The Netherlands' Data Protection Authority — the Autoriteit Persoonsgegevens — has ordered Uber to pay €825 million ($966 million) over how it deactivated driver accounts between 2020 and 2022, according to an August 17 decision. It's the second-largest fine ever issued under the EU's General Data Protection Regulation, behind only the €1.2 billion penalty Ireland imposed on Meta in 2023 over transfers of Facebook user data to the US.
The Dutch authority has no power over labor disputes; it enforces data protection law. What it found was that Uber's systems, in some instances, deactivated drivers without adequate warning or a meaningful way to contest the decision, breaching GDPR's rule against letting an algorithm alone make decisions with serious consequences for a person. The regulator's position: losing platform access means losing income, and that counts as a serious consequence under privacy law, even though the underlying dispute looks like an employment matter.
That distinction matters for coverage purposes. A privacy regulator's fine and a discrimination or wrongful-termination claim sit under different policies — cyber/privacy versus EPL — even when they stem from the same automated process.
Uber says it will appeal, calling the fine disproportionate and noting that only 126 driver accounts were permanently deactivated across Europe in 2021 over low ratings. The regulator counters that some deactivations happened by computer with no human review, and that drivers generally weren't properly told why their accounts were suspended. Dutch appeals typically take years, and the fine is suspended until the process runs its course.
This is Uber's second major Dutch privacy fine in two years. A €290 million penalty landed in 2024 for sending European drivers' personal data to the US without proper safeguards. Both cases trace back to a French drivers' complaint and were handled in the Netherlands, where Uber's European operations are based.
Even though this is a privacy case, not an EPL case, the underlying exposure - algorithms making decisions that affect people's livelihoods without a human check - is now showing up in US employment litigation too. In Mobley v. Workday, a federal judge let key discrimination claims against an AI hiring tool proceed in June 2026, prompting some carriers to write broad AI exclusions into management liability policies, as covered in Insurance Business's report on AI exclusions splitting the EPL market. D&O and tech E&O underwriters are separately asking harder questions about board oversight of automated decision tools, per Insurance Business's coverage of how AI rollout is outpacing risk controls.
GDPR penalties are also frequently uninsurable across much of Europe, a point Insurance Business raised when Microsoft faced a comparable GDPR exposure over LinkedIn's data practices. Some major carriers — AIG, Great American and W.R. Berkley among them — have gone further, seeking approval to cap their own AI-related liability.
For brokers with clients running any automated decision process — suspensions, hiring filters, fraud flags, claims triage — the question is simple: does the client's cyber, EPL or tech E&O coverage respond if a regulator or plaintiff alleges an algorithm, not a person, made the call?
Uber says it will appeal. PersonalData.io, the Swiss digital-rights group that helped drivers obtain records on the automated decisions behind the case, says it's now preparing a separate class-action claim for compensation.