Security News

Uber Hit with Nearly $1 Billion GDPR Fine Over Automated Account Suspensions

Security Week · 24 Aug 2026
Key Takeaway Before deploying automated decision-making tools, ensure a human can review and explain any significant outcome affecting customers or employees.

The Dutch Data Protection Authority has fined Uber 825 million euros (nearly $1 billion) for breaching the EU's General Data Protection Regulation (GDPR). The penalty stems from Uber's use of automated systems to suspend driver accounts, a practice regulators found to be non-compliant with data protection requirements.

While the case involves a global ride-hailing giant, it carries an important lesson for businesses of any size that use automated decision-making tools, whether for staff management, customer service, or account moderation. Regulators worldwide are increasingly scrutinising how organisations use automation involving personal data, particularly when those systems make decisions that significantly affect individuals without adequate human oversight or transparency.

Australian small businesses may not face GDPR directly unless they handle EU customer or worker data, but similar principles apply under the Australian Privacy Act. As automated tools such as AI-driven HR software, chatbots, and account management systems become more common, businesses should ensure these systems are transparent, fair, and reviewable by a person when they impact customers or staff.

GDPR Data Privacy Automation Regulatory Fine Uber

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.