Uber has been fined €825 million ($966 million) by the Dutch data protection regulator over the way its automated systems were used to suspend and deactivate drivers.

The decision puts renewed attention on how technology companies use algorithms to manage workers and raises a broader question: when software makes a decision that can affect someone's income, how much human oversight should be required?

The Dutch Data Protection Authority (AP), known locally as the Autoriteit Persoonsgegevens, said Uber breached the European Union's General Data Protection Regulation (GDPR) through its use of automated decision-making between 2018 and 2022.

The regulator said drivers were not adequately informed about the automated processes and did not receive sufficient human involvement when significant decisions were made about their accounts.

A record-setting penalty

The fine is the second-largest penalty issued under the GDPR, behind the €1.2 billion penalty imposed on Meta in 2023.

The investigation began after complaints were submitted by 171 Uber drivers represented by French human-rights organisation Ligue des droits de l'Homme.

Because Uber's European headquarters are located in Amsterdam, the Dutch regulator handled the case under the EU's cross-border data protection enforcement system.

How Uber's automated systems affected drivers

Algorithms are central to Uber's operations.

The company's technology determines how passengers and drivers are matched, monitors activity, detects potentially fraudulent behaviour and supports pricing and other platform functions.

According to the Dutch regulator, however, some of these automated systems were also involved in decisions that could significantly affect drivers' ability to earn money.

Drivers could be suspended over suspected fraudulent behaviour, including allegations involving unnecessary route changes intended to increase fares or accepting trips without completing them.

Low customer ratings could also contribute to permanent removal from the platform.

The regulator's concern was not simply the use of algorithms. Instead, it focused on situations where automated processing could produce serious consequences without sufficient human intervention or information for the affected driver.

Why human oversight matters

The case highlights an increasingly important distinction in the age of AI.

Using software to recommend a restaurant or determine which video appears in someone's feed generally has limited consequences.

But when an automated system determines whether someone can continue working, access a financial service or use an online platform, the consequences can be much more serious.

A driver who loses access to Uber may immediately lose an important source of income.

Under Article 22 of the GDPR, individuals have protections against decisions based solely on automated processing when those decisions have legal or similarly significant effects.

This means companies need to consider not only whether their algorithms work efficiently, but also whether people affected by those systems have an opportunity to understand and challenge important decisions.

Uber plans to appeal

Uber has rejected the regulator's findings and described the penalty as disproportionate.

The company says the investigation concerns policies that were discontinued several years ago and argues that its current processes include human reviews and safeguards.

Uber also disputes the suggestion that drivers were permanently removed solely through automated processes.

The company said only 126 European drivers were permanently deactivated because of customer ratings in 2021 and maintained that permanent account closures were not carried out exclusively by automated systems.

Uber plans to appeal the decision.

The eventual legal outcome could therefore help clarify what regulators consider to be meaningful human involvement when companies use automated systems to make consequential decisions.

Why this matters beyond Uber

The dispute is part of a much wider conversation about algorithmic management.

Digital platforms increasingly rely on software to manage large workforces.

Ride-hailing companies use algorithms to allocate trips. Delivery platforms monitor cancellations and completion rates. Financial institutions use automated systems to detect suspicious transactions. Online marketplaces use software to identify potential fraud.

Automation allows these companies to operate at a scale that would be impossible with manual reviews alone.

The problem arises when automated systems make mistakes.

A human decision-maker can examine unusual circumstances, listen to an explanation and reconsider the available evidence. An algorithm may simply classify an activity as suspicious and automatically trigger a restriction.

That is why regulators are increasingly interested in transparency, accountability and the ability of individuals to challenge automated decisions.

What African tech companies can learn

The Uber case also has relevance for Africa's growing digital platform economy.

Ride-hailing, delivery and other technology-enabled services have become important sources of income across cities such as Lagos, Nairobi, Johannesburg and Accra.

These platforms increasingly rely on algorithms to determine access to customers, monitor activity and manage accounts.

The Dutch decision does not automatically apply GDPR requirements to every African technology company. However, it demonstrates the direction in which data protection and AI regulation is moving.

African startups using automated decision-making should therefore think beyond efficiency.

If an algorithm can suspend an account, freeze funds, reject a transaction or classify someone as fraudulent, companies need clear processes for reviewing mistakes and allowing affected users to challenge significant decisions.

Automation cannot replace accountability

The €825 million penalty sends a strong message to technology companies: automating a decision does not necessarily remove responsibility for its consequences.

As AI becomes increasingly involved in employment, financial services, insurance, fraud detection and customer management, questions about transparency and human oversight will become more difficult to ignore.

For Uber, the dispute is now headed toward an appeal.

For the wider technology industry, the case could become another important example of the limits regulators are placing on automated decision-making.

The central question is no longer simply what can an algorithm do?

It is increasingly becoming who is responsible when the algorithm gets it wrong?