An Uber driver opens their app one morning. A short message: account suspended, no more rides, no more income. On the other end, no one to speak to, no name attached to the decision. An algorithm has read the driver's latest indicators, an algorithm has ruled, and a system has cut off access. Multiply this by several thousand cases, between 2018 and 2022, and you have the raw material behind the fine that the Dutch data protection authority made public on 21 August 2026, in cooperation with France's CNIL. The UK's Information Commissioner's Office (ICO) applies the same "meaningful human intervention" standard under UK GDPR Article 22, as set out in its published guidance on automated decision-making.
The headline number is 824,990,000 euros (roughly £705 million). The reasoning is more interesting than the number. This is not a security failure, this is not a leak, this is not a badly framed data transfer. This is Article 22 of the GDPR, the provision that forbids a decision producing significant effects on a person from being made solely by a machine, without meaningful human intervention.
A UK SME director who lets automation into daily operations, including on emails, has every interest in understanding exactly what this decision says, and above all what it does not say.
Quick answer: the 824,990,000 euro fine (~£705 million) imposed on Uber sanctions driver deactivations decided without meaningful human intervention, under Article 22 of the GDPR. For a UK SME, the line to hold does not run between manual and automated: it runs between assisting and deciding.
What the Dutch authority and the CNIL just said
The sanction was not imposed by the CNIL. Uber's main European establishment sits in the Netherlands, which makes the Autoriteit Persoonsgegevens (AP) the lead supervisory authority under the GDPR. The CNIL cooperated with the investigation, in particular because the original 2020 complaint came from 171 French drivers, backed by the Ligue des droits de l'Homme. The CNIL relayed the decision in a public statement on 24 August 2026. In the United Kingdom, UK GDPR retains its own Article 22 regime post-Brexit and applies the same standard of meaningful human intervention, as reflected in the ICO's published guidance.
The decision targets two distinct mechanisms. The first temporarily suspends a driver's account when the system suspects fraud. The second temporarily or permanently suspends the account when the customer rating falls below a threshold. In both cases, the authority notes that the algorithm's output produces an immediate effect on the driver, up to and including the loss of their means of earning a living, and that the path from signal to effect involves no meaningful human intervention at any point.
The important word is meaningful. The decision states that the human intervention required by Article 22 assumes an effective power to overturn the machine's output, actually exercised, and not a stamp placed on a result already produced. An operator who signs off by the mile, without looking, does not tick the box. A flow in which refusing costs too much to be done does not tick it either.
Uber has announced an appeal. The final legal qualification is therefore not settled. What is settled, however, is the reading adopted by the lead authority: the amount, the reasoning, and the definition of human intervention together form a signal, independent of the outcome of the appeal.
The real line isn't manual vs automated
The quick read of this case is that automation is becoming risky, and therefore should be abandoned. That would be a comfortable and wrong reading. Article 22 does not target automation: it targets a very precise category, namely a decision based solely on automated processing that produces legal effects or significantly affects the person in a similar way. The word solely does all the work.
The line to hold therefore lies elsewhere. It runs between two things that get conflated in boardroom conversations, ever since artificial intelligence began touching operational processes.
The split to write down in plain terms. Software that assists files, prioritises, summarises, drafts a reply, and waits for a human to look, decide, and click. Software that decides itself produces the effect on the person: it sends, it refuses, it deactivates, it closes a file. The first category is not caught by Article 22, provided the human validation is real. The second falls in as soon as the effect is significant.
This distinction is not a lawyer's trick. It is also what the user feels. A tool that proposes and waits keeps the initiative on their side; a tool that acts alone takes it away. The same gesture that reassures also keeps the human in the loop.
One point of honesty, though: this distinction alone does not push a case out of Article 22. It is necessary, not sufficient. The purpose of the processing, the nature of the effect, the information provided to the individuals concerned, and the redress available also count. The role of a blog post is not to rule in place of your counsel, it is to give you the right question to ask.
What an SME of 5 to 50 people should take from this
The most badly calibrated reading would be to conclude that this case is about platforms and not about your eighteen-person business. UK GDPR and EU GDPR both leave Article 22 untouched by any size threshold: the rule targets the processing, not the organisation that runs it. What changes in practice is the number of situations in which a UK-based SME produces purely automatic decisions that significantly affect a person.
Such situations exist. A CV screening tool that discards applications without any human reading a single one. A customer scoring engine that turns down a file without a salesperson ever opening the record. A standardised reply sent automatically to a complaint, without a manager seeing what the client asked for. None of these has the scale of the Uber case. The legal mechanism at stake, however, belongs to the same family.
A director's first job is therefore to write this list: what, in my business, today, produces an effect on a person without any human having looked? Seven or eight lines, most of the time. Once the list is written, each line is arbitrated calmly, with your counsel where the question is delicate. It is the opposite of the waiting posture that hopes the question will never come up.
What an AI email assistant is, and what it isn't
Email is one of the places where this distinction plays out concretely, because it is one of the places where automation is moving fast. An AI email assistant can read incoming messages, understand their context, file them, prioritise them, summarise them, prepare a draft reply. In some configurations it can also send directly. Both worlds exist, and they do not fall into the same category.
Neston sits explicitly in the first category. The assistant drafts a reply in about four seconds, in the user's own style and taking the recipient into account, then hands it to the human, who rereads, corrects if needed, and sends. Nothing goes out without that step. The tool runs on European hosting, and a Mistral option enables a full EU stack for organisations that require that framework. This architectural choice is also a direct response to what Article 22 says: what produces the effect on the recipient is the validated send, not the model's output. The wider framework of the topic is treated in our AI email and GDPR guide.
The human always validates before sending.
The AI email assistant embeds in Outlook, learns your writing style, prepares a reply in a few seconds, and hands it back to you so that you can reread and validate. Nothing goes out without you. 14-day free trial, no credit card.
Start free trial →Windows 10/11 · Outlook · Mistral EU option
What this fine does NOT change
It does not make automation illegal, it does not make any piece of software a risky object, and it does not exempt you from writing down what your tool does, for whom, with what data, and under whose human eye. It does not replace your hosting analysis, it does not replace your record of processing, it does not replace your solicitor. What it brings is more useful than a new rule: it re-reads an existing rule with a number that makes it audible. At 824,990,000 euros (roughly £705 million), Article 22 stops being an abstraction. It becomes a clause of the contract to write, and a line of daily operation to hold.
FAQ: automated decisions, Article 22 and SMEs
Further reading
- AI email and GDPR: the 2026 compliance guide, the general framework for data processing when a tool reads your emails
- Mistral and Outlook: the European stack for an AI email assistant, what changes when the model is hosted in Europe
- Email productivity on Outlook and Gmail: the method, the operational backdrop on a day-to-day basis
- AI text detectors and professional emails, what a recipient sees when an assistant has drafted the reply
🔬 Sources
- Autoriteit Persoonsgegevens, statement of 21 August 2026: 824,990,000 euro fine against Uber B.V. and Uber Technologies Inc. under Article 22 of the GDPR, for temporary deactivations on suspicion of fraud and temporary or permanent deactivations on low customer rating, decided without meaningful human intervention, on practices observed between 2018 and 2022.
- CNIL, statement relayed on 24 August 2026: cooperation of the CNIL as concerned authority, origin of the case in 2020 with a complaint from 171 French drivers backed by the Ligue des droits de l'Homme, European reach of the decision.
- Regulation (EU) 2016/679 of 27 April 2016, Article 22: "The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her."
- Information Commissioner's Office (ICO), guidance on automated decision-making and profiling: UK GDPR framework on Article 22, including the requirement for meaningful human intervention.
Article published 4 September 2026 · Reading time: 6 minutes · ≈ 1,320 words