Amsterdam court accepts class action against Uber over AI-driven pay algorithms and GDPR violations (September 2026)
In September 2026, drivers from the UK, the Netherlands, and several other European countries filed a class action lawsuit in Amsterdam's district court against Uber. The claim alleges that Uber's AI-powered pay-setting system breaches GDPR, unlawfully uses driver data to train its models, and suppr
Amsterdam Court Accepts Class Action Against Uber Over AI Pay Algorithms: What It Means for Your Business
In September 2026, drivers from the UK, the Netherlands, and several other European countries filed a class action lawsuit in Amsterdam's district court against Uber. The claim alleges that Uber's AI-powered pay-setting system breaches GDPR, unlawfully uses driver data to train its models, and suppresses earnings as a result. The lawsuit seeks both financial damages and an injunction to stop the alleged violations.
This is not a peripheral case. It sits at the intersection of algorithmic decision-making, automated data processing, and worker rights — and it has direct implications for professional services firms operating anywhere that GDPR, or equivalent data protection frameworks, apply.
What the Lawsuit Actually Alleges
The core claims are worth unpacking carefully, because they are not unique to Uber or to the gig economy.
First, the claimants allege that Uber's AI system makes consequential decisions about pay without adequate transparency or human oversight. Under GDPR Article 22, individuals have the right not to be subject to decisions based solely on automated processing that significantly affect them — unless specific conditions are met, including explicit consent or contractual necessity, combined with meaningful human review.
Second, the lawsuit alleges that driver data is being fed into Uber's AI models without a lawful basis for that use. Collecting data for one purpose — say, processing a fare — and then repurposing it to train a pay-setting algorithm is a different processing activity. That requires its own legal basis and, in many cases, explicit disclosure to data subjects.
Third, the claimants argue the system depresses earnings, meaning the algorithmic output causes material financial harm. This matters legally because it strengthens the argument that the processing is "significant" under GDPR's automated decision-making provisions.
None of these allegations have been proven in court. But the fact that Amsterdam's district court has accepted the case means the legal arguments are considered sufficiently substantive to proceed.
Why Professional Services Firms Should Pay Attention
The instinctive response from a law firm, accountancy, or HR consultancy might be: "We are not Uber. We do not have thousands of gig workers." That response misses the point.
Consider how AI is now embedded in professional services operations. Recruitment and HR platforms use AI to screen CVs, rank candidates, and flag performance issues. Accounting firms use AI to assess risk, allocate work, or score client engagements. Marketing agencies use AI to profile audiences and automate personalised outreach. Solicitors are beginning to use AI tools that influence how cases are resourced and billed.
In each of these scenarios, AI systems are making or influencing decisions that significantly affect individuals — employees, candidates, clients. And in each case, the data feeding those systems was collected for purposes that may not have included AI model training.
If your business operates in the EU, or handles the data of EU residents, GDPR applies to you regardless of where your firm is headquartered. If you operate in the UK, the UK GDPR imposes equivalent obligations. Canada's PIPEDA, Australia's Privacy Act, and emerging AI-specific legislation in the US and Middle East are all moving in a similar direction: greater scrutiny of automated decision-making and stricter requirements around data use transparency.
The Specific Compliance Risks This Case Illuminates
Automated decision-making without adequate safeguards. If your firm uses AI to make or significantly influence decisions about individuals — performance ratings, pay banding, client eligibility assessments — you need a documented lawful basis and, in most cases, a mechanism for human review. Many firms have deployed AI tools without revisiting whether their existing legal bases cover these new processing activities.
Secondary use of personal data for AI training. If you are using client, employee, or candidate data to improve or fine-tune AI models, that is a separate processing purpose from the original collection. Your privacy notices almost certainly do not cover this. Your data processing agreements with vendors may not either. This is an area of active regulatory focus across multiple jurisdictions.
Lack of transparency with data subjects. GDPR requires that individuals are told, in plain language, when automated decision-making is taking place and what its significance is. Many firms' privacy policies are silent on AI-driven processes, or describe them in terms so vague as to be meaningless. That is a compliance gap.
Vendor risk. Many professional services firms are not building AI systems themselves — they are buying or licensing them from third-party providers. That does not transfer the compliance obligation. As a data controller, you remain responsible for ensuring that the AI tools you procure comply with applicable data protection law. Your contracts with AI vendors need to reflect this, including provisions around data use, model training, and audit rights.
The Broader International Picture
The Amsterdam case is significant partly because of its jurisdictional reach. Claimants are drawn from multiple countries, the defendant is a US-headquartered company, and the proceedings are taking place in the Netherlands. This cross-border structure reflects the reality of how AI systems operate — they do not respect national boundaries, and neither, increasingly, do the legal claims arising from them.
Regulators in the EU are now operationalising the AI Act alongside GDPR, which introduces additional obligations for high-risk AI systems — including those used in employment contexts. The UK's ICO has made algorithmic transparency a stated enforcement priority. In the US, the FTC has taken action against companies for deceptive uses of automated systems. In Asia-Pacific, Singapore, Japan, and Australia are all developing or updating AI governance frameworks.
The direction of travel is consistent. Businesses that treat AI compliance as a future concern are taking on accumulating risk today.
What to Do Now
The Uber case will take time to resolve, but waiting for the outcome before acting is the wrong approach. Regulatory investigations and civil claims in this space are accelerating, not slowing down.
A practical starting point is to audit your current use of AI and automated decision-making tools, map the personal data those systems process, and assess whether your existing legal bases and privacy disclosures actually cover those activities. Where you identify gaps — and most organisations do — you need a remediation plan that is documented and defensible.
You should also be reviewing your vendor contracts and data processing agreements with any AI tool provider. If those agreements do not address model training, data retention, and audit rights, they need to be updated.
Ops Intel Can Help
At Ops Intel, we work with professional services firms across the UK, EU, US, Canada, the Middle East, and Asia-Pacific to identify and close AI compliance gaps before they become regulatory or legal problems. Our work covers GDPR and UK GDPR obligations, AI Act readiness, automated decision-making frameworks, and vendor risk assessment.
If the Amsterdam case has prompted questions about your own exposure, we would welcome a conversation. Contact Ops Intel today to discuss how we can support your compliance posture — before the issue lands on your desk from a regulator or a claimant's solicitor.
Follow us in Google
See Ops Intel first when AI rules change
One click tells Google you want our compliance briefings near the top of your results — and marks us as a preferred source inside Google's AI answers. It applies to your Google account only, and you can undo it any time.
Work with Ops Intel
Need help navigating AI compliance?
We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.