[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fEPGkCt4Gwsl2Npz07cVGFdN2MQRrMo0J1KWaXU9J7Iw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"8266dd4b-ee4d-442f-884a-ad766ed2c3b8","uber-fined-290m-for-gdpr-violations-in-automated-driver-deactivations","d1b54a40-daec-4756-a600-dd8dd09920da","Uber Fined €290M for GDPR Violations in Automated Driver Deactivations","Uber's automated account deactivation system removed drivers' livelihoods without human review, directly violating GDPR Article 22, which grants individuals the right not to be subject to solely automated decisions that significantly affect them. The lack of transparency meant drivers had no meaningful explanation of why they were deactivated or how to contest the decision. This case highlights that algorithmic decision-making systems touching personal data must be designed with legal compliance, explainability, and human oversight built in from the start — not retrofitted after regulatory scrutiny. The scale of the fine underscores that regulators are increasingly focused on AI and automation as a data rights battleground.","**Immediate Actions:**\n- Audit all automated decision-making systems that affect individuals (employees, contractors, customers) to identify those requiring GDPR Article 22 compliance.\n- Implement a mandatory human review checkpoint for any automated decision that restricts account access or impacts income.\n\n**Long-term Improvements:**\n- Embed explainability and transparency requirements into the design of all algorithmic and AI-driven systems that process personal data.\n- Establish a formal Data Protection Impact Assessment (DPIA) process for any new or modified automated decision system before deployment.\n- Create and publish clear, accessible appeals and redress procedures for individuals affected by automated decisions.\n\n**Governance & Monitoring:**\n- Assign a qualified Data Protection Officer (DPO) with authority to review and veto non-compliant automated systems.\n- Implement ongoing compliance monitoring and internal audits of automated decision pipelines to detect regulatory drift over time.",[12,13,14,15,16,17,18,19],"GDPR Article 22 (Automated individual decision-making)","GDPR Article 13 & 14 (Transparency and information obligations)","GDPR Article 35 (Data Protection Impact Assessment)","NIST AI RMF – GOVERN 1.1 (Accountability for AI decisions)","NIST SP 800-53 AC-2 (Account Management)","CIS Control 3 (Data Protection)","ISO\u002FIEC 27001 A.18.1 (Compliance with legal and contractual requirements)","ITIL Service Design – Compliance and Risk Management","published","2026-08-26T10:21:09.213348+00:00","2026-08-26T10:21:09.131+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AP_(The_Netherlands)_-_Uber_B.V_and_Uber_Technologies_Inc.&diff=52799&oldid=52798","ap-the-netherlands-uber-b-v-and-uber-technologies-inc-b9fab6","AP (The Netherlands) - Uber B.V and Uber Technologies Inc.",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":41,"name":42,"slug":43,"description":44,"color":45},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]