Civil Law And Ai-Managed Employment Decision Systems In Europe .
Civil Law And AI-Managed Employment Decision Systems In Europe
1. Introduction
AI-managed employment decision systems are systems in which artificial intelligence is used to make, recommend, rank, predict, or substantially influence decisions concerning employees or job applicants.
Examples include:
AI CV screening;
automated candidate ranking;
recruitment and job-matching systems;
AI-based promotion recommendations;
automated performance evaluation;
productivity scoring;
allocation of work or shifts;
automated disciplinary-risk assessments;
termination or redundancy recommendations;
employee surveillance and behavioural analysis;
AI assessment of personality, emotion or communication;
algorithmic wage or bonus recommendations.
European law does not generally treat the employer as free from responsibility merely because a computer or third-party AI vendor made the recommendation. The legal issues are instead distributed across employment law, equality law, GDPR, the EU AI Act, contract law, tort/delict law, fundamental rights and procedural remedies.
The EU AI Act expressly identifies AI used in employment, worker management, recruitment, promotion, termination, task allocation and worker monitoring/evaluation as potentially high-risk, because these systems can materially affect careers, livelihoods and workers' rights and may reproduce historical discrimination. (EUR-Lex)
2. Meaning of AI-Managed Employment Decision Systems
An AI-managed employment system may operate at several stages.
| Stage | Possible AI function | Legal risk |
|---|---|---|
| Recruitment | CV screening | discrimination, privacy |
| Selection | Candidate scoring | automated decision-making |
| Interview | Facial/voice analysis | biometric/privacy concerns |
| Hiring | Candidate ranking | equality and transparency |
| Onboarding | Risk/profile classification | data protection |
| Work allocation | Shift/task allocation | discrimination, fairness |
| Performance | Productivity scoring | privacy and accuracy |
| Promotion | Career prediction | indirect discrimination |
| Compensation | Bonus/wage recommendation | equality and contract issues |
| Discipline | Misconduct prediction | due process |
| Termination | Redundancy/termination recommendation | employment-law liability |
| Monitoring | Behaviour/productivity surveillance | privacy and proportionality |
Thus, the dispute may concern not only “Was the employee dismissed unlawfully?”, but also:
How was the AI decision generated, what data was used, who relied upon it, whether a human genuinely reviewed it, and whether the resulting decision complied with equality, privacy and employment law?
3. European Legal Framework
A. EU AI Act
Regulation (EU) 2024/1689—the Artificial Intelligence Act—places employment and worker-management AI within the high-risk framework in specified circumstances.
The legislation expressly covers systems used for:
recruitment and selection;
decisions affecting employment relationships;
promotion;
termination;
task allocation based on individual behaviour or characteristics;
monitoring and evaluation of workers.
The EU legislature specifically recognised the possibility that such systems may reproduce historical discrimination against women, particular age groups, persons with disabilities, racial or ethnic groups and persons with particular sexual orientations. (EUR-Lex)
Therefore, an employer cannot necessarily defend an employment decision simply by saying:
“The AI made the recommendation.”
The system's deployment, data, governance and human oversight may themselves become legally relevant.
4. GDPR and Automated Employment Decisions
The GDPR, especially Article 22, is central where an employment decision is based solely on automated processing, including profiling, and produces legal or similarly significant effects.
Examples can include:
automatic rejection of an applicant;
automatic termination recommendation implemented without meaningful human review;
automated promotion denial;
automated employee classification with substantial employment consequences.
However, not every use of AI in employment is automatically prohibited by Article 22.
The precise questions are:
Is personal data being processed?
Is profiling involved?
Is the decision based solely on automated processing?
Does it produce legal or similarly significant effects?
Does one of the Article 22 exceptions apply?
Are appropriate safeguards available?
Does the person have a meaningful possibility of human intervention and contesting the decision where required?
5. Human Oversight
A major issue is whether the human decision-maker actually exercises independent judgment.
There is an important difference between:
Genuine human review
AI recommends rejection → HR reviews the candidate → HR examines the underlying evidence → HR can disagree with the AI → independent decision is made.
and:
Formal human review
AI recommends rejection → HR merely clicks “approve” in almost every case.
The second situation can create a stronger argument that the human intervention was not genuinely meaningful.
The reasoning in SCHUFA is particularly important because the CJEU recognised circumstances in which an automated score can itself fall within Article 22 where a third party effectively relies on it for the decision. (Infocuria)
6. Discrimination Law
AI-managed employment decisions can create both direct and indirect discrimination.
Direct discrimination
Example:
An AI recruitment model uses sex as a variable and systematically gives male candidates a higher score.
Indirect discrimination
Example:
An apparently neutral algorithm heavily rewards uninterrupted full-time employment histories.
That criterion might disproportionately disadvantage persons who have taken career breaks for childcare or disability-related reasons.
Indirect discrimination requires examination of the applicable equality directive and national law, including whether the criterion can be objectively justified.
Proxy discrimination
The system may not expressly use:
race;
sex;
age;
disability;
but may use variables strongly correlated with them.
Examples:
postcode;
language patterns;
educational institution;
employment gaps;
names;
career history;
commuting distance.
The legal analysis depends on the particular protected ground, causal connection, statistical evidence and applicable justification rules.
7. Important Case Laws
Case 1 — Feryn
Centrum voor gelijkheid van kansen en voor racismebestrijding v Firma Feryn NV
C-54/07, CJEU, 10 July 2008
This is an important recruitment-discrimination authority.
An employer made public statements indicating that it would not recruit people of a particular ethnic or racial origin.
The CJEU held that public discriminatory recruitment statements can constitute direct discrimination even without identifying an individual applicant who was personally rejected. (Infocuria)
Importance for AI employment systems
Suppose an employer states:
“Our AI recruitment system prefers candidates matching our existing workforce.”
If evidence shows that the underlying system systematically excludes a racial or ethnic group, Feryn provides an important principle concerning recruitment discrimination and evidentiary burdens.
Principle
Discriminatory recruitment practices can be legally significant even before an individual hiring rejection is established in the traditional way.
8. Case 2 — Asociația Accept
Asociația Accept v Consiliul Național pentru Combaterea Discriminării
C-81/12, CJEU, 25 April 2013
The case concerned public statements suggesting that a football club would not recruit homosexual players.
The CJEU addressed:
discriminatory recruitment statements;
burden of proof;
evidence creating a presumption of discrimination;
effective, proportionate and dissuasive sanctions.
Once facts capable of establishing a presumption of discrimination are demonstrated, the evidentiary burden can shift under the applicable framework. (curia)
AI application
Imagine an employer's internal documents state:
“The algorithm has been designed to find candidates who fit the company's traditional workforce.”
If statistical evidence subsequently shows a strong disadvantage to a protected group, internal statements and technical documentation could become important evidence.
Principle
AI systems do not eliminate ordinary discrimination-evidence rules.
9. Case 3 — Coleman
Coleman v Attridge Law and Steve Law
C-303/06, CJEU, 17 July 2008
The CJEU considered discrimination related to disability where the employee herself was not disabled but was the primary carer of a disabled child.
The Court recognised protection against discrimination by association under the relevant circumstances. (Infocuria)
AI relevance
An employment algorithm could potentially disadvantage an employee because of characteristics or circumstances associated with a protected characteristic.
For example, an AI system might interpret:
repeated caregiving leave;
flexible-working requests;
attendance patterns;
as negative productivity indicators.
The fact that the algorithm does not contain a variable labelled “disability” does not automatically resolve the discrimination issue.
Principle
The legal analysis looks at the discriminatory effect and causal relationship, not merely the name of the algorithmic variable.
10. Case 4 — CHEZ
CHEZ Razpredelenie Bulgaria AD v Komisia za zashtita ot diskriminatsia
C-83/14, CJEU, 16 July 2015
The case involved electricity meters installed at unusually high locations in areas predominantly inhabited by Roma persons.
The CJEU examined:
direct discrimination;
indirect discrimination;
burden of proof;
apparently neutral measures;
justification;
proportionality;
stigmatizing effects. (Infocuria)
AI relevance
This is highly useful by analogy for algorithmic employment criteria.
An employer may say:
“The algorithm applies exactly the same scoring rule to everyone.”
That does not necessarily end the legal inquiry.
A formally neutral criterion can still create a disproportionate disadvantage for a protected group.
Example
AI gives lower scores to candidates with:
employment gaps;
unconventional educational histories;
certain geographic backgrounds.
The court may need to examine:
whether a protected group is disproportionately disadvantaged;
whether the criterion is genuinely neutral;
whether the employer has a legitimate objective;
whether the system is appropriate;
whether a less discriminatory method was available.
Principle
Algorithmic neutrality at the input level does not necessarily mean equality at the outcome level.
11. Case 5 — HK Danmark / Experian
HK Danmark, acting on behalf of Glennie Kristensen v Experian A/S
C-476/11, CJEU, 26 September 2013
The case concerned age-related differences in an occupational pension arrangement.
The CJEU examined the conditions under which age-based differences can be justified under Directive 2000/78. (Infocuria)
AI relevance
Employment algorithms frequently use age-related variables indirectly.
Examples:
years since graduation;
years of experience;
career progression;
salary history.
A company might argue that these are business-related variables rather than age criteria.
The legal analysis must nevertheless examine whether the criterion produces an age-related disadvantage and whether the relevant legal justification exists.
Principle
A neutral-looking employment criterion can require scrutiny where it creates age-related differential treatment.
12. Case 6 — SCHUFA
OQ v Land Hessen and SCHUFA Holding AG
C-634/21, CJEU, 7 December 2023
This is one of the most important modern European cases for AI-managed decision systems.
The case concerned automated credit scoring.
The CJEU examined Article 22 GDPR and the creation of a probability score concerning an individual's ability to meet financial obligations. (Infocuria)
The Court's reasoning is important because an automated score can fall within Article 22 where the score effectively determines the subsequent decision made by another actor.
Employment relevance
Consider:
AI gives an applicant a score of 42/100 → employer automatically rejects candidates below 50.
The legal question is not necessarily solved by saying:
“The employer made the final decision.”
If the employer mechanically relies upon the AI score, the scoring mechanism may become legally significant under Article 22.
Principle
A supposedly preliminary AI score may itself be legally significant when it effectively determines the final decision.
13. Case 7 — Dun & Bradstreet Austria
CK v Magistrat der Stadt Wien / Dun & Bradstreet Austria
C-203/22, CJEU, 27 February 2025
This case is particularly important for algorithmic explainability.
The CJEU considered Article 15(1)(h) GDPR concerning access to meaningful information about the logic involved in automated decision-making.
The Court held that the explanation must allow the person to understand the automated decision sufficiently to challenge it. (curia)
Importantly, the obligation does not simply mean handing over the entire source code.
The relevant explanation concerns the logic and factors actually applied to the person's case.
Employment application
Suppose an applicant receives:
“Your AI suitability score was 37%, therefore you were rejected.”
That may be inadequate if the individual cannot understand:
what information was used;
which factors materially affected the result;
how those factors contributed to the outcome;
whether inaccurate information was used.
Trade secrets
An employer or AI vendor cannot necessarily respond:
“The algorithm is confidential, so we disclose nothing.”
Dun & Bradstreet shows that trade-secret protection must be reconciled with data-subject rights and effective exercise of those rights. (Infocuria)
Principle
Commercial confidentiality does not automatically eliminate meaningful transparency.
14. Case 8 — Bărbulescu v Romania
Bărbulescu v Romania
ECtHR Grand Chamber, Application No. 61496/08, 5 September 2017
This case concerned employer monitoring of an employee's electronic communications.
The ECtHR held that workplace communications can fall within private life and correspondence under Article 8 ECHR, even where workplace rules restrict personal Internet use. (HUDOC)
The Court emphasised the need for an appropriate balancing exercise.
Relevant considerations include:
whether the employee was notified;
extent of monitoring;
degree of intrusion;
employer's legitimate reasons;
whether less intrusive alternatives existed;
consequences for the employee;
safeguards.
AI-managed workplace relevance
Modern AI management can monitor:
keystrokes;
emails;
messages;
location;
productivity;
mouse activity;
facial expressions;
voice;
working patterns;
behavioural indicators.
The fact that monitoring is performed by AI rather than a human supervisor does not remove Article 8 considerations.
Principle
AI-based workplace monitoring remains subject to privacy and proportionality requirements.
15. Case 9 — López Ribalda and Others v Spain
ECtHR Grand Chamber
Applications Nos. 1874/13 and 8567/13, 17 October 2019
The case involved covert video surveillance of supermarket employees.
The ECtHR examined whether workplace surveillance maintained a fair balance between the employer's interests and employees' privacy rights. It identified factors including:
prior notification;
extent of monitoring;
degree of intrusion;
legitimate justification;
availability of less intrusive measures;
consequences for employees;
appropriate safeguards. (HUDOC)
AI application
This reasoning can become relevant to:
AI video analytics;
automated attendance monitoring;
facial recognition;
behaviour prediction;
productivity surveillance;
AI-based misconduct detection.
The more intrusive the system, the stronger the justification and safeguards generally need to be.
16. Case-Law Summary Table
| Case | Main legal principle | AI-employment relevance |
|---|---|---|
| Feryn, C-54/07 | Recruitment discrimination and evidentiary burden | AI recruitment discrimination |
| Asociația Accept, C-81/12 | Evidence and burden of proof | Discriminatory algorithm evidence |
| Coleman, C-303/06 | Disability discrimination by association | AI proxy/associated characteristics |
| CHEZ, C-83/14 | Direct/indirect discrimination and proportionality | Neutral algorithmic criteria |
| HK Danmark, C-476/11 | Age differentiation and justification | Age-related algorithmic variables |
| SCHUFA, C-634/21 | Automated scoring can trigger Article 22 | AI hiring scores |
| Dun & Bradstreet, C-203/22 | Meaningful explanation of automated decisions | Explainability of AI employment decisions |
| Bărbulescu | Workplace monitoring/privacy | AI employee monitoring |
| López Ribalda | Proportionality of workplace surveillance | AI surveillance and video analytics |
17. Direct Discrimination vs Indirect Discrimination
Direct discrimination
The AI system explicitly uses a protected characteristic or an equivalent discriminatory criterion.
Example:
“Female candidates receive a 10% deduction.”
This creates a straightforward direct-discrimination question.
Indirect discrimination
The system applies a seemingly neutral criterion but disproportionately disadvantages a protected group.
Example:
The algorithm strongly rewards uninterrupted career histories.
This might disadvantage some groups more than others.
The employer may need to demonstrate that the criterion pursues a legitimate objective and satisfies the applicable proportionality/justification requirements.
18. Proxy Discrimination
Proxy discrimination is especially important in AI.
Suppose the employer removes:
“ethnic origin”
from the database.
The algorithm nevertheless uses:
postcode;
language;
school;
surname;
employment history;
and these variables produce a similar discriminatory effect.
The removal of the explicit protected variable therefore does not necessarily eliminate legal risk.
The CHEZ reasoning concerning apparently neutral measures and their discriminatory effects is particularly useful by analogy. (Infocuria)
19. Historical Bias
AI systems often learn from historical employment data.
Suppose a company historically hired:
80% men;
20% women.
An AI model trained on those decisions may learn:
“Past successful employees look more like the historical male workforce.”
The algorithm can then reproduce the historical pattern.
The AI Act itself recognises the possibility of historical discriminatory patterns being reproduced by employment AI. (EUR-Lex)
Therefore:
Historical employer practice → training data → algorithmic pattern → employment decision
can create a legally significant chain.
20. AI-Managed Promotion Decisions
The same legal principles apply after recruitment.
An AI system might rank employees for:
promotion;
leadership;
bonuses;
training;
international assignments.
For example:
AI predicts that Employee A has greater “leadership potential” because of communication patterns.
The employer should be able to examine:
what data generated the prediction;
whether the data is accurate;
whether protected characteristics or proxies affected the result;
whether the system was validated;
whether a human independently evaluated the employee.
21. AI-Managed Termination
Termination presents particularly serious risks.
An employer might use AI to identify:
“Employees likely to leave”
“Low-performing employees”
“Employees likely to become redundant”
The resulting score might influence dismissal.
Potential legal issues include:
1. Accuracy
Was the underlying information correct?
2. Discrimination
Did the model disproportionately identify a protected group?
3. Privacy
Was the information lawfully collected?
4. Automated decision-making
Was the termination effectively determined automatically?
5. Procedural fairness
Was the employee given an opportunity to challenge the assessment?
6. Contractual duties
Did the employer comply with contractual and statutory employment obligations?
22. AI Performance Management
AI performance-management systems may monitor:
number of emails;
response times;
keyboard activity;
meetings;
customer interactions;
sales;
productivity;
attendance;
breaks;
location.
A raw productivity score may be legally unreliable if it fails to consider:
job type;
disability;
caregiving responsibilities;
reasonable adjustments;
technical failures;
workload differences;
quality rather than quantity.
A system that measures employees identically may nevertheless produce unequal effects.
23. AI and Disability
Disability creates particular concerns.
AI recruitment or performance tools might incorrectly penalise:
speech differences;
atypical eye contact;
slower typing;
mobility limitations;
unusual communication patterns;
breaks required for medical reasons.
The Coleman case demonstrates the broad importance of the disability-discrimination principle under EU employment law. (Infocuria)
In practice, employers should therefore consider whether an AI system is compatible with reasonable accommodation obligations under applicable national and EU law.
24. AI Emotion Recognition
AI systems may attempt to infer:
emotional state;
stress;
enthusiasm;
confidence;
honesty;
engagement.
This is legally sensitive.
The AI Act specifically regulates/prohibits certain forms of emotion recognition in employment and other contexts, subject to the statutory exceptions and conditions.
Therefore, an employer should not assume that because an AI vendor commercially offers an “emotion analytics” tool, its deployment is lawful.
25. Employer Liability vs AI Vendor Liability
An important civil-law question is:
Who is liable when the AI makes the wrong employment decision?
Potential actors include:
Employer
Usually central because the employer makes or implements the employment decision.
AI developer
Potential liability may arise depending on the contractual arrangement, statutory duties and applicable product/service liability rules.
AI vendor
May have contractual, data-protection or other liability depending on its role.
Data provider
Potentially relevant if inaccurate or unlawfully obtained data is supplied.
Human decision-maker
May be relevant under national employment law where the human knowingly implements an unlawful decision.
26. Contractual Liability
An AI-management dispute may also become a contractual dispute.
Example:
An employer contracts with an AI company:
“The system must comply with applicable employment and data-protection law.”
The system repeatedly produces discriminatory outcomes.
The employer may potentially assert:
breach of contract;
indemnification;
warranty breach;
service-level breach;
negligence;
regulatory non-compliance.
The precise result depends on the contract and national law.
27. Tort/Delict Liability
An employee or applicant may potentially claim damages where national tort/delict law recognises:
unlawful conduct;
protected interest;
fault or strict liability where applicable;
damage;
causal connection.
Possible losses include:
lost employment opportunity;
lost wages;
reputational harm;
non-material damage;
privacy harm;
discriminatory harm.
But an unlawful AI system does not automatically mean that every person affected has an automatic damages claim. Causation, standing, applicable statutory remedy and proof of damage remain important.
28. Evidence in AI Employment Litigation
AI litigation creates unusual evidentiary problems.
A claimant may need:
| Evidence | Purpose |
|---|---|
| CV/application | Establish candidate characteristics |
| AI score | Demonstrate automated assessment |
| Ranking | Show relative treatment |
| Rejection message | Establish outcome |
| Model documentation | Understand system |
| Training-data documentation | Identify possible historical bias |
| Feature list | Identify variables |
| Audit reports | Examine discriminatory effects |
| Validation records | Test reliability |
| Human-review records | Determine whether review was genuine |
| System logs | Reconstruct decision |
| Version history | Identify model used |
| Threshold settings | Understand rejection mechanism |
| Vendor contract | Allocate responsibility |
| DPIA | Examine privacy assessment |
| Recruitment policy | Compare practice with stated rules |
29. Statistical Evidence
Statistical evidence can become particularly important.
Suppose:
| Group | Applicants | Rejected |
|---|---|---|
| Group A | 10,000 | 3,000 |
| Group B | 10,000 | 7,000 |
The figures may justify further investigation.
But statistical disparity by itself does not automatically establish unlawful discrimination.
The court may need to consider:
sample size;
relevant comparator;
job requirements;
data quality;
causal mechanism;
protected ground;
justification;
alternative explanations;
applicable national legislation.
30. Transparency Does Not Mean Source-Code Disclosure
A common misunderstanding is:
“If the employee has a right to an explanation, the company must provide the complete AI source code.”
That is not necessarily correct.
Dun & Bradstreet is important because the explanation must provide meaningful information enabling the person to understand and challenge the automated decision, while the law also recognises the protection of trade secrets. (Infocuria)
Therefore, the practical dispute may be:
How can sufficient information be disclosed to make the decision challengeable without unnecessarily exposing protected confidential technology?
31. Human Oversight and Rubber-Stamp Decisions
A company might claim:
“The decision was made by HR, not AI.”
Courts may need to examine what actually happened.
Important questions include:
Did HR examine the underlying evidence?
Could HR override the AI?
Did HR understand the score?
Was HR trained?
How frequently did HR disagree with the AI?
Did the employer investigate anomalous results?
Was there a meaningful appeal procedure?
If HR simply confirms an AI recommendation automatically, the distinction between AI recommendation and AI decision may become much less significant.
32. AI Bias Audit
Before deploying an AI employment system, an employer should consider testing:
Pre-deployment
accuracy;
discrimination;
accessibility;
privacy;
security;
data quality;
representative datasets.
During operation
rejection rates;
promotion rates;
performance scores;
false positives;
false negatives;
demographic disparities;
model drift.
After complaints
individual decision reconstruction;
data correction;
human reassessment;
model retraining;
suspension of problematic criteria.
33. Relationship Between AI Act and GDPR
These laws address different aspects.
| GDPR | AI Act |
|---|---|
| Personal-data protection | AI-system regulation |
| Automated decisions | High-risk AI governance |
| Profiling | Risk management |
| Data-subject rights | Provider/deployer obligations |
| Lawfulness of processing | AI-system compliance |
| Access/explanation | Technical/governance transparency |
| Data minimisation | Data governance |
| Article 22 | Human oversight and system obligations |
Compliance with one does not automatically establish compliance with the other.
An employer might have:
GDPR-compliant data processing
but still face an issue under:
AI Act employment-system requirements.
Similarly, an AI system might comply with technical AI governance requirements but still create an unlawful discriminatory employment decision.
34. European Human-Rights Dimension
Employment AI can also engage:
Article 8 ECHR — private life and correspondence;
Article 14 ECHR — non-discrimination;
Article 21 EU Charter — non-discrimination;
Article 47 EU Charter — effective judicial protection;
Article 31 EU Charter — fair and just working conditions;
Article 41 EU Charter where applicable to EU institutions.
The workplace-surveillance cases such as Bărbulescu and López Ribalda demonstrate the importance of proportionality and safeguards when technology intrudes into employees' private sphere. (HUDOC)
35. Main Civil-Law Causes of Action
An AI-managed employment dispute can potentially involve several causes simultaneously:
1. Discrimination
Direct or indirect discrimination.
2. Privacy violation
Unlawful monitoring or processing.
3. GDPR violation
Unlawful processing or automated decision-making.
4. Employment-law breach
Unlawful dismissal, promotion denial, pay decision, etc.
5. Contractual breach
Violation of employment or technology contracts.
6. Tort/delict
Damage caused by unlawful AI deployment.
7. Fundamental-rights violation
Privacy, equality and effective-remedy rights.
8. Regulatory enforcement
Data-protection or AI regulatory proceedings.
36. Practical Legal Test
For an AI employment dispute, a court can conceptually work through the following sequence:
Step 1 — Identify the AI
What exactly did the AI system do?
Step 2 — Identify the decision
Was it:
hiring;
rejection;
promotion;
pay;
task allocation;
monitoring;
discipline;
dismissal?
Step 3 — Identify the human role
Was the decision:
fully automated;
AI-assisted;
independently reviewed by a human?
Step 4 — Identify the data
What information did the system use?
Step 5 — Check accuracy
Was the information correct?
Step 6 — Check discrimination
Was there direct or indirect discrimination?
Step 7 — Check GDPR
Does Article 22 or another GDPR provision apply?
Step 8 — Check AI Act
Is the system within the employment-related high-risk framework?
Step 9 — Check proportionality
Was the system necessary and appropriately designed?
Step 10 — Check explanation
Can the affected person understand and challenge the decision?
Step 11 — Establish causation
Did the AI materially contribute to the employment harm?
Step 12 — Determine remedy
Possible remedies depend on the applicable law and may include:
compensation;
correction of data;
reconsideration;
access to information;
cessation of unlawful processing;
reversal/reassessment of an employment decision;
regulatory sanctions;
injunctions;
contractual damages.
37. Hypothetical Example
Suppose a European company uses AI to select candidates.
The system analyses:
CV;
employment history;
education;
language;
location;
interview video;
communication patterns.
It gives each applicant a score.
A candidate receives 42/100 and is rejected automatically.
The candidate discovers that:
career gaps were heavily penalised;
the system produced substantially lower scores for a particular protected group;
the employer did not explain the score;
HR did not independently review the rejection.
Potential issues could include:
Equality law → discriminatory criterion or effect.
GDPR → profiling/automated decision-making.
AI Act → employment-related high-risk AI requirements where applicable.
Privacy → interview/video processing.
Contract/employment law → consequences of the resulting decision.
Civil liability → damage and causation.
The claimant would then need to establish the relevant legal elements rather than merely proving:
“The AI made a mistake.”
38. Key Legal Principles
AI does not become the employer merely because it makes recommendations.
The employer generally remains legally relevant for employment decisions.
Automated scoring can have legal significance under GDPR Article 22.
Not every AI-assisted decision is automatically prohibited by Article 22.
Human oversight must be meaningful where the applicable law requires it.
A neutral algorithm can potentially produce discriminatory effects.
Removing explicit protected characteristics does not necessarily eliminate proxy discrimination.
Historical training data can reproduce historical discrimination.
AI employment systems require attention to data accuracy.
Employees retain privacy interests at work.
Workplace AI surveillance must be assessed for necessity and proportionality.
Trade secrets do not automatically eliminate meaningful explanation rights.
AI Act compliance and GDPR compliance are separate questions.
Regulatory non-compliance does not automatically establish a private damages claim.
Causation remains essential in civil liability.
39. Six Most Important Cases for Examination
If only six cases are required, the following provide a strong conceptual framework:
1. Feryn — C-54/07
Recruitment discrimination and burden of proof.
2. Asociația Accept — C-81/12
Recruitment discrimination, evidence and burden shifting.
3. CHEZ — C-83/14
Indirect discrimination, apparently neutral measures and proportionality.
4. SCHUFA — C-634/21
Automated scoring and GDPR Article 22.
5. Dun & Bradstreet — C-203/22
Meaningful explanation of automated decision-making.
6. Bărbulescu v Romania
Employee privacy and electronic workplace monitoring.
Additional authorities particularly useful for a broader answer are Coleman, HK Danmark, and López Ribalda. (Infocuria)
40. Short Revision Note
AI-Managed Employment Decision Systems = AI + Recruitment/Management + Employment Decision + Data Processing + Equality + Privacy + Human Oversight + Liability
Core legal areas
EU AI Act
GDPR
Article 22 GDPR
EU equality directives
Employment law
ECHR Article 8
EU Charter
Contract law
Tort/delict law
National procedural remedies
Core risks
algorithmic discrimination;
proxy discrimination;
historical bias;
inaccurate data;
automated rejection;
automated dismissal;
workplace surveillance;
biometric monitoring;
inadequate explanation;
inadequate human review;
vendor liability;
causation and damages.
Case-law keywords
Feryn → recruitment discrimination
Accept → burden of proof
Coleman → disability association
CHEZ → neutral measure/disparate effect
HK Danmark → age discrimination
SCHUFA → automated scoring
Dun & Bradstreet → explanation
Bărbulescu → workplace privacy
López Ribalda → surveillance proportionality
Final legal formula
AI Employment System + Employment Decision + Personal Data + Discriminatory/Unlawful Processing + Material Harm + Causal Connection = Potential Civil/Regulatory Liability
The central European legal question is therefore not simply whether AI was used, but how the system was designed, what data it processed, how it affected the worker, whether the decision was genuinely human-reviewed, whether equality and privacy requirements were respected, and whether the affected person has an effective means of understanding and challenging the outcome. The current EU framework expressly treats employment-related AI as an area requiring heightened scrutiny. (EUR-Lex)

comments