# Italy's Garante fines Foodinho (Glovo) for its rider-management algorithm: €2.6M in 2021, €5M in 2024

> Italy's data-protection regulator, the Garante, twice found the rider-management algorithm of Foodinho, Glovo's Italian food-delivery arm, unlawful under the GDPR. On 5 July 2021 it fined Foodinho €2.6M because riders were not told how the order-assignment and rating algorithms decided their work, had no way to contest those decisions, and faced a risk of discrimination, and it ordered the algorithms changed. On 22 November 2024 it fined the company a further €5M for continuing to process over 35,000 riders' data unlawfully (geolocation sent to third parties even off-duty, until August 2023) and prohibited its use of riders' biometric facial-recognition data.

- Verification status: verified
- Case type: deployment
- Provider: Garante per la protezione dei dati personali (Italy's Data Protection Authority)
- Client: Foodinho S.r.l. (Glovo group; Glovo acquired by Delivery Hero in 2022), Gig-economy food delivery / algorithmic workforce management (named)
- Sector: gig-economy / IT / ops
- Verified on: 2026-08-24
- Canonical URL: https://theinternetninja.com/stories/italy-garante-fines-foodinho-2-6m-for-rider-management-algorithm-2021/
- Source: The Internet Ninja (theinternetninja.com), independent verified-proof platform

## Outcomes

| Metric | Before | After |
| --- | --- | --- |
| 5 July 2021: the Garante fines Foodinho '2,6 milioni di euro' and orders that 'gli algoritmi di prenotazione e assegnazione degli ordini di cibo e prodotti non producano forme di discriminazione', granting '60 giorni ... per avviare le misure ... e ulteriori 90 giorni per completare gli interventi sugli algoritmi' |  |  |
| 22 November 2024: a second order, 'una sanzione di 5 milioni di euro per aver trattato illecitamente i dati personali di oltre 35mila rider', after finding riders' geolocation data 'inviati anche quando il rider non lavora' (up to August 2023), and it prohibits further 'trattamento dei dati biometrici (riconoscimento facciale) dei rider' |  |  |
| First-of-kind cross-border enforcement: 'una operazione congiunta di cooperazione europea, ai sensi del Gdpr, con il Garante spagnolo (AEPD)' |  |  |

## Verification method

Regulator's own published press releases (Garante, 5 July 2021 and 22 November 2024, Tier 1, Italian) for each fine, each corroborated by two independent newsrooms (2021: TechCrunch and Silicon Republic; 2024: the Reuters wire, carried by SRN News and credited by ID Tech Wire, plus Diritto Mercato Tecnologia, a separate Italian legal-tech newsroom that filed its own writeup, not Reuters-derived). All seven sources byte-tied to organic Wayback captures (raw id_ payload sha1 == CDX digest); every quote grep-verified verbatim against its capture. Both primary fine figures re-fetched from the Garante releases on 2026-08-30 and confirmed. The two fines are adjudicated separately and never summed.

## Full case file

## The problem

Foodinho S.r.l. is the Italian food-delivery arm of the Glovo group. It managed and scored its riders through a digital platform whose algorithms booked and assigned delivery orders and evaluated rider performance, drawing on riders' geolocation and other personal data. Italy's data-protection regulator, the Garante per la protezione dei dati personali, found this algorithmic management unlawful, not once but twice. As TechCrunch reported in 2021, "Algorithmic management of gig workers has landed Glovo-owned on-demand delivery firm Foodinho in trouble in Italy where the country's data protection authority" issued a "€2.6 million penalty" ([source](https://techcrunch.com/2021/07/06/italys-dpa-fines-glovo-owned-foodinho-3m-orders-changes-to-algorithmic-management-of-riders/)). This is a regulator-origin, adjudicated public record, a national data-protection authority twice ruling an automated workforce-management system unlawful, not a vendor case study.

## What was built

The system under review was Foodinho's platform for managing riders: the algorithms that book and assign food and product orders and the rating mechanism used to evaluate rider performance ([source](https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9677377)). The Garante examined it, for the first time, through "una operazione congiunta di cooperazione europea, ai sensi del Gdpr, con il Garante spagnolo (AEPD)", a joint operation with Spain's data-protection authority, which oversaw the group parent ([source](https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9677377)).

## The outcome

**2021: <span class="kpi">€2.6M</span> and an order to change the algorithms.** On 5 July 2021 the Garante fined Foodinho "2,6 milioni di euro" ([source](https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9677377)). It found the company "had not adequately informed the workers on the functioning of the system and did not guarantee the accuracy and correctness of the results of the algorithmic systems" ([source](https://techcrunch.com/2021/07/06/italys-dpa-fines-glovo-owned-foodinho-3m-orders-changes-to-algorithmic-management-of-riders/)); Silicon Republic reported that Foodinho "had not adequately explained to riders how the algorithm makes its decisions," and that the company had "150 days to respond to the order and make adequate changes to give riders more clarity" ([source](https://www.siliconrepublic.com/start-ups/glovo-italy-fine-algorithms)). The Garante ordered that "gli algoritmi di prenotazione e assegnazione degli ordini di cibo e prodotti non producano forme di discriminazione," and it "ha concesso a Foodinho 60 giorni di tempo per avviare le misure necessarie per correggere le gravi violazioni rilevate e ulteriori 90 giorni per completare gli interventi sugli algoritmi" ([source](https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9677377)).

**2024: a further <span class="kpi">€5M</span> and a biometric ban.** On 22 November 2024 the Garante announced a second sanction of <span class="kpi">€5 million</span> against Foodinho over the data of <span class="kpi">more than 35,000 riders</span>: "una sanzione di 5 milioni di euro per aver trattato illecitamente i dati personali di oltre 35mila rider attraverso la piattaforma digitale" ([source](https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10074840)). The Reuters wire, carried by SRN News, reported the fine as "5 million euros ($5.20 million) for unlawfully processing the personal data of more than 35,000 riders" ([source](https://srnnews.com/italy-watchdog-fines-foodinho-5-million-euros-for-rider-data-breaches/)). The regulator found that "I dati sulla geolocalizzazione, in particolare, sono inviati anche quando il rider non lavora" ([source](https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10074840)); the Reuters wire adding that "Up to August 2023 this happened also when riders were not working" ([source](https://srnnews.com/italy-watchdog-fines-foodinho-5-million-euros-for-rider-data-breaches/)). The Authority also acted on "trattamento dei dati biometrici (riconoscimento facciale) dei rider utilizzati per la verifica" of identity ([source](https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10074840)), reported as a prohibition on Foodinho "from using biometric data of its riders, such as facial recognition for identity verification" ([source](https://srnnews.com/italy-watchdog-fines-foodinho-5-million-euros-for-rider-data-breaches/)). ID Tech Wire noted the second fine landed "despite Foodinho being fined in 2021 for similar violations" ([source](https://idtechwire.com/finding-gdpr-violations-italian-regulator-preemptively-prohibits-firms-use-of-facial-recognition/)). The Italian legal-tech review Diritto Mercato Tecnologia, in its own writeup, independently reported "una sanzione di 5 milioni di euro a Foodinho srl, parte del gruppo Glovo, per gravi violazioni del Regolamento Generale sulla Protezione dei Dati," with geolocation data shared "fino ad agosto 2023, e talvolta condivisi con terze parti senza il consenso informato degli interessati," alongside the "divieto di utilizzo dei dati biometrici per verificare" riders' identity ([source](https://www.dimt.it/news/rider-il-garante-privacy-dice-no-agli-algoritmi-incontestabili-sanzione-di-5-milioni-a-foodinho-gruppo-glovo/)).

*(Scope note: these are two separate Garante orders against the same company, €2.6M in 2021 and €5M in 2024, stated separately and never summed. This is the Foodinho/Glovo gig-worker algorithmic-management case; it is distinct from the Garante's other data/AI actions and from US matters such as EEOC v. iTutorGroup, Louis v. SafeRent, or the Air Canada chatbot tribunal. The rider counts, about 19,000 in 2021, over 35,000 in 2024, are scale context, not measured harm figures.)*

## A note on the weakest link

Both fines rest on the strongest possible source, the Garante's own adjudications (Tier 1, regulator-origin), so the secondaries corroborate rather than carry them. The weakest load-bearing source is the 2024 corroboration chain: the €5M figure's most-cited English carrier, SRN News, is a syndication of the **Reuters wire**, so SRN News and ID Tech Wire trace to the same original report and count as one independent, not two; the independent second newsroom for the 2024 fine is Diritto Mercato Tecnologia (dimt.it), an Italian legal-tech review that filed its own same-day writeup rather than re-running Reuters. No English-only aggregator carries the primary claim on its own.

## How this was verified

- **Method:** Tier-1 regulator-origin adjudication, the Garante's two published press releases (5 July 2021, doc 9677377; 22 November 2024, doc 10074840), the primary for both fines. Every quoted line above was re-matched this session against the local captures of those releases and the corroborating captures.
- **Corroboration:** the 2021 €2.6M fine is carried firsthand by two independent newsrooms (TechCrunch; Silicon Republic); the 2024 €5M fine and biometric prohibition are carried by the Reuters wire (via SRN News, credited by ID Tech Wire) and by a second, non-Reuters independent, Diritto Mercato Tecnologia. Each capture is byte-tied to an organic Wayback snapshot (raw `id_` payload sha1 == CDX digest).
- **Date verified:** checker round 2, 2026-08-10 (confidence 1.000); verified on 2026-08-24; both fine figures re-fetched from the Garante primaries and re-confirmed on 2026-08-30.
- **The honest limit:** what is confirmed here is the public adjudicated record, the Garante's two orders and their figures. What is not tracked on this page is each order's final disposition (whether either fine was paid, reduced, or challenged on appeal) and the scope and dates over which the unlawful off-duty geolocation transmission and biometric facial-recognition processing were actually stopped and the algorithms remediated. Green never depends on the fined body confirming its own numbers; it rests on the Garante's orders plus the independent public record.

## Related case files

- [Dutch DPA fines the Tax Administration €2.75M for unlawful algorithmic nationality profiling](/stories/dutch-dpa-fines-tax-authority-2-75m-for-unlawful-algorithmic-risk-profiling-in-c/), the closest sibling: another 2021 European DPA fine where a self-learning risk-classification algorithm was ruled an unlawful, discriminatory processing of personal data, not a vendor claim.
- [Spain's AEPD orders Worldcoin to halt biometric iris-scanning](/stories/spain-aepd-orders-worldcoin-tools-for-humanity-to-halt-biometric-iris-scanning-a/), a regulator-origin enforcement in the same family, and one involving the same Spanish authority (AEPD) that co-ran the 2021 Foodinho operation, stopping an automated biometric system on GDPR grounds.
- [ICO orders Serco Leisure to halt unlawful facial-recognition attendance monitoring](/stories/ico-orders-serco-leisure-to-halt-unlawful-facial-recognition-and-fingerprint-att/), a UK data-protection authority striking down another automated biometric system that processed workers' data without a lawful basis.

## Sources

1. Garante per la protezione dei dati personali · "Rider: no a sistemi discriminatori, Foodinho sanzionata" (provvedimento doc 9677377) · 2021-07-05 · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9677377, **Tier 1** (regulator-origin primary; the adjudicating authority's own release; independent-origin, not counted toward corroboration; local capture, Wayback `20210705175421`).
2. Garante per la protezione dei dati personali · "Rider: il Garante privacy sanziona Foodinho (gruppo Glovo)" (provvedimento doc 10074840) · 2024-11-22 · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10074840, **Tier 1** (regulator-origin primary; the adjudicating authority's own release; independent-origin, not counted toward corroboration; local capture, Wayback `20241122162327`).
3. TechCrunch · "Italy's DPA fines Glovo-owned Foodinho $3M, orders changes to algorithmic management of riders" · 2021-07-06 · https://techcrunch.com/2021/07/06/italys-dpa-fines-glovo-owned-foodinho-3m-orders-changes-to-algorithmic-management-of-riders/, **Tier 2** (independent newsroom carrying the €2.6M fine firsthand; local capture, Wayback `20210706123314`).
4. Silicon Republic · "Glovo fined €2.6m in Italy over rider-management algorithms" · 2021-07-06 · https://www.siliconrepublic.com/start-ups/glovo-italy-fine-algorithms, **Tier 2** (independent newsroom; states the 150-day compliance deadline firsthand; local capture, Wayback `20210706174941`).
5. SRN News (Reuters wire) · "Italy watchdog fines Foodinho 5 million euros for rider data breaches" · 2024-11-22 · https://srnnews.com/italy-watchdog-fines-foodinho-5-million-euros-for-rider-data-breaches/, **Tier 2** (Reuters wire carrying the €5M fine, biometric ban and off-duty geolocation firsthand; local capture, Wayback `20241122151934`).
6. ID Tech Wire · "Finding GDPR Violations, Italian Regulator Preemptively Prohibits Firm's Use of Facial Recognition" · 2024-11-25 · https://idtechwire.com/finding-gdpr-violations-italian-regulator-preemptively-prohibits-firms-use-of-facial-recognition/, **Tier 2** (credits the Reuters reporting; same original as source 5, so counts as one independent with it; local capture, Wayback `20250724130133`).
7. Diritto Mercato Tecnologia (dimt.it) · "Rider: il Garante privacy dice no agli algoritmi incontestabili. Sanzione di 5 milioni a Foodinho (gruppo Glovo)" · 2024-11-22 · https://www.dimt.it/news/rider-il-garante-privacy-dice-no-agli-algoritmi-incontestabili-sanzione-di-5-milioni-a-foodinho-gruppo-glovo/, **Tier 2** (independent Italian legal-tech review; its own same-day writeup, not Reuters-derived, the second independent for the 2024 fine; local capture, Wayback `20241214122053`).