Civil Law And Algorithmic System Error Compensation Claims In Europe .
Civil Law and Algorithmic System Error Compensation Claims in Europe
1. Introduction
Algorithmic system error compensation claims arise when an automated or AI-based system produces an incorrect result and that error causes legally recognisable harm to an individual or business.
Examples include:
an AI system making an incorrect medical recommendation;
an automated credit score wrongly denying a service;
an algorithm incorrectly detecting fraud;
an automated insurance system misclassifying risk;
an AI recruitment system wrongly rejecting an applicant;
an automated public-sector system incorrectly denying a benefit;
algorithmic pricing causing a financial loss;
an automated cybersecurity system incorrectly exposing personal data;
an AI decision-support system causing physical or economic injury.
European law does not currently have one universal civil-liability rule saying that every algorithmic error automatically gives rise to compensation. Instead, claims can arise under several overlapping regimes:
GDPR compensation;
contractual liability;
tort/delict liability;
medical negligence;
product liability;
consumer protection;
discrimination law;
public-authority liability;
fundamental-rights remedies.
The most developed EU case law currently concerns data-processing and automated decision-making, particularly under GDPR Article 82.
2. Basic Legal Formula
A simplified algorithmic compensation claim can be represented as:
Algorithmic error
↓
Unlawful conduct / breach of duty
↓
Causation
↓
Actual damage
↓
Compensation
The important point is that:
An algorithm being wrong is not, by itself, always enough to establish a damages claim.
The claimant normally has to connect the technical error to a legally recognised breach, damage and causation.
The CJEU has particularly clearly established this principle in Österreichische Post, C-300/21, and subsequently in MediaMarktSaturn, C-687/21. (curia)
3. Major Sources of European Liability
A. GDPR Article 82
Article 82 provides a right to compensation where processing of personal data infringes the GDPR and causes damage.
It is particularly important where an algorithm uses personal data.
Examples:
AI profiling;
automated scoring;
facial recognition;
health-data algorithms;
behavioural prediction;
automated fraud detection.
B. Contractual Liability
An algorithm may be supplied under a contract.
For example:
Company contracts with an AI provider to process insurance claims.
If the system systematically makes incorrect decisions, questions may arise concerning:
contractual performance;
warranties;
service levels;
professional standards;
limitation clauses;
indemnities;
causation.
The applicable national civil code determines many of these issues.
C. Tort/Delict
A claimant may argue that the defendant failed to exercise reasonable care in:
designing;
selecting;
testing;
deploying;
monitoring;
updating;
the algorithm.
4. Case Law 1 — Österreichische Post, C-300/21
Court: CJEU
Date: 4 May 2023
This is one of the most important European cases concerning compensation for algorithmic data processing.
Österreichische Post used an algorithm to analyse socio-demographic information and predict people's political affinities.
The claimant sought compensation for the consequences of this processing. (curia)
CJEU's important principles
The Court held that mere infringement of the GDPR does not automatically create a right to compensation.
Three elements are relevant:
GDPR infringement;
damage;
causal link between the infringement and the damage.
At the same time, the Court held that non-material damage does not have to exceed an additional minimum seriousness threshold merely to qualify for compensation. (Infocuria)
Importance for algorithmic claims
Suppose:
Algorithm incorrectly profiles an individual.
The claimant cannot simply say:
“The algorithm violated GDPR, therefore I automatically receive damages.”
The claimant must establish the legally relevant damage caused by the infringement.
Principle
Algorithmic illegality and compensable damage are separate questions.
5. Case Law 2 — MediaMarktSaturn, C-687/21
Court: CJEU
Date: 25 January 2024
This case involved personal data being mistakenly given to an unauthorised third party because of an employee error.
The CJEU reaffirmed that Article 82 GDPR requires:
infringement;
damage;
causal connection.
The right to compensation is compensatory rather than punitive. (Infocuria)
The Court also explained that merely fearing possible future misuse of information is not automatically sufficient where the circumstances do not establish actual non-material damage. (Infocuria)
Relevance to algorithms
Imagine:
AI system sends a customer's personal information to the wrong recipient.
The claimant may potentially have a GDPR claim, but the court must still examine:
whether GDPR was infringed;
what damage actually occurred;
whether that damage resulted from the infringement.
Important principle
Compensation under Article 82 is designed to compensate actual damage, not punish the controller.
6. Case Law 3 — Natsionalna agentsia za prihodite, C-340/21
Court: CJEU
Date: 14 December 2023
This case arose after a cyberattack on the Bulgarian National Revenue Agency exposed personal data of millions of people.
Individuals sought compensation for non-material damage, including fear that their information could be misused. (curia)
Importance for algorithmic systems
The case is particularly useful for automated systems because modern algorithms depend heavily on large datasets.
If an algorithmic system:
loses data;
exposes data;
incorrectly protects data;
permits unauthorised access;
the controller may face liability questions.
The Court recognised that fear of potential misuse of personal data can constitute non-material damage, where the relevant conditions are satisfied. (curia)
Example
AI healthcare database is breached → patient's medical information becomes vulnerable → patient develops genuine fear of misuse.
This can be legally different from simply proving that a technical security rule was violated.
7. Case Law 4 — Dun & Bradstreet Austria, C-203/22
Court: CJEU
Date: 27 February 2025
This case concerned automated credit assessment.
An automated scoring system was used to assess an individual's creditworthiness. The CJEU considered the right to obtain meaningful information about the logic involved in automated decision-making. (curia)
The Court emphasised that the explanation must enable the affected person to understand and challenge the automated decision.
Relevance to compensation
Suppose:
Algorithm produces an incorrect score → service denied → financial loss.
The individual may need information about:
data used;
relevant factors;
scoring logic;
accuracy;
role of human intervention.
Without sufficient information, proving the connection between the algorithmic error and the loss may be difficult.
Principle
Explainability can become an important evidentiary component of an algorithmic compensation claim.
The case also demonstrates that trade-secret protection does not automatically eliminate all rights to meaningful information. (curia)
8. Case Law 5 — SCHUFA, C-634/21
Court: CJEU
Date: 7 December 2023
This case concerned automated credit scoring.
The CJEU considered circumstances in which an automated probability score was used by another party to make a decision affecting an individual.
The Court's reasoning is particularly important for GDPR Article 22 and automated individual decision-making.
Relevance to compensation
Imagine:
AI calculates an incorrect risk score.
A company then relies heavily on that score and:
refuses the claimant's application.
Potential legal questions include:
Was the scoring lawful?
Was Article 22 engaged?
Was the information accurate?
Was the decision genuinely human?
Was the score determinative?
Did the claimant suffer financial or non-material damage?
Principle
An organisation cannot necessarily avoid automated-decision safeguards simply by placing a nominal human decision-maker at the end of an algorithmic process.
This makes SCHUFA particularly relevant to civil claims involving algorithmically generated outcomes.
9. Case Law 6 — Nowak v Data Protection Commissioner, C-434/16
Court: CJEU
Date: 20 December 2017
The CJEU adopted a broad understanding of what constitutes personal data.
The case concerned examination answers and examiner comments.
Importance for algorithmic compensation
Modern AI systems generate profiles and predictions from numerous pieces of information.
Examples:
risk scores;
behavioural profiles;
inferred characteristics;
probability assessments;
automated classifications.
The significance of Nowak is that information need not look like a conventional identity record to have personal-data significance.
Compensation relevance
If an algorithm generates or relies upon incorrect personal information, the claimant may potentially use GDPR rights concerning:
access;
rectification;
objection;
restriction;
automated decisions;
compensation.
10. Case Law 7 — Wirtschaftsakademie Schleswig-Holstein, C-210/16
Court: CJEU
Date: 5 June 2018
This case concerned responsibility for processing personal data in connection with a Facebook fan page.
The CJEU recognised circumstances in which multiple actors can have responsibility concerning personal-data processing.
Relevance to algorithmic systems
Modern AI systems frequently involve:
Data provider → AI developer → cloud provider → algorithm operator → final decision-maker
Suppose an algorithm makes an error.
The claimant may ask:
Who is legally responsible?
Potentially relevant actors include:
developer;
controller;
processor;
healthcare institution;
employer;
financial institution;
government authority.
Principle
Technological chains can create legally significant responsibility across multiple actors.
This is particularly important for AI systems operated through third-party vendors.
11. Case Law 8 — Breyer v Germany, C-582/14
Court: CJEU
Date: 19 October 2016
The CJEU considered whether dynamic IP addresses can constitute personal data.
The case is important because it illustrates the broader concept of identifiability in data law.
Algorithmic significance
Algorithms frequently combine information from multiple sources.
Individually harmless information may become identifying when combined with other datasets.
For example:
IP address + browsing behaviour + location + account information.
Therefore, an algorithmic system cannot necessarily avoid data-protection rules simply because one individual data element appears anonymous.
Compensation relevance
If algorithmic processing causes harm through data that can be connected to an identifiable individual, GDPR remedies may become relevant.
12. Case Law 9 — Österreichische Post and the Concept of Loss of Control
Later CJEU case law has clarified the significance of loss of control over personal data.
Loss of control can potentially constitute non-material damage, but the individual must establish that actual damage was suffered; the mere fact of an infringement is not enough. (Curia)
This is important for algorithmic systems because individuals may have little visibility into:
where their data went;
what profiles were created;
what predictions were generated;
which organisations received the output.
13. Case Law 10 — López Ribalda and Others v Spain
Court: ECtHR, Grand Chamber
Date: 17 October 2019
The case concerned covert workplace video surveillance and Article 8 privacy rights.
The ECtHR examined the proportionality of technological monitoring and the safeguards surrounding it. (HUDOC)
Relevance to algorithmic claims
Although this was not an AI case, it provides a useful human-rights framework for automated monitoring.
For example:
Employer uses AI employee-monitoring software → algorithm incorrectly identifies employee as violating company rules → employee suffers dismissal or reputational damage.
Potential questions include:
Was monitoring lawful?
Was it proportionate?
Was the employee adequately informed?
Was the data used for the stated purpose?
Was the automated conclusion accurate?
Were effective remedies available?
Principle
Technological efficiency does not remove proportionality and privacy requirements.
14. What Counts as an Algorithmic System Error?
There are several distinct categories.
1. Input-data error
Incorrect data are supplied.
Example:
Wrong age entered into medical-risk model.
2. Data-quality error
The database contains:
outdated information;
duplicated records;
incomplete records;
inaccurate classifications.
3. Programming error
The algorithm contains a technical defect.
4. Training-data error
The training dataset is insufficiently representative.
5. Model error
The mathematical model incorrectly predicts an outcome.
6. Deployment error
A properly designed model is used in circumstances for which it was not designed.
7. Human-automation error
A human incorrectly relies on an algorithm.
8. Monitoring error
The organisation fails to detect declining model performance.
9. Update error
The system continues using outdated assumptions or software.
10. Integration error
Several systems interact incorrectly.
For example:
hospital database → AI model → electronic records → automated treatment recommendation.
An error may occur at the interface rather than within the AI model itself.
15. Algorithmic Error Does Not Automatically Equal Negligence
This is an important civil-law principle.
Consider:
AI makes a prediction that turns out to be wrong.
That does not automatically establish negligence.
A court may ask:
Was the system reasonably selected?
Was it properly tested?
Were known risks addressed?
Were warnings provided?
Was human oversight appropriate?
Was the system used within its intended purpose?
Was the error reasonably foreseeable?
Did the error cause the claimant's loss?
The applicable standard depends upon the jurisdiction and the particular relationship between the parties.
16. Causation
Causation is usually one of the most difficult issues.
Consider:
Algorithm error
↓
Human accepts recommendation
↓
Wrong decision
↓
Claimant suffers loss
↓
Claimant seeks damages
The defendant may argue:
“The algorithm was wrong, but the loss was caused by the independent human decision.”
The claimant may respond:
“The human decision was based almost entirely on the erroneous algorithmic result.”
Therefore, courts may examine the causal contribution of the algorithm.
17. Counterfactual Analysis
Algorithmic litigation frequently requires a counterfactual question:
What would have happened if the algorithm had produced the correct result?
Example:
AI incorrectly rejects a loan.
The claimant argues:
Correct algorithmic assessment → loan approval → no financial loss.
The defendant may argue:
Even with the correct score, the loan would have been rejected for another reason.
The court therefore needs evidence concerning the hypothetical alternative outcome.
18. Material Damage
Possible economic losses include:
lost income;
lost business;
additional expenses;
denied financial opportunity;
unnecessary medical costs;
contractual losses;
property damage;
loss of investment;
additional administrative costs.
19. Non-Material Damage
Depending on the applicable legal regime, claims can involve:
distress;
anxiety;
reputational harm;
loss of privacy;
loss of control over personal data;
humiliation;
psychological injury.
The GDPR cases demonstrate that non-material damage can be compensable, but the claimant must establish actual damage rather than relying solely on the existence of a GDPR infringement. (curia)
20. Punitive vs Compensatory Damages
Under GDPR Article 82, compensation is fundamentally compensatory.
The CJEU expressly stated in MediaMarktSaturn that the compensation mechanism serves a compensatory function rather than a punitive one. (Infocuria)
Therefore:
Serious misconduct ≠ automatically unlimited damages.
The amount should correspond to the legally compensable damage under the applicable framework.
21. Algorithmic Bias and Compensation
Suppose:
Algorithm systematically produces worse results for Group A.
A claimant may potentially pursue:
Discrimination claim
If a protected characteristic is involved.
Data-protection claim
If personal data are unlawfully processed.
Tort claim
If the defendant breached an applicable duty of care.
Contract claim
If there is a contractual relationship.
Public-law claim
If a public authority made the discriminatory decision.
One algorithmic event can therefore create multiple legal causes of action.
22. Human Oversight
A central question is whether the algorithm merely:
assisted
or actually:
determined
the decision.
Example 1 — Assistance
AI recommends:
“High fraud risk.”
Human investigator examines the evidence independently.
Example 2 — De facto automation
AI recommends:
“High fraud risk.”
Company policy automatically rejects the customer's claim.
The second situation creates substantially greater concerns about automated decision-making and responsibility.
The reasoning in SCHUFA and Dun & Bradstreet Austria is particularly relevant here. (curia)
23. Explainability as Evidence
A claimant may need to know:
what data were used;
what factors influenced the output;
what model version was used;
whether the model had known limitations;
whether human intervention occurred.
Dun & Bradstreet Austria is especially important because the CJEU emphasised meaningful information enabling the individual to understand and challenge the automated decision. (curia)
Thus, explainability can have two functions:
Legal right
and
Evidence for a compensation claim.
24. Trade Secrets
AI companies frequently argue:
“Our algorithm is a trade secret.”
That does not automatically mean that the affected individual receives no information.
The CJEU's Dun & Bradstreet Austria judgment demonstrates that the right to meaningful information and protection of trade secrets have to be reconciled within the legal framework. (Curia)
The objective is not necessarily to disclose the entire source code.
The relevant question is whether sufficient information can be provided to allow the person to understand and challenge the decision.
25. Evidence in Algorithmic Compensation Claims
Important evidence can include:
Technical evidence
source code where legally obtainable;
model documentation;
model cards;
validation reports;
testing records;
audit reports;
error rates;
performance metrics.
Data evidence
input data;
training data;
data-quality records;
correction history.
Operational evidence
logs;
timestamps;
model version;
human overrides;
warnings.
Legal evidence
contracts;
terms of service;
internal policies;
risk assessments;
impact assessments.
26. Expert Evidence
Algorithmic litigation frequently requires two types of expert.
Technical expert
Explains:
how the model worked;
whether it was defective;
accuracy;
bias;
validation;
foreseeable limitations.
Domain expert
Explains the underlying activity.
For example:
doctor for medical AI;
banker for financial algorithms;
engineer for industrial AI;
accountant for financial software.
The court must connect technical error with real-world damage.
27. Responsibility of AI Developers
A developer may potentially face liability where it:
knowingly supplies defective software;
provides inadequate warnings;
makes false performance claims;
fails to correct known defects;
designs a system for an unsuitable purpose;
violates contractual obligations.
But the developer is not automatically liable merely because the system produced a wrong prediction.
The applicable product-liability and national civil-law rules must be examined.
28. Responsibility of Users
The organisation deploying the algorithm may have independent duties.
For example, a hospital may be responsible for:
selecting an appropriate tool;
testing it;
training employees;
monitoring performance;
maintaining safeguards;
ensuring appropriate human oversight.
Thus:
Developer liability and user liability can coexist.
29. Vendor Contracts
AI contracts should ideally address:
accuracy requirements;
permitted uses;
model updates;
cybersecurity;
audit rights;
incident notification;
data protection;
intellectual property;
liability allocation;
indemnification;
insurance;
termination;
preservation of logs.
These contractual provisions can become important in subsequent civil litigation.
30. Public-Sector Algorithmic Errors
Government agencies increasingly use algorithms for:
welfare;
taxation;
immigration;
policing;
healthcare;
public benefits;
fraud detection.
If an algorithm wrongly denies a benefit, the claimant may potentially have:
administrative-law remedies;
constitutional/fundamental-rights claims;
GDPR remedies;
statutory compensation;
national tort/public-authority liability.
The exact remedy differs between European jurisdictions.
31. Algorithmic System Errors and Product Liability
Where AI forms part of a product, product-liability principles can become important.
Potential questions include:
Was the product defective?
Was the software part of the product?
Was the defect foreseeable?
Were warnings adequate?
Was the product updated appropriately?
Did the defect cause injury?
Which economic operator is responsible?
This is especially relevant to:
autonomous vehicles;
medical devices;
industrial robots;
smart machinery;
connected consumer products.
32. Algorithmic Medical Error
Suppose:
AI diagnostic system incorrectly classifies cancer as benign.
The patient suffers because treatment is delayed.
Potential claims could involve:
medical negligence;
hospital liability;
product liability;
contractual liability;
GDPR;
professional liability.
The key causal question is:
Would timely treatment probably have produced a materially better outcome?
This requires medical expert evidence in addition to technical evidence.
33. Algorithmic Financial Error
Suppose:
Automated trading algorithm malfunctions and sells assets at an incorrect price.
Potential losses include:
direct trading loss;
lost opportunity;
transaction costs;
consequential loss.
Potential defendants could include:
trader;
investment firm;
software developer;
exchange participant;
technology provider.
Contractual terms and applicable financial-market rules become particularly important.
34. Algorithmic Employment Error
Example:
AI recruitment system incorrectly rejects an applicant because of a biased model.
Potential claims may involve:
discrimination;
GDPR;
employment law;
tort/delict;
contractual obligations where applicable.
The claimant may seek:
compensation;
correction of data;
reconsideration;
other statutory remedies.
35. Algorithmic Consumer Error
Example:
Automated consumer system incorrectly identifies a customer as fraudulent and freezes their account.
Potential consequences:
inability to access money;
missed payments;
reputational harm;
contractual losses.
The legal analysis can involve:
consumer law;
contract law;
GDPR;
financial regulation;
national civil liability.
36. Algorithmic Error and Foreseeability
Foreseeability is often important in civil liability.
The question may be:
Could a reasonable operator have anticipated this type of failure?
If an organisation knew that:
the model performed poorly on certain groups;
data were incomplete;
the model was outdated;
false positives were frequent;
continued deployment may create stronger arguments concerning breach of duty.
37. Model Drift and Continuing Liability
An algorithm may initially perform well.
Later:
environment changes → model becomes inaccurate.
Examples:
disease characteristics change;
consumer behaviour changes;
economic conditions change;
fraud techniques evolve;
regulations change.
A defendant may therefore need continuing monitoring rather than one-time validation.
38. Multiple Causes of Damage
An algorithmic injury can have several causes.
Example:
Defective training data
poor model design
inadequate human review
failure to update
=
wrong decision
The court may need to determine:
primary cause;
contributing causes;
concurrent causes;
intervening causes;
proportion of responsibility.
National law determines the precise approach.
39. Limitation and Remoteness
Even where an algorithm causes some loss, not every consequence necessarily becomes recoverable.
Courts may consider:
foreseeability;
remoteness;
directness;
mitigation;
contributory negligence;
contractual limitations.
These are largely matters of national civil law.
40. Mitigation of Loss
The claimant may also have a duty to mitigate damage where national law recognises such a principle.
Example:
AI incorrectly rejects an insurance claim.
If the claimant has another legally available mechanism for obtaining urgent treatment but unreasonably fails to use it, the defendant may argue that some subsequent losses were avoidable.
Again, the exact rule depends on the jurisdiction.
41. Algorithmic Error and Data Accuracy
Data accuracy is particularly important.
An organisation may argue:
“The algorithm functioned correctly.”
But that may not answer the legal question if:
The algorithm correctly processed incorrect data.
For example:
Wrong input → correct calculation → wrong result.
The system may therefore be technically functioning while still producing an unacceptable decision.
42. Algorithmic Error and Data Protection
There are two separate possibilities.
Type 1 — Technical algorithm error
The algorithm calculates incorrectly.
Type 2 — GDPR error
The organisation unlawfully processes personal data.
They may occur simultaneously, but they are legally distinct.
Therefore:
Not every algorithmic error is a GDPR violation, and not every GDPR violation is an algorithmic error.
43. Algorithmic Error and Non-Material Damage
European GDPR jurisprudence increasingly recognises that damage need not always be financial.
Potential examples include:
loss of control;
genuine fear of misuse;
distress;
privacy interference.
But the CJEU has consistently required actual damage in addition to the infringement itself.
This distinction is particularly clear when comparing Österreichische Post, Natsionalna agentsia za prihodite, and MediaMarktSaturn. (curia)
44. Consolidated Case-Law Table
| Case | Court | Key principle | Algorithmic compensation relevance |
|---|---|---|---|
| Österreichische Post, C-300/21 | CJEU | Infringement alone does not create compensation; damage and causation required | Core GDPR damages rule |
| MediaMarktSaturn, C-687/21 | CJEU | Compensation is compensatory; actual damage required | Data-processing error |
| Natsionalna agentsia za prihodite, C-340/21 | CJEU | Fear of misuse can constitute non-material damage in appropriate circumstances | Data-security/AI systems |
| Dun & Bradstreet Austria, C-203/22 | CJEU | Meaningful information about automated decision logic | Proof and explainability |
| SCHUFA, C-634/21 | CJEU | Automated scoring can engage Article 22 | Automated decision errors |
| Nowak, C-434/16 | CJEU | Broad concept of personal data | Algorithmic profiles |
| Wirtschaftsakademie, C-210/16 | CJEU | Multiple actors can have responsibility in data processing | AI vendor/controller chains |
| Breyer, C-582/14 | CJEU | Dynamic IP address can constitute personal data | Identifiability and algorithmic data |
| López Ribalda v Spain | ECtHR | Technology-based monitoring must satisfy privacy/proportionality requirements | Automated surveillance |
| Calvelli and Ciglio v Italy | ECtHR | Effective healthcare/legal framework | Medical AI liability |
45. Important Distinction: Direct vs Related Cases
It is important not to describe all of these as cases that directly decided AI compensation claims.
Directly relevant to automated/data systems
SCHUFA
Dun & Bradstreet Austria
Österreichische Post
MediaMarktSaturn
Natsionalna agentsia za prihodite
Broader data/technology authorities
Nowak
Wirtschaftsakademie
Breyer
López Ribalda
These cases provide the legal principles that can be applied to newer algorithmic disputes.
There is still relatively limited European appellate case law involving a standalone AI system error followed by a conventional civil damages judgment.
46. Practical Test for an Algorithmic Compensation Claim
A claimant can analyse the case through the following questions:
Step 1 — What did the algorithm do?
Identify the exact automated output.
Step 2 — Was the output wrong?
Identify the technical or factual error.
Step 3 — Who controlled the system?
Identify:
developer;
operator;
controller;
employer;
healthcare provider;
government authority.
Step 4 — Was there a legal duty?
Possible sources:
contract;
GDPR;
tort;
professional law;
product liability;
equality law;
public law.
Step 5 — Was there a breach?
Examples:
inadequate testing;
inaccurate data;
inadequate security;
unlawful profiling;
discriminatory design.
Step 6 — Was there damage?
Separate:
economic;
physical;
non-material;
reputational damage.
Step 7 — Was the algorithmic error the cause?
Establish the causal chain.
Step 8 — What remedy is available?
Possible remedies include:
compensation;
correction;
deletion;
restriction;
reconsideration;
injunction;
contractual remedies.
47. Hypothetical Example
Consider an AI insurance system.
The system uses historical data to calculate insurance risk.
Because of a database error, the claimant is assigned an abnormally high risk score.
The insurer automatically refuses coverage.
The claimant suffers financial loss.
The legal analysis could be:
Incorrect data
↓
Incorrect algorithmic score
↓
Automated adverse decision
↓
Contractual/legislative breach
↓
Financial damage
↓
Causation
↓
Compensation claim
If personal data were unlawfully processed, GDPR remedies could exist alongside national civil-law remedies.
48. Major Challenges in Litigation
1. Black-box problem
The claimant may not understand the algorithm.
2. Information asymmetry
The defendant often possesses the relevant technical records.
3. Causation
The algorithm may be only one of several causes.
4. Multiple defendants
Developer and user may both be involved.
5. Model evolution
The system may have changed after the disputed decision.
6. Statistical complexity
The claimant may need to establish that the output was materially erroneous.
7. Confidentiality
Source code and trade secrets can complicate disclosure.
8. Cross-border operation
The developer, cloud provider and user may be located in different countries.
49. Emerging European Approach
The emerging European approach can be summarised as:
Algorithmic accountability
data protection
ordinary civil liability
consumer protection
product safety
fundamental rights
rather than creating a completely separate “AI civil law”.
The key development is that courts are increasingly capable of treating automated systems as part of an ordinary legal chain of responsibility.
50. Core Legal Principles
Principle 1
An algorithm is a tool, not an independent legal person.
Principle 2
A technical error does not automatically establish civil liability.
Principle 3
Compensation generally requires legally recognised damage and causation.
Principle 4
GDPR Article 82 is an important independent compensation mechanism where personal-data processing is involved.
Principle 5
Non-material damage can be compensable, but the claimant must establish actual damage.
Principle 6
Automated decision-making may trigger additional GDPR rights.
Principle 7
Meaningful explanation can be important for challenging an automated decision.
Principle 8
Human involvement must be examined substantively, not merely formally.
Principle 9
Developer, operator and controller responsibility can potentially overlap.
Principle 10
National civil law remains crucial for many claims involving physical or purely economic losses.
51. Short Exam Answer
Algorithmic system error compensation claims in Europe concern situations where an AI or automated system produces an incorrect result that causes legally recognised harm. European law does not provide a single universal cause of action for every algorithmic error. Claims may instead arise under GDPR, contract law, tort/delict, product liability, consumer law, discrimination law and public-authority liability.
The leading CJEU authority is Österreichische Post, C-300/21, which establishes that a GDPR infringement alone does not create a compensation right; infringement, damage and causal connection are required. MediaMarktSaturn, C-687/21 confirms the compensatory rather than punitive character of GDPR damages. Natsionalna agentsia za prihodite, C-340/21 recognises that fear of potential misuse of personal data can constitute non-material damage in appropriate circumstances. Dun & Bradstreet Austria, C-203/22 establishes important principles concerning meaningful information about automated decision-making, while SCHUFA, C-634/21 concerns automated scoring and Article 22 GDPR. Nowak, C-434/16, Wirtschaftsakademie, C-210/16, and Breyer, C-582/14 provide broader principles concerning personal data and responsibility.
The central civil-law question is therefore:
Was there a legally relevant error or breach, did it cause actual damage, and can the claimant establish a causal connection between the algorithmic system and that damage?
52. Ultra-Short Revision
Algorithmic System Error Claim =
Algorithmic error
↓
Legal breach/duty
↓
Actual damage
↓
Causation
↓
Compensation
Remember the cases:
Österreichische Post → infringement ≠ automatic damages
MediaMarktSaturn → compensation is compensatory
Natsionalna agentsia za prihodite → fear/misuse and non-material damage
Dun & Bradstreet Austria → meaningful explanation
SCHUFA → automated scoring / Article 22
Nowak → broad personal-data concept
Wirtschaftsakademie → responsibility of multiple data actors
Breyer → identifiability and personal data
López Ribalda → technology + privacy
Calvelli and Ciglio → institutional healthcare responsibility
One-line principle:
European civil liability for algorithmic errors focuses not simply on whether an algorithm was wrong, but on the legal duty governing its use, the actual damage suffered, the causal connection, and the identity of the responsible actor.

comments