← All insights
ClariFi
Plan. Measure. Perform.

From Data to Decisions

EDUCATIONAL COMMENTARY · DECISION GOVERNANCE · KENYA
By ClariFi Editorial12 min read

Of Company Policy and Resulting Consequences

What Uber’s €825 million Dutch penalty teaches African businesses about internal rules, automated decisions, human review and institutional accountability.

POLICY → SYSTEM → DECISION → REVIEW → CONSEQUENCE

Company policy moving through software rules and human review before producing a consequential decision.
ShareWhatsAppLinkedIn

ClariFi

Financial intelligence and decision support for Kenyan MSMEs.

  • Educational commentary
  • Decision governance
  • Kenya MSMEs
Educational commentary

Educational commentary

Opening

A driver opens an application and discovers that access to income has disappeared. No manager called. No hearing occurred. Software converted a company rule into a livelihood-changing decision.

The scene above is illustrative. It does not describe a named real person.

On 21 August 2026 the Dutch data protection authority announced a fine of nearly EUR 825 million after finding that Uber used fully automated systems to deactivate drivers — cutting off platform income — without adequate human assessment or information. The broader lesson for African businesses: a company policy is not merely an internal document. Once encoded into systems and workflows, it becomes a repeated exercise of institutional power, and the organisation inherits the consequences.

A company policy book releases filaments of light that become a river flowing toward a locked shop door at night.
Illustrative: the distance between a written rule and a locked door is the distance between intention and consequence.

That is the moment a written rule stops being an intention and starts being a consequence. For the person on the other side of the screen, the consequence is concrete: income pauses, customers move on, and the next conversation begins with a ticket number instead of a human who can reverse the decision.

What happened?

Authority
Autoriteit Persoonsgegevens (Dutch Data Protection Authority) — a supervisory regulator, not a court.
Penalty
EUR 824,990,000 (nearly EUR 825 million), announced 21 August 2026.
Regulator’s core findings
Fully automated deactivation decisions with significant effects on drivers; insufficient information about automatic decision-making. Conduct period stated by the AP: 2018–2022.
Uber’s position
Disputes the decision and the size of the fine; intends to appeal; points to human review and contest routes in current policy.
Status
Administrative decision under appeal processes — consequential and instructive, not finally settled.

The Uber decision in plain language

What the regulator found — and what Uber disputes

The Dutch regulator concluded that software deactivated driver accounts on fraud flags or low ratings without meaningful human assessment, and that drivers were not adequately informed — making the decisions consequential because they stopped platform income.

A surreal balance scale weighs glowing code tablets against a nest of livelihood light above a city of small shops.
Illustrative: when software can tip the scale on someone’s income, a regulator may ask who held the pan.

According to the AP, between 2018 and 2022 Uber software tracked driving behaviour and customer reviews. When the system flagged suspected fraud or ratings judged too low, accounts were deactivated automatically — temporarily for fraud flags, and permanently where low ratings persisted. The authority said there was no human assessment in that process. Some secondary reports describe European incidents as covering 2020–2022; where dates conflict, this article follows the AP’s stated 2018–2022 period, or uses cautious wording such as historic practices investigated through 2022.

The AP also concluded that Uber did not sufficiently inform drivers about automatic decision-making. The authority states that Uber has since stopped the violations. Income loss made the decisions “similarly significant” in the GDPR sense: a livelihood was at stake, not a minor preference setting.

Uber disagrees. Public reporting attributes to Uber a position that the fine is disproportionate, that the company takes drivers’ rights seriously, that current policies include human review and a route to contest suspensions, and that permanent deactivation was not left to automation alone. Uber’s published deactivation-review pages describe human involvement and an in-app Review Center; those pages state Uber’s current policy position and do not, by themselves, settle the historic facts under appeal.

The case remains important even where practices are described as historic. Retiring a policy does not erase its consequences. Historic rules can remain visible through complaints, audit trails, litigation, regulatory investigations, and damaged trust.

Primary source: Dutch Data Protection Authority announcement. Corroboration: Reuters.

A company policy is never just a document

How internal rules become institutional power

A policy is not merely a document. Once encoded into systems and workflows, it becomes a repeated exercise of institutional power. The consequences — intended, unintended, immediate, and delayed — belong to the organisation that designed and approved it.

Six luminous fantasy chambers for Intention, Rule, Code, Decision, Person, and Consequence connected by a winding path of light.
Illustrative: most organisations guard the first chamber and discover the last. Risk lives in the rooms between.
To the system, it may be a risk flag. To the person affected, it may be a livelihood.

Policy intention → written rule → data and threshold → system or workflow → decision → human impact → explanation and appeal → organisational consequence

  • A threshold

    A number that triggers exclusion, freeze, or decline.

  • A risk score

    A model output treated as a final answer rather than a prompt.

  • An employee instruction

    A script that tells staff to follow the system without exception.

  • An automated flag

    A silent alert that becomes action at machine speed.

  • An account restriction

    Login fails; earning, trading, or access stops.

  • A notice

    Or the absence of one — the person discovers the rule when the door closes.

  • An exception process

    Who can override, with what evidence, in what time.

  • An appeal route

    Or the absence of one — the rubber stamp that cannot reverse.

Policy to consequence

Policy choice → organisational consequence

Illustrative examples of how policy design becomes operational power. Not a description of any specific Kenyan case.

Policy choice → organisational consequence
Policy choiceOperational expressionHuman consequenceOrganisational consequence
Automatic fraud thresholdImmediate account restrictionLoss of access or incomeComplaints, reversals and regulatory exposure
Opaque scoring ruleNo understandable reason suppliedInability to correct an errorDistrust and weak defensibility
Appeal without reversal authorityHuman rubber stampNo meaningful remedyFalse assurance and continuing liability
Unreviewed customer ratingsRatings drive exclusionBias or malicious complaints become consequentialReputational and fairness risk
Retired policy left in system logicLegacy rule continues operatingHistoric harm continuesDelayed legal and financial consequences

The resulting consequences

Six ways a rule lands

When a policy is encoded without explainability, evidence, controls, and outcome tracking, the damage is rarely only regulatory.

Six coloured shockwaves expand from a cracked policy seal — human, regulatory, financial, operational, reputational, and strategic.
Illustrative: one opaque rule can radiate through people, regulators, cash, operations, reputation, and strategy at once.
  • Human and livelihood

    Lost shifts, stalled receivables, damaged trust with customers who expected fulfilment.

  • Legal and regulatory

    Supervisory findings, notification duties, and — where law applies — exposure for solely automated significant decisions.

  • Direct financial

    Fines, legal costs, refunds, idle capacity, and higher cost of capital when controls look weak.

  • Operational

    Support queues explode; exception handling becomes the product; staff invent workarounds.

  • Trust and reputation

    “They locked me out and could not explain why” travels faster than any policy PDF.

  • Strategic and board

    Directors discover they cannot defend a rule they never measured — and pause growth that depends on automation.

Why this is already a Kenyan issue

What this means for Kenyan businesses

Kenya’s Data Protection Act, 2019 — section 35 — already addresses decisions based solely on automated processing that produce legal effects or significantly affect a person. The Dutch decision does not bind Kenyan controllers; it illustrates why boards should map local rules that cut people off from money or access.

An imaginative East African market dawn with teal data threads linking glowing tills to a distant advisory lantern.
Illustrative: section 35 is closest when a till, score, or blacklist can quietly cut someone off from earning.

Section 35(2) sets exceptions where the decision is necessary for entering into or performing a contract, authorised by a law that lays down suitable safeguards, or based on the data subject’s consent. Where a solely automated decision with legal or significant effects is taken, section 35(3)–(4) requires written notification as soon as reasonably practicable, and gives the person a route to request reconsideration or a new decision that is not based solely on automated processing — with a written outcome.

The Data Protection (General) Regulations, 2021 elaborate these duties: inform the person, provide meaningful information about the logic involved, explain significance and consequences, prevent and correct errors, reduce discriminatory effects, and ensure the person can obtain human intervention and express a point of view.

Not every recommendation, score, alert, or calculation is automatically unlawful. Decision support that strengthens human judgement sits in a different place from a system that makes the final consequential decision alone. The question is whether software is the last word — and whether a qualified human can still disagree.

Hypothetical applications (labelled, not verified cases)

  • Digital credit or finance-readiness scoring that auto-declines without a named reviewer.
  • Automated fraud flags that freeze a till or M-Pesa-linked account.
  • Marketplace seller suspension after a threshold or rating.
  • Supplier onboarding blacklists encoded in procurement software.
  • Insurance eligibility cut-offs driven solely by a model.
  • Employee monitoring that triggers automatic disciplinary routing.
  • Practitioner delisting from a platform without contestable reasons.
  • Learner or candidate exclusion from an opportunity by opaque scoring.

See Kenya Data Protection Act section 35 and the Data Protection (General) Regulations, 2021. Related reading: when platform GMV is treated as your sale · when client money is treated as your income.

Meaningful human intervention

A decorative approval button is not oversight

Meaningful human intervention means a qualified person can understand the rule and data, consider new evidence, disagree with the system, reverse or vary the outcome, record reasons, and respond within a reasonable period.

A glass rulebook in a dark library reveals gears and algorithms, with a warm hand of light reaching toward a human-review door.
Illustrative: the law does not ban the machine — it insists on a door a human can still open.
  1. 1.Understand the relevant data and rule.
  2. 2.Consider additional evidence from the affected person.
  3. 3.Identify errors and exceptional circumstances.
  4. 4.Disagree with the system when the facts require it.
  5. 5.Reverse or vary the outcome with authority.
  6. 6.Record reasons in plain language.
  7. 7.Respond within a reasonable period.

Governance self-assessment

The ClariFi Policy-to-Consequence Test

Select Yes, Partial or Not available for one consequential policy that touches customers, staff, riders, agents, or suppliers. Answers stay on this page and are not collected or stored.

Ten glowing lanterns arc around a bronze compass of questions as a policy scroll unfurls beneath paths of light.
Illustrative: the Policy-to-Consequence Test is a circle of questions — if a lantern is dark, the software owns the outcome.
  1. 1.What decision does this policy authorise?
  2. 2.What could the affected person lose — income, access, credit, opportunity, reputation, or time?
  3. 3.What data, threshold, model, or rule produces the outcome?
  4. 4.How are accuracy, bias, manipulation, and exceptional circumstances tested?
  5. 5.Will the affected person receive an understandable reason?
  6. 6.Can a qualified human genuinely investigate and reverse the outcome?
  7. 7.Can the person submit evidence and challenge the decision?
  8. 8.Is the policy version, system output, reviewer, reason, and appeal result logged?
  9. 9.Who owns the policy at management and board level?
  10. 10.When will the policy and its system implementation be reviewed, changed, or retired?

Answer all ten questions to see a governance-readiness result. No outcome is shown until the assessment is complete.

  • Governed: the core consequence chain — decision, loss, data, reason, human review, challenge, and ownership — appears answerable.
  • Gaps to close: one or more material links are incomplete. Map owners, logging, and review dates before scaling the rule.
  • High-priority review: a critical link is missing — especially loss of livelihood, opaque data, absent human reversal, or no owner.

This test is a governance-readiness heuristic. It does not establish legal compliance, certify GDPR or Data Protection Act conformity, or issue a legal verdict.

Results identify areas requiring management review. They are not judicial findings.

Printable equivalent: answer each question in writing with Yes / Partial / Not available, then apply the same band logic above.

Board and owners

Questions for the board

Ask these aloud. Expect straight answers — not a policy PDF.

  1. Question 1

    Which company policies can stop someone earning, trading, borrowing, working, or accessing a service?

  2. Question 2

    Which of those policies are implemented partly or entirely through software?

  3. Question 3

    Who can override the system?

  4. Question 4

    How many decisions are appealed and reversed?

  5. Question 5

    What do reversal rates reveal about data or policy quality?

  6. Question 6

    Can management map every active policy to the system rule that applies it?

  7. Question 7

    Are retired policies removed from code, workflows, templates, and vendor systems?

  8. Question 8

    When was the last Data Protection Impact Assessment or equivalent consequence review?

See also how ClariFi works and privacy.

ClariFi relevance

Evidence-backed decisions — not hidden scores

ClariFi’s positioning is financial intelligence and decision support for Kenyan MSMEs: fewer, better, evidence-backed decisions — not legal advice or automatic regulatory compliance.

Sense → Diagnose → Decide → Act → Learn

Good decision support strengthens human judgement. It does not hide responsibility behind a score.

Where ClariFi’s operating loop includes Learn, that step must examine errors, appeals, overrides, and unintended consequences — not only successful actions.

ClariFi does not provide legal advice, guarantee Data Protection Act compliance, make lending or regulatory decisions, or replace a qualified human reviewer where the law requires one.

Conclusion

Clarity must come before consequence

A policy is a promise about how institutional power will be used.

When technology can apply one rule to thousands of people at machine speed, clarity — of ownership, evidence, notice, and genuine review — must come before consequence. Organisations that treat policy as a PDF and software as destiny inherit both the intended outcomes and the delayed ones.

Sources

Sources and further reading

FAQs

Frequently asked questions

What did the Dutch regulator find against Uber?

The AP announced a EUR 824,990,000 fine after concluding that Uber used fully automated systems to deactivate drivers — with significant effects on income — and failed to inform drivers adequately about that automation. Uber disputes the decision and intends to appeal. It is an administrative decision, not a final court judgment.

Are automated business decisions illegal?

No. GDPR Article 22 and Kenya’s section 35 restrict decisions based solely on automated processing that produce legal or similarly significant effects, subject to exceptions and safeguards. Decision support and scores are not automatically unlawful; unprotected, unexplained, consequential automation is the regulatory concern.

What does section 35 of Kenya’s Data Protection Act require?

It protects people from solely automated decisions with legal or significant effects, subject to contract, legal-authorisation, or consent exceptions. Where such a decision is taken, controllers must notify in writing and, on request, reconsider or take a new non-solely-automated decision, then write back with the outcome.

What counts as meaningful human intervention?

A qualified person who can understand the data and rule, consider new evidence, disagree with the system, reverse or vary the outcome, record reasons, and respond in a reasonable time. A chatbot that restates the policy, or a button that only confirms the machine, is not meaningful oversight.

What should a board review before automating a consequential decision?

Which policies can stop earning or access; which run in software; who can override; appeal and reversal rates; whether every active policy maps to a system rule; whether retired policies are removed from code; and when the last consequence review or DPIA equivalent was done.

CLARITY BEFORE CONSEQUENCE

Good decision support strengthens human judgement. It does not hide responsibility behind a score.

A policy is a promise about how institutional power will be used.

ClariFi is financial intelligence and decision support for Kenyan MSMEs — evidence-backed decisions, clearer reasoning, action tracking, and learning from results. It does not provide legal advice, guarantee Data Protection Act compliance, or make lending or regulatory decisions.

Sense → Diagnose → Decide → Act → Learn — including errors, appeals and overrides.