⚖️ Regulatory

Automated Decisions in Business: What the Uber Fine Means for an SME

An Uber driver opens their app one morning. A short message: account suspended, no more rides, no more income. On the other end, no one to speak to, no name attached to the decision. An algorithm has read the driver's latest indicators, an algorithm has ruled, and a system has cut off access. Multiply this by several thousand cases, between 2018 and 2022, and you have the raw material behind the fine that the Dutch data protection authority made public on 21 August 2026, in cooperation with France's CNIL. The UK's Information Commissioner's Office (ICO) applies the same "meaningful human intervention" standard under UK GDPR Article 22, as set out in its published guidance on automated decision-making.

The headline number is 824,990,000 euros (roughly £705 million). The reasoning is more interesting than the number. This is not a security failure, this is not a leak, this is not a badly framed data transfer. This is Article 22 of the GDPR, the provision that forbids a decision producing significant effects on a person from being made solely by a machine, without meaningful human intervention.

A UK SME director who lets automation into daily operations, including on emails, has every interest in understanding exactly what this decision says, and above all what it does not say.

Quick answer: the 824,990,000 euro fine (~£705 million) imposed on Uber sanctions driver deactivations decided without meaningful human intervention, under Article 22 of the GDPR. For a UK SME, the line to hold does not run between manual and automated: it runs between assisting and deciding.

What the Dutch authority and the CNIL just said

The sanction was not imposed by the CNIL. Uber's main European establishment sits in the Netherlands, which makes the Autoriteit Persoonsgegevens (AP) the lead supervisory authority under the GDPR. The CNIL cooperated with the investigation, in particular because the original 2020 complaint came from 171 French drivers, backed by the Ligue des droits de l'Homme. The CNIL relayed the decision in a public statement on 24 August 2026. In the United Kingdom, UK GDPR retains its own Article 22 regime post-Brexit and applies the same standard of meaningful human intervention, as reflected in the ICO's published guidance.

The decision targets two distinct mechanisms. The first temporarily suspends a driver's account when the system suspects fraud. The second temporarily or permanently suspends the account when the customer rating falls below a threshold. In both cases, the authority notes that the algorithm's output produces an immediate effect on the driver, up to and including the loss of their means of earning a living, and that the path from signal to effect involves no meaningful human intervention at any point.

The important word is meaningful. The decision states that the human intervention required by Article 22 assumes an effective power to overturn the machine's output, actually exercised, and not a stamp placed on a result already produced. An operator who signs off by the mile, without looking, does not tick the box. A flow in which refusing costs too much to be done does not tick it either.

Uber has announced an appeal. The final legal qualification is therefore not settled. What is settled, however, is the reading adopted by the lead authority: the amount, the reasoning, and the definition of human intervention together form a signal, independent of the outcome of the appeal.

The real line isn't manual vs automated

The quick read of this case is that automation is becoming risky, and therefore should be abandoned. That would be a comfortable and wrong reading. Article 22 does not target automation: it targets a very precise category, namely a decision based solely on automated processing that produces legal effects or significantly affects the person in a similar way. The word solely does all the work.

The line to hold therefore lies elsewhere. It runs between two things that get conflated in boardroom conversations, ever since artificial intelligence began touching operational processes.

The split to write down in plain terms. Software that assists files, prioritises, summarises, drafts a reply, and waits for a human to look, decide, and click. Software that decides itself produces the effect on the person: it sends, it refuses, it deactivates, it closes a file. The first category is not caught by Article 22, provided the human validation is real. The second falls in as soon as the effect is significant.

This distinction is not a lawyer's trick. It is also what the user feels. A tool that proposes and waits keeps the initiative on their side; a tool that acts alone takes it away. The same gesture that reassures also keeps the human in the loop.

One point of honesty, though: this distinction alone does not push a case out of Article 22. It is necessary, not sufficient. The purpose of the processing, the nature of the effect, the information provided to the individuals concerned, and the redress available also count. The role of a blog post is not to rule in place of your counsel, it is to give you the right question to ask.

What an SME of 5 to 50 people should take from this

The most badly calibrated reading would be to conclude that this case is about platforms and not about your eighteen-person business. UK GDPR and EU GDPR both leave Article 22 untouched by any size threshold: the rule targets the processing, not the organisation that runs it. What changes in practice is the number of situations in which a UK-based SME produces purely automatic decisions that significantly affect a person.

Such situations exist. A CV screening tool that discards applications without any human reading a single one. A customer scoring engine that turns down a file without a salesperson ever opening the record. A standardised reply sent automatically to a complaint, without a manager seeing what the client asked for. None of these has the scale of the Uber case. The legal mechanism at stake, however, belongs to the same family.

A director's first job is therefore to write this list: what, in my business, today, produces an effect on a person without any human having looked? Seven or eight lines, most of the time. Once the list is written, each line is arbitrated calmly, with your counsel where the question is delicate. It is the opposite of the waiting posture that hopes the question will never come up.

What an AI email assistant is, and what it isn't

Email is one of the places where this distinction plays out concretely, because it is one of the places where automation is moving fast. An AI email assistant can read incoming messages, understand their context, file them, prioritise them, summarise them, prepare a draft reply. In some configurations it can also send directly. Both worlds exist, and they do not fall into the same category.

Neston sits explicitly in the first category. The assistant drafts a reply in about four seconds, in the user's own style and taking the recipient into account, then hands it to the human, who rereads, corrects if needed, and sends. Nothing goes out without that step. The tool runs on European hosting, and a Mistral option enables a full EU stack for organisations that require that framework. This architectural choice is also a direct response to what Article 22 says: what produces the effect on the recipient is the validated send, not the model's output. The wider framework of the topic is treated in our AI email and GDPR guide.

The human always validates before sending.

The AI email assistant embeds in Outlook, learns your writing style, prepares a reply in a few seconds, and hands it back to you so that you can reread and validate. Nothing goes out without you. 14-day free trial, no credit card.

Start free trial →

Windows 10/11 · Outlook · Mistral EU option

What this fine does NOT change

It does not make automation illegal, it does not make any piece of software a risky object, and it does not exempt you from writing down what your tool does, for whom, with what data, and under whose human eye. It does not replace your hosting analysis, it does not replace your record of processing, it does not replace your solicitor. What it brings is more useful than a new rule: it re-reads an existing rule with a number that makes it audible. At 824,990,000 euros (roughly £705 million), Article 22 stops being an abstraction. It becomes a clause of the contract to write, and a line of daily operation to hold.

FAQ: automated decisions, Article 22 and SMEs

Is automatic email sorting an automated decision under Article 22 of the GDPR?
Not on its own. Article 22 targets a decision based solely on automated processing that produces legal effects or significantly affects a person. Filing an email in a folder, giving it a priority, or preparing a draft reply does not have that effect, provided nothing is sent or concluded without a human having seen, decided, and validated. What tips the situation into scope is the production of an effect on a person without any human look.
What counts as meaningful human intervention rather than a rubber-stamp validation?
The Dutch authority states in its decision that this requires an effective power to overturn the machine's output, actually exercised, and not a stamp placed on a result already produced. In practice, the person who validates must see the proposal, understand what produced it, and be able to change or refuse it at no cost. A flow in which no one looks at anything, or in which refusing is too costly to do, does not tick this box. UK GDPR Article 22 uses the same standard.
Is an SME of fewer than 50 people affected the same way as a large platform?
Neither UK GDPR nor EU GDPR sets a size threshold for Article 22. The rule targets the processing, not the organisation that runs it. What changes in practice is the number of situations in which a UK SME of 5 to 50 people actually produces purely automatic decisions that significantly affect a person. Such cases exist, in recruitment, in file scoring, or in standard replies sent without a second look, and a director has every interest in writing that list down.
What should a director watch when deploying an AI email assistant in their business?
Three points, in order. What the tool decides on its own, if it decides anything on its own. What the human actually sees before validating, and how much time they have to do it. What the contract says about the data processed, the location where it is hosted, and the use made of it. An assistant that proposes and waits for a validation falls into one category; a device that sends, refuses, or files without any look falls into another. The difference is not cosmetic.

Further reading

Reading note. The elements cited here come exclusively from the Autoriteit Persoonsgegevens statement of 21 August 2026, the CNIL statement of 24 August 2026, and the text of Article 22 of Regulation (EU) 2016/679, in their state as of the writing date. They inform on a decision and on a text; they do not constitute a legal opinion, a compliance guarantee, or a response to any specific situation. Uber has announced an appeal: the final legal qualification is not settled. For an individual situation, contact your solicitor.
YB
Yvan Bosser
Founder of Neston · Former founder of Comptasanté (exit IK Partners 2023)
Yvan builds Neston, the AI email assistant embedded in Outlook, based on his own experience as an executive. Contact: yvan@neston.fr · LinkedIn.

🔬 Sources

Article published 4 September 2026 · Reading time: 6 minutes · ≈ 1,320 words