ProductsIntelligenceLicensingAnalyst AccessPricingMethodologyContact
Cresthaven AnalyticsIntelligence Brief

France CNIL Data Protection & AI Brief

August 24, 2026·Commission nationale de l’informatique et des libertés (CNIL)·EU

Dutch DPA issues 825 million euro fine against Uber for automated individual decision-making violations under GDPR

The Dutch Data Protection Authority, working with the French CNIL, fined Uber B.V. and Uber Technologies Inc. €824,990,000 on August 24, 2026. The sanction concerns automated individual decisions made about drivers on the Uber platform.

A fine of 824,990,000 euros against Uber B.V. and Uber Technologies Inc. for automated individual decision-making establishes the highest known GDPR penalty on this legal basis and names both the EU entity and the U.S. parent as liable parties.

Platform operators using algorithmic systems to make consequential decisions about workers, whether on deactivation, earnings, or task assignment, face a demonstrated enforcement ceiling that now exceeds 800 million euros under the GDPR's automated decision-making framework.

The cross-border cooperation structure of this action, with the Dutch DPA as lead authority and the CNIL as cooperating authority, confirms that the one-stop-shop mechanism produces binding multi-jurisdictional outcomes that a single-entity or single-country compliance posture does not contain.

  • Largest GDPR Automated-Decision Fine on Record: The 824,990,000 euro penalty against Uber B.V. and Uber Technologies Inc. targets automated individual decision-making affecting platform workers. No prior GDPR enforcement action on this legal basis has reached this scale, establishing a new financial reference point for Article 22 exposure.
  • Platform Operators Face Direct Exposure: Any platform business using algorithmic systems to make consequential individual decisions about workers or contractors, such as deactivation, earnings adjustment, or task allocation, now operates against a demonstrated enforcement ceiling that exceeds 800 million euros.
  • Cross-Border GDPR Cooperation Mechanism Activated: The Dutch DPA acted as lead supervisory authority with the CNIL as cooperating authority, confirming that the one-stop-shop mechanism under GDPR produces binding cross-border outcomes. Firms with EU establishments in multiple member states cannot treat national DPA engagement as a containment strategy.
  • Gig Economy Worker Profiling Is the Target Category: The enforcement action centers on decisions made about drivers, placing algorithmic workforce management squarely within the GDPR's automated decision-making protections. Platforms relying on scoring, ranking, or deactivation algorithms for non-employee workers carry the same legal exposure as those managing employees.
  • Dual-Entity Structure Did Not Limit Liability: Both the Dutch operating entity and the U.S. parent, Uber Technologies Inc., are named respondents. Controllers structured across EU and non-EU entities cannot use corporate separation to limit the reach of a GDPR enforcement action.

- No prior GDPR enforcement action on automated decision-making grounds has produced a penalty at this scale. This represents a clear break from established enforcement practice under that legal basis.

- The action names both the EU operating entity and the U.S. parent as respondents, extending GDPR liability explicitly across the corporate group rather than confining it to the EU-established controller.

- Cooperation between the Dutch DPA and CNIL confirms the one-stop-shop mechanism as an active cross-border enforcement tool, consistent with the pattern of coordinated actions that followed the Irish DPA's Meta decisions from 2022 onward.

HIGH — A final enforcement decision of 824,990,000 euros naming both an EU operating entity and a U.S. parent, introducing the highest known GDPR penalty on the automated decision-making legal basis and establishing a precedent applicable to all platform operators using algorithmic workforce management across the EU.

Monitor the Dutch Data Protection Authority and CNIL for any published decision text, appeal filings by Uber, and follow-on enforcement signals targeting other platform operators using algorithmic workforce management systems.

GDPR Article 22 (automated individual decision-making); GDPR Article 56 (one-stop-shop mechanism); GDPR Article 83 (administrative fines); Dutch Data Protection Authority (Autoriteit Persoonsgegevens) enforcement decision against Uber B.V. and Uber Technologies Inc., August 24, 2026; CNIL cooperation under GDPR Chapter VII

www.cnil.fr — Source ↗

This is a sample intelligence brief from Cresthaven Analytics. Live subscribers receive briefs like this on a daily or weekly cadence depending on tier.