Civil Law And Ai Consumer Manipulation Behavioral Targeting Claims In Europe .
Civil Law and AI Consumer Manipulation & Behavioural Targeting Claims in Europe
1. Introduction
AI consumer manipulation and behavioural targeting concerns the use of artificial intelligence, profiling, recommendation systems, predictive analytics and personalised advertising to influence a consumer's purchasing behaviour.
Examples include:
- AI predicting when a consumer is most likely to buy;
- personalised prices or promotions;
- targeting consumers based on inferred interests, vulnerabilities or emotional states;
- AI-generated advertisements designed for particular psychological profiles;
- recommendation algorithms repeatedly promoting particular products;
- personalised advertising based on browsing, location, purchase and social-media activity;
- AI chatbots persuading consumers to purchase products;
- exploiting urgency, fear of missing out or compulsive behaviour;
- dynamic advertising that changes according to the consumer's predicted willingness to pay;
- hiding important information from a consumer while highlighting information likely to trigger a purchase.
European civil law does not currently contain one single cause of action called an "AI consumer manipulation claim." Instead, a claim may arise through several overlapping legal regimes:
- Unfair commercial practices law
- Consumer contract law
- GDPR and profiling rules
- AI Act requirements
- Digital Services Act
- Product/service liability
- General national contract and tort law
- Competition law in some circumstances
The central legal question is therefore:
Did the AI system merely personalise lawful advertising, or did the design and use of AI materially impair the consumer's ability to make an informed and free transactional decision?
The distinction is important because personalisation by itself is not necessarily unlawful.
2. Meaning of AI Behavioural Targeting
Behavioural targeting involves collecting or analysing information about a person's behaviour and using it to predict or influence future behaviour.
AI can analyse:
- browsing history;
- purchase history;
- search behaviour;
- clicks;
- time spent on particular content;
- device information;
- location;
- social-media activity;
- responses to previous advertisements;
- inferred interests;
- consumer segmentation;
- predicted willingness to purchase;
- predicted susceptibility to particular messages.
The system can then select:
Consumer → Profile → Prediction → Personalised content → Behavioural response → Transaction
The legal problem becomes greater where the AI system is designed not simply to provide relevant information but to exploit a person's particular vulnerability or reduce meaningful consumer choice.
3. Main European Legal Framework
A. Unfair Commercial Practices Directive
Directive 2005/29/EC is central.
It prohibits unfair business-to-consumer commercial practices, including:
- misleading actions;
- misleading omissions;
- aggressive commercial practices;
- practices contrary to professional diligence that materially distort consumer economic behaviour.
The Directive is particularly important because it focuses on the effect of a commercial practice on the consumer's transactional decision.
The CJEU has interpreted "transactional decision" broadly. It can include decisions connected with a purchase, not merely the final decision to pay. Trento Sviluppo, C-281/12 is particularly important here.
B. GDPR
Where AI behavioural targeting involves personal data, GDPR becomes central.
Relevant principles include:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- security;
- accountability.
Particularly important are:
Article 22
Article 22 addresses decisions based solely on automated processing, including profiling, where the decision produces legal effects or similarly significantly affects the individual.
Article 15
Consumers/data subjects may have rights to information concerning automated decision-making and profiling.
Article 21
Individuals may have rights to object to certain processing, including direct marketing.
Article 9
Special-category data receive heightened protection.
This becomes especially important where AI infers sensitive characteristics and uses them for targeting.
4. AI Act
The EU AI Act adds another layer.
The AI Act does not create a general prohibition on every form of personalised advertising.
However, it addresses particularly problematic AI practices, including certain techniques involving subliminal, purposefully manipulative or deceptive techniques where the relevant legal conditions are satisfied.
Therefore, a claimant should distinguish:
ordinary recommendation → personalised marketing → manipulative AI technique → prohibited/high-risk conduct
The factual design and actual operation of the AI system are critical.
5. Digital Services Act
The Digital Services Act is particularly relevant to large online platforms.
It addresses issues involving:
- online advertising;
- transparency;
- recommender systems;
- profiling;
- advertising targeting;
- protection of minors;
- systemic risks;
- certain categories of personalised advertising.
Again, however:
A DSA violation does not automatically establish a private damages claim.
A claimant normally still needs to establish the appropriate private-law cause of action, damage and causation under the applicable legal regime.
6. Important Case Laws
1. Meta Platforms and Others v Bundeskartellamt — C-252/21
CJEU, Grand Chamber, 4 July 2023
This is one of the most important European cases for AI behavioural targeting.
Meta combined information obtained from Facebook with information obtained from other Meta services and third-party websites/apps. This permitted detailed conclusions about users' interests and preferences.
The CJEU examined the interaction between:
- GDPR;
- behavioural data;
- personalised advertising;
- consent;
- legitimate interests;
- competition law.
The Court recognised that the processing of personal data for personalised advertising cannot simply be treated as unrestricted merely because the service is an online social network.
Importance for AI manipulation
An AI advertising system may similarly aggregate:
browsing + purchasing + social activity + behavioural signals → consumer profile → personalised advertising.
The case therefore provides an important foundation for challenging unlawful data-driven targeting.
Legal principle:
Personalisation based on extensive behavioural data remains subject to GDPR requirements.
7. Schrems v Meta Platforms — C-446/21
CJEU, 4 October 2024
This case concerned personalised advertising and the processing of personal data on social networks.
The Court examined issues involving:
- personalised advertising;
- purpose limitation;
- data minimisation;
- special-category data;
- publicly disclosed information;
- use of personal information for advertising.
The case is particularly relevant because it demonstrates that the fact that information is available or has been disclosed in some context does not automatically give an online platform unlimited permission to use it for behavioural advertising.
Relevance to AI
AI targeting systems can make highly detailed inferences from seemingly harmless data.
For example:
search history + viewing behaviour + location + social interactions → inferred personal characteristic → targeted advertisement.
The legal analysis must therefore examine what information was collected, why it was collected and how it was subsequently used.
8. SCHUFA Holding — C-634/21
CJEU, 7 December 2023
Although this case concerns credit scoring rather than advertising, it is highly relevant to AI profiling.
The CJEU considered automated establishment of a probability score concerning an individual's ability to meet payment obligations.
The Court held that automated establishment of such a probability value can fall within Article 22 GDPR where a third party strongly relies upon that score in deciding whether to establish, implement or terminate a contractual relationship.
Relevance to consumer targeting
Imagine an AI system calculating:
- purchasing susceptibility;
- creditworthiness;
- likelihood of accepting a price;
- likelihood of responding to an advertisement.
If that score is then used to make decisions significantly affecting the consumer, Article 22 and associated GDPR protections may become relevant.
Principle:
An algorithmic score cannot necessarily be treated as legally irrelevant merely because the final decision is technically made by another person or entity.
9. Dun & Bradstreet Austria — C-203/22
CJEU, 27 February 2025
This case further developed the GDPR rules concerning automated decision-making and profiling.
The Court considered the individual's right to receive meaningful information about the logic involved in automated processing.
The judgment is important because the explanation must be meaningful enough to enable the individual to understand and challenge the automated decision.
Relevance to AI behavioural targeting
Suppose an AI system determines:
"This consumer is highly susceptible to luxury-product advertising."
If that classification produces significant legal or economic consequences, questions may arise concerning:
- input data;
- profiling methodology;
- relevant variables;
- decision logic;
- accuracy;
- ability to challenge the result.
The case therefore strengthens the importance of algorithmic accountability and explainability.
10. Tiketa — C-536/20
CJEU, 24 February 2022
This case concerned online consumer contracting and information requirements under the Consumer Rights Directive.
The Court examined the responsibilities of an online intermediary concerning consumer information.
It is relevant to AI systems because AI interfaces increasingly act as the consumer's point of interaction with an online business.
Application
An AI shopping assistant cannot simply replace legally required consumer information with conversational persuasion.
For example:
AI assistant: "This is your perfect plan—buy now."
If important contractual information is hidden while persuasive AI-generated statements are emphasised, consumer-law requirements may become relevant.
11. Canal Digital Danmark — C-611/14
CJEU, 26 October 2016
The Court considered misleading advertising under Articles 6 and 7 of the Unfair Commercial Practices Directive.
The trader highlighted one component of the price while presenting another charge less conspicuously.
The Court found that the overall presentation could constitute a misleading practice where it caused or was likely to cause a transactional decision that the consumer otherwise would not have made.
AI relevance
AI can perform the digital equivalent dynamically:
- prominently display the attractive price;
- minimise additional charges;
- emphasise benefits;
- suppress inconvenient information;
- adapt the presentation to the individual consumer.
Therefore, the fact that the presentation was automatically generated does not necessarily prevent ordinary consumer-law analysis.
12. Trento Sviluppo and Centrale Adriatica — C-281/12
CJEU, 19 December 2013
This is an important authority concerning misleading commercial practices and transactional decisions.
The CJEU held that a misleading practice must be capable of causing a consumer to take a transactional decision that they would not otherwise have taken.
The concept of transactional decision is broad and can include decisions directly related to purchasing.
AI relevance
This is particularly useful in AI-targeting litigation.
The claimant need not necessarily show:
"The AI caused me to press the final payment button."
The relevant question may include earlier decisions such as:
- clicking the advertisement;
- visiting a website;
- entering a sales funnel;
- selecting a product;
- accepting a trial;
- providing payment information.
13. CHS Tour Services — C-435/11
CJEU, 19 September 2013
The Court dealt with misleading commercial practices under Directive 2005/29/EC.
The case confirms that a commercial practice can be unfair where it misleads consumers; the analysis does not necessarily depend upon proving a separate breach of professional diligence for a misleading practice falling within Article 6.
AI relevance
If an AI system automatically generates false or materially misleading advertising, the company cannot necessarily escape responsibility simply by saying:
"The algorithm generated it."
The legal analysis must examine the trader's commercial practice and applicable national liability rules.
14. Fuhrmann-2 — C-249/21
CJEU, 7 April 2022
The Court considered online ordering and the requirement that consumers clearly understand when they are assuming a payment obligation.
This is particularly relevant to AI conversational commerce.
Suppose an AI agent says:
"I'll arrange that for you."
If the consumer does not clearly understand whether the statement merely requests information or actually concludes a paid contract, consumer-contract rules become important.
AI principle
AI-generated conversational language cannot automatically eliminate statutory requirements concerning informed consumer consent.
15. Core Legal Issues in an AI Manipulation Claim
A civil claim can normally be analysed through the following questions.
Issue 1 — What data was used?
Determine whether the AI used:
- personal data;
- behavioural data;
- inferred data;
- sensitive data;
- location information;
- purchase history;
- biometric information;
- social-media information.
Issue 2 — Was the profiling lawful?
The claimant should examine:
- lawful basis;
- transparency;
- purpose limitation;
- data minimisation;
- consent;
- objection rights;
- special-category data;
- automated decision-making.
Issue 3 — Was the advertising misleading?
Examples:
- false AI-generated claims;
- hidden conditions;
- manipulated price presentation;
- fake scarcity;
- false urgency;
- misleading recommendations;
- undisclosed commercial influence.
Issue 4 — Was the consumer vulnerable?
Particular attention may be given to:
- children;
- elderly consumers;
- financially distressed consumers;
- consumers with addictive behaviours;
- consumers facing emotional distress;
- consumers with limited digital literacy.
The factual evidence is important. Vulnerability should not simply be assumed from the existence of AI targeting.
16. Psychological Profiling
One of the most difficult areas concerns psychological or emotional profiling.
An AI system might infer:
"Consumer is anxious."
"Consumer is likely to respond to fear-based messaging."
"Consumer is price-sensitive."
"Consumer is likely to purchase immediately under time pressure."
Such profiling can potentially create a much stronger legal issue than ordinary advertising.
However, the legal question is not simply:
"Was AI used?"
Instead:
What did the AI infer, how was the inference used, and did the resulting commercial practice unlawfully impair the consumer's ability to make an informed decision?
17. Dark Patterns + AI
AI can make dark patterns significantly more sophisticated.
Traditional dark pattern:
"Only 2 items left!"
AI-enhanced dark pattern:
AI predicts that a particular consumer responds strongly to scarcity → displays a personalised scarcity message → changes wording according to the consumer's behavioural profile.
Other examples:
Personalised urgency
"Your special price expires in 3 minutes."
Personalised social pressure
"People like you are buying this now."
Personalised emotional appeal
"This product could make your life easier."
Personalised repetition
The system repeatedly displays the same product because it predicts the consumer will eventually purchase.
Friction asymmetry
AI makes purchasing extremely easy but makes cancellation difficult.
These facts can be relevant under consumer-protection rules.
18. Civil Liability
A claimant may potentially pursue several forms of relief depending on national law.
1. Contract remedies
Possible arguments include:
- lack of genuine consent;
- mistake;
- misrepresentation;
- unfair contractual terms;
- invalidity;
- rescission;
- cancellation.
2. Tort/delict liability
Possible elements include:
- unlawful conduct;
- fault or strict liability where applicable;
- damage;
- causation.
3. Consumer remedies
Depending upon national implementation:
- injunction;
- contract cancellation;
- price reduction;
- restitution;
- damages;
- administrative enforcement.
4. GDPR compensation
Article 82 GDPR provides a damages mechanism for material and non-material damage resulting from an infringement, subject to its requirements.
5. Collective redress
Consumer organisations and qualified entities may pursue representative actions where the relevant EU and national framework permits.
19. Causation Is Usually the Difficult Part
A claimant may establish:
AI targeting → unlawful profiling → advertisement → purchase → loss
But the defendant may argue:
"The consumer would have bought the product anyway."
Therefore, evidence becomes crucial.
Relevant evidence can include:
- advertising logs;
- AI prompts;
- model outputs;
- consumer profiles;
- recommendation records;
- A/B testing;
- targeting criteria;
- conversion statistics;
- purchase history;
- algorithmic decision logs;
- internal AI governance documents;
- communications between marketing and AI teams.
20. AI Provider vs Advertiser
Liability should be separated between different actors.
| Actor | Potential issue |
|---|---|
| Advertiser | Misleading/manipulative commercial practice |
| Platform | Targeting, profiling, recommender-system obligations |
| AI developer | Product/service or contractual liability depending on circumstances |
| Data broker | Unlawful data processing/profiling |
| Advertising agency | Contractual/professional liability |
| Marketplace | Intermediary responsibilities |
| Consumer | Consent and transactional decision |
The company that deploys the AI system may remain legally relevant even if another company developed the underlying model.
21. AI Manipulation vs Ordinary Personalisation
This distinction is essential.
| Ordinary personalisation | Potentially problematic manipulation |
|---|---|
| "You viewed running shoes." | "AI detected you are emotionally vulnerable." |
| Shows running shoes | Uses vulnerability to pressure purchase |
| Based on product preference | Based on sensitive/inferred characteristics |
| Transparent advertising | Hidden personalised influence |
| Consumer can easily refuse | Consumer is deliberately pressured |
| Relevant recommendation | Exploitative targeting |
Personalised advertising is not automatically unlawful.
The legal problem becomes stronger where personalisation is combined with:
deception + vulnerability + opacity + coercive design + unlawful profiling + material transactional effect.
22. Relationship Between GDPR and Consumer Law
These regimes can operate together.
For example:
Step 1: AI unlawfully collects behavioural data.
Step 2: AI creates a consumer profile.
Step 3: Profile is used to generate personalised advertising.
Step 4: Advertisement exploits a vulnerability.
Step 5: Consumer purchases a product.
Potential legal analysis:
GDPR → Was the data processing lawful?
Consumer law → Was the commercial practice unfair?
Contract law → Was consent valid?
Tort/delict → Was legally protected interest unlawfully harmed?
Damages law → What loss resulted?
The same technological system can therefore generate multiple legal claims.
23. Evidence Required in Litigation
AI manipulation litigation can be evidence-intensive.
Consumer evidence
- screenshots;
- emails;
- advertisements received;
- purchase records;
- cancellation attempts;
- communications with the chatbot.
Platform evidence
- profile data;
- targeting categories;
- recommender-system logs;
- model outputs;
- advertising-selection records.
Technical evidence
- model version;
- prompts;
- system instructions;
- API logs;
- timestamps;
- automated decision records;
- experimentation records.
Expert evidence
Experts may examine:
- algorithmic behaviour;
- causal influence;
- profiling methodology;
- statistical targeting;
- user-interface design;
- consumer psychology.
24. Important Legal Principle: AI Is Not a Legal Excuse
A company generally cannot avoid ordinary legal obligations merely by saying:
"The AI made the decision."
The relevant question is:
Who designed, deployed, controlled, benefited from and/or legally operated the AI system?
The AI system is generally treated as a technological mechanism rather than automatically becoming an independent legal person capable of bearing contractual responsibility.
25. Six-Plus Case Law Summary
| Case | Main principle | AI behavioural-targeting relevance |
|---|---|---|
| Meta Platforms, C-252/21 | GDPR + behavioural data + personalised advertising | Very high |
| Schrems, C-446/21 | Personal data, purpose limitation, personalised advertising | Very high |
| SCHUFA, C-634/21 | Automated scoring can fall within Article 22 | Very high |
| Dun & Bradstreet, C-203/22 | Meaningful information about automated profiling | Very high |
| Trento Sviluppo, C-281/12 | Misleading practice + transactional decision | High |
| Canal Digital Danmark, C-611/14 | Misleading presentation/omission can distort consumer decisions | High |
| CHS Tour Services, C-435/11 | Misleading commercial practices | High |
| Tiketa, C-536/20 | Online consumer information obligations | Medium-high |
| Fuhrmann-2, C-249/21 | Clear indication of payment obligation | Medium-high |
The first four are especially useful for the AI/profiling/data side, while the latter cases are particularly useful for the consumer-manipulation/commercial-practice side.
26. Practical Legal Test
A European AI behavioural-targeting claim can be organised as:
AI System
↓
Collection of behavioural/personal data
↓
Profiling or inference
↓
Personalised targeting
↓
Manipulative/deceptive technique?
↓
Material effect on consumer decision?
↓
Unlawful processing / unfair commercial practice / invalid consent?
↓
Damage or other legally recognised harm?
↓
Causation
↓
Civil remedy
A useful formula is:
AI Targeting + Personal/Behavioural Profiling + Unlawful or Manipulative Practice + Material Consumer Effect + Damage/Causation = Potential Civil Claim
27. Key Defences Available to Businesses
A business may argue:
- the advertising was ordinary personalisation;
- the consumer was properly informed;
- the processing had a lawful basis;
- no special-category data were used;
- no solely automated significant decision occurred;
- the advertisement was truthful;
- the consumer retained meaningful choice;
- the alleged conduct did not materially affect the transaction;
- no legally recoverable damage occurred;
- the alleged damage was not caused by the AI system.
These issues must be assessed on the actual evidence rather than merely on the fact that AI was involved.
28. Difference Between Regulatory Violation and Civil Claim
This distinction is extremely important.
Regulatory infringement ≠ automatic damages.
For example:
GDPR violation → potentially regulatory consequences and, where Article 82 requirements are satisfied, compensation.
But:
AI used for personalised advertising → does not automatically mean unlawful conduct.
Likewise:
DSA/AI Act non-compliance → does not automatically establish every element of a national civil damages claim.
The claimant still needs the appropriate legal basis and, where relevant, damage and causation.
29. Conclusion
AI consumer manipulation and behavioural-targeting disputes in Europe are developing at the intersection of consumer law, data protection, AI regulation and national civil law.
The most important legal development is that European law increasingly examines not simply whether a consumer saw personalised advertising, but:
- what data were used;
- how the consumer was profiled;
- whether sensitive characteristics were inferred;
- whether the consumer was adequately informed;
- whether automated decision-making was involved;
- whether the commercial practice was misleading or aggressive;
- whether the design exploited vulnerability;
- whether the practice materially affected the consumer's transactional decision;
- and whether the consumer suffered legally recoverable harm.
The combination of Meta Platforms (C-252/21), Schrems (C-446/21), SCHUFA (C-634/21), Dun & Bradstreet (C-203/22), Trento Sviluppo (C-281/12), Canal Digital Danmark (C-611/14), CHS Tour Services (C-435/11), Tiketa (C-536/20) and Fuhrmann-2 (C-249/21) provides a strong doctrinal foundation for analysing these disputes.
Exam/Revision Keywords
AI profiling — behavioural targeting — personalised advertising — consumer vulnerability — dark patterns — GDPR — Article 22 — automated decision-making — profiling — transparency — data minimisation — purpose limitation — personalised advertising — unfair commercial practices — misleading action — misleading omission — aggressive practice — transactional decision — informed consent — AI Act — Digital Services Act — causation — damages — collective redress — algorithmic accountability — explainability — civil liability.

comments