Algorithmic Decision-Making Disputes .
Algorithmic Decision-Making Disputes in Europe
1. Meaning and Scope
Algorithmic decision-making disputes arise when an automated or algorithm-assisted system makes, recommends, ranks, scores, or materially influences a decision affecting an individual or organisation, and the affected party alleges that the decision was unlawful, discriminatory, inaccurate, opaque, disproportionate, procedurally unfair, or caused compensable harm.
Examples include:
automated credit scoring and loan decisions;
insurance pricing and risk assessment;
recruitment and employee evaluation;
welfare and social-security eligibility;
tax-risk assessment;
immigration and border-control decisions;
policing and facial-recognition systems;
healthcare triage;
university admissions;
housing allocation;
fraud detection and account blocking;
automated content moderation;
algorithmic performance management.
There is no single European cause of action called an “algorithmic decision-making claim.” Instead, disputes are normally constructed from several overlapping legal regimes:
GDPR and data-protection law;
EU AI Act;
EU equality and anti-discrimination law;
consumer-protection law;
employment law;
administrative/public law;
contract and tort/delict law;
EU Charter fundamental rights;
ECHR rights;
sector-specific legislation.
A central principle is that the use of an algorithm does not normally transfer legal responsibility from the human or organisation using it to the software itself.
2. What Constitutes an Algorithmic Decision?
An algorithmic decision can exist on a spectrum:
A. Fully automated decision
The system makes the decision without meaningful human intervention.
Example:
A credit application is automatically rejected because an algorithm assigns the applicant a risk score below a predetermined threshold.
This raises the strongest questions under GDPR Article 22.
B. Algorithm-assisted decision
A human formally makes the decision but relies substantially on an algorithmic recommendation.
Example:
A welfare official accepts an algorithm's fraud-risk classification without independently examining the underlying evidence.
The existence of a nominal human decision does not necessarily eliminate concerns about automation.
C. Algorithmic ranking or scoring
The algorithm does not formally make the decision but determines the individual's position in a ranking.
Examples:
credit score;
recruitment score;
insurance risk score;
university admission ranking;
employee-performance score.
D. Algorithmic recommendation
The algorithm recommends an action while a human retains formal authority.
The legal question becomes whether the human review is genuine and meaningful, rather than merely formal.
3. Principal Legal Grounds for Disputes
A. Unlawful Automated Decision-Making
The most important GDPR provision is Article 22.
An individual may have protection where a decision:
is based solely on automated processing;
involves personal data;
produces legal effects or similarly significant effects.
The analysis becomes particularly important where an algorithm determines:
credit eligibility;
employment;
insurance;
welfare benefits;
access to housing;
financial services;
educational opportunities.
The existence of human involvement must be examined substantively rather than merely by asking whether someone clicked an approval button.
4. Right to Human Intervention
Where Article 22 applies, the GDPR framework can require safeguards including:
obtaining human intervention;
expressing one's point of view;
contesting the decision.
Human intervention should be capable of actually changing the result.
A person who merely confirms the algorithmic output without examining the underlying information may provide only nominal human oversight.
This becomes especially important in disputes involving:
automated fraud detection;
employment screening;
immigration decisions;
credit scoring;
welfare fraud systems.
5. Algorithmic Transparency
A person affected by an algorithmic decision may need information concerning:
whether automated processing occurred;
the purpose of the processing;
categories of data used;
existence of profiling;
significance of the processing;
foreseeable consequences;
relevant decision-making logic, where required;
available safeguards;
methods of challenging the decision.
However, transparency does not automatically mean disclosure of source code or model weights.
A court may instead focus on whether the person received enough meaningful information to understand and challenge the decision.
6. Accuracy and Data Quality
Algorithmic decisions can be challenged because the system relies on:
inaccurate personal data;
outdated information;
incomplete information;
erroneous identity matching;
incorrect assumptions;
inappropriate proxy variables;
statistically unreliable data.
For example, a fraud-detection system might associate an individual with fraudulent activity because of an incorrect identity match.
The legal issue is not necessarily whether the algorithm is mathematically sophisticated. It is whether the information and processing used to affect the person were lawful and sufficiently accurate.
7. Algorithmic Discrimination
Algorithms may produce discriminatory outcomes even where discriminatory variables are not explicitly programmed.
For example:
An employment algorithm excludes applicants from a particular group because it relies on historical employment data that reflects earlier discriminatory practices.
Potential legal theories include:
direct discrimination;
indirect discrimination;
disparate treatment;
discriminatory profiling;
discriminatory automated decision-making.
Particularly important protected grounds include:
sex;
race or ethnic origin;
disability;
age;
religion or belief;
sexual orientation;
nationality, where applicable;
other protected characteristics under applicable national and EU law.
8. Proxy Discrimination
An algorithm does not necessarily need to use a protected characteristic directly.
A seemingly neutral variable may act as a proxy.
For example:
postcode → proxy for ethnic or socioeconomic characteristics;
employment history → proxy for sex or disability;
purchasing behaviour → proxy for socioeconomic status;
language patterns → proxy for nationality or ethnicity.
This makes algorithmic discrimination particularly difficult to detect.
The appropriate analysis therefore looks at effects and causal structure, not merely at the list of variables explicitly programmed into the system.
9. Procedural Fairness
Algorithmic decision-making can also produce procedural disputes.
Affected persons may argue that:
they were not told an algorithm was being used;
they could not understand the basis of the decision;
they could not challenge the relevant information;
there was no meaningful human review;
the authority failed to consider individual circumstances;
reasons were inadequate;
the decision-maker improperly delegated discretion to the algorithm.
These issues are particularly important in public-sector decision-making.
An administrative authority generally cannot avoid its legal responsibilities simply by saying:
“The computer produced this result.”
10. Proportionality
Algorithmic systems must also be assessed against proportionality where fundamental rights are engaged.
The basic questions are:
Is the objective legitimate?
Is the algorithmic measure suitable to achieve it?
Is it necessary?
Does the interference imposed on the individual remain proportionate?
For example, an authority might legitimately seek to prevent fraud, but that does not automatically justify:
indiscriminate profiling;
excessive data collection;
permanent risk classification;
disproportionate surveillance;
decisions based exclusively on unreliable statistical correlations.
11. Fundamental Rights
Algorithmic decisions can engage the EU Charter of Fundamental Rights, including:
Article 7 — respect for private and family life;
Article 8 — protection of personal data;
Article 21 — non-discrimination;
Article 41 — good administration;
Article 47 — effective remedy and fair trial;
Article 52 — proportionality of limitations.
The ECHR can also become relevant, particularly:
Article 6 — fair trial;
Article 8 — privacy;
Article 13 — effective remedy;
Article 14 — non-discrimination.
12. Public-Sector Algorithmic Decisions
Government use of algorithms creates an especially important category of dispute.
Examples include:
welfare eligibility;
tax investigations;
immigration screening;
policing;
predictive policing;
public housing;
child-protection risk assessment;
public-sector recruitment;
healthcare allocation.
A public authority must normally remain within its statutory powers.
Possible claims include:
unlawful delegation;
failure to exercise discretion;
improper purpose;
inadequate reasons;
procedural unfairness;
discrimination;
disproportionate interference;
unlawful data processing;
failure to provide an effective remedy.
13. Private-Sector Algorithmic Decisions
Private organisations can also face claims involving:
Banks
Credit scoring and fraud detection.
Insurers
Risk classification and premium calculation.
Employers
Recruitment and performance management.
Platforms
Content ranking and account restrictions.
Retailers
Personalised pricing and profiling.
Technology companies
Recommendation and advertising systems.
Private parties may face contractual, tortious, consumer, data-protection, equality and competition claims.
14. Algorithmic Decision-Making and the EU AI Act
The EU AI Act introduces a risk-based regulatory framework for AI systems.
Particularly important are high-risk AI systems, including certain systems used in areas such as:
employment;
education;
essential services;
law enforcement;
migration;
administration of justice;
democratic processes.
Relevant governance concepts include:
risk management;
data governance;
technical documentation;
record keeping;
transparency;
human oversight;
accuracy;
robustness;
cybersecurity;
monitoring;
incident reporting.
An important distinction must be maintained:
AI Act compliance is not automatically a civil-liability defence.
Likewise:
Violation of the AI Act does not automatically establish every element of a damages claim.
The claimant may still need to establish the relevant duty, breach, causation and legally recognised damage under the applicable legal regime.
15. Major European Case Laws
There is still a relatively young body of direct European case law specifically concerning AI/algorithmic decisions. The following cases therefore include both directly relevant algorithmic authorities and important analogical authorities involving automated processing, discrimination, privacy and technological decision systems.
1. SCHUFA Holding AG — C-634/21
Case: SCHUFA Holding AG (Scoring), C-634/21
Court: CJEU
Date: 7 December 2023
This is one of the most important European authorities on algorithmic decision-making.
SCHUFA generated credit scores concerning individuals. Those scores could substantially influence whether third parties granted credit.
The CJEU considered the relationship between automated scoring and Article 22 GDPR.
Importance
The Court held, in substance, that where a score is generated through automated processing and the recipient of the score places decisive weight on that score in making the final decision, the scoring itself may fall within Article 22.
Significance for algorithmic disputes
A company cannot necessarily avoid Article 22 simply by saying:
“Our algorithm only produces a score; another company formally makes the decision.”
The practical role of the score matters.
This is a foundational principle for disputes involving:
credit scoring;
insurance;
recruitment;
fraud detection;
automated risk classification.
Direct relevance: Very high.
16. Google Spain — C-131/12
Case: Google Spain SL and Google Inc. v Agencia Española de Protección de Datos (AEPD) and Mario Costeja González, C-131/12
CJEU, 13 May 2014
The case concerned Google's search engine and the processing and presentation of personal information.
The CJEU recognised significant responsibilities associated with large-scale algorithmic processing of personal information.
Importance
The judgment demonstrated that an algorithmically operated system can have substantial legal consequences for individuals even where the underlying information originated elsewhere.
Relevance
It is important for:
search algorithms;
ranking systems;
reputational harm;
personal-data processing;
algorithmic indexing;
automated presentation of information.
Direct relevance: High.
17. Österreichische Post — C-300/21
Case: Österreichische Post AG v Österreichische Datenschutzbehörde, C-300/21
CJEU, 4 May 2023
The case concerned unlawful processing of personal data and compensation under Article 82 GDPR.
The CJEU clarified that:
infringement of GDPR rules alone does not automatically establish compensable damage;
actual material or non-material damage must be established;
compensation does not require a particular minimum seriousness threshold in the manner suggested by a de minimis approach.
Relevance to algorithmic decisions
A claimant whose personal data has been unlawfully processed by an algorithm may potentially claim compensation, but must connect the unlawful processing with legally recognised damage.
This is especially relevant to:
profiling;
automated classification;
behavioural prediction;
risk scoring;
algorithmic advertising.
Direct relevance: High.
18. NAP v VB — C-340/21
Case: VB v Natsionalna agentsia za prihodite (NAP), C-340/21
CJEU, 14 December 2023
The case concerned personal-data security following a cyberattack.
The CJEU considered whether fear concerning misuse of personal data could constitute non-material damage.
Importance
The Court recognised that a well-founded fear of misuse can, depending on the circumstances, constitute compensable non-material damage.
Algorithmic significance
The principle can become relevant where algorithmic systems:
classify individuals;
process sensitive information;
expose data through security failures;
create persistent risk profiles.
Direct relevance: Moderate to high.
19. CHEZ Razpredelenie Bulgaria — C-83/14
Case: CHEZ Razpredelenie Bulgaria AD v Komisia za zashtita ot diskriminatsia and Nikolay Nikolov, C-83/14
CJEU, 16 July 2015
The case concerned electricity meters installed in a particular area at a height substantially greater than usual.
The CJEU addressed indirect discrimination.
Importance for algorithms
A measure does not have to explicitly classify people according to a protected characteristic to raise discrimination concerns.
An apparently neutral system can produce a disproportionate disadvantage for a protected group.
Algorithmic application
The reasoning is highly relevant to:
recruitment algorithms;
credit scoring;
welfare algorithms;
insurance algorithms;
housing algorithms.
Direct relevance: Analogical but very important.
20. Test-Achats — C-236/09
Case: Association Belge des Consommateurs Test-Achats ASBL and Others v Conseil des ministres, C-236/09
CJEU, 1 March 2011
The CJEU considered the use of sex-based statistical distinctions in insurance.
The Court invalidated the relevant provision permitting continuing sex-based differentiation in insurance premiums and benefits.
Algorithmic significance
The case demonstrates that statistical justification does not automatically make discriminatory differentiation lawful.
This is particularly important because algorithmic systems frequently rely on statistical correlations.
An insurer cannot necessarily defend a discriminatory outcome merely by saying:
“The statistical data predicts different risks.”
Direct relevance: Analogical, particularly for algorithmic insurance.
21. Feryn — C-54/07
Case: Centrum voor gelijkheid van kansen en voor racismebestrijding v Firma Feryn NV, C-54/07
CJEU, 10 July 2008
The case involved discriminatory recruitment statements.
The Court recognised that discriminatory public statements concerning recruitment could contribute to establishing a discriminatory recruitment practice even without an identifiable individual victim.
Algorithmic significance
This is important for automated recruitment.
A recruitment algorithm may produce discriminatory outcomes because it:
reproduces historical employment patterns;
uses biased training data;
relies on discriminatory proxies;
systematically excludes a protected group.
The absence of a deliberately discriminatory programmer does not necessarily eliminate discrimination concerns.
Direct relevance: Analogical but highly relevant to AI recruitment systems.
22. Asociația Accept — C-81/12
Case: Asociația Accept v Consiliul Național pentru Combaterea Discriminării, C-81/12
CJEU, 25 April 2013
The CJEU addressed discriminatory statements in the employment context.
The Court's reasoning concerned the evidentiary significance of statements suggesting discriminatory recruitment practices.
Algorithmic relevance
It illustrates that discrimination can be established through evidence concerning the operation and environment surrounding a decision-making system, rather than requiring proof that an individual decision-maker consciously intended discrimination.
This can be relevant to algorithmic recruitment systems where:
management adopts discriminatory selection criteria;
historical datasets encode discrimination;
system outputs systematically disadvantage a group.
Direct relevance: Analogical.
23. HK Danmark — Joined Cases C-335/11 and C-337/11
Cases: HK Danmark v Dansk Almennyttigt Boligselskab and Dansk Arbejdsgiverforening v HK Danmark, Joined C-335/11 and C-337/11
CJEU, 11 April 2013
The cases concerned disability discrimination and the scope of reasonable accommodation.
Algorithmic significance
Automated employment systems may disadvantage persons with disabilities because they evaluate workers according to standardised criteria without considering reasonable accommodation.
For example:
An algorithm could classify an employee as unsuitable because of reduced productivity caused by a disability without accounting for legally required accommodation.
The case therefore supports a broader principle that automated uniformity cannot necessarily override equality obligations.
Direct relevance: Analogical.
24. Glukhin v Russia
Case: Glukhin v Russia, Application No. 11519/20
ECtHR, 4 July 2023
The case concerned the use of facial-recognition technology by Russian authorities.
The ECtHR found an interference with the applicant's Article 8 rights.
Importance
The case is highly significant for algorithmic governance because it demonstrates that:
facial recognition is a serious privacy intervention;
technological identification cannot be assessed purely as a technical matter;
authorities must have adequate legal justification and proportionality.
Algorithmic relevance
It is particularly important for:
facial recognition;
biometric identification;
police AI;
predictive surveillance;
automated identification systems.
Direct relevance: High for biometric algorithmic decisions.
25. S. and Marper v United Kingdom
Case: S. and Marper v United Kingdom, Applications Nos. 30562/04 and 30566/04
ECtHR Grand Chamber, 4 December 2008
The case concerned retention of DNA and fingerprints.
The ECtHR found an Article 8 violation in the UK's blanket retention approach.
Algorithmic significance
Modern algorithmic systems increasingly depend upon:
biometric databases;
facial templates;
fingerprints;
DNA;
identity databases.
The case establishes the importance of safeguards surrounding sensitive personal data.
Direct relevance: Analogical but foundational for biometric AI.
26. Big Brother Watch v United Kingdom
Case: Big Brother Watch and Others v United Kingdom, Applications Nos. 58170/13, 62322/14 and 24960/15
ECtHR Grand Chamber, 25 May 2021
The case concerned large-scale electronic surveillance.
The ECtHR examined safeguards governing interception and handling of communications.
Algorithmic significance
Modern surveillance frequently involves algorithmic:
filtering;
pattern recognition;
classification;
prioritisation;
risk assessment.
The case is therefore highly relevant to disputes concerning algorithmic surveillance.
The Court emphasised the importance of safeguards against abuse.
Direct relevance: Analogical but highly important.
27. López Ribalda v Spain
Case: López Ribalda and Others v Spain, Applications Nos. 1874/13 and 8567/13
ECtHR Grand Chamber, 17 October 2019
The case concerned covert workplace video surveillance.
The Court examined the balance between employees' privacy rights and the employer's legitimate interests.
Algorithmic significance
Modern employers increasingly use:
productivity algorithms;
behavioural monitoring;
facial recognition;
keystroke analytics;
automated performance scores;
workplace surveillance systems.
The case provides an important proportionality framework.
Direct relevance: Analogical.
28. Comparative Case-Law Table
| Case | Court | Main principle | Algorithmic relevance |
|---|---|---|---|
| SCHUFA, C-634/21 | CJEU | Automated scoring can fall within Article 22 | Very high |
| Google Spain, C-131/12 | CJEU | Responsibility for large-scale processing of personal information | High |
| Österreichische Post, C-300/21 | CJEU | GDPR damage and compensation | High |
| NAP, C-340/21 | CJEU | Non-material damage/fear after data breach | High |
| CHEZ, C-83/14 | CJEU | Indirect discrimination | High |
| Test-Achats, C-236/09 | CJEU | Statistical differentiation and equality | High |
| Feryn, C-54/07 | CJEU | Discriminatory recruitment evidence | High |
| Asociația Accept, C-81/12 | CJEU | Evidence of discriminatory recruitment | High |
| HK Danmark, C-335/11 & C-337/11 | CJEU | Disability discrimination/accommodation | Moderate–high |
| Glukhin v Russia | ECtHR | Facial recognition and Article 8 | Very high |
| S. and Marper v UK | ECtHR | Biometric-data safeguards | High |
| Big Brother Watch v UK | ECtHR | Surveillance safeguards | High |
| López Ribalda v Spain | ECtHR | Workplace technological surveillance | High |
29. Typical Algorithmic Decision-Making Claims
29.1 Unlawful Automated Decision Claim
The claimant argues:
“A decision producing significant effects was made solely or substantially through automated processing without the safeguards required by law.”
Potential remedy:
human review;
reconsideration;
suspension of decision;
correction;
deletion;
compensation.
29.2 Algorithmic Discrimination Claim
The claimant argues:
“The algorithm disproportionately disadvantages me or a protected group.”
Evidence may include:
selection rates;
error rates;
false-positive rates;
false-negative rates;
demographic outcome comparisons;
model variables;
proxy variables;
training data;
historical decisions.
Statistical disparity is important evidence but does not automatically prove unlawful discrimination. The applicable legal test must still be satisfied.
29.3 Algorithmic Privacy Claim
The claimant may argue:
unlawful profiling;
excessive data collection;
biometric processing;
unlawful tracking;
inadequate transparency;
unlawful retention;
unlawful sharing;
inadequate security.
29.4 Algorithmic Accuracy Claim
The claimant argues that the algorithm relied upon:
incorrect data;
outdated data;
wrongly attributed information;
erroneous risk classifications;
inaccurate identity matching.
This is especially significant in:
credit;
policing;
immigration;
employment;
welfare;
fraud detection.
29.5 Algorithmic Transparency Claim
The claimant may argue:
“I cannot meaningfully understand or challenge the decision because the organisation has not provided legally required information.”
The claimant may seek information concerning:
data used;
purpose;
logic/significance;
consequences;
decision-making structure;
human intervention;
review mechanisms.
29.6 Failure of Human Oversight
The claimant argues:
“The organisation claims that a human made the decision, but the human merely accepted the algorithmic recommendation.”
The strength of this claim depends heavily on the applicable legislation and facts.
Evidence might include:
internal policies;
system interfaces;
review logs;
override rates;
training materials;
employee instructions;
time available for review;
reasons recorded by the human decision-maker.
30. Liability of Different Actors
Algorithmic disputes can involve several defendants.
1. Algorithm developer
Potential responsibility for:
defective design;
inadequate testing;
foreseeable misuse;
software defects;
security vulnerabilities.
2. AI provider
Potential responsibility for:
model performance;
documentation;
warnings;
monitoring;
compliance obligations.
3. Deployer
The organisation using the system may be responsible for:
unlawful purpose;
inappropriate deployment;
inadequate human oversight;
unlawful data processing;
failure to monitor outcomes.
4. Professional user
A doctor, lawyer, banker, employer or other professional may have liability where professional duties require independent judgment.
5. Public authority
A government authority may face:
administrative-law challenges;
fundamental-rights claims;
GDPR claims;
state-liability claims.
31. Causation
Causation is often one of the hardest parts of algorithmic litigation.
A claimant may need to establish a connection between:
algorithm → decision → adverse consequence → legally recognised harm
For example:
Incorrect credit score → loan rejection → financial loss.
Or:
Biased recruitment algorithm → exclusion from selection → lost employment opportunity.
Or:
Incorrect fraud classification → account freezing → business interruption.
Complex systems can make it difficult to determine whether the algorithm actually caused the result or merely contributed to it.
32. Evidentiary Problems
Algorithmic disputes frequently involve information asymmetry.
The organisation may possess:
source code;
model architecture;
training-data documentation;
system logs;
audit reports;
validation studies;
risk assessments;
DPIAs;
model cards;
error-rate statistics;
internal communications.
The claimant may possess very little.
Consequently, procedural mechanisms concerning:
disclosure;
access to personal data;
expert evidence;
judicial inspection;
audit records;
technical documentation
can be extremely important.
33. Remedies
Depending upon the applicable legal regime, possible remedies include:
Corrective remedies
correction of inaccurate data;
reconsideration;
deletion;
restriction of processing.
Procedural remedies
human review;
explanation;
new decision;
access to records.
Injunctive remedies
stopping unlawful processing;
stopping discriminatory use;
suspending deployment.
Financial remedies
compensation;
damages;
reimbursement;
lost-income compensation.
Public-law remedies
annulment;
judicial review;
declaration of unlawfulness;
mandatory reconsideration.
34. Defences
Organisations may argue:
Legitimate objective
The algorithm serves a legitimate purpose such as:
fraud prevention;
public safety;
financial risk management;
cybersecurity.
Human involvement
The organisation may argue that a human actually made the decision.
The court may examine whether that intervention was genuinely substantive.
Statistical accuracy
The organisation may rely on the algorithm's overall accuracy.
But high overall accuracy does not necessarily answer questions of:
individual accuracy;
discrimination;
proportionality;
legality;
transparency.
Consent
Consent may sometimes be relevant, but it does not automatically legitimise every form of algorithmic decision-making.
Trade secrets
Organisations may resist complete disclosure of source code or model architecture.
That does not necessarily eliminate obligations to provide legally required meaningful information.
35. Important Distinction: Algorithmic Error ≠ Automatic Liability
A central principle in algorithmic litigation is:
An incorrect algorithmic result does not automatically establish civil liability.
The claimant may need to establish:
applicable legal duty;
unlawful processing, defect, breach or discriminatory treatment;
causal connection;
legally recognised damage or rights infringement;
appropriate remedy.
For negligence, additional questions such as foreseeability and reasonable precautions may arise.
For GDPR claims, the requirements are different from traditional negligence.
For discrimination claims, proof of discriminatory treatment and applicable burden-shifting rules become central.
36. A Practical Legal Test
A European algorithmic decision-making dispute can be analysed through the following sequence:
Step 1 — Identify the decision
What did the algorithm actually decide or influence?
Step 2 — Identify the actor
Who deployed or controlled it?
Step 3 — Identify the legal regime
Is the dispute primarily:
GDPR?
AI Act?
equality law?
employment law?
consumer law?
administrative law?
tort?
contract?
fundamental rights?
Step 4 — Determine the degree of automation
Was the decision:
fully automated;
algorithm-assisted;
human-controlled?
Step 5 — Examine the data
Was the information:
accurate?
relevant?
lawfully obtained?
sufficiently current?
Step 6 — Examine discrimination
Did the system create:
direct discrimination?
indirect discrimination?
disparate impact?
proxy discrimination?
Step 7 — Examine transparency
Was the affected person adequately informed?
Step 8 — Examine human oversight
Could a human genuinely reconsider and overturn the result?
Step 9 — Examine proportionality
Was the interference necessary and proportionate?
Step 10 — Establish harm and causation
What actual legal or economic consequence resulted?
Step 11 — Determine remedy
Should the decision be:
corrected;
reconsidered;
suspended;
annulled;
compensated?
37. Overall European Legal Position
The emerging European approach can be summarised as follows:
Algorithmic decision-making is not a legally autonomous zone outside ordinary legal responsibility.
An algorithm must operate within existing requirements concerning:
legality;
privacy;
data protection;
equality;
transparency;
human oversight;
proportionality;
procedural fairness;
consumer protection;
professional responsibility;
effective remedies.
The SCHUFA judgment is particularly important because it demonstrates that a supposedly “preliminary” algorithmic score can itself become legally significant where it effectively determines the subsequent decision.
The CHEZ, Test-Achats, Feryn and Asociația Accept cases provide important foundations for analysing algorithmic discrimination. Glukhin, S. and Marper, Big Brother Watch and López Ribalda provide important human-rights principles for biometric and surveillance technologies. Google Spain, Österreichische Post and NAP provide the data-protection and compensation framework.
Core formula
Algorithmic processing → legally relevant decision → applicable legal duty → breach/defect/discrimination/unlawful processing → adverse effect → causation → damage or rights infringement → appropriate remedy.
The most important practical lesson is that “the algorithm decided” is generally not a complete legal defence. The court can examine the organisation's choice to deploy the system, the data supplied to it, its design and validation, the degree of human oversight, the transparency provided to affected persons, and the consequences produced by its operation.

comments