Algorithmic Harm Claims .
1. Meaning of Algorithmic Harm Claims
Algorithmic harm claims arise when an algorithmic or AI-driven system causes legally recognizable harm to an individual, group, business, or public interest.
The harm may result from:
- inaccurate data;
- discriminatory profiling;
- automated decision-making;
- algorithmic scoring;
- defective predictions;
- unlawful surveillance;
- privacy violations;
- erroneous classification;
- automated denial of benefits or services;
- unfair employment decisions;
- reputational damage;
- consumer harm;
- unsafe AI-assisted decisions;
- opaque administrative decisions.
There is no single European cause of action called “algorithmic harm.” Instead, liability is normally constructed from existing legal regimes, including:
- GDPR and data-protection law;
- EU equality law;
- consumer protection;
- contract law;
- tort/delict;
- employment law;
- product liability;
- administrative law;
- fundamental rights;
- ECHR law;
- EU Charter rights.
The basic causal structure can be expressed as:
Data → Algorithm → Output → Decision/Action → Harm → Legal Cause of Action → Remedy
An erroneous algorithmic output by itself does not automatically create liability. The claimant generally must establish the applicable legal duty or right, breach or unlawfulness, legally recognizable damage, and—where required—causation.
2. Types of Algorithmic Harm
A. Economic Harm
Examples include:
- wrongful credit refusal;
- increased insurance premiums;
- loss of employment;
- denial of welfare;
- incorrect taxation;
- financial loss from automated trading;
- discriminatory pricing.
B. Privacy Harm
AI systems may:
- collect excessive personal information;
- infer sensitive characteristics;
- track individuals;
- create behavioural profiles;
- retain information unnecessarily;
- share information unlawfully.
C. Discrimination Harm
An algorithm may disadvantage persons based on:
- sex;
- race or ethnic origin;
- disability;
- age;
- religion;
- sexual orientation;
- other legally protected characteristics.
Discrimination can be direct or indirect.
D. Reputational Harm
AI-generated or algorithmically amplified information can produce:
- false accusations;
- inaccurate profiles;
- defamatory classifications;
- misleading search results;
- incorrect fraud labels;
- erroneous risk scores.
E. Procedural Harm
An individual may suffer harm because:
- the decision is unexplained;
- the person cannot challenge the result;
- no meaningful human review occurs;
- the relevant data cannot be corrected;
- an automated decision is effectively irreversible.
3. Major European Legal Framework
GDPR
The GDPR is central where personal data is involved.
Important principles include:
- lawfulness;
- fairness;
- transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- accountability;
- security.
Particular importance attaches to:
- access rights;
- rectification;
- erasure;
- restriction;
- objection;
- automated decision-making;
- compensation for qualifying infringements.
4. Article 22 GDPR and Automated Decisions
Article 22 is particularly important where a person is subject to a decision based solely on automated processing that produces legal effects or similarly significant effects.
Examples include:
- automated credit decisions;
- employment decisions;
- insurance decisions;
- welfare determinations;
- eligibility decisions.
The legal analysis depends on the precise circumstances and applicable exceptions.
A particularly important question is whether purported human review is genuine or merely formal.
5. Algorithmic Harm and Data Accuracy
One of the simplest forms of algorithmic harm occurs when incorrect data produces an incorrect outcome.
Example:
A credit database incorrectly records that a person defaulted on a loan.
The algorithm then uses that information to calculate a low credit score.
The resulting sequence may be:
Incorrect data → low score → loan refusal → financial loss
The claimant may have several possible legal avenues.
6. Case Law
1. SCHUFA — C-634/21
Court of Justice of the European Union
This is one of the most significant European authorities for algorithmic harm.
The case concerned credit scoring and automated decision-making.
The CJEU examined circumstances in which an algorithmically generated score can effectively determine the outcome for an individual.
Importance
The case demonstrates that an algorithmic score may be legally significant even where a separate organisation formally makes the final decision.
Algorithmic harm principle
An organisation cannot necessarily avoid responsibility by arguing:
“We did not make the decision; we merely supplied the score.”
Where the score effectively determines the decision, the GDPR's automated-decision framework can become relevant.
Practical examples
- credit refusal;
- mortgage refusal;
- insurance assessment;
- employment screening;
- housing allocation.
7. SCHUFA — C-26/22 and C-64/22
These cases further concern credit information and data-protection rights.
They are important for algorithmic harm because they emphasise the significance of:
- accurate information;
- access to personal data;
- correction;
- deletion where appropriate;
- storage periods;
- effective exercise of data-subject rights.
Key principle
An algorithm can produce harmful consequences because the underlying data is wrong, even if the algorithm itself operates exactly as designed.
Thus:
Algorithmic accuracy cannot compensate for inaccurate input data.
8. Nowak v Data Protection Commissioner — C-434/16
The CJEU considered the concept of personal data in relation to examination scripts and examiner comments.
The Court interpreted personal data broadly.
Algorithmic significance
Modern algorithms produce enormous quantities of evaluative information:
- scores;
- classifications;
- predictions;
- risk levels;
- rankings;
- assessments.
Such information can have direct consequences for individuals.
Harm principle
Where algorithmic evaluations constitute personal data, applicable data-protection rights may provide mechanisms for:
- access;
- correction;
- challenge;
- accountability.
9. Google Spain — C-131/12
Google Spain SL and Google Inc. v AEPD and Mario Costeja González
The CJEU considered the responsibility of search engines for processing personal information.
The case produced the famous European right-to-erasure/delisting jurisprudence.
Algorithmic harm significance
Search algorithms can amplify old or inaccurate information.
This may affect:
- employment;
- reputation;
- professional opportunities;
- social relationships;
- access to services.
The case demonstrates that algorithmic systems can create legally relevant harm even where the system does not originally create the underlying information.
10. Google LLC v CNIL — C-507/17
The CJEU subsequently considered the territorial scope of search-engine delisting.
Algorithmic significance
It illustrates the distinction between:
- removing information;
- delisting information from search results;
- geographical scope of removal;
- freedom of expression;
- privacy rights.
This is relevant to modern algorithmic reputation harm because removing an underlying webpage and controlling its algorithmic visibility are not necessarily the same thing.
11. Orange România — C-61/19
This case concerned the requirements for valid consent under data-protection law.
The Court emphasised that consent must satisfy the relevant GDPR conditions.
Algorithmic harm significance
AI systems frequently rely upon extensive personal-data collection.
If the underlying processing is based upon defective consent, the subsequent algorithmic processing may also become legally problematic.
Examples include:
- behavioural profiling;
- targeted advertising;
- AI personalisation;
- biometric analysis;
- consumer prediction.
12. Planet49 — C-673/17
The CJEU examined consent requirements concerning cookies and online tracking.
Algorithmic significance
Online tracking is often the first stage of algorithmic profiling:
Tracking → data collection → profile → prediction → targeted treatment
If the initial data collection is unlawful, subsequent algorithmic processing may also become vulnerable to challenge.
The case therefore demonstrates that algorithmic harm can begin before the algorithm produces its final decision.
13. Wirtschaftsakademie — C-210/16
The CJEU considered responsibility for processing personal data in connection with a Facebook fan page.
The case contributed to the development of the concept of joint responsibility for processing.
Algorithmic significance
Modern AI systems commonly involve multiple actors:
- model developer;
- data provider;
- platform;
- deployer;
- employer;
- analytics provider;
- decision-maker.
The question therefore becomes:
Who is legally responsible for the relevant processing?
An organisation may not necessarily avoid responsibility simply because another company technically operates the algorithm.
14. Fashion ID — C-40/17
The CJEU examined joint controllership in the context of embedded social-media functionality.
Algorithmic significance
The case reinforces the importance of identifying responsibility across technological chains.
For AI systems, the relevant chain may be:
Developer → cloud provider → data supplier → deployer → end-user organisation
The fact that multiple entities participate does not automatically eliminate legal responsibility.
15. Digital Rights Ireland — Joined Cases C-293/12 and C-594/12
The CJEU invalidated the Data Retention Directive because of disproportionate interference with fundamental rights.
Algorithmic significance
Modern AI enables enormous-scale data analysis.
The case demonstrates that:
Technological capability does not itself establish legal necessity or proportionality.
This is particularly relevant to:
- mass surveillance;
- predictive policing;
- behavioural profiling;
- automated security systems;
- government databases.
16. Tele2 Sverige and Watson — Joined Cases C-203/15 and C-698/15
The CJEU addressed indiscriminate retention of communications data.
Algorithmic harm significance
Mass data retention can become particularly intrusive when combined with AI.
Data that appears harmless individually can become highly revealing when algorithmically aggregated.
For example:
Location + communications + contacts + browsing patterns → behavioural profile
The legal concern therefore includes not only the original data collection but also the inferential power created by algorithmic analysis.
17. CHEZ — C-83/14
CHEZ Razpredelenie Bulgaria AD v Komisia za zashtita ot diskriminatsia
This case concerned discriminatory effects involving electricity meters in a predominantly Roma neighbourhood.
Algorithmic significance
The case is particularly useful for indirect algorithmic discrimination.
A system does not need to explicitly classify someone by race to produce discriminatory effects.
A seemingly neutral variable can operate as a proxy.
Examples include:
- postcode;
- language;
- educational institution;
- purchasing history;
- employment patterns.
18. D.H. and Others v Czech Republic
ECtHR Grand Chamber
The Court considered discrimination against Roma children in education.
Statistical evidence was important to the Court's assessment.
Algorithmic significance
Algorithmic discrimination will often be demonstrated statistically rather than through an explicit statement of discriminatory intent.
For example:
An AI recruitment system selects 70% of male applicants but only 25% of similarly qualified female applicants.
The statistical disparity can become an important evidentiary fact.
19. Bărbulescu v Romania
ECtHR Grand Chamber, 2017
The case concerned workplace monitoring of employee communications.
The Court examined whether monitoring was sufficiently justified and proportionate.
Algorithmic significance
AI dramatically increases the capacity to monitor employees.
Traditional monitoring may become:
Email monitoring → AI classification → behavioural profiling → productivity prediction → disciplinary decision
The more powerful the analytical system becomes, the more important proportionality, notice and safeguards become.
20. López Ribalda and Others v Spain
ECtHR Grand Chamber, 2019
The case concerned covert workplace video surveillance.
The Court examined proportionality and safeguards surrounding employee surveillance.
Algorithmic relevance
The case becomes especially significant where surveillance is combined with:
- facial recognition;
- emotion analysis;
- behavioural classification;
- productivity scoring;
- automated misconduct detection.
The fact that a technological system can identify behaviour does not automatically establish that its deployment is lawful.
21. Delfi AS v Estonia
ECtHR Grand Chamber
The Court considered intermediary liability concerning user-generated comments.
Algorithmic significance
Online platforms increasingly use automated moderation systems.
An AI moderation system can:
- incorrectly remove lawful speech;
- fail to remove unlawful content;
- misclassify users;
- amplify harmful material.
The case provides an important framework for considering intermediary responsibility, although it is not itself an AI case.
22. MTE and Index.hu v Hungary
ECtHR
The case concerned online intermediary liability and freedom of expression.
Algorithmic significance
It illustrates the tension between:
- removal of harmful content;
- protection of reputation;
- freedom of expression;
- intermediary responsibility.
AI content moderation must balance these competing interests.
23. Algorithmic Harm in Employment
Potential examples include:
Recruitment
AI rejects candidates based upon biased historical data.
Promotion
An employee receives a low “leadership score” because the system penalises communication styles associated with a protected group.
Dismissal
A predictive system identifies an employee as a likely future problem and recommends termination.
Workplace monitoring
AI classifies an employee as unproductive because of disability-related working patterns.
Potential legal frameworks include:
- equality law;
- employment law;
- GDPR;
- contractual obligations;
- tort/delict;
- fundamental rights.
24. Algorithmic Harm in Credit and Finance
Credit scoring is one of the clearest areas.
Possible chain:
Personal data → credit score → automated recommendation → loan refusal → financial loss
Potential claims may concern:
- inaccurate data;
- unlawful processing;
- discrimination;
- lack of transparency;
- automated decision-making;
- failure to provide effective challenge;
- consequential financial damage.
The SCHUFA cases are especially important.
25. Algorithmic Harm in Public Administration
Government algorithms can affect:
- welfare benefits;
- immigration;
- taxation;
- policing;
- social housing;
- education;
- healthcare.
The legal requirements may include:
- statutory authority;
- procedural fairness;
- equality;
- proportionality;
- reasons;
- transparency;
- effective judicial review.
A government cannot necessarily transform an unlawful administrative decision into a lawful one merely by inserting an algorithm between the official and the citizen.
26. Algorithmic Harm in Consumer Markets
Consumers can be harmed by:
- personalised pricing;
- automated credit scoring;
- targeted advertising;
- dark patterns;
- recommendation systems;
- automated fraud detection;
- AI customer-service decisions.
Relevant legal regimes may include:
- consumer protection;
- GDPR;
- unfair commercial practices law;
- contract law;
- product liability;
- competition law.
27. Causation
Causation is often the hardest part of an algorithmic harm claim.
Consider:
AI gives an applicant a low recruitment score.
The claimant must establish what happened next.
For example:
Low score → rejection → loss of job opportunity → financial loss
But the employer may argue:
“The applicant would have been rejected anyway.”
The claimant therefore needs evidence showing that the algorithmic output materially contributed to the decision.
28. Multiple Causes
Algorithmic harm frequently has several causes.
Example:
Bad data + defective model + human error + inadequate supervision → harmful decision
Courts may therefore have to determine:
- which actor caused the harm;
- whether multiple actors share responsibility;
- whether another event broke the chain of causation;
- whether the claimant contributed to the loss.
29. Algorithmic Harm Does Not Automatically Mean Negligence
This distinction is fundamental.
Suppose an AI medical-support system makes a wrong prediction.
That alone does not automatically establish negligence.
A claimant may need to show:
- a relevant duty;
- breach;
- causation;
- legally recognised damage.
The same principle applies to other algorithmic contexts.
Wrong output ≠ automatic legal liability.
30. Evidence in Algorithmic Harm Claims
Important evidence can include:
- source data;
- input variables;
- algorithmic outputs;
- model documentation;
- audit reports;
- model-validation records;
- logs;
- decision records;
- human-review records;
- statistical testing;
- equality-impact assessments;
- data-protection impact assessments;
- internal communications;
- procurement contracts;
- technical specifications;
- expert evidence.
In complex cases, statistical evidence may be especially important.
31. Defences
A defendant may argue:
No legal duty
The claimant has not established an applicable obligation.
No causation
The algorithm did not actually cause the loss.
Independent human decision
A person independently made the final decision.
Accurate data
The information used by the system was correct.
Legitimate processing
The data processing had a lawful basis.
No legally recognised damage
The claimant suffered inconvenience but not legally compensable damage.
Proportionality
The processing or decision served a legitimate objective and was necessary.
Third-party responsibility
The defendant may argue that another organisation controlled the relevant system.
However, cases such as Wirtschaftsakademie and Fashion ID demonstrate why technological chains do not necessarily eliminate responsibility.
32. Remedies
Depending on the cause of action, possible remedies include:
- compensation;
- rectification;
- erasure;
- restriction of processing;
- objection;
- human reconsideration;
- annulment of administrative decisions;
- reinstatement;
- injunction;
- correction of algorithmic profiles;
- deletion of unlawful data;
- regulatory enforcement;
- reconsideration of affected decisions.
The GDPR can also provide a damages route for qualifying infringements, but a regulatory breach should not automatically be equated with an entitlement to unlimited compensation.
33. Consolidated Case Table
| Case | Court | Key principle | Algorithmic-harm relevance |
|---|---|---|---|
| SCHUFA C-634/21 | CJEU | Automated scoring | Credit and algorithmic decisions |
| SCHUFA C-26/22 & C-64/22 | CJEU | Data rights and credit information | Accuracy and contestability |
| Nowak C-434/16 | CJEU | Personal data | Scores and evaluations |
| Google Spain C-131/12 | CJEU | Search-engine processing | Reputation and ranking |
| Google LLC v CNIL C-507/17 | CJEU | Delisting scope | Algorithmic visibility |
| Orange România C-61/19 | CJEU | Valid consent | AI data collection |
| Planet49 C-673/17 | CJEU | Tracking consent | Profiling infrastructure |
| Wirtschaftsakademie C-210/16 | CJEU | Joint responsibility | AI supply chains |
| Fashion ID C-40/17 | CJEU | Joint controllership | Multiple AI actors |
| CHEZ C-83/14 | CJEU | Indirect discrimination | Algorithmic bias |
| D.H. v Czech Republic | ECtHR GC | Statistical discrimination | Disparate-impact evidence |
| Digital Rights Ireland | CJEU | Proportionality | Mass AI surveillance |
| Tele2 Sverige/Watson | CJEU | Limits on data retention | Predictive profiling |
| Bărbulescu v Romania | ECtHR GC | Workplace monitoring | AI employee surveillance |
| López Ribalda v Spain | ECtHR GC | Surveillance proportionality | AI monitoring |
| Delfi v Estonia | ECtHR GC | Platform responsibility | Automated content moderation |
34. Core Principles
European algorithmic-harm jurisprudence can ultimately be reduced to several important principles:
1. Automation does not eliminate responsibility
A decision does not become legally unreviewable because a computer produced it.
2. Data quality matters
Incorrect data can produce legally significant harm.
3. Neutral algorithms can discriminate
A system does not need to explicitly use a protected characteristic to produce discriminatory effects.
4. Human review must be meaningful where required
A nominal human decision-maker may not be enough.
5. Transparency supports contestability
Affected individuals must have the legally required ability to understand and challenge relevant processing or decisions.
6. Proportionality matters
Technological capability does not itself establish legal necessity.
7. Responsibility can be distributed
Developers, deployers, controllers and other participants may have different legal responsibilities.
8. Harm requires a legal foundation
An undesirable algorithmic result is not automatically a successful damages claim.
Conclusion
Algorithmic Harm Claims in Europe are an emerging form of litigation built principally upon existing legal doctrines rather than a single autonomous AI tort.
The most important authorities include SCHUFA, Nowak, Google Spain, Orange România, Planet49, Wirtschaftsakademie, Fashion ID, CHEZ, D.H. v Czech Republic, Digital Rights Ireland, Tele2 Sverige/Watson, Bărbulescu, López Ribalda and Delfi.
The central legal sequence is:
Algorithm → Data/Model → Output → Human or Automated Decision → Legal/Practical Consequence → Recognised Harm → Causation → Remedy
The strongest claims generally arise where an algorithmic system combines inaccurate data, discriminatory effects, unlawful processing, consequential automated decision-making, inadequate human oversight, lack of meaningful challenge, or disproportionate surveillance. However, algorithmic error alone does not automatically establish liability; the claimant must connect the technological failure to a specific legal duty or right and, where required, establish causation and legally recognised damage.
Available next action: Create a downloadable PDF file here in this chat containing the findings and recommendations above

comments