Uber Hit with Nearly $1 Billion GDPR Fine Over Automated Account Suspensions
The Dutch Data Protection Authority has fined Uber 825 million euros (nearly $1 billion) for breaching the EU's General Data Protection Regulation (GDPR). The penalty stems from Uber's use of automated systems to suspend driver accounts, a practice regulators found to be non-compliant with data protection requirements.
While the case involves a global ride-hailing giant, it carries an important lesson for businesses of any size that use automated decision-making tools, whether for staff management, customer service, or account moderation. Regulators worldwide are increasingly scrutinising how organisations use automation involving personal data, particularly when those systems make decisions that significantly affect individuals without adequate human oversight or transparency.
Australian small businesses may not face GDPR directly unless they handle EU customer or worker data, but similar principles apply under the Australian Privacy Act. As automated tools such as AI-driven HR software, chatbots, and account management systems become more common, businesses should ensure these systems are transparent, fair, and reviewable by a person when they impact customers or staff.