Preparing for Windows 11 26H2: A...
Windows 11 version 26H2 is expected later in 2026, bringing changes to recovery, resilience and the Windows update experience. This...
Read MoreAutomated decision making is becoming embedded in everyday business. Algorithms can identify suspected fraud, assess creditworthiness, screen job applicants, evaluate employee performance, prioritise customers, calculate risk scores and determine whether users should retain access to online services.
For organisations, the attraction is clear. Automation can process large volumes of information quickly and consistently, reduce costs and allow decisions to be made at a scale that would be difficult to achieve manually.
However, a recent €824.99 million GDPR fine against Uber demonstrates what can happen when automated systems move beyond supporting human decisions and effectively start making significant decisions about people themselves.
On 21 August 2026, the Dutch Data Protection Authority announced that it had fined Uber almost €825 million after concluding that the company had used fully automated processes to temporarily or permanently deactivate drivers’ accounts. The decisions included suspensions relating to suspected fraud and low customer ratings. Because drivers could no longer accept journeys or generate income through Uber while their accounts were deactivated, the regulator considered the decisions to have a significant effect on the individuals concerned.
The case provides a timely warning for organisations increasingly looking to artificial intelligence, algorithms and automated systems to make operational decisions. The lesson is not that automated decision making should be avoided. It is that organisations need to understand when automation has moved from assisting a human to replacing them, what consequences those decisions have for individuals and whether the governance surrounding that process is sufficient.
The case originated from a collective complaint submitted to the French data protection regulator, the CNIL, in 2020 on behalf of more than 170 Uber drivers. Because Uber’s main European establishment is in the Netherlands, the Dutch Data Protection Authority led the investigation under the GDPR’s one-stop-shop mechanism, with the CNIL participating in the process.
The investigation considered, among other issues, decisions that resulted in drivers being disconnected from the Uber platform. According to regulators, Uber used automated systems to identify suspected fraudulent behaviour and monitor customer ratings. In certain circumstances, this could result in a driver’s account being temporarily deactivated. Persistently low customer ratings could also result in temporary or permanent deactivation.
The Dutch authority concluded that these decisions were being made without human intervention during the period it investigated. That distinction was crucial. Losing access to an Uber account is not comparable to an algorithm deciding which advert somebody sees or which product appears first in a recommendation list. For a driver reliant on the platform for their income, account deactivation can have an immediate and significant financial impact.
The regulator therefore concluded that Uber had breached GDPR rules governing solely automated individual decision making. It also found that drivers had not been sufficiently informed about the automated nature of the decisions.
Uber strongly disputes the findings and has said it will appeal the decision. The company has argued that its policies include human review, safeguards and opportunities for drivers to challenge suspensions, and that the regulator was examining historical practices which have since been discontinued. The fine should therefore be understood as a regulatory decision that Uber is contesting, rather than the final outcome of the legal dispute.
Automated decision making is sometimes discussed as though data protection law is fundamentally opposed to organisations using algorithms. It is not.
Automation can provide substantial benefits. Decisions can be processed more quickly, large datasets can be analysed consistently, fraudulent activity can be identified sooner and employees can be freed from repetitive administrative work.
The concern arises when an automated system makes a decision about a person that can materially affect their life, finances, employment, opportunities or legal rights, particularly where the person has limited understanding of how that decision was reached or little ability to challenge it.
An algorithm may produce the decision, but the organisation remains responsible for deciding:
Automation does not remove organisational accountability. In some circumstances, it makes that accountability more important.
Under the EU GDPR, Article 22 provides specific protections around decisions based solely on automated processing, including profiling, where those decisions produce legal effects or similarly significantly affect an individual.
The key concepts are solely automated and significant.
A process may involve sophisticated automation without necessarily falling within these rules if a human genuinely evaluates the information and makes the ultimate decision.
Equally, an automated decision does not automatically become a high-risk Article 22 decision simply because a computer made it. Its impact on the individual matters.
Regulatory guidance has traditionally identified automated credit refusals and recruitment decisions as examples where the consequences can be sufficiently significant. The Uber case provides another useful example. If an automated system determines that an individual should lose access to the platform through which they earn their income, the consequences are clearly different from an automated recommendation with little practical impact.
Organisations should therefore examine not only how automated a process is, but what actually happens to the person at the end of it.
One of the most important governance lessons surrounding automated decision making concerns the meaning of human oversight.
It can be tempting to assume that adding a human approval stage automatically means a decision is no longer automated. Regulatory guidance makes clear that meaningful human involvement requires considerably more than this.
The ICO has said that where automation is used to support decisions, the human decision maker should actively assess the recommendation rather than simply approving it routinely. They should have the competence and authority to disagree with the system, consider other relevant information and genuinely influence the outcome.
Consider an automated fraud system that assigns a customer a high-risk score and recommends closing their account. If an employee simply sees the recommendation, clicks “approve” and closes the account without examining the underlying evidence, it may be difficult to argue that the human meaningfully made the decision.
Similarly, if staff are technically permitted to overturn an algorithm but organisational culture, performance targets or system design discourage them from doing so, human oversight may exist on paper while being largely ineffective in practice.
The more useful question is not simply whether a human is involved, but what that review actually involves.
The Uber case is especially relevant to organisations using automation for fraud prevention.
Fraud detection increasingly relies on automated systems because of the sheer quantity of transactions and activity organisations need to monitor. Systems can identify unusual payment patterns, device changes, suspicious login behaviour, identity inconsistencies, transaction velocity, unusual locations and other indicators far more quickly than individual analysts.
However, a fraud indicator is not necessarily proof of fraud. False positives can occur. A legitimate customer may travel unexpectedly. A person’s spending behaviour may change. A new device may be genuine.
The consequences of an automated response therefore matter. Using automation to flag an account for investigation presents a different risk from allowing the same system automatically to suspend the account, reject a payment, terminate a relationship or accuse somebody of fraudulent behaviour.
Organisations need to decide where automation can act independently and where the potential consequences justify meaningful human intervention.
The Dutch authority also criticised Uber over the information provided to drivers about automated decision making. This highlights another common weakness. Individuals may interact with automated systems without realising that consequential decisions are being made about them.
A privacy notice may mention profiling or algorithms deep within several pages of legal wording, but genuine transparency requires organisations to explain their processing in a way that people can reasonably understand.
Individuals should be able to understand:
Organisations do not necessarily need to expose proprietary algorithms or provide every technical detail behind a model. They do, however, need to provide meaningful information that helps individuals understand the process and exercise their rights.
Transparency therefore needs to be designed alongside the automated system, not added to a privacy notice as an afterthought.
For UK organisations, there is an important additional consideration.
The Uber decision concerns the EU GDPR, whereas the UK’s rules on automated decision making have recently changed. The Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D, with all of the Act’s data protection provisions in force by 19 June 2026.
The new UK framework is more permissive. Previously, significant decisions based solely on automated processing were generally restricted unless specific conditions applied, such as necessity for a contract, authorisation by law or explicit consent.
Under the new framework, organisations have greater scope to make significant automated decisions involving ordinary personal information, provided they have an appropriate lawful basis and implement the required safeguards. Stronger restrictions continue where special category data is involved.
This means UK organisations should be careful when reading commentary suggesting that GDPR simply “bans” significant automated decisions. That is no longer an accurate description of the UK position.
However, greater flexibility does not remove the need for oversight and accountability.
The UK’s new Article 22C requires safeguards where a significant decision is made solely through automated processing.
These safeguards must include informing the individual that such a decision has been made, allowing them to make representations and challenge the decision, and enabling them to obtain human intervention.
The legislation also formally defines a decision as solely automated where there is no meaningful human involvement.
For leadership teams, this makes governance around human review particularly important. Simply inserting an employee somewhere in the workflow does not necessarily remove the organisation from the automated decision-making provisions. The organisation needs to understand whether that individual can actually influence the decision.
The Government describes the reforms as allowing greater use of automated decision making while retaining safeguards for individuals, rather than removing those protections altogether.
For UK businesses, therefore, the lesson from Uber remains highly relevant. The legal framework may differ, but the underlying governance questions remain.
Automated systems capable of making significant decisions can present substantial privacy and fairness risks. Organisations should therefore assess those risks before the technology becomes operational.
A Data Protection Impact Assessment provides a structured mechanism for considering questions such as:
The value of a DPIA is not simply that it creates evidence for the compliance file. Used properly, it forces the organisation to challenge how the system will operate before people become dependent on its decisions.
This is particularly important when new AI tools are being introduced quickly because of pressure to improve efficiency. A technology being commercially available does not mean the organisation deploying it has automatically satisfied its own data protection responsibilities.
Automated decision making can easily become fragmented across an organisation.
HR may introduce automated candidate screening. Finance may deploy automated fraud detection. Customer services may implement risk-based account restrictions. Marketing may use behavioural profiling. Security teams may adopt user-behaviour analytics. Procurement teams may purchase products containing AI functionality without necessarily describing them internally as automated decision systems.
As a result, senior management may have no single view of where consequential automated decisions are taking place.
Boards do not need detailed knowledge of every algorithm. However, they should receive assurance that significant automated processes have been identified, risk assessed, appropriately governed and subject to meaningful controls.
Where a system can materially affect an individual’s employment, finances, access to a service or other important interests, leadership should understand the risks associated with relying on that system.
It would be easy to treat automated decision making as an issue primarily concerning the accuracy of AI models. Accuracy certainly matters, but it is only one part of the control environment.
Effective governance should consider the entire lifecycle of the decision. That includes the quality of the input data, the design of the model, the rules applied to its output, the authority given to the system, human review, transparency, appeals, monitoring, incident handling and periodic reassessment.
Organisations should also consider what happens as systems change.
An automated tool originally introduced only to recommend cases for investigation may later be configured to take direct action. An algorithm may be retrained using different data. A supplier may introduce new AI functionality through a software update. A process that originally included meaningful human review may gradually become largely automated as workloads increase.
Compliance therefore cannot be assessed once at procurement and forgotten. Automated decision making requires ongoing oversight.
The Uber decision gives boards and senior management an opportunity to examine where automated decisions already exist within their organisations.
At a minimum, leadership should be able to establish:
The purpose is not to make the board responsible for reviewing individual algorithmic decisions. It is to ensure that somebody is accountable for the systems that make them.
The scale of Uber’s €824.99 million penalty makes the case noteworthy, but the wider significance lies in what it says about the relationship between technology and organisational responsibility.
Businesses are increasingly able to automate decisions that previously required human judgement. That creates enormous opportunities for efficiency, but it also creates the possibility that decisions affecting thousands or millions of people can be made at extraordinary speed, including decisions based on inaccurate information, flawed assumptions or systems that individuals struggle to understand or challenge.
The appropriate response is not to resist automation. It is to govern it.
Organisations should know which decisions have been automated, understand their consequences, ensure that individuals have appropriate safeguards and challenge whether purported human oversight is genuinely meaningful.
For UK organisations, the Data (Use and Access) Act has created greater flexibility around significant automated decisions. That flexibility should not be mistaken for an absence of responsibility. If anything, greater freedom to automate makes effective governance more important.
Algorithms can analyse the information. They can calculate the risk. They can recommend, and increasingly make, the decision. But when that decision materially affects a person, accountability still belongs to the organisation that chose to automate it.
At AJC, we help organisations strengthen the governance, risk management and data protection controls needed to use automated decision making responsibly. Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.
Sources:
https://www.cnil.fr/en/automated-decisions-uber-fined-nearly-eur-825-million
https://www.edpb.europa.eu/documents/guideline/automated-decision-making-and-profiling_en
https://www.legislation.gov.uk/ukpga/2025/18/notes/division/10/index.htm
https://www.gov.uk/guidance/data-use-and-access-act-2025-data-protection-and-privacy-changes
Image accreditation: Viktor Avdeev (July 2020) from Unsplash.com. Last accessed on 8 September 2026. Available at:
https://unsplash.com/photos/white-mercedes-benz-c-class-on-street-during-daytime-Gk3apXDUZiI
Windows 11 version 26H2 is expected later in 2026, bringing changes to recovery, resilience and the Windows update experience. This...
Read MoreIn this series, we introduce the people behind AJC and the experience they bring to the business. In this profile,...
Read MoreA recent cyber security incident affecting London Stansted Airport has highlighted the risks associated with customer data, even when financial...
Read More