Examining whether existing European and domestic human rights law provides adequate protection against algorithmic scoring in credit, employment, and university admissions
I. Introduction
Algorithmic scoring systems have become an infrastructure of modern life. From the determination of creditworthiness to the screening of job applicants and the allocation of university places, decisions of profound consequence are increasingly delegated to automated systems that assign numerical values to human beings and rank them accordingly.[1] These systems promise efficiency, consistency, and objectivity. In practice, they frequently deliver opacity, cumulative disadvantage, and an asymmetry of power between those who design scores and those who are subjected to them.[2] The harms are neither hypothetical nor marginal. In the Netherlands, the tax authorities deployed an algorithmic system that erroneously classified approximately 26,000 parents as having committed fraud in their childcare benefit applications. A disproportionate number of those affected had an immigration background. The families were required to repay large sums, resulting in severe financial and psychological harm. The Dutch data protection authority concluded that the processing of data by the system in question was discriminatory.[3] This is not an isolated incident but a cautionary illustration of what the European Union Agency for Fundamental Rights has described as the real-world impact of decisions made or supported by biased algorithms.[4] In credit, employment, and university
[1] Mireille Hildebrandt, ‘Defining Profiling: A New Type of Knowledge?’ in Mireille Hildebrandt and Serge Gutwirth (eds), Profiling the European Citizen: Cross-Disciplinary Perspectives (Springer 2008) 17, 19–20; Frank Pasquale, Data Access and AI Explainability (Cambridge University Press 2025) s 2.1; Bank of England and Financial Conduct Authority, Artificial Intelligence in UK Financial Services 2024 (Bank of England 2024) 3.
[2] Antoinette Rouvroy and Thomas Berns, ‘Algorithmic Governmentality and Prospects of Emancipation: Disparateness as a Precondition for Individuation through Relationships?’ (trans Elizabeth Libbrecht) (2013) 177 Réseaux 163, 165–67; Sandra Wachter and Brent Mittelstadt, ‘A Right to Reasonable Inferences: Re-Thinking Data Protection Law in the Age of Big Data and AI’ (2019) 2 Columbia Business Law Review 443, 447–49.
[3] European Union Agency for Fundamental Rights, Bias in Algorithms: Artificial Intelligence and Discrimination (Publications Office of the European Union 2022) 7, 17.
[4] ibid 17.
admissions, analogous harms arise daily, diffused across millions of individual decisions and obscured by the opacity that is structural to algorithmic systems.[1]
The legal response to these harms has been hesitant and incomplete. The General Data Protection Regulation confers upon individuals a qualified right against solely automated decision-making with legal or similarly significant effects.[2] The EU AI Act classifies scoring systems in employment, education, and credit assessment as high-risk AI, imposing requirements of transparency, human oversight, and conformity assessment.[3] The European Convention on Human Rights protects the right to private life and prohibits discrimination.[4] Yet the instruments designed to protect individuals were not conceived with algorithmic scoring in mind. Their application has been cautious, their scope contested, and their enforcement patchy, a deficiency the literature on automated decision-making has increasingly identified as procedural rather than substantive.[5] The result is a framework that is incomplete not because the law is absent, but because interpretive ambition has been insufficient. This article argues that the principal failure is one of interpretive ambition rather than legal lacuna. No new, express right against excessive algorithmic scoring is required. Instead, through purposive and evolutive interpretation of Article 8 of the Convention, read in conjunction with Article 14 and the principle of human dignity, and reinforced by a robust reading of the UK GDPR and the EU AI Act, courts and regulators already possess sufficient tools to construct adequate protection. The case for interpretive extension is examined through three concrete scoring contexts, credit and financial scoring, employment and hiring algorithms, and university admissions, which together illustrate the distinctive
[1] Pasquale (n 1) ss 2.3.1–2.3.3; Lilian Edwards and Michael Veale, ‘Slave to the Algorithm? Why a “Right to an Explanation” is Probably Not the Remedy You Are Looking For’ (2017) 16(1) Duke Law & Technology Review 18, 20–22.
[2] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation) [2016] OJ L119/1, art 22; Case C-634/21 OQ v Land Hessen (SCHUFA Holding — Scoring) EU:C:2023:957 (CJEU, 7 December 2023) [21]–[24].
[3] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) [2024] OJ L1689, arts 6, Annex III.
[4] Convention for the Protection of Human Rights and Fundamental Freedoms (European Convention on Human Rights, as amended) (ECHR) arts 8, 14.
[5] Elena Abrusci and Richard Mackenzie-Gray Scott, ‘The Questionable Necessity of a New Human Right Against Being Subject to Automated Decision-Making’ (2023) 31(2) International Journal of Law and Information Technology 114, 115–16; Edwards and Veale (n 5) 20–22.
adopts a doctrinal methodology, grounded in purposive and evolutive interpretation of existing legal instruments and Convention jurisprudence, and tested against the concrete factual contexts of credit, employment, and university admissions scoring.
The article proceeds as follows. Section II defines algorithmic scoring with precision, distinguishes it from general automated decision-making, and analyses the specific harms generated in each of the three case studies. Section III surveys the existing legal framework and identifies its limitations, not as structural gaps requiring new rights, but as failures of interpretation. Section IV develops the case for purposive extension of existing rights, drawing on the living instrument doctrine and established principles of ECHR jurisprudence. Section V addresses the principal objections to this approach. Section VI concludes by identifying the implications for courts, regulators, and the future trajectory of human rights law in the algorithmic age.
II. Algorithmic Scoring: Definitions, Harms, and Stakes
Algorithmic scoring is a species of automated profiling, but it is not coextensive with it. Profiling, in its broadest sense, is the process of discovering correlations between data in databases and applying the resulting patterns to identify, classify, or predict the behaviour of individual subjects.[1] Algorithmic scoring is a specific and consequential variant of this process: the assignment of a numerical value to a person on the basis of data-derived correlations, which then functions as the operative basis for a decision of legal or similarly significant effect.[2] The distinction matters because it determines the scope of legal protection. General profiling encompasses a wide range of data-processing activities, many of which do not directly determine outcomes. Algorithmic scoring, by contrast, compresses the complexity of a human being into a single figure and deploys that figure as the mechanism of social allocation, comprising credit, employment, or educational opportunity.
The particular character of algorithmic scoring emerges from what Hildebrandt identifies as the actuarial logic underlying modern profiling systems.[3] Unlike human judgment, which is capable of attending to context, exception, and individual narrative, algorithmic scoring operates by extrapolating from past behaviour to future probability on the basis of statistical correlations that do not establish causal or motivational relationships.[4] The score does not represent a person; it represents the probability that this person resembles a category of persons who have behaved in a particular way. In consequence, algorithmic scoring is structurally incapable of individualised assessment. It applies, in Hildebrandt’s terminology, a non-distributive profile, one whose attributes do not necessarily belong to every member of the category assigned, to individual human beings as though it were a distributive one.[5] This is the theoretical foundation of the harm the law must address.
Three harms are common across all applications of algorithmic scoring and are directly relevant to the human rights framework examined in this article. The first is opacity: the individual subject of a score typically has no access to the knowledge used to categorise them, cannot anticipate the criteria applied, and cannot meaningfully contest the result.[6] This opacity is structural rather than incidental: it is not a defect that can be corrected by disclosure of a single variable, but a consequence of the complexity of the correlational models on which scores depend.[7] The second harm is cumulative disadvantage: algorithmic systems trained on historical data tend to reproduce and entrench existing inequalities, because the patterns they identify in past outcomes reflect the biases embedded in the social conditions that generated those outcomes.[8] The European Union Agency for Fundamental Rights has demonstrated empirically that such feedback loops can intensify over time, such that initial bias in training data is progressively amplified by each iteration of the model.[9] The third harm is power asymmetry: the entities that design, deploy, and profit from scoring systems possess information, expertise, and resources that the scored individual fundamentally lacks. Rouvroy and Berns have argued that algorithmic power operates at the level of populations rather than subjects, rendering individual rights-based challenge structurally inadequate, since the framework of individual rights presupposes a subject capable of identifying, articulating, and contesting the source of harm.[10] This is precisely what algorithmic opacity denies.Credit and financial scoring represents the paradigm case. The Court of Justice of the European Union confronted this directly in OQ v Land Hessen (the SCHUFA case), in which it held that the automated generation of a creditworthiness probability score by a credit reference agency constitutes automated individual decision-making for the purposes of Article 22 GDPR where lenders rely strongly on that score to grant or refuse credit.[11] The Court’s analysis reveals the characteristic structure of algorithmic scoring harm: the individual’s access to credit, a matter of substantial practical consequence, is determined by a figure generated throu
[1] Hildebrandt (n 1) 19.
[2] GDPR (n 6) art 22 and Recital 71; SCHUFA (n 6) [21]–[24].
[3] Hildebrandt (n 1) 21–22.
[4] ibid 18–19.
[5] ibid 21.
[6] Wachter and Mittelstadt (n 2) 447–49; Pasquale (n 1) s 2.3.
[7] Edwards and Veale (n 5) 30–35.
[8] Rouvroy and Berns (n 2) 168–70; Jeffrey Dastin, ‘Amazon Scraps Secret AI Recruiting Tool That Showed Bias Against Women’ (Reuters, 10 October 2018).
[9] FRA (n 3) 29–30, 46.
[10] Rouvroy and Berns (n 2) 172–75; Abrusci and Mackenzie-Gray Scott (n 9) 121.
[11] SCHUFA (n 6) [45]–[51].



