The Uber Fine: Automated Decisions and Meaningful Human Review in the EU and UK

Updated: 6 days ago
Title: The Uber Fine: Automated Decisions and Meaningful Human Review in the EU and UK
Date: 26 August 2026
Type: Paper
Author: SAASiQ (contact@saasiq.ai)
Word count: 2401 words
Reading time: 9 min
Published: 26-08-2026
The Dutch data protection authority announced on 21 August that it had fined Uber €824,990,000 for deactivating drivers' accounts automatically, with no person reviewing the decisions first. It is the second-largest fine issued under the GDPR, after Meta's €1.2 billion in 2023. This paper covers what the regulator found, where the same kind of decision sits in HR, finance and public-sector systems, how the UK's rules now differ from the EU's after the Data (Use and Access) Act, and what an organisation running automated decisions should check.
What the Dutch regulator decided
The fine was issued by the Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, and is generally reported as €825 million. It concerns the way Uber suspended and removed drivers from its platform. Monique Verdier, the AP's deputy chair, said: "A computer should not make decisions on its own that have major consequences for you. These decisions should have been looked at first by a human being."
The case started with complaints from 171 French drivers, filed through the Ligue des droits de l'Homme. TechCrunch links it to Brahim Ben Ali, a driver who first complained in 2019. The complaints ended up in the Netherlands because Uber's European headquarters is in Amsterdam, and under the GDPR's one-stop-shop arrangement the authority where a company has its main EU establishment leads a cross-border case.
At €824.99 million the fine is 1.85 per cent of Uber's 2025 turnover of €44.5 billion, according to Implicator. It is Uber's third fine from the AP, after €290 million in 2024 over transfers of driver data to the US, and an earlier €10 million.
Uber's spokesperson told TechCrunch: "We strongly disagree with this decision and disproportionate fine." The company says most suspensions are brief and that permanent deactivations were reviewed by people, and it will appeal. Implicator reports Uber citing only 126 permanent deactivations for low ratings across Europe in 2021.
How the deactivations worked
Two kinds of decision were involved. Uber's systems suspended driver accounts temporarily when they detected suspected fraud, such as unnecessary detours or trips that were accepted and then not completed. Drivers whose customer ratings stayed low were deactivated permanently. Either way, a driver earned nothing from Uber while the account was switched off. NOS and Implicator put the conduct between 2018 and 2022, and Computable gives 2020 to 2022.
The main breach is of Article 22 of the GDPR, which gives people the right not to be subject to a decision based solely on automated processing where the decision has legal or similarly significant effects on them. Being cut off from paid work is that kind of effect. The AP also found breaches of the transparency duties in Articles 13 and 14. According to Computable, drivers were not properly told how the decisions were made, and they had no meaningful way to contest them.
Uber's defence concentrates on the permanent deactivations, where it says people were involved, and on the small number of them. The temporary suspensions were automated too. Uber's point that most were brief goes to how long a driver lost income, and says nothing about whether anyone looked at the decision before it was made.
Verdier's test is that the decision is "looked at first by a human being", before it takes effect. On the AP's reasoning, a review that happens after a driver has already been locked out, or a complaint process that eventually restores the account, comes too late. The ICO's draft guidance in the UK, covered below, takes the same view and adds that designing the system does not count as human involvement.
The same gap inside large employers
On 26 August Computerworld covered a Reuters investigation into Meta's Project OT, a plan to replace staff with AI agents. Meta had planned cuts of up to 60 per cent in some teams. Code changes rose 220 per cent year on year, but user-facing features rose only 36 per cent. Major technical and security incidents rose 40 per cent, and the time staff spent firefighting rose 70 per cent. Meta laid off about 10 per cent of staff instead of the planned cuts. Internal posts described "large-scale, disruptive actions that humans are unlikely to execute."
Meta's agents were changing code, so Article 22 does not come into it, but Meta's figures show what happens when agents are judged by activity. Counting what the agents produced (code changes) told Meta much less than counting what reached users (features) and what broke (incidents). Terra Higginson of Info-Tech said: "Unchecked AI agents are a bad idea. Removing humans is a bad idea."
Closer to the Uber case, HR Dive reported on 21 August a survey by The Predictive Index of 399 managers and 208 chief executives. Of the managers, 72 per cent said public AI tools help them prepare for difficult conversations, and 44 per cent had entered employee names and performance details into them. Only 45 per cent of organisations had a written policy on AI in performance management. Anthony Belluccia of The Predictive Index said "trusting a manager and knowing they're set up for a specific hard conversation are two different things."
Approval steps are also appearing as a product feature. Slack Code, reported by VentureBeat on 20 August and summarised by AI Weekly, puts coding agents including Claude Code, Devin, GitHub Copilot and Vercel's agents into shared channels, where a person inspects the changes and approves them before they go to production. The same week a VentureBeat survey of 107 enterprises found that 21 per cent had no real-time monitoring of what their agents cost, and 64 per cent ran three or more platforms to orchestrate them.
The UK rules after the Data (Use and Access) Act
The UK has moved in the other direction. Section 80 of the Data (Use and Access) Act 2025 replaces Article 22 of the UK GDPR with four new articles, 22A to 22D. Clifford Chance reports that these provisions commenced on 5 February 2026.
Article 22A sets the definitions. A decision is based solely on automated processing where there is "no meaningful human involvement in the taking of the decision", and it is significant if it has a legal or similarly significant effect on the person. Article 22B restricts significant, solely automated decisions based on special category data, such as health or ethnicity, to three cases: explicit consent, necessity for a contract, or where the law requires or authorises it.
Article 22C applies to every significant, solely automated decision. The organisation has to put safeguards in place that let the person get information about the decision, make representations, obtain human intervention and contest the decision. Article 22D allows the Secretary of State to set out in regulations what counts as meaningful human involvement. No such regulations have been made yet.
The effect is that the UK default has moved from prohibition to permission with safeguards. Outside special category data, a UK organisation can now make significant decisions about people automatically, provided the Article 22C safeguards are in place. The EU's Article 22, the one applied to Uber, still prohibits it subject to its own exceptions. On a plain reading, a UK system like the one the AP described would not be banned outright, but it would still fail on the safeguards, since the AP found drivers had no meaningful way to contest decisions.
The ICO's draft test for meaningful involvement
The ICO consulted on draft guidance on automated decision-making and profiling from 31 March to 29 May 2026, alongside a separate report on automated decisions in recruitment.
According to Covington's summary of the draft, human involvement has to be active, "not a token gesture". The reviewer has to be trained, has to understand the logic and limits of the system, and has to be able to change the decision before it applies, every time. Designing the system does not count as involvement in the decision itself.
A reviewer who sees only the system's recommendation, with no access to the inputs, is in no position to understand its logic, and so does not meet the test. Nor does a queue where the decision takes effect first and a reviewer can only reverse it later, because the reviewer cannot change it before it applies.
The ICO's own guidance plans page puts the final version at Winter 2026. Some secondary sources had expected it in summer 2026. The same page schedules guidance on agentic AI for Spring 2027.
The EU position and platform workers
In the EU the Article 22 prohibition stands. The Platform Work Directive has to be transposed into national law by 2 December 2026. It requires platforms to disclose how they use algorithmic management and to provide human review of algorithmic decisions that affect platform workers. According to Remote Work Europe, only Italy had a draft law as of May 2026.
The EU AI Act's high-risk rules for employment systems apply from 2 December 2027, as covered in the SAASiQ paper of 12 August.
A UK organisation with staff, contractors or customers in the EU is subject to both regimes. For a system that makes decisions about people in both jurisdictions, the practical course is to design to the EU standard. A decision that a trained person genuinely reviews before it takes effect is not solely automated, so it sits outside both Article 22 and Articles 22A to 22D.
Where automated decisions sit in HR, finance and public services
In HR systems, automated decisions with significant effects show up as absence triggers that start a formal process when a threshold is crossed, performance flags generated from activity data, screening rules that reject job applicants before a recruiter sees them, and scheduling tools that allocate or withdraw shifts. Each of these can affect someone's pay or job. Whether they are solely automated depends on what happens between the system's output and the effect on the person.
In finance systems, credit holds that stop a customer's orders, supplier on-hold decisions that stop payments, expense audit rules that reject claims automatically and fraud flags that freeze an account all act on a rule or a score. Where the customer, supplier or claimant is an individual, such as an employee, a sole trader or a contractor paid through accounts payable, data protection law applies to the decision.
Public bodies carry extra disclosure duties. Benefits processing, licensing and enforcement triage all use rules and scores to decide which cases move forward. Central government departments and arm's-length bodies have had to publish records under the Algorithmic Transparency Recording Standard since 2025, which puts these tools on the public record whether or not a person reviews each decision.
Many of these decisions are produced by rules and agents that suppliers and systems integrators configure inside SaaS suites during an implementation, and the configuration decides whether a person sees the case before it takes effect. The design work behind that configuration is not itself human involvement in the decision, on the ICO's draft reading.
Designing review into the workflow
In workflow terms, the decision should sit in a pending state until a named, trained reviewer has acted on it. The reviewer's screen should show the inputs the system used and its reason for the recommendation, in words a person can follow, alongside the recommendation itself. The reviewer should be able to change the outcome, and the system should record who reviewed each decision, when, and whether they changed it.
The Article 22C safeguards become the second half of the same design. The person affected needs to be told a decision was made about them and on what basis, and needs a route to make representations, ask for a person to look again and contest the outcome. In practice that means a notice template, a case type in the service desk or HR system for challenges, and a time limit for responding.
Reason codes need to be readable by people. A suspension recorded only as a rule number tells the reviewer and the affected person very little. One recorded with the reason in plain words, such as the number of trips accepted and not completed over a stated period, gives both of them something to check and, if it is wrong, to dispute.
Reviewing every decision has a staffing cost, and that cost belongs in the business case for the automation. If the volumes are too high for a person to review each one properly, that is a sign the decision may need redesigning, for example so the system recommends and a person decides only the cases that affect someone's income or employment.
What organisations should do now
The first step is an inventory of automated decisions and agent actions that have legal or similarly significant effects on people. It should cover the rules and scores inside HR, finance and case management systems as well as any new AI features, and record for each one what triggers it, what it does, whether a person sees it before it takes effect, and who that person is.
The second is to classify each entry. A decision about someone covered by the EU GDPR falls under Article 22 and its prohibition. A decision about someone in the UK falls under Articles 22A to 22D, with the stricter rule in 22B where special category data is involved. Where both apply, the EU standard should govern the design.
The third is to put the approval step before the decision takes effect, and to give people notice of the decision and a way to contest it. Public bodies in scope of the ATRS should check that their records describe how human review actually works.
The fourth is contractual. Suppliers should be asked to expose the logic behind automated decisions and the logs of what was decided and by whom, and that obligation should be written into the contract. The last, from Meta's experience, is to measure outcomes: the number of decisions overturned on review, complaints upheld and errors found, as well as the volume of decisions the system processes.
Dates to hold
Uber's appeal against the AP decision has no published date. Member states must transpose the Platform Work Directive by 2 December 2026. The ICO's final guidance on automated decision-making is due in Winter 2026, and the Secretary of State may make regulations defining meaningful human involvement under Article 22D at any point. The ICO's guidance on agentic AI is scheduled for Spring 2027.
SAASiQ - Intelligent Solutions for SaaS ©


