← All case files
verified deployment food delivery · IT · ops

Italy's Garante fines Deliveroo €2.5M for its rider-management algorithm — 2021

On 22 July 2021 Italy's data-protection regulator, the Garante, fined Deliveroo Italy €2.5 million for unlawfully processing the data of about 8,000 riders: non-transparent order-assignment and shift-booking algorithms, geolocation captured every 12 seconds, and routes stored for six months. It ordered Deliveroo to add human-review safeguards and correct the algorithms within 60 plus 90 days.

MetricBeforeAfter
€2.5M GDPR fine (order n. 285, 22 July 2021) for unlawfully processing about 8,000 riders' data
Regulator finding that the order-assignment and shift-booking algorithms were non-transparent and potentially discriminatory
Order to add human-review safeguards and correct the algorithms — 60 days for the violations, a further 90 days for the algorithms

The problem

Deliveroo Italy s.r.l. ran its food-delivery operation on a digital platform that managed and scored its riders through software rather than people. Italy’s data-protection regulator, the Garante per la protezione dei dati personali, ruled that management unlawful. As the GRC news desk reported, “Italian data protection authority Garante has imposed a €2.5m ($3.0m) financial penalty on food delivery company Deliveroo for disproportionate collection of workers’ data and lack of transparency in use of algorithms” (source). This is a regulator-origin, adjudicated public record — a national data-protection authority ruling an automated workforce-management system unlawful — not a vendor case study (source).

What was built

The system under review was Deliveroo’s platform for managing riders: the algorithms that assigned delivery orders and booked work shifts, running on top of intensive monitoring of rider behaviour. The Garante found that the offences included collecting far too much data, in the GRC desk’s account “checking riders’ location every 12 seconds, recording deviations from estimated delivery times, storing riders’ routes for six months, and their communications with customer care” (source). The Garante’s own newsletter described the same near-continuous tracking as a “rilevazione ogni 12 secondi della posizione” (a reading of the position every 12 seconds) (source). The decision followed an investigation the authority had opened in June 2019 (source).

The outcome

€2.5M and about 8,000 riders. A&O Shearman’s data-protection team recorded that “On 2 August 2021, the Italian supervisory authority (Garante) announced that is has imposed a fine of EUR 2.5 million against a food delivery company Deliveroo Italy s.r.l. (Deliveroo) for violation of several requirements of the GDPR” (source). The Garante’s own newsletter states the penalty as “2 milioni e 500 mila euro” (2 million 500 thousand euro) (source); the GRC desk adds that the case “involved numerous, serious violations of European and national privacy legislation in how the digital-based company handled personal data of around 8,000 riders” (source).

A non-transparent, potentially discriminatory algorithm. The Garante found that the violations concerned, among other things, “la mancata trasparenza degli algoritmi utilizzati per la gestione dei rider, sia per l’assegnazione degli ordini sia per la prenotazione dei turni di lavoro” (the lack of transparency of the algorithms used to manage riders, both for assigning orders and for booking work shifts) (source). A&O Shearman confirmed the same finding firsthand: “Garante noted that Deliveroo was not sufficiently transparent about the algorithms used for the management of its riders, for both the assignment of orders and for the booking of work shifts” (source). The GRC desk reported that the regulator “has ordered Deliveroo to provide riders with precise information on how the assignment system works” (source).

An order to fix it, on the clock: 60 days plus 90. The Garante granted the company “60 giorni di tempo per correggere le violazioni riscontrate e ulteriori 90 giorni per completare gli interventi sugli algoritmi” (60 days to correct the violations found and a further 90 days to complete the work on the algorithms) (source); the GRC desk reports the same two deadlines, “60 days to correct the violations and a further 90 days to complete the interventions on algorithms” (source).

(Scope note: this is the Deliveroo Italy order n. 285 of 22 July 2021 — a €2.5M fine. It is distinct from, and never summed with, the Garante’s separate fines against Foodinho, the Glovo group’s Italian arm (€2.6M in 2021 and €5M in 2024), and from the Dutch DPA’s €824.99M fine against Uber in 2026. The ~8,000 figure is the number of riders whose data was processed, not a measured-harm metric.)

The fine rests on the strongest possible source — the Garante’s own published adjudication (Tier 1, regulator-origin) — so the secondaries corroborate rather than carry it. The weakest load-bearing sources are the two English-language secondaries: GRC World Forums is an independent compliance news desk and A&O Shearman is a law-firm insight, both reputable but neither the primary filing; the precise Italian wording, the 12-second geolocation and the six-month retention are anchored to the Garante’s own newsletter, not the secondaries. No provider marketing is used anywhere in this file.

How this was verified

  • Method: Tier-1 regulator-origin adjudication — the Garante’s own newsletter of 2 August 2021 announcing order n. 285 of 22 July 2021 (doc. 9685994) against Deliveroo Italy, the primary for both critical claims (the €2.5M fine over ~8,000 riders’ data, and the non-transparent order-assignment/shift-booking algorithms plus the 60+90-day remediation order). Every quoted line above was captured live this session into sources/ and re-matched verbatim against those captures.
  • Corroboration: the €2.5M fine, the ~8,000 riders and the non-transparent algorithms are carried firsthand by two independent Tier-2 sources — GRC World Forums (“€2.5m ($3.0m) financial penalty … around 8,000 riders”) and A&O Shearman (“a fine of EUR 2.5 million against … Deliveroo Italy s.r.l.”). The 12-second geolocation and six-month retention are stated by the Garante and independently by GRC.
  • Date verified: maker round 1, 2026-09-01 (handed to the checker; no confidence claimed by the maker).
  • Archives: each source carries a Wayback snapshot — Garante newsletter web/20260901210547, GRC World Forums web/20260901210603, A&O Shearman web/20260901210626.
  • What green would still require: the independent public record of the order’s final disposition — whether the €2.5M sanction was paid, reduced, or challenged before the ordinary courts, and any court outcome — sought in the Garante’s follow-up publications and Italian court dockets, plus independent confirmation that the ordered algorithm changes and human-review safeguards were implemented in the 60+90-day window. Green never depends on Deliveroo confirming its own numbers; it rests on the Garante’s order plus the independent public record. The checker granted green on round 1 (confidence 1.000) against that standard; the page awaits the owner’s final validation.

Sources

  1. Garante per la protezione dei dati personali · “Rider: il Garante privacy sanziona Deliveroo Italy per 2,5 milioni di euro” (newsletter of 2 August 2021; order n. 285 of 22 July 2021, doc. 9685994) · 2021-08-02 · https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9687860Tier 1 (regulator-origin primary; the adjudicating authority’s own publication; independent-origin, not counted toward corroboration; local capture, Wayback 20260901210547).
  2. GRC World Forums · “Deliveroo fined for privacy and transparency breaches in Italy” · 2021-08 · https://www.grcworldforums.com/protective-security/deliveroo-fined-for-privacy-and-transparency-breaches-in-italy/2329.articleTier 2 (independent compliance news desk carrying the €2.5M fine, the ~8,000 riders, the 12-second geolocation, the six-month retention and the 60/90-day deadlines firsthand; local capture, Wayback 20260901210603).
  3. A&O Shearman (Allen & Overy Shearman) · “Italian data protection authority fines 2 food delivery companies for non-compliant algorithmic processing” · 2021-08-02 · https://www.aoshearman.com/en/insights/ao-shearman-on-data/italian-data-protection-authority-fines-2-food-delivery-companies-non-compliant-processingTier 2 (independent law-firm data-protection insight; states the €2.5M fine, the 2 August 2021 announcement, the June 2019 investigation start and the non-transparent management algorithms firsthand; local capture, Wayback 20260901210626).

Deliveroo digital platform: order-assignment and shift-booking algorithms plus performance monitoring via near-continuous rider geolocation

Verification record
Status
verified
Method
Regulator-origin adjudication. Primary is the Garante's own published newsletter of 2 August 2021 announcing order n. 285 of 22 July 2021 (Tier 1, Italian), corroborated firsthand on the €2.5M fine, the ~8,000 riders and the non-transparent algorithms by two independent newsrooms (GRC World Forums; A&O Shearman insight). Every quoted line was captured live into sources/ and bound to a Wayback snapshot.
Provider
Garante per la protezione dei dati personali (Italy's Data Protection Authority)
Client
Deliveroo Italy s.r.l. · Gig-economy food delivery / algorithmic workforce management
Disclosure
named
Questions this file answers
Why did Italy's Garante fine Deliveroo €2.5 million?

In order n. 285 of 22 July 2021, the Garante fined Deliveroo Italy €2.5 million for unlawfully processing the data of about 8,000 riders: non-transparent order-assignment and shift-booking algorithms, geolocation captured every 12 seconds, and delivery routes stored for six months.

What did the Garante order Deliveroo to change about its rider-management algorithm?

The Garante ordered Deliveroo to give riders precise information on how the assignment system works and to add human-review safeguards, granting 60 days to correct the violations and a further 90 days to complete the interventions on the algorithms.