Smartphone sul cruscotto di un auto di notte con simbolo di spegnimento

Immagine creata con IAAI-generated image

Automated deactivations and Article 22 of Regulation (EU) 2016/679: the fine imposed on Uber and the algorithmic management of work

In August 2026 the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), in cooperation with the French data protection authority (CNIL), imposed on Uber B.V. and Uber Technologies Inc. a fine of EUR 824,990,000 for having taken automated individual decisions in respect of the platform’s drivers (CNIL). It is the third fine arising from the same collective complaint, and the fourth imposed overall by the Dutch authority on the company, and it is today one of the highest ever imposed under the General Data Protection Regulation.

More than the amount, what matters is the subject of the finding, because it concerns the way in which numerous European organisations, well beyond transport platforms, manage work today.

What was penalised: deactivation without human intervention

The Dutch authority held that the temporary deactivation of a driver’s account in the event of suspected fraud, and the deactivation, first temporary and then permanent, in the event of low ratings from customers, constitute automated individual decisions. The reason for that qualification is a single one: the total absence of human intervention in the decision-making process. Those decisions, the authority observes, significantly affect the drivers, who, with their account blocked, can no longer carry out rides or earn an income.

It is therefore a case in which automation replaces, rather than supports, human assessment: no operator examines the system’s alert, and the alert alone determines the closure of the account. The company was also found to have failed to inform the drivers adequately of the existence of that automated decision-making process.

Article 22 of Regulation (EU) 2016/679: the scope of automated decision-making

The legal basis is Article 22 of Regulation (EU) 2016/679, which grants the data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her. The provision admits exceptions, among them the necessity for entering into or performing a contract and explicit consent, but in that case it imposes minimum safeguards: the right to obtain human intervention on the part of the controller, to express one’s point of view and to contest the decision.

Three elements of this case deserve to be isolated, because they recur wherever people are managed by means of software.

The first is that the relevant effect need not be legal in the strict sense. The deactivation of an account is not a dismissal, it is not an administrative measure, it does not formally alter any relationship: it does, however, affect the person similarly and significantly, because it removes the possibility of working. It is the material consequence that qualifies the decision, not its formal guise.

The second is that suspicion is not a finding. Deactivation for suspected fraud takes place before any verification, on an alert generated by the system, and its reversibility does not make it harmless: in the time that elapses between the block and any reactivation, the harm has already occurred.

The third is that an assessment expressed by third parties, such as the score assigned by customers, is not for that reason alone a neutral piece of data. Turned into an automatic threshold, it becomes the criterion for a decision on the continuation of the relationship, with the biases that customer ratings may incorporate, which is exactly the question we addressed when discussing algorithmic discrimination and scoring systems.

The proceedings: the collective complaint, the one-stop shop and the series of fines

The procedural path is as instructive as the merits. In 2020 the CNIL received a collective complaint from the association Ligue des droits de l’Homme, acting on behalf of more than 170 drivers of the platform, supplemented in 2021 and concerning the information provided to individuals, transfers of data outside the European Union and automated deactivations. Since Uber has its main establishment in the Netherlands, competence to investigate fell to the Dutch authority under the one-stop-shop mechanism, while the CNIL cooperated in the inspections, in the analysis of the evidence and in the examination of the draft decision.

The first two fines in the series concerned the other two aspects of the complaint: EUR 10 million on 11 December 2023 for shortcomings in the information provided to drivers, EUR 290 million on 22 July 2024 for transfers of data outside the Union. The conduct now penalised took place, according to the investigating authority, between 2018 and 2022, and has ceased. The Dutch authority notes that the company has lodged an appeal against the fine, and according to press reports Uber has described it as disproportionate: the proceedings are therefore not closed.

The implications for organisations other than platforms

It would be reductive to regard the case as a matter for transport platforms. The structure at issue, a threshold calculated by the system that on its own produces an effect on a person’s position, is extremely widespread and often invisible: the automatic screening of applications that excludes a profile before a recruiter sees it, the risk score that blocks a payment or suspends an account, the anti-fraud system that disables a user, the automatic assessment that determines the allocation of shifts or access to a bonus.

In Italy the rules are becoming stricter precisely on this point. Article 11 of Law No 132 of 23 September 2025 does not contain, contrary to what is often read, a prohibition on wholly automated decisions: it requires safe, reliable and transparent use, information to the worker and a prohibition on discrimination. The actual prohibition is entrusted to the implementing decree on authorities and training, which appears to have been approved but not yet published, and which, according to what has been announced, will prohibit decisions based solely on automated processing in matters of the establishment, modification and termination of the employment relationship and of disciplinary measures, with nullity of any dismissal adopted in breach; the draft decree, in the version that has circulated, adds the worker’s right to an intelligible statement of reasons. We addressed that design when writing about the Italian implementation of the AI Act. In the meantime, however, Article 22 of the European regulation already applies, and it is the basis on which this fine was built.

On the side of platform-mediated work, the direction is the same as we observed when commenting on International Labour Organization Convention No 193.

Critical aspects: human intervention between effective safeguard and formal compliance

The reading of this decision that is gaining ground is that it is enough to insert a person into the process to make it compliant. We consider this reading mistaken, for two reasons.

The first is that Article 22 requires meaningful human intervention, not a formal step. An operator who approves hundreds of alerts a day in bulk, without being able to access the elements on which the system relied and without any margin to depart from them, exercises no assessment at all, but merely validates. The result is a substantially automated decision, to which human intervention adds only a formal endorsement, which is exactly the situation the provision seeks to avoid, and which arises whenever human oversight is sized according to cost rather than risk.

The second is that human intervention, where it exists, typically focuses on the outcome and not on the criteria. The person called upon to check looks at the individual case, not at the threshold that generated it, nor at the distribution of outcomes across thousands of cases. If the threshold is poorly calibrated, or if the score feeding it reflects customer bias, the reviewer is in no position to detect this, because they examine the individual case and not the body of results. The effective safeguard, in systems of this kind, lies upstream, in the definition of the criterion and in the periodic measurement of its effects, and this is the reason why the “data governance” of Article 10 of the AI Act and the human oversight of Article 14 must be read as organisational obligations and not as documentary formalities.

There is, finally, an aspect that this case brings out with particular clarity. The right to contest the decision, guaranteed by Article 22, presupposes that the data subject knows that an automated decision has been taken and on what it was based. If the information is lacking, as was found in this case, the safeguard remains ineffective, because the data subject cannot contest a decision of whose existence they are unaware. It is the same knot that resurfaces, in another form, when one asks who is answerable for actions carried out autonomously by a system, as we observed in relation to artificial intelligence agents.

Conclusions

The fine does not penalise the use of an algorithm to detect fraud or measure customer satisfaction, which remain lawful activities. It penalises having derived from that calculation, automatically and without anyone intervening, a consequence that deprives a person of the possibility of working, and having failed to inform the drivers. For those in Italy who manage staff, contractors or suppliers with the assistance of automated systems, the check to be carried out concerns not the technology but the organisation: identifying the points at which a calculated value on its own produces an effect on a person, establishing who can stop it and with what information, and ensuring that the data subject knows that the mechanism exists. There is no need to wait for the implementing decree: Article 22 of the European regulation has applied for eight years.

Author: Valentina Grazia Sapuppo


AI AnthropoCosmic In evidenzaAI AnthropoCosmicUn progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo, che mette al centro la dignità della persona nella progettazione dei sistemi. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicAn international project for an AI at the service of humanity, the environment and the cosmos, placing human dignity at the centre of system design. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article
Intervista Radio Radio IntervistaLegge e colossi del digitaleIl patteggiamento di Meta sui minori non è una condanna. Stati Uniti ed Europa seguono strade opposte, e sugli agenti di IA resta aperta la domanda su chi risponde.Un Giorno Speciale su Radio Radio, con Alessio De Paolis · audio dal minuto 2:26:00Ascolta l’intervistaGuarda il videoLeggi l’articolo
Digital Omnibus ContributoIl Digital Omnibus cambia l’AI ActNuove scadenze per i sistemi ad alto rischio e un chiarimento sull’obbligo di AI literacy: più tempo per adeguarsi, nessuno sconto sulla preparazione di persone e processi.Articolo scritto per il blog di SkillaLeggi su Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo tra i relatori del festival dedicato a protezione dei dati, archivi digitali e regole del futuro. Interviene sul tema «Le regole dell’IA: nuove leggi o principi del diritto?».Venerdì 6 novembre 2026, ore 16:30, Ex Convitto Palmieri, LecceL’interventoLa scheda relatriceIl festival
AI AnthropoCosmic 2026Moderatrice e relatriceAI AnthropoCosmic 2026Valentina Grazia Sapuppo nel progetto dell’Università Pontificia Salesiana su Persona, Ambiente e Cosmo: moderazione della sessione mattutina del Convegno finale e intervento negli AI Laboratori del Domani su commercio elettronico e IA.14 novembre 2026, online · 28 novembre 2026, Università Pontificia Salesiana, RomaIl convegnoL’incontroIl contributoLa relatriceIl progetto
Interview Radio Radio InterviewLaw and the digital giantsThe Meta settlement on minors is not a conviction. The United States and Europe take opposite paths, and on AI agents the question of who answers remains open.Un Giorno Speciale on Radio Radio, with Alessio De Paolis · audio from 2:26:00 · in ItalianListen to the interviewWatch the videoRead the article
Digital Omnibus ContributionThe Digital Omnibus reshapes the AI ActNew deadlines for high-risk systems and a clarification on the AI literacy duty: more time to comply, no discount on preparing people and processes.Article written for the Skilla blog, in ItalianRead on Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo among the speakers of the festival on data protection, digital archives and the rules of the future. She takes part in the panel «The rules of AI: new laws or principles of law?».Friday 6 November 2026, 16:30, Ex Convitto Palmieri, LecceThe panelSpeaker profileThe festival
AI AnthropoCosmic 2026Moderator and speakerAI AnthropoCosmic 2026Valentina Grazia Sapuppo in the project of the Università Pontificia Salesiana on Person, Environment and Cosmos: moderator of the morning session of the closing conference and speaker at the AI Laboratori del Domani on e-commerce and AI.14 November 2026, online · 28 November 2026, Università Pontificia Salesiana, Rome · sessions held in ItalianThe conferenceThe sessionThe contributionSpeakerThe project