Algorithmic Decision Harm Claims .

1. Meaning and Scope

Algorithmic decision harm claims arise when an algorithmic or AI-assisted system makes, recommends, ranks, predicts, or materially influences a decision that causes legally recognizable harm to an individual or organization.

Examples include algorithms used for:

  • credit approval or refusal;
  • recruitment and hiring;
  • employee evaluation;
  • dismissal and promotion;
  • insurance underwriting;
  • healthcare decisions;
  • welfare-benefit allocation;
  • immigration and asylum processing;
  • tax and fraud detection;
  • policing and risk assessment;
  • education admissions;
  • housing allocation;
  • content moderation;
  • automated pricing;
  • fraud detection;
  • customer classification.

The central legal issue is not simply that an algorithm produced an incorrect result. The claimant normally must establish an applicable legal duty or right, unlawful processing or decision-making, causation, and legally recognizable damage or prejudice.

2. No Independent “Algorithmic Harm” Cause of Action

European law does not generally treat “algorithmic harm” as one autonomous cause of action.

A claim may instead be based upon:

  • GDPR;
  • equality and anti-discrimination law;
  • employment law;
  • consumer law;
  • contract;
  • tort/delict;
  • administrative law;
  • fundamental rights;
  • sector-specific regulation;
  • product liability;
  • professional negligence.

Accordingly:

Algorithmic error ≠ automatic legal liability.

A claimant must identify the legal rule that was breached.

3. Typical Causal Chain

A useful framework is:

Data → Algorithm → Score/Prediction → Decision → Consequence → Damage

For example:

Incorrect personal data → AI credit score → low score → loan refusal → inability to purchase property → financial loss

The claimant may need to prove each legally relevant part of this chain.

4. Main Types of Algorithmic Decision Harm

A. Financial Harm

Examples:

  • credit refusal;
  • incorrect insurance premium;
  • wrongful benefit withdrawal;
  • automated tax assessment;
  • incorrect fraud classification.

B. Employment Harm

Examples:

  • automated rejection of an applicant;
  • discriminatory recruitment;
  • inaccurate productivity score;
  • automated dismissal recommendation;
  • denial of promotion.

C. Privacy Harm

Algorithms may infer:

  • health characteristics;
  • political preferences;
  • behavior;
  • financial risk;
  • personality;
  • relationships.

Such processing can interfere with data-protection and privacy rights.

D. Equality Harm

Algorithmic systems may reproduce or amplify historical discrimination.

Examples:

  • gender-biased recruitment;
  • racial proxies in credit scoring;
  • disability discrimination;
  • age discrimination.

The relevant legal test depends upon the applicable equality legislation.

E. Procedural Harm

An individual may be harmed because:

  • no reasons were supplied;
  • the decision could not be challenged;
  • there was no human review;
  • inaccurate data could not be corrected;
  • the decision-maker relied entirely on an opaque score.

5. GDPR as a Major Legal Framework

The GDPR is central to algorithmic decision-harm claims where personal data is involved.

Important provisions include:

  • Article 5 — fairness, lawfulness and transparency;
  • Article 12 — transparent communication;
  • Article 13 — information where data is collected;
  • Article 14 — information where data is obtained indirectly;
  • Article 15 — access;
  • Article 16 — rectification;
  • Article 21 — objection;
  • Article 22 — automated individual decision-making;
  • Articles 24–25 — controller responsibility and data protection by design;
  • Article 35 — data-protection impact assessments;
  • Article 82 — compensation and liability.

6. Article 22 — Automated Individual Decision-Making

Article 22 is particularly important where a person is subjected to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significant effects.

Potential examples include:

  • automated credit refusal;
  • automated employment rejection;
  • automatic termination of benefits;
  • automated insurance decisions.

However, Article 22 should not be interpreted as a general prohibition on all algorithmic decision-making.

Its application depends upon the precise circumstances and the exceptions provided by the GDPR.

7. Leading Case Law

1. SCHUFA Holding AG, C-634/21

This is arguably the most important modern CJEU case concerning algorithmic decision-making.

Background

SCHUFA generated credit scores concerning individuals.

Those scores were used by third parties when assessing creditworthiness.

Legal significance

The CJEU examined the circumstances in which automated scoring can fall within the GDPR's rules concerning automated individual decision-making.

A critical point is that the algorithm does not necessarily need to issue the final formal decision itself.

Consider:

AI score → bank relies on score → loan rejected.

The fact that the bank technically makes the final decision does not necessarily remove the algorithmic processing from the legal analysis.

Importance for harm claims

The case demonstrates that algorithmic systems can create legally significant consequences even when their output is formally described as a "recommendation."

8. SCHUFA, Joined Cases C-26/22 and C-64/22

These cases further examined data-protection rights in the context of credit information.

Relevance

They concern important issues involving:

  • access;
  • personal data;
  • credit information;
  • retention;
  • individual control over data.

Algorithmic harm significance

If an algorithmic decision depends upon inaccurate or unlawfully retained information, the claimant may have rights to:

  • access;
  • correction;
  • restriction;
  • objection;
  • other applicable remedies.

9. Nowak v Data Protection Commissioner, C-434/16

Principle

The CJEU adopted a broad interpretation of personal data.

Information relating to an individual's performance or assessment can qualify as personal data where it relates to an identifiable person.

Algorithmic significance

Suppose an AI recruitment system generates:

"Candidate suitability: 38/100."

The assessment may have data-protection relevance if it relates to the identifiable applicant.

Likewise:

"Employee termination risk: 87%."

The resulting assessment can potentially fall within data-protection rights.

Harm significance

The case supports the ability of individuals to exercise data-protection rights concerning information used to evaluate them.

10. Google Spain, C-131/12

Principle

The CJEU recognized important data-protection rights concerning search-engine processing of personal information.

Algorithmic relevance

Search engines rely extensively upon automated:

  • indexing;
  • ranking;
  • classification;
  • retrieval.

The case establishes that automated technological processing can have significant legal consequences for individuals.

Harm

A person may suffer:

  • reputational harm;
  • employment harm;
  • privacy harm;
  • social harm.

The technological nature of the search engine does not eliminate legal responsibility.

11. Google LLC v CNIL, C-507/17

This case concerned the territorial scope of search-engine delisting.

Importance

The CJEU had to balance:

  • privacy;
  • data protection;
  • freedom of information;
  • public access to information.

Algorithmic harm relevance

It demonstrates that algorithmic systems frequently affect multiple competing rights.

A remedy must therefore be proportionate rather than automatically requiring complete removal of information everywhere.

12. Orange România, C-61/19

Principle

Consent must be:

  • freely given;
  • specific;
  • informed;
  • unambiguous.

Algorithmic harm relevance

Where algorithmic profiling relies on personal information obtained through consent, the underlying consent must itself be legally valid.

A company cannot simply place important algorithmic processing inside a confusing or bundled consent mechanism and assume that the individual agreed.

13. Planet49, C-673/17

This case concerned cookies and online tracking.

Algorithmic significance

Tracking technologies can provide the data used by:

  • advertising algorithms;
  • recommendation engines;
  • profiling systems;
  • behavioral prediction models.

Harm relevance

Where algorithmic decision-making depends upon unlawful data collection, the legality of the underlying processing becomes an important part of the claim.

14. Wirtschaftsakademie Schleswig-Holstein, C-210/16

Principle

The CJEU recognized responsibility for certain processing activities even where another company operates the technological platform.

Algorithmic harm significance

Consider:

Employer → AI vendor → cloud provider → model output.

The employer cannot necessarily avoid responsibility merely by saying:

"We didn't build the algorithm."

The legal question is who determines the relevant purposes and means of processing and what responsibilities arise under the applicable law.

15. Fashion ID, C-40/17

This case concerned a website operator using a third-party social-media plug-in.

Principle

Responsibility can arise for certain processing activities even where the organization does not operate the entire technical system.

Algorithmic relevance

Modern AI systems frequently involve:

  • model providers;
  • application developers;
  • data suppliers;
  • cloud providers;
  • deployers.

Responsibility therefore needs to be allocated according to the actual roles performed.

16. Digital Rights Ireland, C-293/12 and C-594/12

Principle

The CJEU subjected large-scale data retention to strict fundamental-rights scrutiny.

Algorithmic significance

Large-scale data collection can later be used for:

  • profiling;
  • prediction;
  • risk scoring;
  • behavioral analysis.

The case establishes the importance of:

  • necessity;
  • proportionality;
  • safeguards.

Harm relevance

The more intrusive the algorithmic processing, the stronger the need for adequate legal safeguards.

17. Tele2 Sverige and Watson, C-203/15 and C-698/15

This case concerned communications-data retention.

Principle

Generalized and indiscriminate retention can create serious fundamental-rights concerns.

Algorithmic relevance

Retained data can be analyzed algorithmically to identify:

  • behavioral patterns;
  • relationships;
  • movements;
  • risks.

The case is therefore important for understanding the fundamental-rights limits of large-scale algorithmic analysis.

18. Heylens, C-222/86

Although predating modern AI, Heylens is highly relevant to algorithmic decision harm.

Principle

Effective judicial protection requires meaningful reasons for decisions affecting legal interests.

Algorithmic application

Suppose an authority says:

"The algorithm rejected your application."

That may be insufficient where applicable law requires reasons.

A technological system cannot simply replace legally required justification.

19. Sopropé, C-349/07

Principle

The CJEU recognized the importance of the right to be heard in EU-law procedures.

Algorithmic relevance

Imagine an automated fraud-detection system flags a business.

The authority immediately imposes a penalty.

If the applicable legal framework requires an opportunity to respond, the algorithmic flag cannot necessarily replace that procedural safeguard.

20. M.M., C-277/11

The CJEU examined procedural safeguards in administrative decision-making.

Algorithmic significance

Where an automated risk assessment materially contributes to a public decision, procedural fairness remains relevant.

An algorithm cannot automatically eliminate:

  • participation;
  • access to relevant information;
  • effective review.

21. Algorithmic Discrimination Claims

Algorithmic decision harm can involve direct or indirect discrimination.

Example

An employer's recruitment algorithm systematically ranks male applicants higher.

Potential issues include:

  • equality law;
  • employment law;
  • GDPR;
  • statistical evidence;
  • indirect discrimination.

The claimant may seek information about:

  • training data;
  • input variables;
  • selection criteria;
  • model performance;
  • group disparities.

But statistical correlation alone does not necessarily establish unlawful discrimination. The applicable legal test must be satisfied.

22. Employment Example

Suppose an employer uses AI to assign workers a productivity score.

Employee A receives:

42/100.

The system predicts:

"High probability of poor future performance."

The employer dismisses A.

A potential claim might involve:

  1. inaccurate data;
  2. unlawful profiling;
  3. lack of transparency;
  4. automated decision-making;
  5. discrimination;
  6. breach of employment law;
  7. procedural unfairness;
  8. economic and/or non-material damage.

The claimant would need to determine which legal causes of action actually apply.

23. Credit Example

Suppose:

AI credit score = 390
Mortgage application = refused.

The applicant discovers that the score was based partly on outdated information.

Potential claims could concern:

  • inaccurate personal data;
  • access rights;
  • rectification;
  • automated decision-making;
  • transparency;
  • unlawful processing;
  • consequential financial harm.

SCHUFA is especially important in this context.

24. Public Administration Example

Suppose a welfare authority uses an algorithm to identify supposedly fraudulent benefit recipients.

An individual is classified:

"High fraud risk."

Benefits are suspended.

The individual argues:

  • the data was incorrect;
  • no explanation was given;
  • no opportunity to respond existed;
  • the algorithm contained discriminatory assumptions.

Potential legal avenues could include:

  • GDPR;
  • administrative law;
  • equality law;
  • EU fundamental rights;
  • national constitutional law;
  • judicial review.

25. Algorithmic Harm and Causation

Causation is often the most difficult part of these claims.

Suppose:

Algorithm gives low score → human reviews application → human independently rejects applicant.

The claimant must ask:

Did the algorithm actually cause the rejection?

Contrast this with:

Algorithm automatically rejects → no human review → applicant loses job.

The causal connection may be considerably stronger.

Therefore, courts may need to examine:

  • whether the algorithm was determinative;
  • whether humans independently reviewed it;
  • whether the decision would have been different without the algorithm;
  • whether another factor independently caused the harm.

26. Human Oversight

Calling a decision "human-reviewed" does not necessarily end the analysis.

The relevant question may be:

Was the human review genuine and capable of changing the outcome?

A person who merely accepts an AI score without examination may provide little meaningful protection.

By contrast, a decision-maker who:

  • examines the underlying evidence;
  • checks the algorithmic output;
  • considers contradictory information;
  • has authority to override the system;

may provide substantially stronger human oversight.

27. Accuracy and Data Quality

Algorithmic decisions are only as reliable as the relevant data and methodology.

Problems may arise from:

  • outdated information;
  • duplicate records;
  • incorrect identities;
  • missing data;
  • biased historical records;
  • proxy variables;
  • data contamination.

Under data-protection law, inaccurate personal data can itself create a legal problem.

28. Bias and Proxy Variables

Algorithms can discriminate without explicitly using a protected characteristic.

For example, a system may not use:

"race"

but use:

  • postcode;
  • school;
  • occupation;
  • language;
  • purchasing behavior.

These variables may operate as proxies.

Whether that constitutes unlawful discrimination depends upon the applicable legal framework and evidence.

29. Algorithmic Harm in Healthcare

AI can assist with:

  • diagnosis;
  • triage;
  • treatment recommendations;
  • risk prediction.

A harmful algorithmic recommendation might produce:

incorrect prediction → inappropriate treatment → physical injury.

Potential liability could involve:

  • medical negligence;
  • product liability;
  • professional responsibility;
  • data protection;
  • medical-device regulation.

The fact that the physician relied on AI does not automatically transfer all responsibility to the AI developer.

30. Algorithmic Harm in Insurance

Algorithms may determine:

  • risk classification;
  • premium;
  • coverage;
  • fraud suspicion.

Potential harm includes:

  • unjustified premium increases;
  • refusal of insurance;
  • discriminatory treatment;
  • incorrect fraud classification.

The relevant legal regime can involve insurance regulation, consumer law, equality law and data protection.

31. Algorithmic Harm in Education

AI can influence:

  • admissions;
  • examination evaluation;
  • student-risk scores;
  • scholarship allocation.

Potential claims include:

  • discrimination;
  • procedural unfairness;
  • inaccurate data;
  • lack of transparency;
  • unlawful automated decision-making.

Public universities may additionally face administrative-law and fundamental-rights requirements.

32. Algorithmic Harm and Fundamental Rights

Algorithmic decision-making can affect:

Article 8 ECHR

Private and family life.

Article 6 ECHR

Fair hearing where civil rights/obligations or criminal charges are being determined.

Article 13 ECHR

Effective remedy.

Article 14 ECHR

Non-discrimination in conjunction with another Convention right.

EU Charter Article 7

Private and family life.

Article 8

Protection of personal data.

Article 21

Non-discrimination.

Article 47

Effective remedy and fair trial.

33. Defences

Organizations may argue:

1. Human decision-maker

The algorithm only provided assistance.

2. No significant effect

The algorithmic output was merely informational.

3. Lawful processing

The organization had a valid legal basis.

4. Accurate information

The claimant's data was correct.

5. Independent causation

The alleged harm resulted from another decision or event.

6. No legally recognizable damage

The claimant cannot establish compensable harm.

7. Legitimate interests

The organization may rely on a legally recognized interest, subject to applicable requirements.

8. Security or trade secrets

Certain information may legitimately be restricted, although this does not necessarily eliminate all transparency obligations.

34. Remedies

Depending on the legal basis, remedies can include:

  • access to personal data;
  • rectification;
  • erasure;
  • restriction of processing;
  • objection;
  • human intervention where applicable;
  • reconsideration;
  • annulment of an administrative decision;
  • reinstatement in employment cases;
  • injunction;
  • compensation;
  • regulatory penalties.

The appropriate remedy depends upon the specific cause of action.

35. Damages

A major distinction must be made between:

Unlawful algorithmic processing

and

Compensable harm.

A claimant may prove an infringement but still face a separate question concerning whether the infringement caused legally compensable damage.

Possible damage can include:

  • financial loss;
  • lost employment opportunity;
  • reputational injury;
  • privacy interference;
  • emotional/non-material harm where legally recognized;
  • loss of opportunity, depending on the applicable law.

36. Evidence

Important evidence includes:

Algorithmic evidence

  • model documentation;
  • decision logs;
  • input variables;
  • output scores;
  • audit records;
  • validation results.

Data evidence

  • source data;
  • personal-data records;
  • correction history;
  • data provenance.

Procedural evidence

  • decision letters;
  • reasons;
  • internal review records;
  • human-review documents.

Statistical evidence

  • error rates;
  • false-positive rates;
  • demographic disparities;
  • comparative outcomes.

Expert evidence

  • data scientists;
  • statisticians;
  • AI auditors;
  • domain specialists.

37. Practical Legal Test

A strong algorithmic decision-harm analysis can follow this sequence:

Step 1 — Identify the algorithm

What system produced or influenced the decision?

Step 2 — Identify the decision

What decision was made?

Step 3 — Identify the affected right

Was it:

  • employment;
  • credit;
  • privacy;
  • equality;
  • property;
  • benefits;
  • healthcare;
  • education?

Step 4 — Identify the legal duty

Which law applies?

Step 5 — Determine the degree of automation

Was the algorithm:

  • merely advisory;
  • influential;
  • substantially determinative;
  • fully automated?

Step 6 — Examine data quality

Was the underlying information accurate and lawfully obtained?

Step 7 — Examine transparency

Was meaningful information provided?

Step 8 — Examine human review

Was review real or merely formal?

Step 9 — Establish causation

Did the algorithm actually cause the harmful outcome?

Step 10 — Establish damage

What legally recognizable harm occurred?

Step 11 — Determine remedy

What relief is available under the particular legal regime?

38. Consolidated Case Table

CaseCourtCore principleAlgorithmic harm relevance
SCHUFA, C-634/21CJEUAutomated credit scoring and significant decisionsVery high
SCHUFA, C-26/22 & C-64/22CJEUAccess/data rights in credit-information contextVery high
Nowak, C-434/16CJEUBroad concept of personal dataHigh
Google Spain, C-131/12CJEUAutomated search processing and individual rightsHigh
Google v CNIL, C-507/17CJEUPrivacy and information balancingHigh
Orange România, C-61/19CJEUValid informed consentHigh
Planet49, C-673/17CJEUOnline tracking and consentHigh
Wirtschaftsakademie, C-210/16CJEUResponsibility in digital ecosystemsHigh
Fashion ID, C-40/17CJEUResponsibility for third-party processingHigh
Digital Rights Ireland, C-293/12 & C-594/12CJEUProportionality and safeguardsHigh
Tele2 Sverige/Watson, C-203/15 & C-698/15CJEUData processing and fundamental rightsHigh
Heylens, C-222/86CJEUReasons and effective legal protectionHigh analogical authority
Sopropé, C-349/07CJEURight to be heardHigh analogical authority
M.M., C-277/11CJEUProcedural safeguardsHigh analogical authority

39. Overall Legal Principle

The European approach to algorithmic decision harm can be summarized as:

The use of an algorithm does not remove the legal responsibility of the organization or authority that deploys, controls, relies upon, or is legally responsible for the decision-making process.

At the same time:

An incorrect algorithmic result does not automatically establish liability.

A successful claim ordinarily requires a legally recognized basis such as:

unlawful processing / discrimination / breach of duty / procedural unfairness / defective product / contractual breach → harmful decision → causation → legally recognizable damage → appropriate remedy.

The most important modern authority is SCHUFA (C-634/21) because it demonstrates how an apparently intermediate algorithmic score can become legally significant when it effectively determines or strongly influences a consequential decision. Nowak, Google Spain, Wirtschaftsakademie, Fashion ID, Digital Rights Ireland, Tele2, Heylens, Sopropé and M.M. provide the broader principles of personal-data protection, responsibility, proportionality, transparency, procedural fairness and effective legal protection needed to analyze algorithmic decision-harm claims.

LEAVE A COMMENT