organisations need to decide where automation can act independently and where the potential consequences justify meaningful human intervention.

Transparency Matters Before Something Goes Wrong

The Dutch authority also criticised Uber over the information provided to drivers about automated decision making. This highlights another common weakness. Individuals may interact with automated systems without realising that consequential decisions are being made about them.

A privacy notice may mention profiling or algorithms deep within several pages of legal wording, but genuine transparency requires organisations to explain their processing in a way that people can reasonably understand.

Individuals should be able to understand:

  • What information is being assessed
  • Why it is being assessed
  • What type of automated decision could result
  • What the consequences might be
  • How they can challenge the outcome

Organisations do not necessarily need to expose proprietary algorithms or provide every technical detail behind a model. They do, however, need to provide meaningful information that helps individuals understand the process and exercise their rights.

Transparency therefore needs to be designed alongside the automated system, not added to a privacy notice as an afterthought.

The UK Position Has Changed

For UK organisations, there is an important additional consideration.

The Uber decision concerns the EU GDPR, whereas the UK’s rules on automated decision making have recently changed. The Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D, with all of the Act’s data protection provisions in force by 19 June 2026.

The new UK framework is more permissive. Previously, significant decisions based solely on automated processing were generally restricted unless specific conditions applied, such as necessity for a contract, authorisation by law or explicit consent.

Under the new framework, organisations have greater scope to make significant automated decisions involving ordinary personal information, provided they have an appropriate lawful basis and implement the required safeguards. Stronger restrictions continue where special category data is involved.

This means UK organisations should be careful when reading commentary suggesting that GDPR simply “bans” significant automated decisions. That is no longer an accurate description of the UK position.

However, greater flexibility does not remove the need for oversight and accountability.

Safeguards Still Matter Under the New UK Rules

The UK’s new Article 22C requires safeguards where a significant decision is made solely through automated processing.

These safeguards must include informing the individual that such a decision has been made, allowing them to make representations and challenge the decision, and enabling them to obtain human intervention.

The legislation also formally defines a decision as solely automated where there is no meaningful human involvement.

For leadership teams, this makes governance around human review particularly important. Simply inserting an employee somewhere in the workflow does not necessarily remove the organisation from the automated decision-making provisions. The organisation needs to understand whether that individual can actually influence the decision.

The Government describes the reforms as allowing greater use of automated decision making while retaining safeguards for individuals, rather than removing those protections altogether.

For UK businesses, therefore, the lesson from Uber remains highly relevant. The legal framework may differ, but the underlying governance questions remain.

A DPIA Should Come Before Deployment, Not After a Complaint

Automated systems capable of making significant decisions can present substantial privacy and fairness risks. Organisations should therefore assess those risks before the technology becomes operational.

A Data Protection Impact Assessment provides a structured mechanism for considering questions such as:

  • What personal information does the system use?
  • Where does that information come from?
  • How accurate is it?
  • Could inaccurate information produce an adverse decision?
  • Could particular groups be disproportionately affected?
  • How significant are the consequences of a false positive?
  • What human review exists?
  • Can an individual challenge the decision?
  • How quickly can an incorrect decision be reversed?
  • How will the organisation detect systematic errors or bias?

The value of a DPIA is not simply that it creates evidence for the compliance file. Used properly, it forces the organisation to challenge how the system will operate before people become dependent on its decisions.

This is particularly important when new AI tools are being introduced quickly because of pressure to improve efficiency. A technology being commercially available does not mean the organisation deploying it has automatically satisfied its own data protection responsibilities.

Boards Need Visibility of Automated Decision Making

Automated decision making can easily become fragmented across an organisation.

HR may introduce automated candidate screening. Finance may deploy automated fraud detection. Customer services may implement risk-based account restrictions. Marketing may use behavioural profiling. Security teams may adopt user-behaviour analytics. Procurement teams may purchase products containing AI functionality without necessarily describing them internally as automated decision systems.

As a result, senior management may have no single view of where consequential automated decisions are taking place.

Boards do not need detailed knowledge of every algorithm. However, they should receive assurance that significant automated processes have been identified, risk assessed, appropriately governed and subject to meaningful controls.

Where a system can materially affect an individual’s employment, finances, access to a service or other important interests, leadership should understand the risks associated with relying on that system.

Governance Must Extend Beyond the Algorithm

It would be easy to treat automated decision making as an issue primarily concerning the accuracy of AI models. Accuracy certainly matters, but it is only one part of the control environment.

Effective governance should consider the entire lifecycle of the decision. That includes the quality of the input data, the design of the model, the rules applied to its output, the authority given to the system, human review, transparency, appeals, monitoring, incident handling and periodic reassessment.

Organisations should also consider what happens as systems change.

An automated tool originally introduced only to recommend cases for investigation may later be configured to take direct action. An algorithm may be retrained using different data. A supplier may introduce new AI functionality through a software update. A process that originally included meaningful human review may gradually become largely automated as workloads increase.

Compliance therefore cannot be assessed once at procurement and forgotten. Automated decision making requires ongoing oversight.

What Should Senior Leaders Be Asking?

The Uber decision gives boards and senior management an opportunity to examine where automated decisions already exist within their organisations.

At a minimum, leadership should be able to establish:

  • Where algorithms or AI systems make, recommend or materially influence decisions about individuals
  • Which of those decisions could have legal, financial, employment-related or similarly significant consequences
  • Whether human intervention is genuinely meaningful rather than simply procedural
  • How individuals are informed about automated decision making and how they can challenge an outcome
  • Whether appropriate DPIAs, lawful basis assessments, accuracy checks and fairness reviews have been completed
  • Who within the organisation is accountable for monitoring these systems after deployment

The purpose is not to make the board responsible for reviewing individual algorithmic decisions. It is to ensure that somebody is accountable for the systems that make them.

Automation Does Not Automate Accountability

The scale of Uber’s €824.99 million penalty makes the case noteworthy, but the wider significance lies in what it says about the relationship between technology and organisational responsibility.

Businesses are increasingly able to automate decisions that previously required human judgement. That creates enormous opportunities for efficiency, but it also creates the possibility that decisions affecting thousands or millions of people can be made at extraordinary speed, including decisions based on inaccurate information, flawed assumptions or systems that individuals struggle to understand or challenge.

The appropriate response is not to resist automation. It is to govern it.

Organisations should know which decisions have been automated, understand their consequences, ensure that individuals have appropriate safeguards and challenge whether purported human oversight is genuinely meaningful.

For UK organisations, the Data (Use and Access) Act has created greater flexibility around significant automated decisions. That flexibility should not be mistaken for an absence of responsibility. If anything, greater freedom to automate makes effective governance more important.

Algorithms can analyse the information. They can calculate the risk. They can recommend, and increasingly make, the decision. But when that decision materially affects a person, accountability still belongs to the organisation that chose to automate it.

At AJC, we help organisations strengthen the governance, risk management and data protection controls needed to use automated decision making responsibly. Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.

Sources:

https://autoriteitpersoonsgegevens.nl/en/current/uber-fined-nearly-825-million-euros-for-automated-driver-blocking

https://www.cnil.fr/en/automated-decisions-uber-fined-nearly-eur-825-million

https://www.reuters.com/world/dutch-regulator-fines-uber-966-million-automating-driver-suspensions-document-2026-08-21/

https://www.edpb.europa.eu/documents/guideline/automated-decision-making-and-profiling_en

https://www.legislation.gov.uk/ukpga/2025/18/notes/division/10/index.htm

https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-how-does-this-affect-me/

https://www.gov.uk/guidance/data-use-and-access-act-2025-data-protection-and-privacy-changes

Image accreditation: Viktor Avdeev (July 2020) from Unsplash.com. Last accessed on 8 September 2026. Available at:
https://unsplash.com/photos/white-mercedes-benz-c-class-on-street-during-daytime-Gk3apXDUZiI

In case you missed it...

Windows 11 26H2
Preparing for Windows 11 26H2: A...

Windows 11 version 26H2 is expected later in 2026, bringing changes to recovery, resilience and the Windows update experience. This...

Read More
emmanuel charlot
Meet Emmanuel Charlot, Risk and Fraud...

In this series, we introduce the people behind AJC and the experience they bring to the business. In this profile,...

Read More
stansted airport cyber attack
London Stansted Cyber Attack: Customer Data...

A recent cyber security incident affecting London Stansted Airport has highlighted the risks associated with customer data, even when financial...

Read More

Get in touch

    By submitting this form you are consenting that your data be handled in accordance with our Privacy Notice and we will be in touch regarding your enquiry.