A Computer Decided, and Nobody Checked
The Netherlands' data protection authority just issued Uber the second-largest GDPR fine ever recorded: €825 million, for automated software that suspended and permanently deactivated driver accounts between 2018 and 2022 based on suspected fraud patterns or persistently low customer ratings — with no human review built into the process. The case originated with 171 French drivers who filed the original complaint; the regulator's investigation identified 126 permanent deactivations across Europe in 2021 alone. Uber is appealing.
The regulator's deputy chair, Monique Verdier, put the underlying principle plainly: "A computer should not make decisions on its own that have major consequences for you." That's not a novel legal theory — GDPR has required meaningful human oversight of significant automated decisions since 2018. What's notable is that it took eight years and a nine-figure fine to make a platform the size of Uber actually build that oversight in.
The Ruling Is a Floor, Not a Ceiling — and It Only Covers Europe
Here's what I think gets lost in coverage that treats this as a story about Uber getting punished: the ruling establishes a specific, enforceable standard — meaningful human review before an automated decision that costs someone their livelihood — and that standard exists precisely nowhere outside jurisdictions with GDPR-equivalent enforcement. Uber, Bolt, inDrive, and Yango all operate extensively across African cities, frequently using comparable algorithmic systems to score drivers, flag "suspicious" behavior, and deactivate accounts. None of those markets have a data protection authority positioned to extract a €825 million fine, and none have GDPR's Article 22-style right to meaningful human review of automated decisions written into enforceable law with real penalties attached.
That's not a hypothetical gap. It's the same system, the same failure mode, and functionally zero recourse for the driver on the other end of it. A driver deactivated by algorithm in Lagos or Nairobi today has, in practice, far less standing to contest that decision than a driver in Amsterdam did even before this ruling forced Uber to change anything.
Why This Should Be Treated as a Policy Template, Not Just a Headline
The useful part of this ruling, for African regulators specifically, isn't the fine amount — it's the specificity of what triggered it: automated decisions with material economic consequences, made without adequate disclosure that they were automated, and without a human review path before the consequence lands. That's a concrete, exportable standard, not an abstract principle about "responsible AI." Countries developing data protection frameworks — South Africa's POPIA already has some automated-decision provisions, and other national AI and data policies are still being drafted — have a real, tested template sitting in front of them, backed by a regulator's actual enforcement reasoning rather than theory.
What It Means for You
If you're building or operating any platform that uses algorithmic scoring to make account-level decisions — deactivation, demonetization, access restriction — the Dutch ruling is a preview of where enforcement is heading even in markets that don't have GDPR yet: disclosure that a decision was automated, and a genuine human review path before the consequence is final, are moving from best practice to legal requirement. Building that review step in now is cheaper than retrofitting it after a regulator or a lawsuit forces the issue, and the "computer decided" defense is now demonstrably a losing one, not just a bad look.