The drivers never met the thing that ended their work. On a suspicion of fraud, or customer ratings judged persistently low, the Dutch data protection authority found, Uber's systems deactivated driver accounts automatically, and where low ratings persisted, permanently. The authority, the Autoriteit Persoonsgegevens, has now priced that design at 824,990,000 euro.

The authority's findings are short enough to fit in a sentence each. Uber made fully automated decisions about its drivers. It did not sufficiently inform them that a machine was deciding. The first is Article 22 of the GDPR, which bars leaving a decision with this kind of effect on a person to software alone. The second is Article 13: tell people what is being done with their information. The rule was seven years old before the fine arrived. The decision was confirmed on 21 August 2026; Uber has appealed, and no court has ruled.

The Uber decision reached the European Data Protection Board's public pages on 8 October. A day later the Board listed three more, all from Italy's Garante per la protezione dei dati personali, and read together the four make a tour of the ordinary ways a data duty fails inside a working company.

Start with the one that followed people for a quarter of a century. IQVIA Solutions Italy held health records on one million patients of 800 family doctors, each patient carrying a code that allowed them to be followed over time. The Garante held the data were not anonymous at all: set beside year of birth, sex, diagnoses, prescriptions, vaccinations and location data, the code let individual patients be singled out and re-identified by reasonably available means. The records reached back to 2001 with no retention period ever defined, no impact assessment had been run, and the security around it was found inadequate. The fine, by decision number 710 of 23 September 2026, is 7,000,000 euro.

Then the refusal that one system heard and another ignored. A customer of Banco Bilbao Vizcaya Argentaria's Italian branch turned off commercial messages in the bank's app and said no again to customer service. The marketing ran on for seven more months, October 2025 to May 2026, because the recorded refusal never reached the platform doing the sending. The bank called it a technical fault. The Garante fined it 5,508,000 euro anyway, by injunction number 613 of 3 September 2026, and the holding is the part worth keeping: a customer's no, recorded in one system, is not enough if the organisation cannot guarantee every other system obeys it.

The smallest of the four may be the easiest to recognise from inside any business. Passengers with disabilities or reduced mobility had to complete Emirates' medical information form before assistance was given. The privacy notice that was supposed to explain what happened to those forms, on the website and from assistance staff, was found not sufficiently clear and complete, and the health data on them was kept for seven years, longer than the Garante held strictly necessary. The decision of 14 May 2026 cost the airline 180,000 euro, under Articles 5(1)(a), 5(1)(e), 12 and 13.

Add it up and the four decisions come to 837,678,000 euro, across a ride platform, a health data company, a bank and an airline. What they share is the age of the rules they broke: Articles 5, 12, 13, 21 and 22 have all been in force since 25 May 2018.

Which leaves a question worth asking out loud. Each of these companies has a compliance department. If that department had been running a system holding every obligation that applies, written down and on record, would the mistake its authority describes have been there to find? The published decisions say what was done, not what anyone knew.

There is an irony in the largest of the four. ComplianceSME's GDPR system is free, and one person at Uber running it today would have the automated-decision duty in front of them: its own section, in the regulation's own words, documented and dated.

Nor is the question reserved for companies with 824 million euro to lose. A firm of thirty people selling software into Germany and Ireland from a base in Manchester carries Article 22 just as Uber does, under both the EU GDPR and the UK GDPR, and the free system covers both, section by section.

What costs a small company its week is hunting for the answer it already found once. Compliance Complete puts every obligation that applies, with its document and its date, under one account.

More from ComplianceSME

Every claim and its source

Four national enforcement decisions listed on 8 and 9 October 2026: European Data Protection Board, national news pages, read 10 October 2026. The Uber decision at 824,990,000 euro, the finding of fully automated decisions on drivers with temporary and permanent deactivation on fraud suspicion or low customer ratings, the finding of insufficient information to drivers, Articles 22 and 13, and the appeal with no final judicial decision: Autoriteit Persoonsgegevens announcement, confirmed 21 August 2026; European Data Protection Board national news item of 8 October 2026. The IQVIA Solutions Italy fine of 7,000,000 euro, decision number 710 of 23 September 2026, the one million patients of 800 general practitioners, the patient code permitting tracking over time, the data fields listed, the finding that the data were not anonymous and could be re-identified by reasonably available means, the absent legal basis, the inadequate information to patients, the undefined retention period for data reaching back to 2001, the absent impact assessment and the inadequate security measures: Garante per la protezione dei dati personali press release of 2 October 2026. The Banco Bilbao Vizcaya Argentaria Italian branch fine of 5,508,000 euro, injunction number 613 of 3 September 2026, the seven months of commercial messages from October 2025 to May 2026 after the refusal, the refusal recorded in one system and not reaching the sending platform, the technical fault, Articles 5(1)(a), 12, 21 and 24, and the holding on applying a refusal across all systems: Garante ordinanza ingiunzione number 613 of 3 September 2026; Garante newsletter number 551 of 11 September 2026. The Emirates fine of 180,000 euro, the decision of 14 May 2026, the medical information form required before assistance, the notice held not sufficiently clear and complete on the website and from assistance staff, the seven-year retention held longer than strictly necessary, and Articles 5(1)(a), 5(1)(e), 12 and 13: Garante decision of 14 May 2026; Garante newsletter number 548 of 17 June 2026. The 25 May 2018 application date of Regulation (EU) 2016/679 and the content of Articles 5, 12, 13, 21 and 22: Regulation (EU) 2016/679 as in force. The total of 837,678,000 euro is the sum of the four fines as each authority states them. Every figure above was read at the publishing authority on 10 October 2026, and no figure in this article is taken from any report of those decisions.