Automated Decision-Making in Canada: What Uber's €825M Fine Means for Your Business
By Laith Sarhan
Data Protection & Cybersecurity Product Counsel
On August 21, 2026, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, or AP) confirmed it had fined Uber €825 million — roughly US$966 million, or about C$1.3 billion — for deactivating drivers' accounts through automated systems without meaningful human review, and without telling drivers the decisions were automated. The decision, dated August 17 and first reported by Reuters, is the second-largest GDPR fine ever issued, behind only Ireland's €1.2 billion Meta decision in 2023. It works out to a reported ~1.85% of Uber's 2025 worldwide turnover — nearly half the 4% statutory maximum.
This is not a data breach fine. No data was leaked, hacked, or sold. The AP's position is that the decision-making process itself was illegal: software decided, with no human genuinely in the loop, when a driver stopped earning income. GDPR Article 22 prohibits decisions based solely on automated processing that produce legal or similarly significant effects, unless narrow exceptions apply — and even then, the individual must get human intervention, a chance to express their point of view, and a way to contest the decision. Uber's human "review," the regulator found, didn't meet that standard, and drivers were never adequately informed any of it was happening. Uber says it "fundamentally disagrees," calls the fine disproportionate, and will appeal.
If you run a Canadian business and you've read this far thinking "that's a European problem," the rest of this article is for you. The same legal logic is already on our books — binding in Quebec today, and coming federally in Bill C-36.
What the Dutch Regulator Actually Found
The decision covers conduct from 2020 to 2022. Uber temporarily suspended drivers suspected of fraud — for example, taking unnecessary detours to inflate fares — and in some cases permanently deactivated accounts after low customer ratings. According to the reporting on the decision, these actions were taken by automated systems, and drivers were neither adequately warned nor given a real opportunity to be heard by a person. The case originated with complaints from drivers in France and landed with the AP because Uber's European headquarters is in Amsterdam, making the Dutch authority its lead regulator under the GDPR's one-stop-shop mechanism.
The fine is the fourth the AP has imposed on Uber: €600,000 in 2018 (data breach), €10 million in 2023, €290 million in August 2024 (transfers of driver data to the US), and now €825 million for automated decision-making. It is also the regulatory culmination of litigation that drivers' unions have been running in the Netherlands for years. In the 2023 "robo-firing" appeals (Uber drivers v. Uber, Amsterdam Court of Appeal, ECLI:NL:GHAMS:2023:793), the court held that Uber's claimed human involvement in account deactivations was "not much more than a purely symbolic act" — reviewers in a risk team who neither heard the driver nor genuinely reconsidered the algorithm's output. A person who clicks "confirm" on the software's recommendation is not human intervention; the reviewer must be able to actually change the outcome.
That doctrine — symbolic review is no review — is the single most important operational takeaway from the entire saga, and it is what regulators on both sides of the Atlantic are now converging on.
What Applies in Canada Right Now
Canada has no single "automated decision-making law," but three regimes already bite, and the gap between Canadian and European rules is much smaller than most businesses assume.
1. Quebec Law 25, s. 12.1. This is Canada's only general, in-force automated decision provision, and it tracks the GDPR closely. Where an organization uses personal information to render a decision based exclusively on automated processing, it must inform the individual no later than when it communicates the decision. On request, it must also provide the personal information used, the reasons and principal factors and parameters behind the decision, the right to have the information corrected, and the opportunity to submit observations to a person in a position to review the decision. It has applied since September 22, 2023, to any private-sector organization handling Quebec residents' personal information — no revenue threshold, no employee-count threshold. The regulator, the Commission d'accès à l'information (CAI), can impose administrative monetary penalties of up to the greater of $10 million or 2% of worldwide turnover, with penal fines up to the greater of $25 million or 4%, and Law 25's private right of action carries a $1,000 statutory damages floor per person. The CAI signalled its enforcement posture in a January 2025 brief on AI in the workplace, urging employers to disclose partially or fully automated decision tools as soon as their use is confirmed and flagging algorithmic management as a transparency, proportionality, and discrimination risk.
2. Ontario's AI hiring disclosure — in force since January 1, 2026. The Working for Workers Four Act, 2024 amended the Employment Standards Act to require employers to disclose the use of artificial intelligence to screen, assess, or select applicants in publicly advertised job postings. It is a transparency rule, not a review-rights rule — but it means "we use AI in hiring" is now a regulated statement in Canada's largest province.
3. PIPEDA — the federal gap. The federal private-sector law has no provision specifically addressing automated decisions, no order-making power, and a maximum offence fine of $100,000. The Office of the Privacy Commissioner has argued since 2020 that PIPEDA should add a right to a meaningful explanation and a right to contest automated decisions, and confirmed in March 2026 that existing privacy principles apply to AI systems — but the OPC's tools remain recommendations and negotiated resolutions. Outside Quebec, meaningful automated-decision accountability in Canada is currently a matter of regulator guidance and litigation risk, not statute. BC's and Alberta's Personal Information Protection Acts are in the same position.
The New Federal Legislation: Bill C-36 and the PPCDA
On June 15, 2026, the federal government tabled Bill C-36, the third attempt in six years to replace PIPEDA's privacy provisions (after C-11 died in 2021 and C-27 — with its Artificial Intelligence and Data Act — died when Parliament was prorogued in early 2025). Bill C-36 would enact the Protecting Privacy and Consumer Data Act (PPCDA). Second Reading is expected in the fall sitting.
Two features matter here. First, the PPCDA's automated decision provision (s. 63) defines an "automated decision system" more broadly than the GDPR: any technology that assists or replaces the judgment of human decision-makers — rules-based systems, regression, predictive analytics, machine learning, deep learning, neural networks. The GDPR's and Law 25's trigger is a decision made solely or exclusively by automated means; the PPCDA reaches systems that merely assist human judgment. The threshold for the individual's rights is a prediction, recommendation, or decision with a "legal or similarly significant effect" — language lifted from the GDPR — and, echoing Law 25, individuals would get both an explanation and the right to make written representations to a human employee able to review the decision. Second, the enforcement architecture is new: a Digital Safety and Data Protection Commission with order-making powers and administrative monetary penalties up to the greater of $10 million or 3% of gross global revenue, indictable offences up to the greater of $25 million or 5%, and — for the first time at the federal level — a private right of action for damages once a contravention is established.
Bill C-36 is not law, and AI-specific rules were deliberately left for separate legislation still in the works. But the direction is unambiguous: every serious Canadian proposal now includes automated-decision transparency, explanation, and human review. The question for businesses is not whether to build this capability, but whether to build it once, properly, before a regulator or plaintiff asks to see it.
Meanwhile in Europe
The Uber decision is one move in a broader European enforcement build-out:
- The AP is writing the playbook. In April 2026 it opened consultation on draft guidance, The Right to an Explanation in Automated Decision-Making, covering what explanation obligations require under Article 22, the difference between general and specific explanations, and techniques like SHAP values and counterfactual explanations. Expect that guidance to be cited in the next enforcement decision.
- The Platform Work Directive (EU) 2024/2831 requires human oversight of algorithmic management for platform workers, with member state transposition due by December 2, 2026 — extending Uber-style obligations across the gig economy regardless of privacy law.
- The EU AI Act's high-risk obligations took effect on August 2, 2026. AI systems used for recruitment, work allocation, and monitoring of workers are classified high-risk (Annex III), pulling algorithmic management into conformity assessments, human oversight requirements, and documentation duties that sit alongside the GDPR.
- The one counter-current: the Commission's late-2025 Digital Omnibus proposals would narrow Article 22, and the Netherlands is among the member states that have formally pushed back. If Article 22 survives the omnibus intact, the €825 million fine is the new floor for enforcement expectations, not an outlier.
How the Regimes Compare
| GDPR Art. 22 (EU) | Law 25, s. 12.1 (Quebec) | PPCDA (Bill C-36, proposed) | PIPEDA (federal, current) | |
|---|---|---|---|---|
| Status | In force | In force since Sept 2023 | First reading June 15, 2026 | In force |
| Trigger | Decision based solely on automated processing with legal/significant effect | Decision based exclusively on automated processing | System that assists or replaces human judgment; prediction/recommendation/decision with legal or similarly significant effect | None specific to automated decisions |
| Individual rights | Human intervention, express point of view, contest the decision, explanation | Notice, explanation of principal factors, correction, observations to a human reviewer | Explanation + written representations to a human employee able to review | General access/challenge rights only |
| Regulator | National DPAs (AP for Uber) | CAI (Quebec) | Digital Safety and Data Protection Commission | OPC (recommendations only) |
| Max penalty | Greater of €20M or 4% global turnover | AMPs: $10M or 2%; penal: $25M or 4% | AMPs: $10M or 3%; offences: $25M or 5% | Offences up to $100,000 |
| Private action | Via member state law (Art. 82 damages) | Yes — $1,000 statutory floor | Yes — after contravention established, 2-year limitation | Federal Court after OPC report (damages) |
What Canadian Businesses Should Do Now
- Inventory your automated decisions. Any system that rejects, suspends, terminates, scores, prices, or gates a person — customers, workers, tenants, borrowers, applicants — with no genuine human checkpoint is the Uber fact pattern. Fraud flagging, hiring screens, credit and eligibility scoring, account enforcement. Write the list before someone else does.
- Fix "human in the loop" so it survives scrutiny. The Amsterdam court's standard is the one regulators will reach for: the reviewer must have the information, the authority, and the time to actually change the outcome, and must hear the individual's side. A rubber-stamp queue is documented evidence against you.
- Build the Quebec workflow if you touch Quebec residents. s. 12.1 notice at decision time, and a response process for explanation/correction/review requests. This is live compliance, not horizon-scanning.
- Paper the transparency layer. Job postings in Ontario, privacy notices everywhere else: say when decisions are automated, in plain language, before the individual asks.
- Treat C-36 as a design spec. If you're building or buying decision systems now, require explanation outputs, human-review workflows, and decision logging in your requirements docs and vendor contracts. Retrofitting after the PPCDA passes — or after a complaint — is the expensive path.
- If you operate in the EU, assume Article 22 is now actively enforced. The era of Article 22 as the GDPR's sleeping provision ended with a €825 million exclamation point.
FAQ
Is automated decision-making illegal in Canada?
No — but it is regulated in Quebec and transparency-regulated elsewhere. Quebec's Law 25 (s. 12.1) imposes notice, explanation, correction, and human-review obligations on decisions made exclusively by automated processing, and has since September 2023. Ontario has required AI use disclosure in publicly advertised job postings since January 1, 2026. Federally, PIPEDA has no automated-decision provision at all; Bill C-36 would add explanation and human-review rights if passed.
What exactly did Uber do wrong under GDPR Article 22?
Between 2020 and 2022, Uber suspended and deactivated European drivers' accounts — on fraud suspicions and, in some cases, low customer ratings — through systems the Dutch regulator found made those decisions solely by automated means, without meaningful human review, and without adequately informing drivers. Article 22 prohibits solely automated decisions with legal or similarly significant effects unless individuals get genuine human intervention, a chance to express their point of view, and a way to contest. The fine, dated August 17, 2026, is €825 million. Uber is appealing.
What counts as "meaningful" human review of an automated decision?
Per the Amsterdam Court of Appeal's 2023 Uber rulings: the reviewer must have the information, authority, and time to genuinely reconsider — and must hear the affected person's side. An employee who rubber-stamps the algorithm's output is, in the court's words, "not much more than a purely symbolic act." Practically: document who reviewed, what they saw, and what they changed or confirmed, or your human-in-the-loop is evidence against you.
Does Quebec's Law 25 apply to businesses outside Quebec?
Yes, in practice. Law 25 applies to any private-sector organization that collects, uses, or discloses the personal information of Quebec residents in the course of carrying on an enterprise — regardless of where the organization is located. If your product or workforce touches Quebec residents and any feature renders exclusively automated decisions about them, s. 12.1 applies to you, with penalties up to the greater of $25 million or 4% of worldwide turnover.
When does Bill C-36 (the PPCDA) become law?
It hasn't, and may change before it does. Bill C-36 was tabled June 15, 2026, with Second Reading expected in the fall sitting; coming into force would follow by Order in Council after passage, with a transition period. It is the third attempt at federal privacy reform in six years — both predecessors died on the Order Paper — so plan against its substance but don't treat it as settled law.
Do automated-decision rules apply to AI hiring and HR tools?
They are the most exposed category. Exclusively automated resume screening or candidate rejection triggers Law 25 s. 12.1 for Quebec candidates; Ontario requires disclosing AI screening in job postings; the CAI's 2025 workplace AI brief flagged algorithmic management as a priority risk; and in the EU, employment and worker-management AI is classified high-risk under the AI Act as of August 2, 2026. The Uber fine itself was, at bottom, a workforce-management case.
What are the penalties for getting automated decisions wrong?
It depends on jurisdiction. EU: up to 4% of global turnover — Uber's fine equals roughly 1.85% of its 2025 turnover. Quebec: administrative penalties up to the greater of $10 million or 2% of worldwide turnover, penal fines up to $25 million or 4%, plus a private right of action with a $1,000 statutory damages floor per person. Under Bill C-36 as proposed: AMPs up to the greater of $10 million or 3% of gross global revenue and indictable offences up to $25 million or 5%. Under current PIPEDA: offence fines capped at $100,000 — a gap Bill C-36 is designed to close.