ClariFi
Financial intelligence and decision support for Kenyan MSMEs.
- Educational commentary
- Decision governance
- Kenya MSMEs
Educational commentary
Opening
A driver opens an application and discovers that access to income has disappeared. No manager called. No hearing occurred. Software converted a company rule into a livelihood-changing decision.
The scene above is illustrative. It does not describe a named real person.
On 21 August 2026 the Dutch data protection authority announced a fine of nearly EUR 825 million after finding that Uber used fully automated systems to deactivate drivers — cutting off platform income — without adequate human assessment or information. The broader lesson for African businesses: a company policy is not merely an internal document. Once encoded into systems and workflows, it becomes a repeated exercise of institutional power, and the organisation inherits the consequences.

That is the moment a written rule stops being an intention and starts being a consequence. For the person on the other side of the screen, the consequence is concrete: income pauses, customers move on, and the next conversation begins with a ticket number instead of a human who can reverse the decision.
What happened?
- Authority
- Autoriteit Persoonsgegevens (Dutch Data Protection Authority) — a supervisory regulator, not a court.
- Penalty
- EUR 824,990,000 (nearly EUR 825 million), announced 21 August 2026.
- Regulator’s core findings
- Fully automated deactivation decisions with significant effects on drivers; insufficient information about automatic decision-making. Conduct period stated by the AP: 2018–2022.
- Uber’s position
- Disputes the decision and the size of the fine; intends to appeal; points to human review and contest routes in current policy.
- Status
- Administrative decision under appeal processes — consequential and instructive, not finally settled.
The Uber decision in plain language
What the regulator found — and what Uber disputes
The Dutch regulator concluded that software deactivated driver accounts on fraud flags or low ratings without meaningful human assessment, and that drivers were not adequately informed — making the decisions consequential because they stopped platform income.

According to the AP, between 2018 and 2022 Uber software tracked driving behaviour and customer reviews. When the system flagged suspected fraud or ratings judged too low, accounts were deactivated automatically — temporarily for fraud flags, and permanently where low ratings persisted. The authority said there was no human assessment in that process. Some secondary reports describe European incidents as covering 2020–2022; where dates conflict, this article follows the AP’s stated 2018–2022 period, or uses cautious wording such as historic practices investigated through 2022.
The AP also concluded that Uber did not sufficiently inform drivers about automatic decision-making. The authority states that Uber has since stopped the violations. Income loss made the decisions “similarly significant” in the GDPR sense: a livelihood was at stake, not a minor preference setting.
Uber disagrees. Public reporting attributes to Uber a position that the fine is disproportionate, that the company takes drivers’ rights seriously, that current policies include human review and a route to contest suspensions, and that permanent deactivation was not left to automation alone. Uber’s published deactivation-review pages describe human involvement and an in-app Review Center; those pages state Uber’s current policy position and do not, by themselves, settle the historic facts under appeal.
The case remains important even where practices are described as historic. Retiring a policy does not erase its consequences. Historic rules can remain visible through complaints, audit trails, litigation, regulatory investigations, and damaged trust.
Primary source: Dutch Data Protection Authority announcement. Corroboration: Reuters.
A company policy is never just a document
How internal rules become institutional power
A policy is not merely a document. Once encoded into systems and workflows, it becomes a repeated exercise of institutional power. The consequences — intended, unintended, immediate, and delayed — belong to the organisation that designed and approved it.

To the system, it may be a risk flag. To the person affected, it may be a livelihood.
Policy intention → written rule → data and threshold → system or workflow → decision → human impact → explanation and appeal → organisational consequence
A threshold
A number that triggers exclusion, freeze, or decline.
A risk score
A model output treated as a final answer rather than a prompt.
An employee instruction
A script that tells staff to follow the system without exception.
An automated flag
A silent alert that becomes action at machine speed.
An account restriction
Login fails; earning, trading, or access stops.
A notice
Or the absence of one — the person discovers the rule when the door closes.
An exception process
Who can override, with what evidence, in what time.
An appeal route
Or the absence of one — the rubber stamp that cannot reverse.
Policy to consequence
Policy choice → organisational consequence
Illustrative examples of how policy design becomes operational power. Not a description of any specific Kenyan case.
| Policy choice | Operational expression | Human consequence | Organisational consequence |
|---|---|---|---|
| Automatic fraud threshold | Immediate account restriction | Loss of access or income | Complaints, reversals and regulatory exposure |
| Opaque scoring rule | No understandable reason supplied | Inability to correct an error | Distrust and weak defensibility |
| Appeal without reversal authority | Human rubber stamp | No meaningful remedy | False assurance and continuing liability |
| Unreviewed customer ratings | Ratings drive exclusion | Bias or malicious complaints become consequential | Reputational and fairness risk |
| Retired policy left in system logic | Legacy rule continues operating | Historic harm continues | Delayed legal and financial consequences |
The resulting consequences
Six ways a rule lands
When a policy is encoded without explainability, evidence, controls, and outcome tracking, the damage is rarely only regulatory.

Human and livelihood
Lost shifts, stalled receivables, damaged trust with customers who expected fulfilment.
Legal and regulatory
Supervisory findings, notification duties, and — where law applies — exposure for solely automated significant decisions.
Direct financial
Fines, legal costs, refunds, idle capacity, and higher cost of capital when controls look weak.
Operational
Support queues explode; exception handling becomes the product; staff invent workarounds.
Trust and reputation
“They locked me out and could not explain why” travels faster than any policy PDF.
Strategic and board
Directors discover they cannot defend a rule they never measured — and pause growth that depends on automation.
Why this is already a Kenyan issue
What this means for Kenyan businesses
Kenya’s Data Protection Act, 2019 — section 35 — already addresses decisions based solely on automated processing that produce legal effects or significantly affect a person. The Dutch decision does not bind Kenyan controllers; it illustrates why boards should map local rules that cut people off from money or access.

Section 35(2) sets exceptions where the decision is necessary for entering into or performing a contract, authorised by a law that lays down suitable safeguards, or based on the data subject’s consent. Where a solely automated decision with legal or significant effects is taken, section 35(3)–(4) requires written notification as soon as reasonably practicable, and gives the person a route to request reconsideration or a new decision that is not based solely on automated processing — with a written outcome.
The Data Protection (General) Regulations, 2021 elaborate these duties: inform the person, provide meaningful information about the logic involved, explain significance and consequences, prevent and correct errors, reduce discriminatory effects, and ensure the person can obtain human intervention and express a point of view.
Not every recommendation, score, alert, or calculation is automatically unlawful. Decision support that strengthens human judgement sits in a different place from a system that makes the final consequential decision alone. The question is whether software is the last word — and whether a qualified human can still disagree.
Hypothetical applications (labelled, not verified cases)
- Digital credit or finance-readiness scoring that auto-declines without a named reviewer.
- Automated fraud flags that freeze a till or M-Pesa-linked account.
- Marketplace seller suspension after a threshold or rating.
- Supplier onboarding blacklists encoded in procurement software.
- Insurance eligibility cut-offs driven solely by a model.
- Employee monitoring that triggers automatic disciplinary routing.
- Practitioner delisting from a platform without contestable reasons.
- Learner or candidate exclusion from an opportunity by opaque scoring.
See Kenya Data Protection Act section 35 and the Data Protection (General) Regulations, 2021. Related reading: when platform GMV is treated as your sale · when client money is treated as your income.
Meaningful human intervention
A decorative approval button is not oversight
Meaningful human intervention means a qualified person can understand the rule and data, consider new evidence, disagree with the system, reverse or vary the outcome, record reasons, and respond within a reasonable period.

- 1.Understand the relevant data and rule.
- 2.Consider additional evidence from the affected person.
- 3.Identify errors and exceptional circumstances.
- 4.Disagree with the system when the facts require it.
- 5.Reverse or vary the outcome with authority.
- 6.Record reasons in plain language.
- 7.Respond within a reasonable period.
Governance self-assessment
The ClariFi Policy-to-Consequence Test
Select Yes, Partial or Not available for one consequential policy that touches customers, staff, riders, agents, or suppliers. Answers stay on this page and are not collected or stored.

Answer all ten questions to see a governance-readiness result. No outcome is shown until the assessment is complete.
- Governed: the core consequence chain — decision, loss, data, reason, human review, challenge, and ownership — appears answerable.
- Gaps to close: one or more material links are incomplete. Map owners, logging, and review dates before scaling the rule.
- High-priority review: a critical link is missing — especially loss of livelihood, opaque data, absent human reversal, or no owner.
This test is a governance-readiness heuristic. It does not establish legal compliance, certify GDPR or Data Protection Act conformity, or issue a legal verdict.
Results identify areas requiring management review. They are not judicial findings.
Printable equivalent: answer each question in writing with Yes / Partial / Not available, then apply the same band logic above.
Board and owners
Questions for the board
Ask these aloud. Expect straight answers — not a policy PDF.
Question 1
Which company policies can stop someone earning, trading, borrowing, working, or accessing a service?
Question 2
Which of those policies are implemented partly or entirely through software?
Question 3
Who can override the system?
Question 4
How many decisions are appealed and reversed?
Question 5
What do reversal rates reveal about data or policy quality?
Question 6
Can management map every active policy to the system rule that applies it?
Question 7
Are retired policies removed from code, workflows, templates, and vendor systems?
Question 8
When was the last Data Protection Impact Assessment or equivalent consequence review?
See also how ClariFi works and privacy.
ClariFi relevance
Evidence-backed decisions — not hidden scores
ClariFi’s positioning is financial intelligence and decision support for Kenyan MSMEs: fewer, better, evidence-backed decisions — not legal advice or automatic regulatory compliance.
Sense → Diagnose → Decide → Act → Learn
Good decision support strengthens human judgement. It does not hide responsibility behind a score.
Where ClariFi’s operating loop includes Learn, that step must examine errors, appeals, overrides, and unintended consequences — not only successful actions.
ClariFi does not provide legal advice, guarantee Data Protection Act compliance, make lending or regulatory decisions, or replace a qualified human reviewer where the law requires one.
Conclusion
Clarity must come before consequence
A policy is a promise about how institutional power will be used.
When technology can apply one rule to thousands of people at machine speed, clarity — of ownership, evidence, notice, and genuine review — must come before consequence. Organisations that treat policy as a PDF and software as destiny inherit both the intended outcomes and the delayed ones.
Sources
Sources and further reading
- Dutch Data Protection Authority — Uber fine announcement (EN)
- Dutch Data Protection Authority — announcement (NL)
- GDPR consolidated text — Articles 13–15 and 22 (EUR-Lex)
- Kenya Data Protection Act, 2019 — section 35 (Kenya Law)
- Data Protection (General) Regulations, 2021 — LN 263 (Kenya Law)
- Reuters — Dutch regulator fines Uber over automated suspensions
- NDTV — Netherlands fines Uber 825 million euros
- Uber — Deactivations: Losing Account Access (current policy, accessed 2026-08-23)
FAQs
Frequently asked questions
What did the Dutch regulator find against Uber?
The AP announced a EUR 824,990,000 fine after concluding that Uber used fully automated systems to deactivate drivers — with significant effects on income — and failed to inform drivers adequately about that automation. Uber disputes the decision and intends to appeal. It is an administrative decision, not a final court judgment.
Are automated business decisions illegal?
No. GDPR Article 22 and Kenya’s section 35 restrict decisions based solely on automated processing that produce legal or similarly significant effects, subject to exceptions and safeguards. Decision support and scores are not automatically unlawful; unprotected, unexplained, consequential automation is the regulatory concern.
What does section 35 of Kenya’s Data Protection Act require?
It protects people from solely automated decisions with legal or significant effects, subject to contract, legal-authorisation, or consent exceptions. Where such a decision is taken, controllers must notify in writing and, on request, reconsider or take a new non-solely-automated decision, then write back with the outcome.
What counts as meaningful human intervention?
A qualified person who can understand the data and rule, consider new evidence, disagree with the system, reverse or vary the outcome, record reasons, and respond in a reasonable time. A chatbot that restates the policy, or a button that only confirms the machine, is not meaningful oversight.
What should a board review before automating a consequential decision?
Which policies can stop earning or access; which run in software; who can override; appeal and reversal rates; whether every active policy maps to a system rule; whether retired policies are removed from code; and when the last consequence review or DPIA equivalent was done.
CLARITY BEFORE CONSEQUENCE
Good decision support strengthens human judgement. It does not hide responsibility behind a score.
A policy is a promise about how institutional power will be used.
ClariFi is financial intelligence and decision support for Kenyan MSMEs — evidence-backed decisions, clearer reasoning, action tracking, and learning from results. It does not provide legal advice, guarantee Data Protection Act compliance, or make lending or regulatory decisions.
Sense → Diagnose → Decide → Act → Learn — including errors, appeals and overrides.