Algorithmic Decision Harm Claims .
1. Meaning and Scope
Algorithmic decision harm claims arise when an algorithmic or AI-assisted system makes, recommends, ranks, predicts, or materially influences a decision that causes legally recognizable harm to an individual or organization.
Examples include algorithms used for:
- credit approval or refusal;
- recruitment and hiring;
- employee evaluation;
- dismissal and promotion;
- insurance underwriting;
- healthcare decisions;
- welfare-benefit allocation;
- immigration and asylum processing;
- tax and fraud detection;
- policing and risk assessment;
- education admissions;
- housing allocation;
- content moderation;
- automated pricing;
- fraud detection;
- customer classification.
The central legal issue is not simply that an algorithm produced an incorrect result. The claimant normally must establish an applicable legal duty or right, unlawful processing or decision-making, causation, and legally recognizable damage or prejudice.
2. No Independent “Algorithmic Harm” Cause of Action
European law does not generally treat “algorithmic harm” as one autonomous cause of action.
A claim may instead be based upon:
- GDPR;
- equality and anti-discrimination law;
- employment law;
- consumer law;
- contract;
- tort/delict;
- administrative law;
- fundamental rights;
- sector-specific regulation;
- product liability;
- professional negligence.
Accordingly:
Algorithmic error ≠ automatic legal liability.
A claimant must identify the legal rule that was breached.
3. Typical Causal Chain
A useful framework is:
Data → Algorithm → Score/Prediction → Decision → Consequence → Damage
For example:
Incorrect personal data → AI credit score → low score → loan refusal → inability to purchase property → financial loss
The claimant may need to prove each legally relevant part of this chain.
4. Main Types of Algorithmic Decision Harm
A. Financial Harm
Examples:
- credit refusal;
- incorrect insurance premium;
- wrongful benefit withdrawal;
- automated tax assessment;
- incorrect fraud classification.
B. Employment Harm
Examples:
- automated rejection of an applicant;
- discriminatory recruitment;
- inaccurate productivity score;
- automated dismissal recommendation;
- denial of promotion.
C. Privacy Harm
Algorithms may infer:
- health characteristics;
- political preferences;
- behavior;
- financial risk;
- personality;
- relationships.
Such processing can interfere with data-protection and privacy rights.
D. Equality Harm
Algorithmic systems may reproduce or amplify historical discrimination.
Examples:
- gender-biased recruitment;
- racial proxies in credit scoring;
- disability discrimination;
- age discrimination.
The relevant legal test depends upon the applicable equality legislation.
E. Procedural Harm
An individual may be harmed because:
- no reasons were supplied;
- the decision could not be challenged;
- there was no human review;
- inaccurate data could not be corrected;
- the decision-maker relied entirely on an opaque score.
5. GDPR as a Major Legal Framework
The GDPR is central to algorithmic decision-harm claims where personal data is involved.
Important provisions include:
- Article 5 — fairness, lawfulness and transparency;
- Article 12 — transparent communication;
- Article 13 — information where data is collected;
- Article 14 — information where data is obtained indirectly;
- Article 15 — access;
- Article 16 — rectification;
- Article 21 — objection;
- Article 22 — automated individual decision-making;
- Articles 24–25 — controller responsibility and data protection by design;
- Article 35 — data-protection impact assessments;
- Article 82 — compensation and liability.
6. Article 22 — Automated Individual Decision-Making
Article 22 is particularly important where a person is subjected to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significant effects.
Potential examples include:
- automated credit refusal;
- automated employment rejection;
- automatic termination of benefits;
- automated insurance decisions.
However, Article 22 should not be interpreted as a general prohibition on all algorithmic decision-making.
Its application depends upon the precise circumstances and the exceptions provided by the GDPR.
7. Leading Case Law
1. SCHUFA Holding AG, C-634/21
This is arguably the most important modern CJEU case concerning algorithmic decision-making.
Background
SCHUFA generated credit scores concerning individuals.
Those scores were used by third parties when assessing creditworthiness.
Legal significance
The CJEU examined the circumstances in which automated scoring can fall within the GDPR's rules concerning automated individual decision-making.
A critical point is that the algorithm does not necessarily need to issue the final formal decision itself.
Consider:
AI score → bank relies on score → loan rejected.
The fact that the bank technically makes the final decision does not necessarily remove the algorithmic processing from the legal analysis.
Importance for harm claims
The case demonstrates that algorithmic systems can create legally significant consequences even when their output is formally described as a "recommendation."
8. SCHUFA, Joined Cases C-26/22 and C-64/22
These cases further examined data-protection rights in the context of credit information.
Relevance
They concern important issues involving:
- access;
- personal data;
- credit information;
- retention;
- individual control over data.
Algorithmic harm significance
If an algorithmic decision depends upon inaccurate or unlawfully retained information, the claimant may have rights to:
- access;
- correction;
- restriction;
- objection;
- other applicable remedies.
9. Nowak v Data Protection Commissioner, C-434/16
Principle
The CJEU adopted a broad interpretation of personal data.
Information relating to an individual's performance or assessment can qualify as personal data where it relates to an identifiable person.
Algorithmic significance
Suppose an AI recruitment system generates:
"Candidate suitability: 38/100."
The assessment may have data-protection relevance if it relates to the identifiable applicant.
Likewise:
"Employee termination risk: 87%."
The resulting assessment can potentially fall within data-protection rights.
Harm significance
The case supports the ability of individuals to exercise data-protection rights concerning information used to evaluate them.
10. Google Spain, C-131/12
Principle
The CJEU recognized important data-protection rights concerning search-engine processing of personal information.
Algorithmic relevance
Search engines rely extensively upon automated:
- indexing;
- ranking;
- classification;
- retrieval.
The case establishes that automated technological processing can have significant legal consequences for individuals.
Harm
A person may suffer:
- reputational harm;
- employment harm;
- privacy harm;
- social harm.
The technological nature of the search engine does not eliminate legal responsibility.
11. Google LLC v CNIL, C-507/17
This case concerned the territorial scope of search-engine delisting.
Importance
The CJEU had to balance:
- privacy;
- data protection;
- freedom of information;
- public access to information.
Algorithmic harm relevance
It demonstrates that algorithmic systems frequently affect multiple competing rights.
A remedy must therefore be proportionate rather than automatically requiring complete removal of information everywhere.
12. Orange România, C-61/19
Principle
Consent must be:
- freely given;
- specific;
- informed;
- unambiguous.
Algorithmic harm relevance
Where algorithmic profiling relies on personal information obtained through consent, the underlying consent must itself be legally valid.
A company cannot simply place important algorithmic processing inside a confusing or bundled consent mechanism and assume that the individual agreed.
13. Planet49, C-673/17
This case concerned cookies and online tracking.
Algorithmic significance
Tracking technologies can provide the data used by:
- advertising algorithms;
- recommendation engines;
- profiling systems;
- behavioral prediction models.
Harm relevance
Where algorithmic decision-making depends upon unlawful data collection, the legality of the underlying processing becomes an important part of the claim.
14. Wirtschaftsakademie Schleswig-Holstein, C-210/16
Principle
The CJEU recognized responsibility for certain processing activities even where another company operates the technological platform.
Algorithmic harm significance
Consider:
Employer → AI vendor → cloud provider → model output.
The employer cannot necessarily avoid responsibility merely by saying:
"We didn't build the algorithm."
The legal question is who determines the relevant purposes and means of processing and what responsibilities arise under the applicable law.
15. Fashion ID, C-40/17
This case concerned a website operator using a third-party social-media plug-in.
Principle
Responsibility can arise for certain processing activities even where the organization does not operate the entire technical system.
Algorithmic relevance
Modern AI systems frequently involve:
- model providers;
- application developers;
- data suppliers;
- cloud providers;
- deployers.
Responsibility therefore needs to be allocated according to the actual roles performed.
16. Digital Rights Ireland, C-293/12 and C-594/12
Principle
The CJEU subjected large-scale data retention to strict fundamental-rights scrutiny.
Algorithmic significance
Large-scale data collection can later be used for:
- profiling;
- prediction;
- risk scoring;
- behavioral analysis.
The case establishes the importance of:
- necessity;
- proportionality;
- safeguards.
Harm relevance
The more intrusive the algorithmic processing, the stronger the need for adequate legal safeguards.
17. Tele2 Sverige and Watson, C-203/15 and C-698/15
This case concerned communications-data retention.
Principle
Generalized and indiscriminate retention can create serious fundamental-rights concerns.
Algorithmic relevance
Retained data can be analyzed algorithmically to identify:
- behavioral patterns;
- relationships;
- movements;
- risks.
The case is therefore important for understanding the fundamental-rights limits of large-scale algorithmic analysis.
18. Heylens, C-222/86
Although predating modern AI, Heylens is highly relevant to algorithmic decision harm.
Principle
Effective judicial protection requires meaningful reasons for decisions affecting legal interests.
Algorithmic application
Suppose an authority says:
"The algorithm rejected your application."
That may be insufficient where applicable law requires reasons.
A technological system cannot simply replace legally required justification.
19. Sopropé, C-349/07
Principle
The CJEU recognized the importance of the right to be heard in EU-law procedures.
Algorithmic relevance
Imagine an automated fraud-detection system flags a business.
The authority immediately imposes a penalty.
If the applicable legal framework requires an opportunity to respond, the algorithmic flag cannot necessarily replace that procedural safeguard.
20. M.M., C-277/11
The CJEU examined procedural safeguards in administrative decision-making.
Algorithmic significance
Where an automated risk assessment materially contributes to a public decision, procedural fairness remains relevant.
An algorithm cannot automatically eliminate:
- participation;
- access to relevant information;
- effective review.
21. Algorithmic Discrimination Claims
Algorithmic decision harm can involve direct or indirect discrimination.
Example
An employer's recruitment algorithm systematically ranks male applicants higher.
Potential issues include:
- equality law;
- employment law;
- GDPR;
- statistical evidence;
- indirect discrimination.
The claimant may seek information about:
- training data;
- input variables;
- selection criteria;
- model performance;
- group disparities.
But statistical correlation alone does not necessarily establish unlawful discrimination. The applicable legal test must be satisfied.
22. Employment Example
Suppose an employer uses AI to assign workers a productivity score.
Employee A receives:
42/100.
The system predicts:
"High probability of poor future performance."
The employer dismisses A.
A potential claim might involve:
- inaccurate data;
- unlawful profiling;
- lack of transparency;
- automated decision-making;
- discrimination;
- breach of employment law;
- procedural unfairness;
- economic and/or non-material damage.
The claimant would need to determine which legal causes of action actually apply.
23. Credit Example
Suppose:
AI credit score = 390
Mortgage application = refused.
The applicant discovers that the score was based partly on outdated information.
Potential claims could concern:
- inaccurate personal data;
- access rights;
- rectification;
- automated decision-making;
- transparency;
- unlawful processing;
- consequential financial harm.
SCHUFA is especially important in this context.
24. Public Administration Example
Suppose a welfare authority uses an algorithm to identify supposedly fraudulent benefit recipients.
An individual is classified:
"High fraud risk."
Benefits are suspended.
The individual argues:
- the data was incorrect;
- no explanation was given;
- no opportunity to respond existed;
- the algorithm contained discriminatory assumptions.
Potential legal avenues could include:
- GDPR;
- administrative law;
- equality law;
- EU fundamental rights;
- national constitutional law;
- judicial review.
25. Algorithmic Harm and Causation
Causation is often the most difficult part of these claims.
Suppose:
Algorithm gives low score → human reviews application → human independently rejects applicant.
The claimant must ask:
Did the algorithm actually cause the rejection?
Contrast this with:
Algorithm automatically rejects → no human review → applicant loses job.
The causal connection may be considerably stronger.
Therefore, courts may need to examine:
- whether the algorithm was determinative;
- whether humans independently reviewed it;
- whether the decision would have been different without the algorithm;
- whether another factor independently caused the harm.
26. Human Oversight
Calling a decision "human-reviewed" does not necessarily end the analysis.
The relevant question may be:
Was the human review genuine and capable of changing the outcome?
A person who merely accepts an AI score without examination may provide little meaningful protection.
By contrast, a decision-maker who:
- examines the underlying evidence;
- checks the algorithmic output;
- considers contradictory information;
- has authority to override the system;
may provide substantially stronger human oversight.
27. Accuracy and Data Quality
Algorithmic decisions are only as reliable as the relevant data and methodology.
Problems may arise from:
- outdated information;
- duplicate records;
- incorrect identities;
- missing data;
- biased historical records;
- proxy variables;
- data contamination.
Under data-protection law, inaccurate personal data can itself create a legal problem.
28. Bias and Proxy Variables
Algorithms can discriminate without explicitly using a protected characteristic.
For example, a system may not use:
"race"
but use:
- postcode;
- school;
- occupation;
- language;
- purchasing behavior.
These variables may operate as proxies.
Whether that constitutes unlawful discrimination depends upon the applicable legal framework and evidence.
29. Algorithmic Harm in Healthcare
AI can assist with:
- diagnosis;
- triage;
- treatment recommendations;
- risk prediction.
A harmful algorithmic recommendation might produce:
incorrect prediction → inappropriate treatment → physical injury.
Potential liability could involve:
- medical negligence;
- product liability;
- professional responsibility;
- data protection;
- medical-device regulation.
The fact that the physician relied on AI does not automatically transfer all responsibility to the AI developer.
30. Algorithmic Harm in Insurance
Algorithms may determine:
- risk classification;
- premium;
- coverage;
- fraud suspicion.
Potential harm includes:
- unjustified premium increases;
- refusal of insurance;
- discriminatory treatment;
- incorrect fraud classification.
The relevant legal regime can involve insurance regulation, consumer law, equality law and data protection.
31. Algorithmic Harm in Education
AI can influence:
- admissions;
- examination evaluation;
- student-risk scores;
- scholarship allocation.
Potential claims include:
- discrimination;
- procedural unfairness;
- inaccurate data;
- lack of transparency;
- unlawful automated decision-making.
Public universities may additionally face administrative-law and fundamental-rights requirements.
32. Algorithmic Harm and Fundamental Rights
Algorithmic decision-making can affect:
Article 8 ECHR
Private and family life.
Article 6 ECHR
Fair hearing where civil rights/obligations or criminal charges are being determined.
Article 13 ECHR
Effective remedy.
Article 14 ECHR
Non-discrimination in conjunction with another Convention right.
EU Charter Article 7
Private and family life.
Article 8
Protection of personal data.
Article 21
Non-discrimination.
Article 47
Effective remedy and fair trial.
33. Defences
Organizations may argue:
1. Human decision-maker
The algorithm only provided assistance.
2. No significant effect
The algorithmic output was merely informational.
3. Lawful processing
The organization had a valid legal basis.
4. Accurate information
The claimant's data was correct.
5. Independent causation
The alleged harm resulted from another decision or event.
6. No legally recognizable damage
The claimant cannot establish compensable harm.
7. Legitimate interests
The organization may rely on a legally recognized interest, subject to applicable requirements.
8. Security or trade secrets
Certain information may legitimately be restricted, although this does not necessarily eliminate all transparency obligations.
34. Remedies
Depending on the legal basis, remedies can include:
- access to personal data;
- rectification;
- erasure;
- restriction of processing;
- objection;
- human intervention where applicable;
- reconsideration;
- annulment of an administrative decision;
- reinstatement in employment cases;
- injunction;
- compensation;
- regulatory penalties.
The appropriate remedy depends upon the specific cause of action.
35. Damages
A major distinction must be made between:
Unlawful algorithmic processing
and
Compensable harm.
A claimant may prove an infringement but still face a separate question concerning whether the infringement caused legally compensable damage.
Possible damage can include:
- financial loss;
- lost employment opportunity;
- reputational injury;
- privacy interference;
- emotional/non-material harm where legally recognized;
- loss of opportunity, depending on the applicable law.
36. Evidence
Important evidence includes:
Algorithmic evidence
- model documentation;
- decision logs;
- input variables;
- output scores;
- audit records;
- validation results.
Data evidence
- source data;
- personal-data records;
- correction history;
- data provenance.
Procedural evidence
- decision letters;
- reasons;
- internal review records;
- human-review documents.
Statistical evidence
- error rates;
- false-positive rates;
- demographic disparities;
- comparative outcomes.
Expert evidence
- data scientists;
- statisticians;
- AI auditors;
- domain specialists.
37. Practical Legal Test
A strong algorithmic decision-harm analysis can follow this sequence:
Step 1 — Identify the algorithm
What system produced or influenced the decision?
Step 2 — Identify the decision
What decision was made?
Step 3 — Identify the affected right
Was it:
- employment;
- credit;
- privacy;
- equality;
- property;
- benefits;
- healthcare;
- education?
Step 4 — Identify the legal duty
Which law applies?
Step 5 — Determine the degree of automation
Was the algorithm:
- merely advisory;
- influential;
- substantially determinative;
- fully automated?
Step 6 — Examine data quality
Was the underlying information accurate and lawfully obtained?
Step 7 — Examine transparency
Was meaningful information provided?
Step 8 — Examine human review
Was review real or merely formal?
Step 9 — Establish causation
Did the algorithm actually cause the harmful outcome?
Step 10 — Establish damage
What legally recognizable harm occurred?
Step 11 — Determine remedy
What relief is available under the particular legal regime?
38. Consolidated Case Table
| Case | Court | Core principle | Algorithmic harm relevance |
|---|---|---|---|
| SCHUFA, C-634/21 | CJEU | Automated credit scoring and significant decisions | Very high |
| SCHUFA, C-26/22 & C-64/22 | CJEU | Access/data rights in credit-information context | Very high |
| Nowak, C-434/16 | CJEU | Broad concept of personal data | High |
| Google Spain, C-131/12 | CJEU | Automated search processing and individual rights | High |
| Google v CNIL, C-507/17 | CJEU | Privacy and information balancing | High |
| Orange România, C-61/19 | CJEU | Valid informed consent | High |
| Planet49, C-673/17 | CJEU | Online tracking and consent | High |
| Wirtschaftsakademie, C-210/16 | CJEU | Responsibility in digital ecosystems | High |
| Fashion ID, C-40/17 | CJEU | Responsibility for third-party processing | High |
| Digital Rights Ireland, C-293/12 & C-594/12 | CJEU | Proportionality and safeguards | High |
| Tele2 Sverige/Watson, C-203/15 & C-698/15 | CJEU | Data processing and fundamental rights | High |
| Heylens, C-222/86 | CJEU | Reasons and effective legal protection | High analogical authority |
| Sopropé, C-349/07 | CJEU | Right to be heard | High analogical authority |
| M.M., C-277/11 | CJEU | Procedural safeguards | High analogical authority |
39. Overall Legal Principle
The European approach to algorithmic decision harm can be summarized as:
The use of an algorithm does not remove the legal responsibility of the organization or authority that deploys, controls, relies upon, or is legally responsible for the decision-making process.
At the same time:
An incorrect algorithmic result does not automatically establish liability.
A successful claim ordinarily requires a legally recognized basis such as:
unlawful processing / discrimination / breach of duty / procedural unfairness / defective product / contractual breach → harmful decision → causation → legally recognizable damage → appropriate remedy.
The most important modern authority is SCHUFA (C-634/21) because it demonstrates how an apparently intermediate algorithmic score can become legally significant when it effectively determines or strongly influences a consequential decision. Nowak, Google Spain, Wirtschaftsakademie, Fashion ID, Digital Rights Ireland, Tele2, Heylens, Sopropé and M.M. provide the broader principles of personal-data protection, responsibility, proportionality, transparency, procedural fairness and effective legal protection needed to analyze algorithmic decision-harm claims.

comments