The Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, has fined Uber €824,990,000 after finding that the company relied on fully automated decision-making processes to decide on the deactivation of their drivers’ accounts. This is the fourth fine issued by the AP against Uber, and the largest issued to date from the authority.
The AP’s Findings
Uber used software to monitor its drivers’ driving behaviour, and also their customer reviews. When a suspicion of fraud was detected, or customer ratings were too low, the driver's account was automatically deactivated, either temporarily or permanently.
From the AP’s investigation, it was found that the final decision over the drivers’ account deactivation was a fully automated decision-making process, with no human intervention or review at any point of the process. Also, drivers were never adequately informed.
A fully automated decision that clearly entails major consequences for the drivers, whose income from Uber was lost.
Therefore, the AP based its decision on two main findings:
- Violation of Art. 22 para. 1 GDPR, that prohibits fully automated decision making, in particular when the automated process decides on something with a major and real economic impact and consequence on data subjects, as in this case, with the loss of a source of income.
- Failure to properly inform the drivers that they were subject to this automated decision-making process, about how the process worked and the impact and relevance of the envisaged consequences of that processing.
GDPR’s Prohibition on Automated Decision-Making Processes
Art. 22 para. 1 GDPR clearly gives data subjects “the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her”.
The loss of a source of income due to a fully automated decision, without the presence of a human assessment anywhere along the process, is a precise example of the kind of consequence targeted by the GDPR. Exceptions are provided in Art. 22 GDPR (in particular: contractual necessity, authorized by EU or member state law, or consent) but none are applicable in this case.
On the specific legal reasoning used by Uber in its defence, we may learn more once the full decision is published, which hasn’t happened yet.
Why This Matters
This decision confirms a strict approach by many data protection authorities in Europe on the topic of Art 22 GDPR application.
Companies do not have to read this as a no-go for automated decision-making processes, but as an opportunity to understand the limits and requirements of similar processing activities.
The absence of a “human in the loop” approach will always, regardless of the sector, be the tipping point, together with an appropriate information to data subjects, in particular when the output of the decision-making process affects people’s contracts incomes or access to a service.
When a company is evaluating the implementation of an automated decision-making process, or has doubts about an already existing one, always involve your DPO or privacy counsel to assess it and set up the necessary legal and practical requirements.
No comments