What Uber's €825m GDPR Fine Means for Marketing Automation
The Dutch DPA fined Uber €825 million for letting software deactivate drivers with no human involved. Which of your automations are actually caught.
On 21 August 2026 the Dutch Data Protection Authority fined Uber €824,990,000. It is the second-largest GDPR penalty ever issued, behind only the €1.2 billion Ireland imposed on Meta in 2023.
What makes it worth an hour of a marketer's attention is what it is not about. No data was transferred unlawfully to the United States. No cookie banner was missing. No database was breached. Uber was fined for letting software make a decision about a person, with real consequences for that person, without a human being involved.
That is a much broader hazard than ride-hailing, and a lot of marketing stacks contain something shaped like it.
What the Regulator Actually Found
Uber ran systems that monitored two data streams: driver behaviour and customer ratings. When those systems flagged suspected fraud, the driver's account was suspended. When ratings stayed low, the account could be removed permanently. In both cases the driver's income from the platform stopped, and in neither case did a person assess the decision before the consequence attached.
The Autoriteit Persoonsgegevens found two breaches. First, the prohibition in Article 22 of the GDPR on decisions based solely on automated processing that produce legal effects or similarly significant consequences. Second, a failure to tell drivers adequately that automated decision-making was happening at all.
Monique Verdier, deputy chair of the AP, put the principle in one sentence: "A computer should not make decisions on its own that have major consequences for you. These decisions should have been looked at first by a human being."
The conduct ran until 2022, with reporting placing its start at 2018. The case reached the Dutch regulator by an indirect route: 171 French drivers took their situation to the Ligue des droits de l'Homme, which complained to the French regulator CNIL, and because Uber's European headquarters sit in the Netherlands, the AP became lead supervisory authority under the GDPR's one-stop shop.
For scale, the fine is roughly 1.85% of Uber's approximately €44.5 billion global turnover in 2025, against a statutory ceiling of 4%. It is also, on its own, equivalent to around 72% of all GDPR fines issued across the entire European Economic Area during 2025.
The Line Is Consequence, Not Technology
Here is the part most coverage gets wrong, and the part that matters for your stack.
Article 22 is not an AI rule. It says nothing about machine learning, model complexity, or whether your vendor markets a feature as artificial intelligence. A simple threshold on a spreadsheet is caught if it produces the right kind of outcome, and a sophisticated neural network is not caught if it does not.
The test is whether the output attaches a legal or similarly significant consequence to an identifiable person, with no meaningful human involvement. That is the whole question.
This is why the Uber decision sits alongside a run of European enforcement that has nothing to do with taxis: Austria's regulator ruling on automated credit scoring in 2025, a German court ordering Schufa to explain individual score calculations, and a Berlin court upholding an order against a solar company running automated credit checks before booking site visits. The reasoning travels because the structure is identical.
Which Marketing Automations Are Caught
Most are not. It is worth being precise rather than alarmed, because the panicked reading of this fine ("our lead scoring is illegal now") is wrong and will send teams chasing the wrong work.
| Generally outside Article 22 | Potentially inside Article 22 |
|---|---|
| Lead scoring that routes a record to a salesperson who then decides | Automated rejection of a credit, finance or insurance application |
| Choosing which creative, offer or subject line someone sees | Automated account suspension or ban that cuts off income or access |
| Audience segmentation for campaign targeting | Automated eligibility screening that materially denies a service |
| Churn prediction that triggers a human outreach | Individualised dynamic pricing that materially changes someone's terms |
| Send-time optimisation and frequency capping | Automated CV screening that rejects candidates without review |
Advertising profiling that only decides which message a person sees generally falls outside, because selecting a creative is not a legal or similarly significant effect. That is the reasoning, and it is worth understanding rather than memorising, because the boundary moves with consequence.
Lead scoring is the instructive case. A score that helps a human prioritise a call is fine. The same score becomes an Article 22 problem the moment it automatically declines an application, closes an account, or withholds something the person is otherwise entitled to. Nothing about the model changed. What changed is that the output stopped being advice and started being a decision.
What "Human Involvement" Has to Mean
If you are relying on a person being in the loop, the standard is higher than most teams assume.
The AP consulted on this in March 2025 and took a clear position: a human assessor must hold genuine authority to overrule the automated outcome, and must actually exercise judgement when the case warrants it. A reviewer who approves whatever the system proposes is not meaningful involvement. Neither is a person who lacks the standing, the information or the time to disagree.
In practice that means asking three questions about any automated decision in your stack:
- Does the reviewer see the underlying reasoning, or only the output?
- Can the reviewer overturn the outcome without escalating to someone else?
- Does the audit log show reversals actually happening?
If the answer to the third is "never", you have a rubber stamp rather than a safeguard, and the AP has said so in writing.
The Second Limb: You Have to Explain It
The transparency finding is the quieter half of this decision and the easier one to fall foul of.
Where automated decision-making is in operation, the GDPR requires that affected people be told it is happening, given meaningful information about the logic involved, and told the significance and envisaged consequences. Notifying someone that their account has been suspended does not discharge that duty. The AP opened a separate consultation in April 2026 on precisely what such an explanation must contain, including how far trade secrets can limit disclosure.
If your privacy notice does not mention automated decision-making, and something in your stack makes one, that gap is the cheapest thing on this list to fix. It is also worth checking what your vendor's documentation says, since you cannot describe the logic of a system you have never had explained to you. Ask for it in writing, in the same conversation as the Data Processing Agreement.
Two Honest Caveats
Uber is appealing, and says its current policies include human review and a route for drivers to dispute outcomes. It told reporters it no longer makes permanent deactivation decisions solely by automated means. Roughly 40% of the headline value of GDPR fines announced to date has been annulled or is under active challenge, so the announced number and the collected number are different things. Amazon's €746 million fine went back to the regulator on appeal.
The law itself is moving. The European Commission's Digital Omnibus, proposed in November 2025, would restructure Article 22 from an individual right into a set of permissible processing conditions, and would state explicitly that offering a human alternative does not prevent a controller from deciding by automated means. Had that text been in force during Uber's conduct period, the analysis would have looked different. It is a proposal, not law, and building your process on the assumption that it passes in its current form would be optimistic.
Neither caveat changes what a European regulator has just demonstrated it is willing to do.
What To Do This Quarter
- Inventory the automated decisions in your stack. Not the automations, the decisions. Anything where a system's output attaches a consequence to a named person without a person looking.
- Sort them by consequence, not by how clever the technology is. A rules engine that suspends accounts matters more than an AI feature that picks subject lines.
- For anything with real consequence, check the human step is real. Authority to overrule, information to overrule with, and evidence in the logs that it happens.
- Update your privacy notice to disclose automated decision-making where it exists, with the logic and the consequences.
- Ask vendors how their scoring works before you wire an automatic consequence to it. If they will not explain the logic, you cannot explain it to a data subject either.
None of this requires abandoning marketing automation. It requires knowing which of your automations decide things about people, and putting a person with actual authority in front of those specific ones.
Frequently Asked Questions
Does Article 22 ban automated decision-making?
No. It restricts decisions based solely on automated processing that have legal or similarly significant effects on someone. Automation that informs a human decision, or that has no significant consequence for the individual, is not caught.
Is lead scoring illegal under the GDPR now?
No. Scoring that helps a person prioritise their work is not an Article 22 decision. It becomes one if the score automatically produces a significant consequence, such as declining an application or closing an account, with nobody able to intervene.
Does this apply to AI tools specifically?
Article 22 is technology-neutral and predates the current wave of AI tools. A hard-coded rule can breach it and a machine learning model can comply with it. Separately, the EU AI Act adds its own transparency duties, which we cover in labelling AI-generated content in the EU.
What counts as meaningful human involvement?
On the Dutch regulator's stated position, a reviewer with genuine authority to overturn the automated outcome, who has the information needed to assess it, and who actually exercises that judgement. Approval without scrutiny does not qualify.
Why did a Dutch regulator fine Uber over French drivers?
Uber's European headquarters are in the Netherlands, which makes the AP the lead supervisory authority under the GDPR's one-stop shop mechanism. The complaint originated with French drivers via the CNIL, and the AP coordinated the decision with other European supervisors.
If you are auditing what makes decisions about people in your stack, our directory lists European marketing automation and CRM software with hosting location, ownership and DPA status verified against each vendor's own published documents.
Looking for GDPR-compliant alternatives?
Browse our directory of European marketing tools , all verified for GDPR compliance and EU data hosting.