What Is The General Data Protection Regulation? The European Law Behind Uber’s €825 Million Fine

Most people know the General Data Protection Regulation (GDPR) as the law that’s responsible for those endless cookie consent pop-ups that appear on virtually every website (everybody’s favourite thing in the world). But Europe’s landmark privacy legislation is about much more than cookies.

In fact, it’s powerful enough to land one of the world’s biggest tech companies in a heap of trouble, along with a lovely €825 million fine. Indeed, Uber’s been hit with this punishment at the hands of Dutch regulators who recently ruled that the company had violated GDPR by automatically suspending drivers without sufficient human involvement in the decision-making process. Following the recent Uber Freight cyberattack a few weeks back, it’s safe to say the company’s having a bit of a rough month.

But in this specific instance, the case has once again thrust GDPR back into the spotlight and highlighted a lesser-known part of the regulation that’s becoming increasingly relevant in the age of AI and automation.

So, what exactly is GDPR, and why has it become such a big deal?

 

What Is GDPR?

 

The General Data Protection Regulation is a European Union law that came into effect in May 2018, so it’s nothing new. Its primary aim is to give individuals more control over how their personal data is collected, stored and used. It’s a way to provide a general level of protection over our data in the modern age.

Important to note, however, is that GDPR doesn’t only apply to European companies. Any organisation that handles the personal data of EU residents can fall within its scope, regardless of where that organisation is based.

The regulation covers a wide range of activities, including how businesses collect customer information, how long they keep it, who they share it with and how they protect it from misuse. Under GDPR, individuals have a number of rights, including the right to access their data, correct inaccurate information, request that their data be deleted and understand how their information is being processed.

Since its introduction, GDPR has become one of the world’s most influential privacy laws, inspiring similar regulations in countries and regions around the globe.

 

 

Why Has Uber Been Fined?

 

The Uber case is centred on a section of GDPR that many people have never heard of. That is, protections against significant decisions being made solely by automated systems. And while it’s not a part of the regulation we’ve heard a lot about, I’d be as bold as to say that it may be one of the most important parts of it.

According to the Dutch Data Protection Authority, Uber used automated systems to suspend or deactivate drivers in Europe without providing enough transparency or meaningful human review. The regulator argued that these decisions could have a significant impact on a driver’s livelihood, making them exactly the kind of decisions GDPR was designed to scrutinise. After all, the idea is that these big decisions that affect human life deserve a little more consideration and empathy than a simple AI evaluation.

Ultimately, regulators believe that drivers were sometimes being judged by algorithms rather than people. And that’s a problem, because GDPR generally gives individuals the right not to be subject to decisions based solely on automated processing when those decisions have legal or similarly significant effects on them.

Uber has since disputed the findings and said it intends to appeal the decision. We’ve reached out to Uber for comment, but as of 24 August, we have not yet had any response.

 

GDPR Is No Longer Just About Data

 

Cases like Uber’s demonstrate how GDPR has evolved beyond its reputation as a privacy law. Today, it is increasingly becoming a regulation that shapes how companies deploy technology.

When GDPR was first introduced, many businesses focused on compliance measures such as privacy notices, consent forms and data storage policies. But now, regulators are paying closer attention to how algorithms make decisions and whether humans remain involved in the process. This change is particularly important as artificial intelligence becomes more and more widely used.

From recruitment software and loan approvals to fraud detection systems and content moderation tools, algorithms are making more decisions than ever before. The question regulators are increasingly asking, however, is quite simple: when technology makes a decision that could significantly affect someone’s life, should a human still have the final say? And it seems like the overwhelming answer from most people is yes, or at least that humans should be part of the conversation.

 

Why This Matters Beyond the Uber Debacle

 

Uber is far from the only company using automation to make decisions, and in many ways, that’s pr0bably part of the point. Across industries, businesses are turning to AI and algorithms to improve efficiency, reduce costs and process vast amounts of information.

And from a business perspective, that makes perfect sense. But the challenge arises when those systems begin making decisions that affect people’s jobs, finances, opportunities or access to services.

The Uber case serves as a reminder that while automation can speed things up, it doesn’t necessarily remove accountability. Under GDPR, companies are still responsible for ensuring that people understand how decisions are being made and have access to meaningful review processes when necessary.

For technology companies, that could become one of the defining regulatory challenges of the next decade.

 

Living With the GDPR

 

Europe has often taken a tougher approach to regulating technology than many other regions, and the GDPR is perhaps the clearest example of that philosophy.

While critics argue that strict regulation can slow innovation, many supporters believe it creates important safeguards in a world where personal data has become one of the most valuable resources on the planet.

Indeed, the Uber fine highlights how that debate is evolving. This isn’t just about who owns your data or whether a company can send you marketing emails (although those are important factors). Now, it’s also abuot the role technology should play in decisions that affect real people.

And as AI systems become more sophisticated, that question is only going to become more important. For businesses, GDPR is no longer simply a compliance exercise; it’s becoming a rulebook for how technology itself should be used.