Attention Extraction Liability .

1. Meaning of Attention Extraction Liability

Attention Extraction Liability is an emerging area of European civil, regulatory, consumer, privacy and fundamental-rights law concerning situations where digital platforms, applications, advertisers or other businesses deliberately design systems to capture, prolong, manipulate, or monetise a person's attention in ways that may cause legally recognised harm.

The concept is particularly relevant to:

  • social-media platforms;
  • video-sharing platforms;
  • search engines;
  • online games;
  • streaming services;
  • mobile applications;
  • recommendation systems;
  • advertising platforms;
  • influencer platforms;
  • online marketplaces;
  • AI assistants and generative-AI services.

The business model is often described as the attention economy: the user's time, engagement and behavioural information become economically valuable.

However, European law does not currently recognise a standalone cause of action called “attention extraction liability.” Liability generally has to be established through existing legal regimes such as:

  • consumer protection;
  • unfair commercial practices;
  • GDPR;
  • digital-platform regulation;
  • product liability;
  • contract law;
  • negligence/delict;
  • discrimination;
  • children's rights;
  • privacy;
  • freedom of expression;
  • competition law;
  • fundamental rights.

2. What Is “Attention Extraction”?

Attention extraction may involve design features intended to encourage continued engagement, such as:

  • infinite scrolling;
  • autoplay;
  • personalised recommendations;
  • push notifications;
  • streaks;
  • variable rewards;
  • gamification;
  • social validation;
  • personalised advertising;
  • engagement-based ranking;
  • emotionally provocative recommendations;
  • dark patterns;
  • frictionless purchasing;
  • intermittent notifications;
  • algorithmic content sequencing.

Not every such practice is unlawful.

The legal issue arises when the design crosses a legally relevant threshold, for example by:

materially distorting consumer behaviour, unlawfully processing personal data, exploiting vulnerability, discriminating against users, violating children's protections, or causing compensable harm.

3. Why Attention Extraction Creates Liability Questions

Traditional consumer law generally assumes that individuals make decisions with reasonable autonomy.

Algorithmic platforms can complicate that assumption.

A platform may:

  1. collect behavioural data;
  2. infer preferences;
  3. predict engagement;
  4. rank content;
  5. deliver personalised material;
  6. measure the user's reaction;
  7. update the recommendation model;
  8. repeat the cycle.

The result is a feedback loop:

Data → prediction → recommendation → attention → behavioural data → improved prediction → further attention

This creates a potential legal issue concerning manipulation of consumer autonomy.

4. European Legal Framework

A. Digital Services Act

The Digital Services Act (DSA) is particularly important.

Regulation (EU) 2022/2065 imposes obligations on online platforms concerning:

  • transparency;
  • recommender systems;
  • advertising;
  • dark patterns;
  • protection of minors;
  • systemic risks;
  • very large online platforms;
  • risk mitigation.

Article 25 is particularly important because it addresses dark patterns.

The DSA restricts interface designs that materially distort or impair users' ability to make free and informed decisions.

5. DSA and Recommender Systems

Large platforms must address systemic risks associated with their services.

Relevant risks may include:

  • dissemination of harmful content;
  • negative effects on physical and mental well-being;
  • manipulation;
  • risks to minors;
  • discrimination;
  • electoral processes;
  • public health.

The DSA therefore moves the legal framework beyond:

“Was an individual piece of content unlawful?”

toward:

“Does the platform's overall design and algorithmic system create systemic risks?”

That is highly significant for attention-extraction claims.

6. GDPR

Attention-extraction systems often depend on extensive personal-data processing.

Platforms may process:

  • browsing behaviour;
  • clicks;
  • viewing duration;
  • search history;
  • location;
  • device information;
  • inferred preferences;
  • interaction patterns;
  • social relationships.

Potentially relevant GDPR principles include:

Article 5

Lawfulness, fairness, transparency, purpose limitation and data minimisation.

Article 6

Lawful bases for processing.

Article 9

Special-category data.

Article 13–14

Transparency.

Article 21

Right to object.

Article 22

Automated individual decision-making.

Article 25

Privacy by design and default.

Article 35

Data-protection impact assessments.

Article 82

Compensation.

7. Consumer Protection

The Unfair Commercial Practices Directive 2005/29/EC is highly relevant.

It addresses commercial practices that:

  • deceive consumers;
  • omit material information;
  • use aggressive practices;
  • materially distort consumer economic behaviour.

Attention-extraction techniques can become problematic where interface design is used to manipulate consumers into:

  • purchases;
  • subscriptions;
  • continued engagement;
  • disclosure of data;
  • acceptance of commercial terms.

8. Dark Patterns

Dark patterns are interface designs that steer users toward decisions they might not otherwise make.

Examples include:

  • making “accept” easy but “reject” difficult;
  • hiding cancellation;
  • preselecting options;
  • misleading button labels;
  • repeated prompts;
  • emotional pressure;
  • countdown timers;
  • deceptive subscription design.

Under the DSA, certain dark patterns are expressly prohibited.

Under consumer law and GDPR, other manipulative designs may also be unlawful depending upon their effects.

9. Children and Attention Extraction

Children receive heightened protection.

Attention-extraction systems directed toward children can involve:

  • games;
  • social media;
  • video platforms;
  • advertising;
  • educational applications.

The legal framework includes:

  • GDPR;
  • DSA;
  • EU consumer law;
  • Charter Article 24;
  • ECHR Article 8;
  • national child-protection law.

The fact that children voluntarily click on content does not necessarily establish meaningful autonomy.

10. Important European Case Law

1. Meta Platforms Ireland Ltd v Bundeskartellamt, C-252/21

CJEU

This is one of the most important modern cases for attention-economy analysis.

The case concerned Meta's processing and combination of personal data for personalised services and advertising.

The CJEU examined:

  • consent;
  • legitimate interests;
  • data combination;
  • competition law;
  • GDPR;
  • user autonomy.

Relevance to attention extraction

Attention-based platforms often monetise behavioural data.

The judgment demonstrates that the economic model of a platform does not eliminate GDPR constraints.

The fact that personalised advertising is commercially useful does not automatically establish a lawful basis for all associated data processing.

Principle: behavioural data used to support platform monetisation remains subject to European data-protection requirements.

Classification: Directly relevant.

11. SCHUFA Holding AG, Joined Cases C-26/22 and C-64/22

The CJEU addressed automated scoring under GDPR Article 22.

The case is important because automated systems can generate decisions or assessments that significantly affect individuals.

Attention-economy relevance

Platforms increasingly generate:

  • engagement scores;
  • recommendation profiles;
  • advertising profiles;
  • risk assessments;
  • behavioural predictions.

A platform may therefore not be able to avoid regulatory scrutiny merely by claiming:

“The algorithm only predicts behaviour.”

Where algorithmic profiling has significant legal or similarly significant effects, GDPR safeguards become important.

Classification: Analogical but highly relevant.

12. Österreichische Post AG, C-300/21

The CJEU considered compensation under GDPR Article 82.

The Court clarified that:

  • infringement alone does not automatically establish compensable damage;
  • but EU law does not impose an additional seriousness threshold as a precondition for every claim;
  • actual compensable damage must nevertheless be established.

Attention-extraction relevance

A user alleging harmful profiling or intrusive behavioural processing must distinguish:

unlawful processing

from

compensable damage.

Potential harm may include non-material damage where the legal requirements are satisfied.

Classification: Direct GDPR compensation authority.

13. NAP v Bundesrepublik Deutschland, C-340/21

This case concerned personal-data security and GDPR compensation.

It is relevant to attention-extraction systems because platforms accumulate enormous quantities of behavioural data.

A security failure involving:

  • viewing histories;
  • search history;
  • interests;
  • location;
  • inferred preferences;

could expose highly revealing information.

Principle

Organisations processing extensive personal data must take appropriate security measures, and GDPR liability can arise where legally recognised damage results from unlawful processing or inadequate security.

Classification: Direct GDPR authority; analogical to attention data.

14. Planet49, C-673/17

CJEU

Planet49 concerned online cookies and consent.

The CJEU examined whether pre-ticked boxes could establish valid consent.

Importance for attention extraction

Tracking technologies frequently underpin the attention economy.

Cookies and similar technologies can enable:

tracking → profiling → personalisation → engagement optimisation.

The case demonstrates that user consent must satisfy meaningful legal requirements rather than being manufactured through interface design.

Classification: Directly relevant.

15. Orange România, C-61/19

The CJEU examined the validity of consent and whether contractual or interface arrangements genuinely demonstrated freely given consent.

The case is important because consent cannot simply be presumed from passive behaviour or an unclear contractual process.

Attention-economy significance

A platform cannot necessarily say:

“The user clicked through the interface, therefore they consented.”

The legal quality of the consent process matters.

Classification: Directly relevant to consent-based attention systems.

16. Google Spain, C-131/12

The CJEU recognised important rights concerning personal data and online search results.

Attention-economy relevance

Search engines and platforms influence what information users see.

This can affect:

  • reputation;
  • autonomy;
  • access to information;
  • personal profiles.

The case demonstrates that digital intermediaries can have independent responsibilities concerning personal data.

Classification: Analogical but foundational.

17. Glawischnig-Piesczek v Facebook Ireland, C-18/18

The CJEU considered the responsibility of online platforms concerning unlawful user-generated content and injunctions.

Attention-economy relevance

Platform architecture determines:

  • what content is displayed;
  • how long it remains visible;
  • what is recommended;
  • what receives greater prominence.

Although the case primarily concerns unlawful content and intermediary obligations, it illustrates the possibility of judicial orders directed at platform systems.

Classification: Analogical but important.

18. Delfi AS v Estonia, Application No. 64569/09

ECtHR Grand Chamber

Delfi concerned intermediary liability for unlawful user comments.

The Court examined:

  • platform responsibility;
  • freedom of expression;
  • protection of others;
  • commercial nature of the platform;
  • mechanisms for responding to harmful content.

Attention-extraction significance

The case demonstrates that a platform's business model and role in disseminating content can matter to the proportionality analysis.

However, it does not establish that platforms are liable for every harmful consequence of user engagement.

Classification: Analogical.

19. Glukhin v Russia, Application No. 11519/20

The ECtHR examined facial-recognition technology and privacy.

Attention-economy relevance

Although not a platform-engagement case, the decision illustrates the heightened privacy concerns surrounding technological profiling.

Platforms may combine:

  • behavioural data;
  • biometric information;
  • location;
  • facial recognition.

Such systems can create highly intrusive profiles.

Classification: Analogical.

20. TikTok and Child-Focused Platform Regulation

European regulators have increasingly examined platform design and child protection.

The legal issues include:

  • age assurance;
  • recommender systems;
  • addictive or manipulative design;
  • targeted advertising;
  • privacy;
  • child safety.

Even where a particular enforcement action is administrative rather than a civil damages case, it helps establish the regulatory environment in which future attention-extraction claims may arise.

21. Attention Extraction and Causation

Causation is one of the biggest difficulties.

A claimant may argue:

“The platform deliberately designed its system to keep me engaged, and I suffered harm.”

The court must then determine:

  1. What feature caused the engagement?
  2. Was the feature intentionally designed for that purpose?
  3. Was the resulting harm foreseeable?
  4. Was the harm legally attributable to the platform?
  5. Were there intervening causes?
  6. Did the claimant have meaningful control?
  7. Did third-party content contribute?
  8. Did the platform know about the risk?
  9. Were safer alternatives available?

This makes attention-extraction liability more difficult than simply proving excessive screen time.

22. “Addiction” and Legal Liability

The concept of technological addiction is legally complicated.

A claimant may experience:

  • compulsive use;
  • sleep disruption;
  • anxiety;
  • loss of productivity;
  • financial loss;
  • educational difficulties;
  • social harm.

But:

The existence of compulsive or excessive use does not automatically establish legal liability.

The claimant must identify a recognised legal duty and establish the necessary elements of the relevant cause of action.

23. Negligence-Based Attention Claims

Under national civil law, a claimant might attempt to establish:

Duty

The platform owed a legally recognised duty.

Breach

The platform's design or conduct fell below the applicable standard.

Foreseeability

The harm was reasonably foreseeable.

Causation

The design materially contributed to the harm.

Damage

The claimant suffered legally compensable injury or loss.

This is particularly relevant where platforms allegedly know that particular design features create foreseeable risks to vulnerable users.

24. Product Liability

The newer European product-liability framework increasingly recognises software and digital components.

This could become relevant where:

  • an app is treated as a product;
  • defective design contributes to harm;
  • safety expectations are violated;
  • AI or software creates foreseeable risks.

However, not every harmful business model is automatically a “defective product.”

The precise classification depends on the relevant legal framework.

25. Attention Extraction and Privacy

Privacy harm can occur even without financial loss.

Examples include:

  • persistent behavioural tracking;
  • inference of intimate preferences;
  • monitoring of emotional states;
  • profiling;
  • manipulation based on vulnerabilities.

Article 8 ECHR and GDPR can therefore become important even where the claimant cannot prove traditional economic damage.

26. Attention Extraction and Freedom of Choice

European consumer law increasingly protects consumer autonomy.

The question is not simply:

“Did the consumer click?”

It may instead be:

“Was the consumer's decision-making materially distorted by the commercial practice?”

This is particularly important for:

  • subscription services;
  • gambling-like mechanisms;
  • in-app purchases;
  • influencer advertising;
  • personalised advertising;
  • dark patterns.

27. Attention Extraction and Competition Law

Attention is also an economic resource.

A dominant platform may control:

  • user attention;
  • advertising inventory;
  • data;
  • recommendation infrastructure.

Competition law may become relevant if a platform uses market power to:

  • exclude competitors;
  • self-preference;
  • exploit users;
  • impose unfair conditions;
  • restrict interoperability.

However, competition-law dominance alone does not create a general civil right to be free from attention extraction.

There must be an identifiable competition-law infringement.

28. Attention Extraction and Advertising

Targeted advertising may involve:

  1. collecting behavioural data;
  2. profiling the user;
  3. predicting likely responses;
  4. selecting an advertisement;
  5. measuring engagement;
  6. refining the profile.

Potential legal concerns include:

  • GDPR;
  • ePrivacy rules;
  • DSA;
  • consumer protection;
  • discrimination;
  • children's rights.

Particularly sensitive cases may involve targeting based on:

  • health;
  • political views;
  • religion;
  • sexuality;
  • psychological vulnerability.

29. Attention Extraction and Vulnerable Persons

Liability arguments become stronger where platforms target people who may have reduced capacity to resist manipulation.

Examples include:

  • children;
  • elderly users;
  • persons with cognitive impairments;
  • persons experiencing psychological vulnerability;
  • persons with gambling problems.

The legal analysis should therefore consider whether the platform knew or should have known about the vulnerability.

30. Attention Extraction and AI

AI intensifies the issue.

An AI system can dynamically determine:

  • what content to recommend;
  • when to send notifications;
  • what emotional tone to use;
  • what advertisement to display;
  • which users are most responsive;
  • when to offer incentives.

This creates a potentially continuous optimisation process:

Observe → predict → intervene → measure → optimise.

The more autonomous and personalised the system becomes, the more important transparency, auditability, human oversight and risk assessment become.

31. Possible Defences

Platforms may argue:

User autonomy

The user voluntarily chose to use the service.

Legitimate business purpose

Engagement is necessary to provide the service.

Freedom of expression

Recommendation systems support users' access to information.

Consent

The user agreed to the relevant processing or terms.

Lack of causation

The alleged harm resulted from other factors.

Lack of damage

No legally compensable loss has been established.

Third-party responsibility

The harmful content came from users or advertisers.

These defences do not automatically succeed; their strength depends upon the specific facts.

32. Remedies

Possible remedies include:

Injunctions

Preventing unlawful design or processing.

Data-protection orders

Requiring cessation or modification of processing.

Deletion

Removing unlawfully collected personal data.

Rectification

Correcting inaccurate profiles.

Compensation

Where GDPR or national law requirements are satisfied.

Consumer remedies

Potential cancellation, restitution or damages.

Regulatory penalties

Available to competent regulators under relevant legislation.

Structural remedies

Requiring changes to:

  • recommender systems;
  • consent mechanisms;
  • advertising architecture;
  • age protections;
  • dark-pattern interfaces.

33. Consolidated Case-Law Table

CaseCourtPrincipal RuleAttention-Extraction Relevance
Meta Platforms v Bundeskartellamt, C-252/21CJEUData processing, consent, advertising and competitionBehavioural-data monetisation
SCHUFA, C-26/22 & C-64/22CJEUAutomated scoring and Article 22Algorithmic profiling
Österreichische Post, C-300/21CJEUGDPR compensationHarm from profiling/data processing
NAP, C-340/21CJEUSecurity and non-material damageBehavioural-data breaches
Planet49, C-673/17CJEUValid consent for trackingTracking underlying attention systems
Orange România, C-61/19CJEUFreely given consentManipulative consent interfaces
Google Spain, C-131/12CJEUOnline personal-data rightsDigital profiling/reputation
Glawischnig-Piesczek, C-18/18CJEUPlatform obligations/injunctionsPlatform architecture
Delfi v EstoniaECtHRPlatform responsibility and expressionContent/engagement ecosystem
Glukhin v RussiaECtHRTechnology and privacyAlgorithmic profiling
López Ribalda v SpainECtHRSurveillance proportionalityBehavioural monitoring

34. Direct vs Analogical Authorities

Because attention-extraction liability is an emerging legal category, it is important to distinguish the cases.

Most directly relevant

  • Meta Platforms
  • Planet49
  • Orange România
  • Österreichische Post
  • NAP
  • SCHUFA

These directly concern data processing, profiling, consent, automated processing or digital systems.

Important analogical authorities

  • Google Spain
  • Glawischnig-Piesczek
  • Delfi
  • Glukhin
  • López Ribalda

These do not establish a general doctrine of attention-extraction liability but help establish broader European principles concerning platform responsibility, privacy, surveillance and digital autonomy.

35. Practical Legal Test

An attention-extraction claim can be structured as follows:

Design feature → responsible actor → purpose → data processing → user vulnerability → legal duty → manipulation/distortion → foreseeable harm → causation → damage → remedy

Example

Suppose a platform:

  • profiles a 15-year-old;
  • predicts emotional vulnerability;
  • recommends increasingly extreme content;
  • sends repeated notifications;
  • optimises recommendations for maximum engagement.

The legal analysis would ask:

  1. Is the user a minor?
  2. What personal data is being processed?
  3. Is profiling taking place?
  4. What is the legal basis?
  5. Is the processing transparent?
  6. Does the system use dark patterns?
  7. Does the recommender create systemic risks?
  8. Were child-protection safeguards implemented?
  9. Was the harm foreseeable?
  10. Did the platform know about the risk?
  11. Did the platform have safer alternatives?
  12. What remedy is available?

36. Emerging Liability Model

European law is moving away from a simplistic model:

“The user voluntarily used the platform.”

toward a more sophisticated model:

“Was the user's autonomy meaningfully preserved in an environment deliberately optimised through data and algorithms?”

This does not mean that all persuasive design is unlawful.

Rather, liability becomes more plausible where there is a combination of:

  • extensive profiling;
  • vulnerability;
  • deceptive design;
  • lack of transparency;
  • unlawful processing;
  • systemic risk;
  • foreseeable harm;
  • failure to mitigate.

37. Conclusion

Attention Extraction Liability in Europe is an emerging, multi-layered field rather than an established standalone cause of action.

The principal legal foundations are:

  1. GDPR — controls behavioural tracking, profiling, consent and automated decision-making.
  2. Digital Services Act — addresses dark patterns, recommender systems and systemic platform risks.
  3. Consumer law — protects consumers against materially distorting or aggressive commercial practices.
  4. Fundamental-rights law — protects privacy, autonomy, dignity and children's interests.
  5. Product and tort/delict law — may address physical or other compensable harm caused by defective systems or negligent design.
  6. Competition law — can address exploitation or exclusion involving dominant digital platforms.

The central European legal principle can be stated as:

A platform's ability to capture attention is not itself unlawful; liability may arise when the methods used to capture or monetise attention unlawfully undermine autonomy, violate data-protection rules, exploit vulnerability, create prohibited manipulation, or cause legally recognised harm.

The most important jurisprudential progression is therefore:

tracking → profiling → personalisation → manipulation → systemic risk → legally protected autonomy → liability.

LEAVE A COMMENT