The Dutch Data Protection Authority (AP) fined Uber €825 million ($966 million) for violating Europe’s General Data Protection Regulation (GDPR).

This penalty represents the second-largest fine ever issued under GDPR.

The regulator found Uber used automated systems to deactivate driver accounts without sufficient human oversight between 2020 and 2022.

These algorithmic decisions resulted in temporary suspensions for suspected fraud without providing drivers a way to challenge the actions.

The AP led the investigation because Uber maintains its European headquarters in the Netherlands.

The case originated from a complaint filed by drivers in France.

Uber plans to appeal the decision and labeled the fine disproportionate.

The company stated its current policies now include human reviews for all permanent deactivation decisions.