A Dutch regulator just put a number on what it costs to let an algorithm manage people without a human in the loop, and the number is 825 million euros. The fine against Uber is not really a story about one company’s software. It is the clearest signal yet that automated personnel decisions, the kind of hire, discipline, and terminate calls that HR tech vendors have spent a decade selling as efficiency gains, now carry regulatory exposure on the scale of the largest privacy penalties ever issued.

What the AP found

The Autoriteit Persoonsgegevens, the Dutch data protection authority, fined Uber 824,990,000 euros after ruling that the company made fully automated decisions about its drivers in violation of the GDPR’s ban on decisions with significant consequences that involve no human being. Between 2018 and 2022, Uber used software to track drivers’ behavior and customer ratings. When that software detected a suspicion of fraud or persistently low ratings, it temporarily or permanently deactivated the driver’s account, cutting off their income through the platform, with no person reviewing the call first. The AP also found Uber failed to adequately inform drivers that automated systems were making these decisions about them.

“Uber has committed serious infringements,” said Monique Verdier, deputy chair of the AP. “Drivers were deactivated without pardon. From one moment to the next, they no longer had any income through Uber. That’s forbidden. A computer should not make decisions on its own that have major consequences for you. These decisions should have been looked at first by a human being.”

Advertisement

HRTech Your brand belongs here. Reach the decision-makers who read HRTech every day. Premium placements across the site and newsletter. Advertise with us

The investigation began when 171 French drivers complained to the Ligue des droits de l’Homme, a French human rights organization, which took the case to France’s privacy regulator, CNIL. Because Uber’s European headquarters sits in the Netherlands, the case moved to the AP under the GDPR’s one-stop-shop mechanism, with the AP coordinating closely with CNIL and aligning its decision with other European regulators. Uber has stopped the practice and has filed an appeal disputing the ruling. It is the fourth fine the AP has levied against Uber, following penalties of 600,000 euros in 2018, 10 million euros in 2023, and 290 million euros in 2024, the latter two still under separate appeal. At 825 million euros, it ranks as the second-largest GDPR fine ever issued, trailing only the 1.2 billion euro penalty Ireland’s regulator imposed on Meta in 2023. Fines under the GDPR are capped at 4% of a company’s global annual turnover; Uber reported roughly 44.5 billion euros in global turnover in 2025.

The shift this signals for HR tech

Uber’s driver accounts are not employment relationships in the traditional sense, and that distinction has mattered enormously in prior gig economy litigation. It does not matter here. The GDPR’s Article 22 restriction on automated decision-making applies to any decision with legal or similarly significant effects on a person, and cutting off someone’s income qualifies regardless of their employment classification. That is the detail HR technology buyers should sit with: the same legal reasoning applies just as directly to an HRIS that auto-flags an employee for termination based on a performance score, an applicant tracking system that auto-rejects candidates without human review, or an AI monitoring tool that auto-escalates a disciplinary case. None of those tools are hypothetical. Vendors across recruiting, performance management, and workforce monitoring have built and marketed exactly this kind of automation, often explicitly on the promise that it removes human bottlenecks from decisions.

The AP’s ruling draws a specific, replicable line: automation is fine for flagging and surfacing information, but a human has to make the final call on anything with major consequences for a worker, and the organization has to tell people that automated systems are involved in the process at all. Both requirements sound modest in the abstract and are routinely skipped in practice, because “human in the loop” is often implemented as a rubber stamp rather than genuine review, and disclosure of automated decision-making is rarely built into onboarding or policy documents with any specificity.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

What it means for the HR leader

Any HR leader who has approved an AI tool that screens, scores, disciplines, or terminates without a documented human review step should treat this fine as the cost of that gap made concrete. The exposure is not limited to companies with EU operations in the narrow sense either: the GDPR’s one-stop-shop mechanism means a single national regulator can act on behalf of the whole bloc, and any organization processing the personal data of EU-based workers or contractors, including remote hires, falls under the same rules regardless of where its headquarters sits. This coverage has already tracked a parallel liability front opening in the U.S., where AI notetaking tools have drawn direct lawsuits over recording without consent, and where courts are increasingly willing to let workplace AI claims proceed rather than dismissing them as novel. The throughline across both fronts is the same: regulators and courts are no longer treating “the AI did it” as a defense, and vendors marketing automation as a way to remove human judgment from consequential decisions are selling their customers a liability, not just a feature.

The practical fix is not complicated, even if the compliance program to prove it is. Every automated system touching hiring, performance, discipline, or pay needs a documented point where a human with real authority to overturn the algorithm reviews the outcome before it takes effect, and workers need to be told, in plain language, when an automated system is involved in a decision about them. Employers that can produce that documentation walk away from this story with a checklist. Employers that cannot are looking at the same math the AP just did to Uber, just waiting for their own regulator or plaintiff’s attorney to run it.

See also: Courts Are Writing HR AI’s Rulebook Now and AI Notetakers Now Face Direct Legal Liability.

Source: Autoriteit Persoonsgegevens