Disclaimer: This article has been updated since its initial publication to include comments from Uber.
Most people know the General Data Protection Regulation (GDPR) as the law that’s responsible for those endless cookie consent pop-ups that appear on virtually every website (everybody’s favourite thing in the world). But Europe’s landmark privacy legislation is about much more than cookies.
In fact, it’s powerful enough to land one of the world’s biggest tech companies in a heap of trouble, along with a lovely €825 million fine. Indeed, Uber’s been hit with this punishment at the hands of Dutch regulators who recently ruled that the company had violated GDPR by automatically suspending drivers without sufficient human involvement in the decision-making process. Following the recent Uber Freight cyberattack a few weeks back, it’s safe to say the company’s having a bit of a rough month.
But in this specific instance, the case has once again thrust GDPR back into the spotlight and highlighted a lesser-known part of the regulation that’s becoming increasingly relevant in the age of AI and automation.
So, what exactly is GDPR, and why has it become such a big deal?
What Is GDPR?
The General Data Protection Regulation is a European Union law that came into effect in May 2018, so it’s nothing new. Its primary aim is to give individuals more control over how their personal data is collected, stored and used. It’s a way to provide a general level of protection over our data in the modern age.
Important to note, however, is that GDPR doesn’t only apply to European companies. Any organisation that handles the personal data of EU residents can fall within its scope, regardless of where that organisation is based.
The regulation covers a wide range of activities, including how businesses collect customer information, how long they keep it, who they share it with and how they protect it from misuse. Under GDPR, individuals have a number of rights, including the right to access their data, correct inaccurate information, request that their data be deleted and understand how their information is being processed.
Since its introduction, GDPR has become one of the world’s most influential privacy laws, inspiring similar regulations in countries and regions around the globe.
More from News
- GCSE Results Day: What Is The Most Valuable Thing A 16-Year-Old Can Do With AI Right Now?
- Your “Private” Instagram Account May Not Be As Private As You Think
- YouTube Is Paying Creators Millions To Stay Off Netflix – And Penalising Those Who Don’t
- OpenAI Has Built A Teen Mode For ChatGPT – Will It Actually Protect Young People?
- Airlock Digital Completes Independent IRAP Assessment At The Protected Level
- The Fabled Return Of MySpace: Are We Romanticising Life Before Algorithms?
- Google’s $10M Spirit Airlines Purchase Reveals The Potential Hidden Value Of Bankruptcy
- Uber Freight’s Cyberattack: What Are The Risks After Data Is Stolen?
Why Has Uber Been Fined?
The Uber case is centred on a section of GDPR that many people have never heard of. That is, protections against significant decisions being made solely by automated systems. And while it’s not a part of the regulation we’ve heard a lot about, I’d be as bold as to say that it may be one of the most important parts of it.
According to the Dutch Data Protection Authority, Uber used automated systems to suspend or deactivate drivers in Europe without providing enough transparency or meaningful human review. The regulator argued that these decisions could have a significant impact on a driver’s livelihood, making them exactly the kind of decisions GDPR was designed to scrutinise. After all, the idea is that these big decisions that affect human life deserve a little more consideration and empathy than a simple AI evaluation.
Ultimately, regulators believe that drivers were sometimes being judged by algorithms rather than people. And that’s a problem, because GDPR generally gives individuals the right not to be subject to decisions based solely on automated processing when those decisions have legal or similarly significant effects on them.
Uber’s Response: “We Strongly Disagree”
Uber has responded to our request for comment on the €825 million fine with the following statement from a company spokesperson:
“We strongly disagree with this decision and disproportionate fine, which we will appeal. The AP examined historic policies that were discontinued years ago. We take decisions that affect drivers’ ability to earn extremely seriously and we’re fully committed to fair treatment. This includes human reviews, robust safeguards and the opportunity for drivers to appeal our decisions if they believe we made a mistake.”
Basically, they’re saying that the GDPR has been unfairly, inaccurately and improperly enforced, saying that the regulator’s decision focuses on practices that are no longer in use and does not accurately reflect how the platform operates today.
According to the company, the systems examined by the Dutch regulator were phased out several years ago – that is, temporary fraud waitlisting ended in 2021, while ratings-based deactivations across the EU ended in 2022. Uber says that there is, therefore, no ongoing violation taking place, and what they’ve ruled on is outdated.
The company also maintains that drivers were not being permanently removed for fraud without human oversight, directly opposing accusations made against the company. It says accounts flagged for potentially fraudulent activity were temporarily waitlisted while being reviewed, and that most affected drivers were able to return to the platform quickly. Uber also notes that nearly three-quarters of these drivers were back online within a day and most within four days.
Uber further argues that its current deactivation processes do, in fact, include human review, safeguards and appeals mechanisms that allow drivers to challenge decisions. In some markets, including France, additional review processes have been introduced through agreements with driver representatives and unions, according to Uber. And importantly, the company also believes that the fine is “disproportionate”, particularly given the relatively small number of drivers affected.
Generally speaking, it seems as though Uber’s argument is threefold:
- They’re being penalised for practices that are no longer in use.
- The GDPR has imposed a fine based on a specific interpretation of the regulation in question.
- The punishment doesn’t fit the crime.
Further to that, they’re making a broader point that goes beyond just their own legal dispute. That is, if this “novel” interpretation of the GDPR continues to be implemented and enforced, it’s fair to expect that it’s going to become increasingly difficult for companies to use technology for the purpose of maintaining safety, quality and fraud prevention measures. That is, regulating these issues in this way will, in their opinion, be counterproductive in the overall goal of trying to improve safety and protection for consumers.
Uber has confirmed that it plans to appeal the ruling, and that due to the appeal process, the fine isn’t payable until their appeals have either been won or exhausted, which could take several years.
GDPR Is No Longer Just About Data
Regardless of the outcome of this particular situation, cases like Uber’s demonstrate how GDPR has evolved beyond its reputation as a privacy law. Today, it is increasingly becoming a regulation that shapes how companies deploy technology.
When GDPR was first introduced, many businesses focused on compliance measures such as privacy notices, consent forms and data storage policies. But now, regulators are paying closer attention to how algorithms make decisions and whether humans remain involved in the process. This change is particularly important as artificial intelligence becomes more and more widely used.
From recruitment software and loan approvals to fraud detection systems and content moderation tools, algorithms are making more decisions than ever before. The question regulators are increasingly asking, however, is quite simple: when technology makes a decision that could significantly affect someone’s life, should a human still have the final say? And it seems like the overwhelming answer from most people is yes, or at least that humans should be part of the conversation.
Why This Matters Beyond the Uber Debacle
Uber is far from the only company using automation to make decisions, and in many ways, that’s probably part of the point. Across industries, businesses are turning to AI and algorithms to improve efficiency, reduce costs and process vast amounts of information.
And from a business perspective, that makes perfect sense. But the challenge arises when those systems begin making decisions that affect people’s jobs, finances, opportunities or access to services.
The Uber case serves as a reminder that while automation can speed things up, it doesn’t necessarily remove accountability. Under GDPR, companies are still responsible for ensuring that people understand how decisions are being made and have access to meaningful review processes when necessary.
For technology companies, that could become one of the defining regulatory challenges of the next decade.
Living With the GDPR
Europe has often taken a tougher approach to regulating technology than many other regions, and the GDPR is perhaps the clearest example of that philosophy.
While critics argue that strict regulation can slow innovation, many supporters believe it creates important safeguards in a world where personal data has become one of the most valuable resources on the planet.
Indeed, the Uber fine highlights how that debate is evolving. This isn’t just about who owns your data or whether a company can send you marketing emails (although those are important factors). Now, it’s also about the role technology should play in decisions that affect real people.
And as AI systems become more sophisticated, that question is only going to become more important. For businesses, GDPR is no longer simply a compliance exercise; it’s becoming a rulebook for how technology itself should be used.
