Algorithmic Decision-Making Disputes .

Algorithmic Decision-Making Disputes in Europe

1. Meaning and Scope

Algorithmic decision-making disputes arise when an automated or algorithm-assisted system makes, recommends, ranks, scores, or materially influences a decision affecting an individual or organisation, and the affected party alleges that the decision was unlawful, discriminatory, inaccurate, opaque, disproportionate, procedurally unfair, or caused compensable harm.

Examples include:

automated credit scoring and loan decisions;

insurance pricing and risk assessment;

recruitment and employee evaluation;

welfare and social-security eligibility;

tax-risk assessment;

immigration and border-control decisions;

policing and facial-recognition systems;

healthcare triage;

university admissions;

housing allocation;

fraud detection and account blocking;

automated content moderation;

algorithmic performance management.

There is no single European cause of action called an “algorithmic decision-making claim.” Instead, disputes are normally constructed from several overlapping legal regimes:

GDPR and data-protection law;

EU AI Act;

EU equality and anti-discrimination law;

consumer-protection law;

employment law;

administrative/public law;

contract and tort/delict law;

EU Charter fundamental rights;

ECHR rights;

sector-specific legislation.

A central principle is that the use of an algorithm does not normally transfer legal responsibility from the human or organisation using it to the software itself.

2. What Constitutes an Algorithmic Decision?

An algorithmic decision can exist on a spectrum:

A. Fully automated decision

The system makes the decision without meaningful human intervention.

Example:

A credit application is automatically rejected because an algorithm assigns the applicant a risk score below a predetermined threshold.

This raises the strongest questions under GDPR Article 22.

B. Algorithm-assisted decision

A human formally makes the decision but relies substantially on an algorithmic recommendation.

Example:

A welfare official accepts an algorithm's fraud-risk classification without independently examining the underlying evidence.

The existence of a nominal human decision does not necessarily eliminate concerns about automation.

C. Algorithmic ranking or scoring

The algorithm does not formally make the decision but determines the individual's position in a ranking.

Examples:

credit score;

recruitment score;

insurance risk score;

university admission ranking;

employee-performance score.

D. Algorithmic recommendation

The algorithm recommends an action while a human retains formal authority.

The legal question becomes whether the human review is genuine and meaningful, rather than merely formal.

3. Principal Legal Grounds for Disputes

A. Unlawful Automated Decision-Making

The most important GDPR provision is Article 22.

An individual may have protection where a decision:

is based solely on automated processing;

involves personal data;

produces legal effects or similarly significant effects.

The analysis becomes particularly important where an algorithm determines:

credit eligibility;

employment;

insurance;

welfare benefits;

access to housing;

financial services;

educational opportunities.

The existence of human involvement must be examined substantively rather than merely by asking whether someone clicked an approval button.

4. Right to Human Intervention

Where Article 22 applies, the GDPR framework can require safeguards including:

obtaining human intervention;

expressing one's point of view;

contesting the decision.

Human intervention should be capable of actually changing the result.

A person who merely confirms the algorithmic output without examining the underlying information may provide only nominal human oversight.

This becomes especially important in disputes involving:

automated fraud detection;

employment screening;

immigration decisions;

credit scoring;

welfare fraud systems.

5. Algorithmic Transparency

A person affected by an algorithmic decision may need information concerning:

whether automated processing occurred;

the purpose of the processing;

categories of data used;

existence of profiling;

significance of the processing;

foreseeable consequences;

relevant decision-making logic, where required;

available safeguards;

methods of challenging the decision.

However, transparency does not automatically mean disclosure of source code or model weights.

A court may instead focus on whether the person received enough meaningful information to understand and challenge the decision.

6. Accuracy and Data Quality

Algorithmic decisions can be challenged because the system relies on:

inaccurate personal data;

outdated information;

incomplete information;

erroneous identity matching;

incorrect assumptions;

inappropriate proxy variables;

statistically unreliable data.

For example, a fraud-detection system might associate an individual with fraudulent activity because of an incorrect identity match.

The legal issue is not necessarily whether the algorithm is mathematically sophisticated. It is whether the information and processing used to affect the person were lawful and sufficiently accurate.

7. Algorithmic Discrimination

Algorithms may produce discriminatory outcomes even where discriminatory variables are not explicitly programmed.

For example:

An employment algorithm excludes applicants from a particular group because it relies on historical employment data that reflects earlier discriminatory practices.

Potential legal theories include:

direct discrimination;

indirect discrimination;

disparate treatment;

discriminatory profiling;

discriminatory automated decision-making.

Particularly important protected grounds include:

sex;

race or ethnic origin;

disability;

age;

religion or belief;

sexual orientation;

nationality, where applicable;

other protected characteristics under applicable national and EU law.

8. Proxy Discrimination

An algorithm does not necessarily need to use a protected characteristic directly.

A seemingly neutral variable may act as a proxy.

For example:

postcode → proxy for ethnic or socioeconomic characteristics;

employment history → proxy for sex or disability;

purchasing behaviour → proxy for socioeconomic status;

language patterns → proxy for nationality or ethnicity.

This makes algorithmic discrimination particularly difficult to detect.

The appropriate analysis therefore looks at effects and causal structure, not merely at the list of variables explicitly programmed into the system.

9. Procedural Fairness

Algorithmic decision-making can also produce procedural disputes.

Affected persons may argue that:

they were not told an algorithm was being used;

they could not understand the basis of the decision;

they could not challenge the relevant information;

there was no meaningful human review;

the authority failed to consider individual circumstances;

reasons were inadequate;

the decision-maker improperly delegated discretion to the algorithm.

These issues are particularly important in public-sector decision-making.

An administrative authority generally cannot avoid its legal responsibilities simply by saying:

“The computer produced this result.”

10. Proportionality

Algorithmic systems must also be assessed against proportionality where fundamental rights are engaged.

The basic questions are:

Is the objective legitimate?

Is the algorithmic measure suitable to achieve it?

Is it necessary?

Does the interference imposed on the individual remain proportionate?

For example, an authority might legitimately seek to prevent fraud, but that does not automatically justify:

indiscriminate profiling;

excessive data collection;

permanent risk classification;

disproportionate surveillance;

decisions based exclusively on unreliable statistical correlations.

11. Fundamental Rights

Algorithmic decisions can engage the EU Charter of Fundamental Rights, including:

Article 7 — respect for private and family life;

Article 8 — protection of personal data;

Article 21 — non-discrimination;

Article 41 — good administration;

Article 47 — effective remedy and fair trial;

Article 52 — proportionality of limitations.

The ECHR can also become relevant, particularly:

Article 6 — fair trial;

Article 8 — privacy;

Article 13 — effective remedy;

Article 14 — non-discrimination.

12. Public-Sector Algorithmic Decisions

Government use of algorithms creates an especially important category of dispute.

Examples include:

welfare eligibility;

tax investigations;

immigration screening;

policing;

predictive policing;

public housing;

child-protection risk assessment;

public-sector recruitment;

healthcare allocation.

A public authority must normally remain within its statutory powers.

Possible claims include:

unlawful delegation;

failure to exercise discretion;

improper purpose;

inadequate reasons;

procedural unfairness;

discrimination;

disproportionate interference;

unlawful data processing;

failure to provide an effective remedy.

13. Private-Sector Algorithmic Decisions

Private organisations can also face claims involving:

Banks

Credit scoring and fraud detection.

Insurers

Risk classification and premium calculation.

Employers

Recruitment and performance management.

Platforms

Content ranking and account restrictions.

Retailers

Personalised pricing and profiling.

Technology companies

Recommendation and advertising systems.

Private parties may face contractual, tortious, consumer, data-protection, equality and competition claims.

14. Algorithmic Decision-Making and the EU AI Act

The EU AI Act introduces a risk-based regulatory framework for AI systems.

Particularly important are high-risk AI systems, including certain systems used in areas such as:

employment;

education;

essential services;

law enforcement;

migration;

administration of justice;

democratic processes.

Relevant governance concepts include:

risk management;

data governance;

technical documentation;

record keeping;

transparency;

human oversight;

accuracy;

robustness;

cybersecurity;

monitoring;

incident reporting.

An important distinction must be maintained:

AI Act compliance is not automatically a civil-liability defence.

Likewise:

Violation of the AI Act does not automatically establish every element of a damages claim.

The claimant may still need to establish the relevant duty, breach, causation and legally recognised damage under the applicable legal regime.

15. Major European Case Laws

There is still a relatively young body of direct European case law specifically concerning AI/algorithmic decisions. The following cases therefore include both directly relevant algorithmic authorities and important analogical authorities involving automated processing, discrimination, privacy and technological decision systems.

1. SCHUFA Holding AG — C-634/21

Case: SCHUFA Holding AG (Scoring), C-634/21
Court: CJEU
Date: 7 December 2023

This is one of the most important European authorities on algorithmic decision-making.

SCHUFA generated credit scores concerning individuals. Those scores could substantially influence whether third parties granted credit.

The CJEU considered the relationship between automated scoring and Article 22 GDPR.

Importance

The Court held, in substance, that where a score is generated through automated processing and the recipient of the score places decisive weight on that score in making the final decision, the scoring itself may fall within Article 22.

Significance for algorithmic disputes

A company cannot necessarily avoid Article 22 simply by saying:

“Our algorithm only produces a score; another company formally makes the decision.”

The practical role of the score matters.

This is a foundational principle for disputes involving:

credit scoring;

insurance;

recruitment;

fraud detection;

automated risk classification.

Direct relevance: Very high.

16. Google Spain — C-131/12

Case: Google Spain SL and Google Inc. v Agencia Española de Protección de Datos (AEPD) and Mario Costeja González, C-131/12
CJEU, 13 May 2014

The case concerned Google's search engine and the processing and presentation of personal information.

The CJEU recognised significant responsibilities associated with large-scale algorithmic processing of personal information.

Importance

The judgment demonstrated that an algorithmically operated system can have substantial legal consequences for individuals even where the underlying information originated elsewhere.

Relevance

It is important for:

search algorithms;

ranking systems;

reputational harm;

personal-data processing;

algorithmic indexing;

automated presentation of information.

Direct relevance: High.

17. Österreichische Post — C-300/21

Case: Österreichische Post AG v Österreichische Datenschutzbehörde, C-300/21
CJEU, 4 May 2023

The case concerned unlawful processing of personal data and compensation under Article 82 GDPR.

The CJEU clarified that:

infringement of GDPR rules alone does not automatically establish compensable damage;

actual material or non-material damage must be established;

compensation does not require a particular minimum seriousness threshold in the manner suggested by a de minimis approach.

Relevance to algorithmic decisions

A claimant whose personal data has been unlawfully processed by an algorithm may potentially claim compensation, but must connect the unlawful processing with legally recognised damage.

This is especially relevant to:

profiling;

automated classification;

behavioural prediction;

risk scoring;

algorithmic advertising.

Direct relevance: High.

18. NAP v VB — C-340/21

Case: VB v Natsionalna agentsia za prihodite (NAP), C-340/21
CJEU, 14 December 2023

The case concerned personal-data security following a cyberattack.

The CJEU considered whether fear concerning misuse of personal data could constitute non-material damage.

Importance

The Court recognised that a well-founded fear of misuse can, depending on the circumstances, constitute compensable non-material damage.

Algorithmic significance

The principle can become relevant where algorithmic systems:

classify individuals;

process sensitive information;

expose data through security failures;

create persistent risk profiles.

Direct relevance: Moderate to high.

19. CHEZ Razpredelenie Bulgaria — C-83/14

Case: CHEZ Razpredelenie Bulgaria AD v Komisia za zashtita ot diskriminatsia and Nikolay Nikolov, C-83/14
CJEU, 16 July 2015

The case concerned electricity meters installed in a particular area at a height substantially greater than usual.

The CJEU addressed indirect discrimination.

Importance for algorithms

A measure does not have to explicitly classify people according to a protected characteristic to raise discrimination concerns.

An apparently neutral system can produce a disproportionate disadvantage for a protected group.

Algorithmic application

The reasoning is highly relevant to:

recruitment algorithms;

credit scoring;

welfare algorithms;

insurance algorithms;

housing algorithms.

Direct relevance: Analogical but very important.

20. Test-Achats — C-236/09

Case: Association Belge des Consommateurs Test-Achats ASBL and Others v Conseil des ministres, C-236/09
CJEU, 1 March 2011

The CJEU considered the use of sex-based statistical distinctions in insurance.

The Court invalidated the relevant provision permitting continuing sex-based differentiation in insurance premiums and benefits.

Algorithmic significance

The case demonstrates that statistical justification does not automatically make discriminatory differentiation lawful.

This is particularly important because algorithmic systems frequently rely on statistical correlations.

An insurer cannot necessarily defend a discriminatory outcome merely by saying:

“The statistical data predicts different risks.”

Direct relevance: Analogical, particularly for algorithmic insurance.

21. Feryn — C-54/07

Case: Centrum voor gelijkheid van kansen en voor racismebestrijding v Firma Feryn NV, C-54/07
CJEU, 10 July 2008

The case involved discriminatory recruitment statements.

The Court recognised that discriminatory public statements concerning recruitment could contribute to establishing a discriminatory recruitment practice even without an identifiable individual victim.

Algorithmic significance

This is important for automated recruitment.

A recruitment algorithm may produce discriminatory outcomes because it:

reproduces historical employment patterns;

uses biased training data;

relies on discriminatory proxies;

systematically excludes a protected group.

The absence of a deliberately discriminatory programmer does not necessarily eliminate discrimination concerns.

Direct relevance: Analogical but highly relevant to AI recruitment systems.

22. Asociația Accept — C-81/12

Case: Asociația Accept v Consiliul Național pentru Combaterea Discriminării, C-81/12
CJEU, 25 April 2013

The CJEU addressed discriminatory statements in the employment context.

The Court's reasoning concerned the evidentiary significance of statements suggesting discriminatory recruitment practices.

Algorithmic relevance

It illustrates that discrimination can be established through evidence concerning the operation and environment surrounding a decision-making system, rather than requiring proof that an individual decision-maker consciously intended discrimination.

This can be relevant to algorithmic recruitment systems where:

management adopts discriminatory selection criteria;

historical datasets encode discrimination;

system outputs systematically disadvantage a group.

Direct relevance: Analogical.

23. HK Danmark — Joined Cases C-335/11 and C-337/11

Cases: HK Danmark v Dansk Almennyttigt Boligselskab and Dansk Arbejdsgiverforening v HK Danmark, Joined C-335/11 and C-337/11
CJEU, 11 April 2013

The cases concerned disability discrimination and the scope of reasonable accommodation.

Algorithmic significance

Automated employment systems may disadvantage persons with disabilities because they evaluate workers according to standardised criteria without considering reasonable accommodation.

For example:

An algorithm could classify an employee as unsuitable because of reduced productivity caused by a disability without accounting for legally required accommodation.

The case therefore supports a broader principle that automated uniformity cannot necessarily override equality obligations.

Direct relevance: Analogical.

24. Glukhin v Russia

Case: Glukhin v Russia, Application No. 11519/20
ECtHR, 4 July 2023

The case concerned the use of facial-recognition technology by Russian authorities.

The ECtHR found an interference with the applicant's Article 8 rights.

Importance

The case is highly significant for algorithmic governance because it demonstrates that:

facial recognition is a serious privacy intervention;

technological identification cannot be assessed purely as a technical matter;

authorities must have adequate legal justification and proportionality.

Algorithmic relevance

It is particularly important for:

facial recognition;

biometric identification;

police AI;

predictive surveillance;

automated identification systems.

Direct relevance: High for biometric algorithmic decisions.

25. S. and Marper v United Kingdom

Case: S. and Marper v United Kingdom, Applications Nos. 30562/04 and 30566/04
ECtHR Grand Chamber, 4 December 2008

The case concerned retention of DNA and fingerprints.

The ECtHR found an Article 8 violation in the UK's blanket retention approach.

Algorithmic significance

Modern algorithmic systems increasingly depend upon:

biometric databases;

facial templates;

fingerprints;

DNA;

identity databases.

The case establishes the importance of safeguards surrounding sensitive personal data.

Direct relevance: Analogical but foundational for biometric AI.

26. Big Brother Watch v United Kingdom

Case: Big Brother Watch and Others v United Kingdom, Applications Nos. 58170/13, 62322/14 and 24960/15
ECtHR Grand Chamber, 25 May 2021

The case concerned large-scale electronic surveillance.

The ECtHR examined safeguards governing interception and handling of communications.

Algorithmic significance

Modern surveillance frequently involves algorithmic:

filtering;

pattern recognition;

classification;

prioritisation;

risk assessment.

The case is therefore highly relevant to disputes concerning algorithmic surveillance.

The Court emphasised the importance of safeguards against abuse.

Direct relevance: Analogical but highly important.

27. López Ribalda v Spain

Case: López Ribalda and Others v Spain, Applications Nos. 1874/13 and 8567/13
ECtHR Grand Chamber, 17 October 2019

The case concerned covert workplace video surveillance.

The Court examined the balance between employees' privacy rights and the employer's legitimate interests.

Algorithmic significance

Modern employers increasingly use:

productivity algorithms;

behavioural monitoring;

facial recognition;

keystroke analytics;

automated performance scores;

workplace surveillance systems.

The case provides an important proportionality framework.

Direct relevance: Analogical.

28. Comparative Case-Law Table

CaseCourtMain principleAlgorithmic relevance
SCHUFA, C-634/21CJEUAutomated scoring can fall within Article 22Very high
Google Spain, C-131/12CJEUResponsibility for large-scale processing of personal informationHigh
Österreichische Post, C-300/21CJEUGDPR damage and compensationHigh
NAP, C-340/21CJEUNon-material damage/fear after data breachHigh
CHEZ, C-83/14CJEUIndirect discriminationHigh
Test-Achats, C-236/09CJEUStatistical differentiation and equalityHigh
Feryn, C-54/07CJEUDiscriminatory recruitment evidenceHigh
Asociația Accept, C-81/12CJEUEvidence of discriminatory recruitmentHigh
HK Danmark, C-335/11 & C-337/11CJEUDisability discrimination/accommodationModerate–high
Glukhin v RussiaECtHRFacial recognition and Article 8Very high
S. and Marper v UKECtHRBiometric-data safeguardsHigh
Big Brother Watch v UKECtHRSurveillance safeguardsHigh
López Ribalda v SpainECtHRWorkplace technological surveillanceHigh

29. Typical Algorithmic Decision-Making Claims

29.1 Unlawful Automated Decision Claim

The claimant argues:

“A decision producing significant effects was made solely or substantially through automated processing without the safeguards required by law.”

Potential remedy:

human review;

reconsideration;

suspension of decision;

correction;

deletion;

compensation.

29.2 Algorithmic Discrimination Claim

The claimant argues:

“The algorithm disproportionately disadvantages me or a protected group.”

Evidence may include:

selection rates;

error rates;

false-positive rates;

false-negative rates;

demographic outcome comparisons;

model variables;

proxy variables;

training data;

historical decisions.

Statistical disparity is important evidence but does not automatically prove unlawful discrimination. The applicable legal test must still be satisfied.

29.3 Algorithmic Privacy Claim

The claimant may argue:

unlawful profiling;

excessive data collection;

biometric processing;

unlawful tracking;

inadequate transparency;

unlawful retention;

unlawful sharing;

inadequate security.

29.4 Algorithmic Accuracy Claim

The claimant argues that the algorithm relied upon:

incorrect data;

outdated data;

wrongly attributed information;

erroneous risk classifications;

inaccurate identity matching.

This is especially significant in:

credit;

policing;

immigration;

employment;

welfare;

fraud detection.

29.5 Algorithmic Transparency Claim

The claimant may argue:

“I cannot meaningfully understand or challenge the decision because the organisation has not provided legally required information.”

The claimant may seek information concerning:

data used;

purpose;

logic/significance;

consequences;

decision-making structure;

human intervention;

review mechanisms.

29.6 Failure of Human Oversight

The claimant argues:

“The organisation claims that a human made the decision, but the human merely accepted the algorithmic recommendation.”

The strength of this claim depends heavily on the applicable legislation and facts.

Evidence might include:

internal policies;

system interfaces;

review logs;

override rates;

training materials;

employee instructions;

time available for review;

reasons recorded by the human decision-maker.

30. Liability of Different Actors

Algorithmic disputes can involve several defendants.

1. Algorithm developer

Potential responsibility for:

defective design;

inadequate testing;

foreseeable misuse;

software defects;

security vulnerabilities.

2. AI provider

Potential responsibility for:

model performance;

documentation;

warnings;

monitoring;

compliance obligations.

3. Deployer

The organisation using the system may be responsible for:

unlawful purpose;

inappropriate deployment;

inadequate human oversight;

unlawful data processing;

failure to monitor outcomes.

4. Professional user

A doctor, lawyer, banker, employer or other professional may have liability where professional duties require independent judgment.

5. Public authority

A government authority may face:

administrative-law challenges;

fundamental-rights claims;

GDPR claims;

state-liability claims.

31. Causation

Causation is often one of the hardest parts of algorithmic litigation.

A claimant may need to establish a connection between:

algorithm → decision → adverse consequence → legally recognised harm

For example:

Incorrect credit score → loan rejection → financial loss.

Or:

Biased recruitment algorithm → exclusion from selection → lost employment opportunity.

Or:

Incorrect fraud classification → account freezing → business interruption.

Complex systems can make it difficult to determine whether the algorithm actually caused the result or merely contributed to it.

32. Evidentiary Problems

Algorithmic disputes frequently involve information asymmetry.

The organisation may possess:

source code;

model architecture;

training-data documentation;

system logs;

audit reports;

validation studies;

risk assessments;

DPIAs;

model cards;

error-rate statistics;

internal communications.

The claimant may possess very little.

Consequently, procedural mechanisms concerning:

disclosure;

access to personal data;

expert evidence;

judicial inspection;

audit records;

technical documentation

can be extremely important.

33. Remedies

Depending upon the applicable legal regime, possible remedies include:

Corrective remedies

correction of inaccurate data;

reconsideration;

deletion;

restriction of processing.

Procedural remedies

human review;

explanation;

new decision;

access to records.

Injunctive remedies

stopping unlawful processing;

stopping discriminatory use;

suspending deployment.

Financial remedies

compensation;

damages;

reimbursement;

lost-income compensation.

Public-law remedies

annulment;

judicial review;

declaration of unlawfulness;

mandatory reconsideration.

34. Defences

Organisations may argue:

Legitimate objective

The algorithm serves a legitimate purpose such as:

fraud prevention;

public safety;

financial risk management;

cybersecurity.

Human involvement

The organisation may argue that a human actually made the decision.

The court may examine whether that intervention was genuinely substantive.

Statistical accuracy

The organisation may rely on the algorithm's overall accuracy.

But high overall accuracy does not necessarily answer questions of:

individual accuracy;

discrimination;

proportionality;

legality;

transparency.

Consent

Consent may sometimes be relevant, but it does not automatically legitimise every form of algorithmic decision-making.

Trade secrets

Organisations may resist complete disclosure of source code or model architecture.

That does not necessarily eliminate obligations to provide legally required meaningful information.

35. Important Distinction: Algorithmic Error ≠ Automatic Liability

A central principle in algorithmic litigation is:

An incorrect algorithmic result does not automatically establish civil liability.

The claimant may need to establish:

applicable legal duty;

unlawful processing, defect, breach or discriminatory treatment;

causal connection;

legally recognised damage or rights infringement;

appropriate remedy.

For negligence, additional questions such as foreseeability and reasonable precautions may arise.

For GDPR claims, the requirements are different from traditional negligence.

For discrimination claims, proof of discriminatory treatment and applicable burden-shifting rules become central.

36. A Practical Legal Test

A European algorithmic decision-making dispute can be analysed through the following sequence:

Step 1 — Identify the decision

What did the algorithm actually decide or influence?

Step 2 — Identify the actor

Who deployed or controlled it?

Step 3 — Identify the legal regime

Is the dispute primarily:

GDPR?

AI Act?

equality law?

employment law?

consumer law?

administrative law?

tort?

contract?

fundamental rights?

Step 4 — Determine the degree of automation

Was the decision:

fully automated;

algorithm-assisted;

human-controlled?

Step 5 — Examine the data

Was the information:

accurate?

relevant?

lawfully obtained?

sufficiently current?

Step 6 — Examine discrimination

Did the system create:

direct discrimination?

indirect discrimination?

disparate impact?

proxy discrimination?

Step 7 — Examine transparency

Was the affected person adequately informed?

Step 8 — Examine human oversight

Could a human genuinely reconsider and overturn the result?

Step 9 — Examine proportionality

Was the interference necessary and proportionate?

Step 10 — Establish harm and causation

What actual legal or economic consequence resulted?

Step 11 — Determine remedy

Should the decision be:

corrected;

reconsidered;

suspended;

annulled;

compensated?

37. Overall European Legal Position

The emerging European approach can be summarised as follows:

Algorithmic decision-making is not a legally autonomous zone outside ordinary legal responsibility.

An algorithm must operate within existing requirements concerning:

legality;

privacy;

data protection;

equality;

transparency;

human oversight;

proportionality;

procedural fairness;

consumer protection;

professional responsibility;

effective remedies.

The SCHUFA judgment is particularly important because it demonstrates that a supposedly “preliminary” algorithmic score can itself become legally significant where it effectively determines the subsequent decision.

The CHEZ, Test-Achats, Feryn and Asociația Accept cases provide important foundations for analysing algorithmic discrimination. Glukhin, S. and Marper, Big Brother Watch and López Ribalda provide important human-rights principles for biometric and surveillance technologies. Google Spain, Österreichische Post and NAP provide the data-protection and compensation framework.

Core formula

Algorithmic processing → legally relevant decision → applicable legal duty → breach/defect/discrimination/unlawful processing → adverse effect → causation → damage or rights infringement → appropriate remedy.

The most important practical lesson is that “the algorithm decided” is generally not a complete legal defence. The court can examine the organisation's choice to deploy the system, the data supplied to it, its design and validation, the degree of human oversight, the transparency provided to affected persons, and the consequences produced by its operation.

LEAVE A COMMENT