Algorithmic Harm Claims .

1. Meaning of Algorithmic Harm Claims

Algorithmic harm claims arise when an algorithmic or AI-driven system causes legally recognizable harm to an individual, group, business, or public interest.

The harm may result from:

  • inaccurate data;
  • discriminatory profiling;
  • automated decision-making;
  • algorithmic scoring;
  • defective predictions;
  • unlawful surveillance;
  • privacy violations;
  • erroneous classification;
  • automated denial of benefits or services;
  • unfair employment decisions;
  • reputational damage;
  • consumer harm;
  • unsafe AI-assisted decisions;
  • opaque administrative decisions.

There is no single European cause of action called “algorithmic harm.” Instead, liability is normally constructed from existing legal regimes, including:

  • GDPR and data-protection law;
  • EU equality law;
  • consumer protection;
  • contract law;
  • tort/delict;
  • employment law;
  • product liability;
  • administrative law;
  • fundamental rights;
  • ECHR law;
  • EU Charter rights.

The basic causal structure can be expressed as:

Data → Algorithm → Output → Decision/Action → Harm → Legal Cause of Action → Remedy

An erroneous algorithmic output by itself does not automatically create liability. The claimant generally must establish the applicable legal duty or right, breach or unlawfulness, legally recognizable damage, and—where required—causation.

2. Types of Algorithmic Harm

A. Economic Harm

Examples include:

  • wrongful credit refusal;
  • increased insurance premiums;
  • loss of employment;
  • denial of welfare;
  • incorrect taxation;
  • financial loss from automated trading;
  • discriminatory pricing.

B. Privacy Harm

AI systems may:

  • collect excessive personal information;
  • infer sensitive characteristics;
  • track individuals;
  • create behavioural profiles;
  • retain information unnecessarily;
  • share information unlawfully.

C. Discrimination Harm

An algorithm may disadvantage persons based on:

  • sex;
  • race or ethnic origin;
  • disability;
  • age;
  • religion;
  • sexual orientation;
  • other legally protected characteristics.

Discrimination can be direct or indirect.

D. Reputational Harm

AI-generated or algorithmically amplified information can produce:

  • false accusations;
  • inaccurate profiles;
  • defamatory classifications;
  • misleading search results;
  • incorrect fraud labels;
  • erroneous risk scores.

E. Procedural Harm

An individual may suffer harm because:

  • the decision is unexplained;
  • the person cannot challenge the result;
  • no meaningful human review occurs;
  • the relevant data cannot be corrected;
  • an automated decision is effectively irreversible.

3. Major European Legal Framework

GDPR

The GDPR is central where personal data is involved.

Important principles include:

  • lawfulness;
  • fairness;
  • transparency;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • accountability;
  • security.

Particular importance attaches to:

  • access rights;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • automated decision-making;
  • compensation for qualifying infringements.

4. Article 22 GDPR and Automated Decisions

Article 22 is particularly important where a person is subject to a decision based solely on automated processing that produces legal effects or similarly significant effects.

Examples include:

  • automated credit decisions;
  • employment decisions;
  • insurance decisions;
  • welfare determinations;
  • eligibility decisions.

The legal analysis depends on the precise circumstances and applicable exceptions.

A particularly important question is whether purported human review is genuine or merely formal.

5. Algorithmic Harm and Data Accuracy

One of the simplest forms of algorithmic harm occurs when incorrect data produces an incorrect outcome.

Example:

A credit database incorrectly records that a person defaulted on a loan.

The algorithm then uses that information to calculate a low credit score.

The resulting sequence may be:

Incorrect data → low score → loan refusal → financial loss

The claimant may have several possible legal avenues.

6. Case Law

1. SCHUFA — C-634/21

Court of Justice of the European Union

This is one of the most significant European authorities for algorithmic harm.

The case concerned credit scoring and automated decision-making.

The CJEU examined circumstances in which an algorithmically generated score can effectively determine the outcome for an individual.

Importance

The case demonstrates that an algorithmic score may be legally significant even where a separate organisation formally makes the final decision.

Algorithmic harm principle

An organisation cannot necessarily avoid responsibility by arguing:

“We did not make the decision; we merely supplied the score.”

Where the score effectively determines the decision, the GDPR's automated-decision framework can become relevant.

Practical examples

  • credit refusal;
  • mortgage refusal;
  • insurance assessment;
  • employment screening;
  • housing allocation.

7. SCHUFA — C-26/22 and C-64/22

These cases further concern credit information and data-protection rights.

They are important for algorithmic harm because they emphasise the significance of:

  • accurate information;
  • access to personal data;
  • correction;
  • deletion where appropriate;
  • storage periods;
  • effective exercise of data-subject rights.

Key principle

An algorithm can produce harmful consequences because the underlying data is wrong, even if the algorithm itself operates exactly as designed.

Thus:

Algorithmic accuracy cannot compensate for inaccurate input data.

8. Nowak v Data Protection Commissioner — C-434/16

The CJEU considered the concept of personal data in relation to examination scripts and examiner comments.

The Court interpreted personal data broadly.

Algorithmic significance

Modern algorithms produce enormous quantities of evaluative information:

  • scores;
  • classifications;
  • predictions;
  • risk levels;
  • rankings;
  • assessments.

Such information can have direct consequences for individuals.

Harm principle

Where algorithmic evaluations constitute personal data, applicable data-protection rights may provide mechanisms for:

  • access;
  • correction;
  • challenge;
  • accountability.

9. Google Spain — C-131/12

Google Spain SL and Google Inc. v AEPD and Mario Costeja González

The CJEU considered the responsibility of search engines for processing personal information.

The case produced the famous European right-to-erasure/delisting jurisprudence.

Algorithmic harm significance

Search algorithms can amplify old or inaccurate information.

This may affect:

  • employment;
  • reputation;
  • professional opportunities;
  • social relationships;
  • access to services.

The case demonstrates that algorithmic systems can create legally relevant harm even where the system does not originally create the underlying information.

10. Google LLC v CNIL — C-507/17

The CJEU subsequently considered the territorial scope of search-engine delisting.

Algorithmic significance

It illustrates the distinction between:

  • removing information;
  • delisting information from search results;
  • geographical scope of removal;
  • freedom of expression;
  • privacy rights.

This is relevant to modern algorithmic reputation harm because removing an underlying webpage and controlling its algorithmic visibility are not necessarily the same thing.

11. Orange România — C-61/19

This case concerned the requirements for valid consent under data-protection law.

The Court emphasised that consent must satisfy the relevant GDPR conditions.

Algorithmic harm significance

AI systems frequently rely upon extensive personal-data collection.

If the underlying processing is based upon defective consent, the subsequent algorithmic processing may also become legally problematic.

Examples include:

  • behavioural profiling;
  • targeted advertising;
  • AI personalisation;
  • biometric analysis;
  • consumer prediction.

12. Planet49 — C-673/17

The CJEU examined consent requirements concerning cookies and online tracking.

Algorithmic significance

Online tracking is often the first stage of algorithmic profiling:

Tracking → data collection → profile → prediction → targeted treatment

If the initial data collection is unlawful, subsequent algorithmic processing may also become vulnerable to challenge.

The case therefore demonstrates that algorithmic harm can begin before the algorithm produces its final decision.

13. Wirtschaftsakademie — C-210/16

The CJEU considered responsibility for processing personal data in connection with a Facebook fan page.

The case contributed to the development of the concept of joint responsibility for processing.

Algorithmic significance

Modern AI systems commonly involve multiple actors:

  • model developer;
  • data provider;
  • platform;
  • deployer;
  • employer;
  • analytics provider;
  • decision-maker.

The question therefore becomes:

Who is legally responsible for the relevant processing?

An organisation may not necessarily avoid responsibility simply because another company technically operates the algorithm.

14. Fashion ID — C-40/17

The CJEU examined joint controllership in the context of embedded social-media functionality.

Algorithmic significance

The case reinforces the importance of identifying responsibility across technological chains.

For AI systems, the relevant chain may be:

Developer → cloud provider → data supplier → deployer → end-user organisation

The fact that multiple entities participate does not automatically eliminate legal responsibility.

15. Digital Rights Ireland — Joined Cases C-293/12 and C-594/12

The CJEU invalidated the Data Retention Directive because of disproportionate interference with fundamental rights.

Algorithmic significance

Modern AI enables enormous-scale data analysis.

The case demonstrates that:

Technological capability does not itself establish legal necessity or proportionality.

This is particularly relevant to:

  • mass surveillance;
  • predictive policing;
  • behavioural profiling;
  • automated security systems;
  • government databases.

16. Tele2 Sverige and Watson — Joined Cases C-203/15 and C-698/15

The CJEU addressed indiscriminate retention of communications data.

Algorithmic harm significance

Mass data retention can become particularly intrusive when combined with AI.

Data that appears harmless individually can become highly revealing when algorithmically aggregated.

For example:

Location + communications + contacts + browsing patterns → behavioural profile

The legal concern therefore includes not only the original data collection but also the inferential power created by algorithmic analysis.

17. CHEZ — C-83/14

CHEZ Razpredelenie Bulgaria AD v Komisia za zashtita ot diskriminatsia

This case concerned discriminatory effects involving electricity meters in a predominantly Roma neighbourhood.

Algorithmic significance

The case is particularly useful for indirect algorithmic discrimination.

A system does not need to explicitly classify someone by race to produce discriminatory effects.

A seemingly neutral variable can operate as a proxy.

Examples include:

  • postcode;
  • language;
  • educational institution;
  • purchasing history;
  • employment patterns.

18. D.H. and Others v Czech Republic

ECtHR Grand Chamber

The Court considered discrimination against Roma children in education.

Statistical evidence was important to the Court's assessment.

Algorithmic significance

Algorithmic discrimination will often be demonstrated statistically rather than through an explicit statement of discriminatory intent.

For example:

An AI recruitment system selects 70% of male applicants but only 25% of similarly qualified female applicants.

The statistical disparity can become an important evidentiary fact.

19. Bărbulescu v Romania

ECtHR Grand Chamber, 2017

The case concerned workplace monitoring of employee communications.

The Court examined whether monitoring was sufficiently justified and proportionate.

Algorithmic significance

AI dramatically increases the capacity to monitor employees.

Traditional monitoring may become:

Email monitoring → AI classification → behavioural profiling → productivity prediction → disciplinary decision

The more powerful the analytical system becomes, the more important proportionality, notice and safeguards become.

20. López Ribalda and Others v Spain

ECtHR Grand Chamber, 2019

The case concerned covert workplace video surveillance.

The Court examined proportionality and safeguards surrounding employee surveillance.

Algorithmic relevance

The case becomes especially significant where surveillance is combined with:

  • facial recognition;
  • emotion analysis;
  • behavioural classification;
  • productivity scoring;
  • automated misconduct detection.

The fact that a technological system can identify behaviour does not automatically establish that its deployment is lawful.

21. Delfi AS v Estonia

ECtHR Grand Chamber

The Court considered intermediary liability concerning user-generated comments.

Algorithmic significance

Online platforms increasingly use automated moderation systems.

An AI moderation system can:

  • incorrectly remove lawful speech;
  • fail to remove unlawful content;
  • misclassify users;
  • amplify harmful material.

The case provides an important framework for considering intermediary responsibility, although it is not itself an AI case.

22. MTE and Index.hu v Hungary

ECtHR

The case concerned online intermediary liability and freedom of expression.

Algorithmic significance

It illustrates the tension between:

  • removal of harmful content;
  • protection of reputation;
  • freedom of expression;
  • intermediary responsibility.

AI content moderation must balance these competing interests.

23. Algorithmic Harm in Employment

Potential examples include:

Recruitment

AI rejects candidates based upon biased historical data.

Promotion

An employee receives a low “leadership score” because the system penalises communication styles associated with a protected group.

Dismissal

A predictive system identifies an employee as a likely future problem and recommends termination.

Workplace monitoring

AI classifies an employee as unproductive because of disability-related working patterns.

Potential legal frameworks include:

  • equality law;
  • employment law;
  • GDPR;
  • contractual obligations;
  • tort/delict;
  • fundamental rights.

24. Algorithmic Harm in Credit and Finance

Credit scoring is one of the clearest areas.

Possible chain:

Personal data → credit score → automated recommendation → loan refusal → financial loss

Potential claims may concern:

  • inaccurate data;
  • unlawful processing;
  • discrimination;
  • lack of transparency;
  • automated decision-making;
  • failure to provide effective challenge;
  • consequential financial damage.

The SCHUFA cases are especially important.

25. Algorithmic Harm in Public Administration

Government algorithms can affect:

  • welfare benefits;
  • immigration;
  • taxation;
  • policing;
  • social housing;
  • education;
  • healthcare.

The legal requirements may include:

  • statutory authority;
  • procedural fairness;
  • equality;
  • proportionality;
  • reasons;
  • transparency;
  • effective judicial review.

A government cannot necessarily transform an unlawful administrative decision into a lawful one merely by inserting an algorithm between the official and the citizen.

26. Algorithmic Harm in Consumer Markets

Consumers can be harmed by:

  • personalised pricing;
  • automated credit scoring;
  • targeted advertising;
  • dark patterns;
  • recommendation systems;
  • automated fraud detection;
  • AI customer-service decisions.

Relevant legal regimes may include:

  • consumer protection;
  • GDPR;
  • unfair commercial practices law;
  • contract law;
  • product liability;
  • competition law.

27. Causation

Causation is often the hardest part of an algorithmic harm claim.

Consider:

AI gives an applicant a low recruitment score.

The claimant must establish what happened next.

For example:

Low score → rejection → loss of job opportunity → financial loss

But the employer may argue:

“The applicant would have been rejected anyway.”

The claimant therefore needs evidence showing that the algorithmic output materially contributed to the decision.

28. Multiple Causes

Algorithmic harm frequently has several causes.

Example:

Bad data + defective model + human error + inadequate supervision → harmful decision

Courts may therefore have to determine:

  • which actor caused the harm;
  • whether multiple actors share responsibility;
  • whether another event broke the chain of causation;
  • whether the claimant contributed to the loss.

29. Algorithmic Harm Does Not Automatically Mean Negligence

This distinction is fundamental.

Suppose an AI medical-support system makes a wrong prediction.

That alone does not automatically establish negligence.

A claimant may need to show:

  1. a relevant duty;
  2. breach;
  3. causation;
  4. legally recognised damage.

The same principle applies to other algorithmic contexts.

Wrong output ≠ automatic legal liability.

30. Evidence in Algorithmic Harm Claims

Important evidence can include:

  • source data;
  • input variables;
  • algorithmic outputs;
  • model documentation;
  • audit reports;
  • model-validation records;
  • logs;
  • decision records;
  • human-review records;
  • statistical testing;
  • equality-impact assessments;
  • data-protection impact assessments;
  • internal communications;
  • procurement contracts;
  • technical specifications;
  • expert evidence.

In complex cases, statistical evidence may be especially important.

31. Defences

A defendant may argue:

No legal duty

The claimant has not established an applicable obligation.

No causation

The algorithm did not actually cause the loss.

Independent human decision

A person independently made the final decision.

Accurate data

The information used by the system was correct.

Legitimate processing

The data processing had a lawful basis.

No legally recognised damage

The claimant suffered inconvenience but not legally compensable damage.

Proportionality

The processing or decision served a legitimate objective and was necessary.

Third-party responsibility

The defendant may argue that another organisation controlled the relevant system.

However, cases such as Wirtschaftsakademie and Fashion ID demonstrate why technological chains do not necessarily eliminate responsibility.

32. Remedies

Depending on the cause of action, possible remedies include:

  • compensation;
  • rectification;
  • erasure;
  • restriction of processing;
  • objection;
  • human reconsideration;
  • annulment of administrative decisions;
  • reinstatement;
  • injunction;
  • correction of algorithmic profiles;
  • deletion of unlawful data;
  • regulatory enforcement;
  • reconsideration of affected decisions.

The GDPR can also provide a damages route for qualifying infringements, but a regulatory breach should not automatically be equated with an entitlement to unlimited compensation.

33. Consolidated Case Table

CaseCourtKey principleAlgorithmic-harm relevance
SCHUFA C-634/21CJEUAutomated scoringCredit and algorithmic decisions
SCHUFA C-26/22 & C-64/22CJEUData rights and credit informationAccuracy and contestability
Nowak C-434/16CJEUPersonal dataScores and evaluations
Google Spain C-131/12CJEUSearch-engine processingReputation and ranking
Google LLC v CNIL C-507/17CJEUDelisting scopeAlgorithmic visibility
Orange România C-61/19CJEUValid consentAI data collection
Planet49 C-673/17CJEUTracking consentProfiling infrastructure
Wirtschaftsakademie C-210/16CJEUJoint responsibilityAI supply chains
Fashion ID C-40/17CJEUJoint controllershipMultiple AI actors
CHEZ C-83/14CJEUIndirect discriminationAlgorithmic bias
D.H. v Czech RepublicECtHR GCStatistical discriminationDisparate-impact evidence
Digital Rights IrelandCJEUProportionalityMass AI surveillance
Tele2 Sverige/WatsonCJEULimits on data retentionPredictive profiling
Bărbulescu v RomaniaECtHR GCWorkplace monitoringAI employee surveillance
López Ribalda v SpainECtHR GCSurveillance proportionalityAI monitoring
Delfi v EstoniaECtHR GCPlatform responsibilityAutomated content moderation

34. Core Principles

European algorithmic-harm jurisprudence can ultimately be reduced to several important principles:

1. Automation does not eliminate responsibility

A decision does not become legally unreviewable because a computer produced it.

2. Data quality matters

Incorrect data can produce legally significant harm.

3. Neutral algorithms can discriminate

A system does not need to explicitly use a protected characteristic to produce discriminatory effects.

4. Human review must be meaningful where required

A nominal human decision-maker may not be enough.

5. Transparency supports contestability

Affected individuals must have the legally required ability to understand and challenge relevant processing or decisions.

6. Proportionality matters

Technological capability does not itself establish legal necessity.

7. Responsibility can be distributed

Developers, deployers, controllers and other participants may have different legal responsibilities.

8. Harm requires a legal foundation

An undesirable algorithmic result is not automatically a successful damages claim.

Conclusion

Algorithmic Harm Claims in Europe are an emerging form of litigation built principally upon existing legal doctrines rather than a single autonomous AI tort.

The most important authorities include SCHUFA, Nowak, Google Spain, Orange România, Planet49, Wirtschaftsakademie, Fashion ID, CHEZ, D.H. v Czech Republic, Digital Rights Ireland, Tele2 Sverige/Watson, Bărbulescu, López Ribalda and Delfi.

The central legal sequence is:

Algorithm → Data/Model → Output → Human or Automated Decision → Legal/Practical Consequence → Recognised Harm → Causation → Remedy

The strongest claims generally arise where an algorithmic system combines inaccurate data, discriminatory effects, unlawful processing, consequential automated decision-making, inadequate human oversight, lack of meaningful challenge, or disproportionate surveillance. However, algorithmic error alone does not automatically establish liability; the claimant must connect the technological failure to a specific legal duty or right and, where required, establish causation and legally recognised damage.

Available next action: Create a downloadable PDF file here in this chat containing the findings and recommendations above

LEAVE A COMMENT