The Dutch Data Protection Authority recently slapped Uber with an €825 million fine, on the grounds that between 2018 and 2022 Uber had used an automated system to suspend or disable some drivers’ accounts, yet had not adequately informed the drivers of the existence and basis of the automated decisions, nor provided the human intervention required under the General Data Protection Regulation (GDPR). The case originated from complaints by French drivers. Because Uber’s European headquarters are in the Netherlands, the Dutch regulator ultimately led the investigation. Uber denied that the permanent disabling was entirely machine-made, argued that the fine was wildly disproportionate, and has already announced an appeal.
This money will not be distributed to the suspended drivers. It is an administrative fine under Article 83 of the GDPR, whose main functions are punishment and deterrence; if drivers want compensation, they must separately prove illegality, damage, and causation under Article 82. The Court of Justice of the European Union has also made it clear that compensation under Article 82 is purely compensatory and cannot be used to impose punishment; a GDPR violation by itself does not automatically create a claim to damages. The digital-rights organization that helped the drivers file complaints is preparing a collective compensation lawsuit, but the number of participants and the per-person amount have not yet been determined.
In Hu Yilin’s view, the Uber case could originally have been about a rather simple right: when drivers are subjected to a serious sanction, can they know exactly what happened and get a chance to correct mistakes? But GDPR combines this question with a special distrust of automation, broad compliance powers for administrative authorities, and huge fines calculated according to a company’s global turnover, ultimately producing a system that is both expensive and not necessarily truly respectful of individual autonomy.

Automatic suspension is not the original sin
Uber’s automated risk-control system takes temporary suspension or disabling measures based on signals such as abnormal detours, suspected completion of a trip after accepting it without intending to do so, and passenger ratings. The Dutch regulator held that some decisions have a major impact on drivers’ livelihoods and therefore cannot be made by a computer alone without sufficient notice and human intervention; Uber, by contrast, maintains that temporary suspensions are usually brief, and that permanent disabling does not happen without human review. The two sides still have obvious disputes over the scope of the facts and the number of drivers affected.
Hu Yilin does not think that using algorithms to make decisions is in itself unfair. On the contrary, when there is suspicion of deceiving passengers or a safety risk, “automation should be beyond reproach, and in a certain sense, automation is needed.”
If the system finds that a driver may have deliberately taken a detour to inflate the fare, the platform can certainly suspend that driver from taking orders first. Requiring the platform to complete a lengthy human review before taking any action means that new passengers must continue to bear the risk during the investigation. For the platform, promptly blocking risk is not only a matter of business freedom, but may also be a responsibility toward passengers.
What really needs to be guaranteed is not some abstract “right to be sanctioned by human beings,” but whether drivers can know:
which order triggered the judgment; whether the system relied on a passenger complaint, GPS traces, or ratings; which specific rule the driver violated; how long the suspension will last; and through what channel rebuttal evidence can be submitted.
Hu Yilin summed up his basic demand this way: “What I support is probably only the necessary transparency, namely that when users are banned they should have the right to know the exact reason.”
But knowing the reason does not mean that everything must be handed over to humans. The procedure he imagines can first be carried out by machines: the driver explains that a certain stretch of road was jammed or closed at the time, and the platform then automatically verifies this against road data, contemporaneous vehicle trajectories, and so on; if the reason holds, the account can be restored immediately, and even the losses during the suspension can be compensated automatically. Only when the system cannot resolve the issue and the two sides still disagree on the facts should the matter be escalated to human review, industry arbitration, or a court.
In his view, drivers may in fact prefer this approach, because machine review is usually faster and does not require repeated back-and-forth with customer service. “One should not forcefully stipulate which link must involve human intervention.”
Article 22 of GDPR embodies a different institutional intuition: as a principle, individuals have the right not to be subject to decisions based purely on automation and having significant effects; even in exceptions such as performance of a contract, legal authorization, or the person’s explicit consent, the law still requires safeguards, including the right to human intervention, to express one’s views, and to challenge the decision.
Hu Yilin believes that this design easily sacralizes “human beings” themselves. A staff member who merely glances at an algorithmic conclusion and then clicks to confirm it is not any more independent or accurate than a second, more independent automated system. What procedural justice should protect is reasons, objections, and effective error correction, not a flesh-and-blood body leaving a formal signature on the final decision.
Data is not merely isolated property belonging to one person
The Uber case also exposes another contradiction in data rights.
Drivers naturally want to know which order was deemed abnormal. But the penalty may stem from a passenger’s report, and passengers often want to remain anonymous when reporting, so as not to suffer retaliation. Especially in ride-hailing, food delivery, and home services, even if the platform does not directly provide the name and only states the exact time and specific reason, the driver may still easily figure out who complained.
Thus, the driver’s right to know may directly become a safety risk for the passenger.
Hu Yilin emphasizes that “very often, the relationship of data is not just between the user and the platform, but between users and other users.” A trip contains the driver’s location, conduct, and income, and also the passenger’s journey, evaluation, and sense of safety; one cannot simply assume that because a piece of data “concerns me,” I therefore have unlimited rights of access and disposition over it.
GDPR itself is not entirely unaware of this conflict. Article 15 stipulates that providing a copy of data must not harm the rights and freedoms of others; the European Data Protection Board also requires enterprises, in specific cases, to redact parts that may harm others, rather than understanding the right of access as unlimited disclosure of raw materials.
But Hu Yilin believes that this kind of balancing is not suitable to be completely preemptively resolved by a top-down, unified list of rights. The platform can provide the driver with a factual summary sufficient for an appeal, while the platform or an independent reviewer examines the full complaint; the driver then submits rebuttal evidence such as road closures or navigation failures. How to draw the line between explaining sanctions and protecting complainants requires continual adjustment based on the specific business, risks, and user relationships.
Larger platforms should, in moral terms, establish truly usable review mechanisms, but he does not approve of the government prescribing in advance what procedure every platform must adopt. Drivers can turn to public opinion, unions, strikes, contract litigation, or the courts; if the platform refuses to improve, it will also bear the costs of reputational damage and labor attrition.
This does not guarantee that the market will automatically produce ideal outcomes, but it preserves space for different platforms and labor communities to explore different rules.
Looking at the formalism of “consent” through Cookie pop-ups
Hu Yilin’s dissatisfaction with GDPR-style data governance is also reflected in the most ordinary Cookie pop-up.
He uses the example of a restaurant owner remembering regular customers: when a customer has come several times, the owner remembers his taste and directly asks, “The usual?”—that is a natural, friendly, and efficient continuing interaction. In his view, a website using first-party Cookies to remember language, login status, and ordinary preferences has a similar character, and should not have to stage a legal authorization ritual every time a user visits.
The Cookie consent pop-ups common in Europe are not entirely caused by GDPR alone, but are the result of the combination of e-privacy rules and GDPR consent standards; under current EU rules, Cookies strictly necessary to keep a website running do not, in fact, require consent.
The problem is that real-world pop-ups have already become a kind of compliance performance: websites keep asking, users keep clicking, and both sides know that very few people are truly reading. Hu Yilin argues that rather than having every website repeatedly ask for permission, control should be returned to the user’s device.
On the first use of a browser or the first encounter with ad tracking, the browser can provide a global choice: allow or reject cross-site tracking. Once the user makes a decision, websites follow the browser signal and do not need to keep popping up windows. Such a mechanism is both more real than site-by-site authorization and more in line with the technical structure of the internet.
But he also distinguishes ordinary browsing memory from data actively submitted by the user. Delivery addresses, phone numbers, ID documents, and similar information are extra data the user provides to the platform in order to complete a specific transaction, and the scope of use should be clearly explained at the stage of registration or form-filling. A customer gives an address to a merchant in order to receive goods; that does not naturally mean consenting to the merchant selling the address to a marketing company.
In other words, whether explicit consent is needed should not be determined by technical labels such as “is it a Cookie,” but by whether the data use goes beyond the user’s reasonable understanding of the current relationship.
The right to be forgotten and others’ right to remember
Hu Yilin likewise does not accept that individuals have an absolute right to delete all “data related to me.”
A person of course may delete a blog post or social-media post they control themselves. But if the post has already been quoted, criticized, forwarded by others, and entered public discussion, the original author cannot simply because of regret demand that all responses and historical traces disappear together.
“Exercising your right to be forgotten is tantamount to depriving others of their right to remember.”
The deletion right in GDPR is also not absolute; it preserves exceptions for freedom of expression and information, public archives, scientific research, and legal claims. But Hu Yilin believes that the name “the right to be forgotten” still easily creates a misunderstanding: as if individuals could once again regain control over collective memory.
He is more in favor of strictly separating two kinds of data.
One kind is public expression that has already entered social relations, including others’ quotations, comments, and reports. These records cannot be erased solely at the original author’s unilateral will.
The other kind is data that platforms continue to store and use in the backend, such as deleted private messages, precise location records, ad-click history, and user profiles. These have not become part of other people’s normal expression; once the original service relationship ends, for the platform to continue possessing and using these data requires stronger justification.
On the issue of data portability, he makes a similar distinction. Information that users actively fill in, and records of operations that actually occurred, can be requested in a common format and taken away; but the spending tendencies, interest categories, and predictive profiles inferred by the platform from those behaviors may well contain the platform’s own models, organizational logic, and commercial creativity, and should not, as a matter of course, be regarded as property that the user can simply carry off wholesale.
What he opposes is not privacy, but nanny-style regulation
Hu Yilin does not advocate letting tech companies collect information without any constraints, nor does he oppose slowing technological innovation in the name of freedom. What he opposes is interpreting “protecting the individual” as meaning that administrative agencies should continuously manage all data relations on the individual’s behalf.
I think GDPR hinders Europe’s technological innovation, yet fails to truly protect human rights; it is a foolish move that sacrifices both efficiency and freedom. I support curbing overly rapid innovation in the tech industry in order to respect human freedom, but freedom is the premise, whereas GDPR is in fact a kind of nanny-style centralized control, a paternalistic form of management. It does not truly respect everyone’s freedom; rather, it attempts to do authoritarian things in the name of protecting human rights.
The European Commission’s own assessment acknowledges that GDPR still faces divergences in interpretation among member states, thereby increasing business costs, hampering cross-border operations, and possibly obstructing some research and innovation; the compliance burden borne by small and medium-sized enterprises has been especially and persistently criticized.
These materials do not by themselves prove that the relative weakness of Europe’s tech industry is entirely caused by GDPR. Capital markets, fragmentation of the single market, and the structure of talent and industry are equally important. But they at least show that the legal uncertainty and administrative costs brought about by GDPR are not some excuse invented by tech companies.
Hu Yilin’s criticism of the EU is also not “the EU has no right to govern Europe.” A jurisdiction can of course set its own market rules; North Korea likewise does not escape external moral criticism simply because its system applies only to its own territory. What he opposes is rules that are themselves unjust and internally inconsistent, not the EU crossing some national border.
Why 825 million euros is not the driver’s compensation
One of the things about the Uber fine that most disgusts him is that the administrative authorities, in the name of “deterrence,” collect a huge sum, while drivers who suffer wrongful deactivation do not automatically receive a single cent as a result.
The institutional division of GDPR is quite clear: Article 82 is responsible for compensating the material or non-material harm actually suffered by individuals; Article 83 separately allows supervisory authorities to impose effective, proportionate, and deterrent administrative fines, calculated up to a certain percentage of a company’s global turnover. The European Court has also made clear that Article 82 cannot serve a punitive function; compensation should, in principle, only fully make up for actual losses.
Hu Yilin believes that this dual-track structure turns the government into the biggest beneficiary.
If drivers lose income because of wrongful deactivation, the government can help them obtain evidence, organize class actions, notify potential victims, reduce litigation costs, and allow courts to apply twofold, tenfold, or even higher multipliers depending on the degree of intent. Large direct payments to individuals could likewise have a deterrent effect, without needing fines to flow into the state treasury.
He opposes using a company’s global turnover as the basis for punishment. When the government makes a mistake and must pay state compensation, no one would argue that 4% of national tax revenue should be paid to a particular victim; by the same token, a company’s scale cannot by itself indicate how much loss a specific violation caused.
“If you can’t even calculate the actual harm clearly, then you should not casually assign blame.”
“Calculate clearly” here does not mean precision down to every cent. Emotional harm, loss of opportunity, and privacy violations all require judicial estimation in the first place. If a company illegally uses the data of 1 million people and gains 100 million euros in profit, then that 100 million euros of unlawful gains can serve as an important anchor for collective redress, allowing a rough estimate of each affected person’s basic share, and then weighting it according to data sensitivity, duration of use, individual losses, and the company’s degree of malice.
Strictly speaking, a company’s 100 million euros in unlawful gains does not mean that users have each lost exactly 100 million euros in total. But it at least provides a scale closer to the specific conduct than global turnover, and it also prevents the company from retaining all its gains simply because individual harms are dispersed and hard to prove one by one.
In his proposal, compensation should first, as far as possible, be notified to and distributed to the affected users. Funds that are temporarily unclaimed should continue to be held so that users may claim them later, rather than being immediately handed over to the government, public-interest organizations, or returned to the company.
This system would encounter difficulties in implementation: how to identify the affected group, how to prove that the profits came from particular data, and who should bear the cost of class actions. But in Hu Yilin’s view, these difficulties cannot justify a supervisory authority simply setting a huge figure on its own based on global turnover.
A data law different from GDPR
Starting from Uber’s deactivation, cookies, the right to be forgotten, and compensation mechanisms, what Hu Yilin proposes is not “no data protection,” but a system with a different center of gravity.
Automated decision-making may be used broadly, and high-risk cases may be suspended first and appealed afterward; platforms should explain specific reasons, allow users to submit counterevidence, and provide different layers of correction such as machine, human, arbitration, or court review, but without sanctifying human intervention.
First-party websites may normally remember users’ preferences, while cross-platform ad tracking should be governed by a unified, global allow-or-deny option provided by the browser, no longer forcing each website to repeatedly solicit formal consent.
Access, rectification, and deletion should all be understood as rights of request and objection, rather than as an individual’s unilateral ownership of shared data. The platform must take into account the rights of passengers, drivers, complainants, citers, and other participants at the same time.
Once public expression has entered social discussion, it may not be erased from others’ memories simply because the original author has changed their mind; and backend data that the platform continues to store and use internally should allow users to opt out once the service purpose has ended.
When fraud, misuse, or actual harm occurs, the law should facilitate individual and collective lawsuits, and compensate those affected on the basis of losses and unlawful gains; the government should mainly be responsible for courts, notification, evidence, and enforcement, rather than treating regulatory fines as its own income.
This route is not necessarily easier to implement than GDPR. It depends more on courts, collective action, press oversight, trade unions, and market competition, and it will also allow some violations that have not yet caused provable harm to escape huge penalties.
But that risk itself is precisely the price of freedom that Hu Yilin is willing to accept.
Neither machines nor regulators can be black boxes
The Uber case still has to go through appeal. Whether the Dutch regulator accurately identified an automatic permanent deactivation, how many drivers were actually affected, and whether Uber’s appeal procedures at the time were truly effective cannot yet be fully judged from the public materials available. The detailed calculation behind the 825 million-euro fine has also not yet been fully presented to the public.
This creates an irony in the case: the regulator punished Uber for failing to adequately explain algorithmic decisions, yet has not adequately explained itself why it happened to fine 825 million euros.
Hu Yilin does not demand that drivers must face a manager overflowing with human warmth. He acknowledges that machines can be faster, more consistent, and may be less subject than humans to bias and personal connections. But a major decision must be understandable, challengeable, and correctable.
The same requirement should apply to public power.
The question has never been merely whether machines can deactivate accounts, but who holds the power of explanation, the power to correct errors, and the power to ultimately take the money. If a platform’s algorithm must not become a cold black box, then the regulator’s punitive algorithm should likewise not become another black box—more expensive, and more coercive.
Translated from the Chinese original with AI assistance. The original text is authoritative.
Leave a Reply