Civil Law And Algorithmic Public Health Decision Errors In Europe .

Civil Law and Algorithmic Public Health Decision Errors in Europe

1. Introduction

Algorithmic public-health decision errors arise when governments, hospitals, public-health authorities, insurers, laboratories, or healthcare providers use algorithms, AI systems, automated risk scores, predictive models, or data-driven decision-support tools and the system produces an incorrect or harmful outcome.

Examples include:

an algorithm incorrectly identifying a person as high-risk for a disease;

an AI triage system assigning a patient a low priority;

a predictive model incorrectly predicting mortality or hospitalisation;

an automated vaccination-priority system excluding an eligible person;

an algorithm wrongly identifying someone as infected or contagious;

an AI system producing an incorrect diagnosis or treatment recommendation;

an automated public-health surveillance system incorrectly linking individuals to an outbreak;

an algorithm using biased health or demographic data;

an automated system disclosing sensitive health information;

an algorithmic resource-allocation system denying access to scarce treatment.

European law does not yet have one single, comprehensive body of case law specifically dealing with AI-generated public-health decisions. Therefore, the legal framework has to be constructed from several groups of authorities: GDPR automated-decision cases, health-data cases, medical-negligence cases, and European human-rights jurisprudence.

This distinction is important: many of the cases below are closely related authorities rather than cases in which a court expressly decided liability for an AI public-health algorithm.

2. Meaning of Algorithmic Public-Health Decision Error

An algorithmic public-health decision error occurs when an automated or algorithm-assisted system produces an inaccurate, unlawful, discriminatory, incomplete, or unsafe decision that causes harm.

A simplified chain is:

Data → Algorithm → Risk assessment → Public-health decision → Individual harm

For example:

Patient data → AI risk model → “Low emergency risk” → delayed treatment → serious injury.

The legal question is not simply whether the algorithm was technically wrong.

The court may ask:

Was the data accurate?

Was the algorithm lawfully used?

Was the decision fully automated?

Was meaningful human review available?

Was the system properly validated?

Was the health authority negligent?

Was the patient informed?

Was sensitive health data lawfully processed?

Was there discrimination?

Did the error cause legally compensable damage?

3. Main European Legal Framework

Several areas of law can apply simultaneously.

A. GDPR

Particularly relevant provisions include:

Article 5 — principles of processing;

Article 6 — lawful processing;

Article 9 — special categories of personal data, including health data;

Article 13–15 — information and access;

Article 16 — rectification;

Article 21 — objection;

Article 22 — automated individual decision-making;

Article 25 — data protection by design and default;

Article 32 — security;

Article 35 — data-protection impact assessment;

Article 82 — compensation.

B. National civil liability

Depending on the Member State, liability may arise through:

medical negligence;

professional negligence;

contractual liability;

tort/delict;

public-authority liability;

hospital liability;

product liability;

vicarious liability;

defective-service principles.

C. European Convention on Human Rights

Particularly relevant:

Article 2 — right to life;

Article 8 — private life and medical confidentiality;

Article 14 — non-discrimination;

Article 6 — fair proceedings.

D. EU fundamental rights

Relevant Charter provisions include:

Article 7 — private and family life;

Article 8 — protection of personal data;

Article 21 — non-discrimination;

Article 35 — health protection;

Article 47 — effective remedy and fair trial.

4. Case Law

Case 1 — SCHUFA Holding (Scoring), C-634/21

Court: CJEU
Date: 7 December 2023

This is one of the most important European authorities for automated decision-making.

The case concerned automated credit scoring rather than public health. However, its reasoning is highly relevant where a health authority or healthcare provider uses an algorithm to produce a score that substantially determines an individual's treatment or access to services.

The Court held that an automated establishment of a probability value may constitute automated individual decision-making under Article 22 GDPR where another party strongly relies on that score in making a decision concerning the person.

Relevance to public health

Suppose:

AI calculates a patient's probability of deterioration = 12%.

If the hospital automatically uses that score to decide:

“No intensive-care treatment required,”

Article 22 issues may arise.

The important question becomes whether the algorithm is merely assisting a human decision-maker or is effectively determining the outcome.

Legal principle

A supposedly “technical” algorithm cannot automatically escape legal scrutiny simply because the final decision is formally made by another person.

Importance: Very high for AI triage, hospital-risk scoring, vaccination prioritisation, epidemiological risk classification and similar systems. (Curia)

5. Case 2 — Dun & Bradstreet Austria, C-203/22

Court: CJEU
Date: 27 February 2025

This case concerned automated credit assessment.

The CJEU considered the individual's right to receive meaningful information about the logic involved in automated decision-making.

The Court emphasised that the explanation must allow the individual to understand and challenge the automated decision. (curia)

Application to public health

Imagine an automated health-risk system produces:

“Patient: low priority.”

The hospital should not necessarily be able to respond:

“The computer said so.”

If the automated assessment materially affects the individual, questions may arise about:

what data were used;

what factors influenced the result;

whether the information was accurate;

whether relevant factors were omitted;

whether the system was biased;

whether the result can be challenged.

The case also demonstrates that trade-secret arguments do not automatically eliminate the individual's rights. The competent authority or court can balance competing interests. (Curia)

Principle

Algorithmic opacity cannot automatically defeat legal accountability.

6. Case 3 — Nowak v Data Protection Commissioner, C-434/16

Court: CJEU
Date: 20 December 2017

The CJEU adopted a broad understanding of personal data.

The case concerned examination answers and examiner comments. The Court concluded that such information could constitute personal data relating to the candidate. (Infocuria)

Importance for public-health algorithms

An algorithm may create or infer information about a person, such as:

disease probability;

infection probability;

mortality risk;

genetic risk;

treatment response;

mental-health risk;

likelihood of hospitalisation.

Such information can have legal significance even if it is not a traditional medical record.

Civil-law importance

If an algorithm generates an erroneous health profile, the individual may potentially seek:

access;

correction;

restriction of processing;

objection where applicable;

compensation where GDPR requirements are satisfied.

The central lesson from Nowak is that personal-data protection extends beyond simple identity information. (Infocuria)

7. Case 4 — Österreichische Post, C-300/21

Court: CJEU
Date: 4 May 2023

This case concerned algorithmic processing of personal information and compensation under Article 82 GDPR.

The CJEU established an important three-part structure:

infringement of the GDPR;

damage;

causal link between the infringement and the damage.

A GDPR infringement alone does not automatically create a right to compensation. At the same time, the Court rejected a requirement that non-material damage must pass a separate minimum seriousness threshold. (curia)

Application to public-health algorithms

Suppose an algorithm incorrectly classifies an individual as having a serious infectious disease.

The claimant would need to establish, depending on the legal basis of the claim:

Unlawful processing → identifiable harm → causal connection.

Possible harm could include:

financial loss;

loss of employment;

unnecessary medical expenditure;

psychological harm;

reputational harm;

loss of privacy;

social stigma.

Principle

Algorithmic error and legal damage are related but not identical concepts.

A technically incorrect prediction does not automatically establish every element of a damages claim.

8. Case 5 — Lindqvist, C-101/01

Court: CJEU
Date: 6 November 2003

Although predating the GDPR, Lindqvist remains important to the European understanding of health information.

The case concerned publication of personal information on the internet. The Court recognised that information concerning an individual's physical or mental health falls within the concept of health-related personal data. (EUR-Lex)

Application

An algorithmic public-health system may process:

infection status;

medical history;

vaccination information;

disability;

genetic characteristics;

treatment history;

epidemiological status.

These categories receive heightened legal protection.

Principle

Health information is not ordinary administrative information.

Consequently, an algorithmic public-health system must pay particular attention to:

purpose limitation;

data minimisation;

accuracy;

security;

lawful processing;

confidentiality.

9. Case 6 — Calvelli and Ciglio v Italy

Court: ECtHR, Grand Chamber
Date: 17 January 2002

This is a major medical-negligence authority.

The ECtHR recognised that Article 2 requires States to establish an appropriate framework protecting patients' lives.

Importantly, where medical negligence is involved, an effective legal system does not necessarily require criminal punishment in every case. A civil remedy capable of establishing liability and providing appropriate redress may satisfy the procedural obligation. (HUDOC)

Algorithmic application

Imagine:

Public hospital introduces an AI triage system → system has known validation problems → hospital continues relying on it → patient dies.

Potential legal questions include:

Was the algorithm properly validated?

Did the hospital have adequate safeguards?

Was human supervision sufficient?

Were known limitations ignored?

Was there an effective mechanism for investigating the death?

Can responsibility be established through civil proceedings?

Principle

Technological automation does not remove the State's obligation to maintain an effective healthcare and accountability framework.

10. Case 7 — Šilih v Slovenia

Court: ECtHR, Grand Chamber
Date: 9 April 2009

The case concerned the death of a young man following medical treatment and the effectiveness of proceedings concerning alleged medical negligence.

The ECtHR emphasised the procedural obligation to establish what happened and determine responsibility through an effective system. The case involved delays and deficiencies in proceedings concerning medical negligence. (ECHR-KS)

Relevance to algorithmic health errors

Algorithmic cases can be technically complicated.

An investigation may need to examine:

source data;

training data;

model architecture;

validation studies;

version history;

software logs;

human interventions;

warnings generated by the system;

hospital protocols.

If courts simply accept:

“The AI made an error,”

without investigating the circumstances, accountability may become impossible.

Principle

Technological complexity cannot eliminate effective investigation of serious healthcare errors.

11. Case 8 — Lopes de Sousa Fernandes v Portugal

Court: ECtHR, Grand Chamber
Date: 19 December 2017

This is another major medical-negligence authority.

The case involved the death of a patient after postoperative complications. The Court distinguished ordinary medical negligence from more exceptional situations involving systemic dysfunction or denial of emergency healthcare. It found a procedural Article 2 violation because the domestic system failed to provide an adequate and timely response to the arguable medical-negligence allegations. (ECHR-KS)

Algorithmic significance

The case is particularly useful where an algorithmic error is part of a larger healthcare system.

For example:

defective algorithm + inadequate hospital protocol + inadequate monitoring + failure to investigate warnings.

The legal analysis should not necessarily isolate the software from the surrounding system.

Principle

Courts should examine the whole chain of healthcare decision-making, rather than treating the algorithm as an independent actor.

12. Case 9 — Y v Turkey

Court: ECtHR
Year: 2015

This authority concerns medical information and public-health protection.

The ECtHR recognised that medical secrecy is extremely important but is not absolute. In appropriate circumstances, health information may be shared within a healthcare system to protect patients, healthcare workers and public health.

At the same time, sensitive health information must be handled with safeguards against abuse and stigmatisation. (ECHR-KS)

Algorithmic significance

Public-health AI often requires large datasets.

For example:

hospital records → national database → disease-prediction model → public-health intervention.

The fact that information is useful for public health does not mean that every subsequent use is automatically lawful.

Principle

Public-health utility must be balanced against privacy, confidentiality and safeguards against misuse.

13. Case 10 — Căldărari v Republic of Moldova

Court: ECtHR
Date: 2 July 2026

This recent case involved alleged medical negligence following anaesthesia, severe neurological damage and later death. The Court addressed both the substantive healthcare obligations and the failure to provide an adequate and timely response to arguable medical-negligence claims. (HUDOC)

The Court emphasised that State responsibility for healthcare failures can become particularly significant where there is a systemic or structural dysfunction, rather than merely an isolated medical mistake. (HUDOC)

Algorithmic significance

This distinction is extremely useful for AI healthcare disputes.

There is a difference between:

One-off algorithmic error

and

systemic algorithmic failure, such as:

defective training data;

systematic demographic bias;

defective validation;

repeated false negatives;

known software defects;

inadequate monitoring;

systematic failure to update the model.

A systemic defect may raise substantially broader questions of institutional responsibility.

14. Main Types of Algorithmic Public-Health Errors

A. Data-input error

The algorithm receives incorrect information.

Example:

Patient's diabetes status incorrectly recorded as “no”.

The model then produces a misleading risk score.

Liability issue

The relevant question may be:

Who was responsible for collecting, entering and maintaining the data?

B. Training-data error

The algorithm was trained on data that does not adequately represent the relevant population.

For example:

Model developed mainly using data from one demographic population but deployed on a substantially different population.

Possible consequences:

unequal diagnostic accuracy;

systematic false negatives;

systematic false positives;

discriminatory treatment.

15. C. Model-design error

The algorithm may use inappropriate variables or weights.

For example:

Algorithm gives excessive weight to historical hospital utilisation.

A patient who historically had poor access to healthcare may consequently appear healthier than another patient with similar medical needs.

This can create a form of structural bias.

16. D. Implementation Error

The model itself may be reasonably designed, but the hospital or authority implements it incorrectly.

Example:

AI is designed as a decision-support system, but staff treat its recommendation as mandatory.

This can convert a support tool into a de facto automated decision system.

17. E. Human-overreliance

A human technically makes the final decision but simply accepts the algorithm's recommendation.

This creates the problem of:

“human-in-the-loop” versus meaningful human review.

A genuine human review should normally involve the ability to:

question the algorithm;

inspect relevant information;

depart from the recommendation;

document reasons;

identify obvious anomalies.

A person merely clicking “approve” may not provide meaningful safeguards.

18. F. Model Drift

A health model may become less accurate over time.

For example:

An epidemic changes → disease characteristics change → model continues relying on old data.

This can create:

outdated risk predictions;

incorrect resource allocation;

incorrect treatment recommendations;

false public-health alerts.

Therefore, algorithmic governance must include continuous validation, not merely validation at the moment of deployment.

19. G. Bias and Discrimination

Public-health algorithms can indirectly discriminate through variables such as:

age;

sex;

geographic location;

socioeconomic characteristics;

disability;

ethnicity;

healthcare utilisation;

insurance status.

Even when a protected characteristic is not directly included, proxy variables may reproduce similar effects.

The legal question is not merely:

“Did the programmer include race?”

It can also be:

“Did the overall system produce unjustified differential treatment connected with a protected characteristic?”

20. H. False Positive

A false positive occurs when the algorithm incorrectly identifies a person as having a condition or risk.

Example:

AI incorrectly identifies a healthy person as infectious.

Possible consequences:

isolation;

unnecessary medication;

employment consequences;

stigma;

psychological harm;

unnecessary medical treatment.

21. I. False Negative

A false negative may be even more significant in a clinical context.

Example:

AI incorrectly predicts that a patient is low risk.

The patient is therefore:

denied urgent treatment;

assigned a lower triage priority;

discharged prematurely.

If injury follows, traditional medical-negligence principles may become relevant in addition to GDPR issues.

22. Algorithmic Health Data and GDPR

Health information is a special category of personal data under GDPR Article 9.

Therefore, public-health AI systems require careful legal analysis concerning:

Lawfulness

There must be an applicable legal basis.

Purpose limitation

Data collected for one purpose should not automatically be reused for unrelated purposes.

Data minimisation

Only appropriate information should be processed.

Accuracy

Incorrect data can produce incorrect automated decisions.

Security

Large-scale health datasets require strong safeguards.

Transparency

Individuals may have rights concerning information about processing and automated decision-making.

23. Article 22 GDPR and Public Health Algorithms

Article 22 is particularly significant.

The basic issue is:

Can an individual be subjected to a decision based solely on automated processing that produces legal or similarly significant effects?

This becomes complicated in healthcare because many systems are described as:

“decision-support tools.”

The legal classification therefore depends not merely on the software's label but on how the system actually functions.

Example

System A:

AI recommends:

“Consider intensive monitoring.”

Doctor independently evaluates the patient.

This is different from:

System B:

AI produces:

“No intensive monitoring.”

Hospital policy automatically follows the recommendation.

The second scenario raises substantially stronger automated-decision concerns.

The reasoning of SCHUFA is therefore highly relevant. (Curia)

24. Right to Explanation

Dun & Bradstreet Austria is particularly important here.

An affected individual may need meaningful information sufficient to understand and challenge an automated outcome. (curia)

For healthcare systems, meaningful information could concern:

principal factors influencing the result;

relevant patient data;

significant variables;

the role of the algorithm;

whether human review occurred;

whether the result was subsequently overridden.

The objective is not necessarily to disclose every line of source code.

The important issue is whether the individual can meaningfully understand and challenge the decision.

25. Accuracy of Health Data

Algorithmic decisions are only as reliable as the information supplied to them.

Consider:

Incorrect medical record → AI model → incorrect risk score → incorrect treatment decision.

The legal responsibility may potentially exist at several levels:

person who entered the information;

hospital maintaining the database;

software provider;

healthcare professional;

public authority;

institution responsible for deployment.

This creates a multi-actor liability problem.

26. Causation

Causation is one of the hardest issues in algorithmic medical litigation.

A claimant may need to demonstrate:

Algorithmic error → incorrect decision → medical harm.

But several other factors may exist:

Algorithmic error
↓
Doctor's decision
↓
Patient's pre-existing condition
↓
Treatment delay
↓
Complication.

The defendant may argue that the harm would have occurred anyway.

Therefore, courts may need:

medical experts;

technical experts;

statistical evidence;

model validation records;

hospital records;

audit logs;

counterfactual analysis.

27. Expert Evidence

Algorithmic healthcare cases can require two categories of experts.

Medical expert

Determines:

appropriate medical treatment;

medical causation;

injury;

prognosis.

Technical/AI expert

Determines:

model operation;

accuracy;

validation;

bias;

data quality;

system limitations;

software logs;

model updates.

A court may therefore have to understand both:

“Was the medical decision wrong?”

and

“Why did the algorithm contribute to that decision?”

28. Public Authority Liability

Where the algorithm is operated by a public-health authority, additional questions may arise.

For example:

Government creates an automated vaccination-priority system.

The system incorrectly excludes a category of vulnerable individuals.

Potential questions include:

Was the system lawful?

Was there a reasonable regulatory framework?

Was there adequate testing?

Was the exclusion discriminatory?

Was there an effective appeal mechanism?

Did the authority know about the error?

Did it respond after receiving complaints?

The ECtHR's medical-negligence jurisprudence shows that States can have positive obligations concerning healthcare safety and accountability. (ECHR-KS)

29. Civil Liability of Hospitals

A hospital may potentially be liable where:

it negligently selected an unsuitable algorithm;

it failed to validate the system;

it ignored known limitations;

it failed to train staff;

it relied excessively on automated recommendations;

it failed to maintain the system;

it failed to investigate algorithmic warnings.

The important principle is:

Delegating a healthcare function to software does not necessarily delegate the legal responsibility for the consequences.

30. Liability of AI Developers

The developer may become relevant where an algorithm is:

defectively designed;

inadequately tested;

misleadingly marketed;

supplied with inadequate warnings;

technically defective;

inappropriate for the intended clinical environment.

However, liability depends heavily on the applicable national civil and product-liability law.

A healthcare provider may remain liable even where the software developer also bears responsibility.

31. Product Liability Dimension

Where AI is incorporated into a medical device or healthcare product, European product-liability rules may become relevant.

The legal inquiry can include:

Was the product defective?

Was it reasonably safe?

Were adequate instructions supplied?

Was the software updated?

Did the defect cause injury?

Who qualifies as the responsible economic operator?

Modern software-based medical products therefore create overlap between:

medical negligence + product liability + data protection + AI regulation.

32. Privacy and Public Health

The ECtHR recognises that medical confidentiality is fundamental, while also accepting that health information can sometimes be shared for legitimate public-health purposes.

In Y v Turkey, the Court's materials emphasise that health information may need to circulate among relevant healthcare personnel for appropriate treatment and protection of public health, but sensitive information must be handled with safeguards against abuse and stigmatisation. (ECHR-KS)

Therefore:

Public-health purpose ≠ unlimited data access.

33. Discrimination

Algorithmic health decisions can produce:

Direct discrimination

The algorithm explicitly uses a protected characteristic.

Indirect discrimination

A seemingly neutral variable produces disproportionate disadvantage.

Proxy discrimination

A variable indirectly reproduces a protected characteristic.

Structural discrimination

The whole dataset or institutional design systematically disadvantages a group.

Potential legal sources include:

EU equality law;

national anti-discrimination law;

Article 14 ECHR;

Article 21 EU Charter;

GDPR principles where personal-data processing is involved.

34. Right to Life

Article 2 ECHR can become relevant where an algorithmic healthcare error contributes to death.

The authorities show two important ideas.

First, States must maintain an appropriate healthcare regulatory framework. Calvelli and Ciglio is central here. (HUDOC)

Second, there must be an effective mechanism for investigating arguable medical negligence. Šilih and Lopes de Sousa Fernandes are particularly important. (ECHR-KS)

Therefore, a serious algorithmic medical error cannot simply be treated as:

“computer malfunction.”

The surrounding institutional responsibility must be examined.

35. Algorithmic Error vs Medical Negligence

These should be distinguished.

Algorithmic error

The software generates an incorrect output.

Medical negligence

A healthcare professional or institution breaches the applicable professional standard.

Institutional negligence

The hospital or authority fails to establish adequate safeguards.

Data-protection infringement

Personal data are processed unlawfully.

Discrimination

The system produces legally impermissible differential treatment.

One incident may involve all five simultaneously.

36. Example

Assume a European public hospital introduces an AI triage system.

The algorithm was trained primarily on historical data from younger patients.

An elderly patient arrives with serious symptoms.

The AI assigns a low-risk score.

The doctor follows the score without independent examination.

The patient is discharged and later suffers permanent injury.

Potential claims could concern:

1. Medical negligence

Was the doctor's reliance on the system reasonable?

2. Institutional negligence

Did the hospital properly validate the system?

3. Algorithmic bias

Did the system systematically underestimate elderly patients?

4. GDPR

Was the patient's data processed lawfully?

5. Automated decision-making

Was the human involvement meaningful?

6. Causation

Did the algorithmic error cause the treatment delay?

7. Damages

What physical, financial and non-material losses resulted?

37. Defences

Healthcare institutions may argue:

A. Human decision

The algorithm only provided advice.

B. No causation

The injury would have occurred anyway.

C. Reasonable professional practice

The medical professional acted according to accepted standards.

D. Data supplied by another institution

The defendant did not create the inaccurate information.

E. State-of-the-art limitation

The defect could not reasonably have been identified at the relevant time, subject to the applicable legal regime.

F. Public-health necessity

The processing or decision was necessary to protect public health.

However, public-health necessity does not automatically eliminate every other legal requirement.

38. Damages

Depending on the jurisdiction and cause of action, possible losses include:

medical expenses;

rehabilitation costs;

lost earnings;

future care costs;

disability-related costs;

pain and suffering;

psychological harm;

loss of quality of life;

privacy harm;

reputational harm;

non-material damage.

For GDPR claims specifically, Österreichische Post confirms the importance of establishing infringement, damage and causal connection. (Infocuria)

39. Burden of Proof

Algorithmic litigation creates an unusual evidentiary problem.

The claimant may not know:

what data were used;

which variables mattered;

which model version operated;

whether the model was updated;

whether a human overrode the model;

whether the algorithm had known accuracy problems.

This creates an information asymmetry between the individual and the institution.

The reasoning in Dun & Bradstreet Austria is therefore particularly significant because meaningful information can assist an affected individual in understanding and challenging automated decision-making. (Curia)

40. Importance of Audit Logs

Healthcare algorithms should ideally preserve:

input data;

output;

model version;

timestamp;

user identity;

human intervention;

override;

warning messages;

subsequent corrections.

Without such information, establishing causation may become extremely difficult.

In litigation, these records can become important evidence.

41. Human Oversight

A legally responsible healthcare system should distinguish between:

Genuine human oversight

The doctor independently evaluates the patient and can reject the AI recommendation.

Formal human oversight

The doctor merely confirms the AI result.

The second model creates a risk of automation bias.

The legal significance will depend on the applicable law and the actual facts.

42. Role of the European Courts

The current European case law can broadly be divided into four groups:

CategoryImportant authorities
Automated decisionsSCHUFA, C-634/21; Dun & Bradstreet Austria, C-203/22
Personal/health dataNowak, C-434/16; Lindqvist, C-101/01
Data-related compensationÖsterreichische Post, C-300/21
Medical/public-health liabilityCalvelli and Ciglio; Šilih; Lopes de Sousa Fernandes; Y v Turkey; Căldărari

This combination is more legally accurate than treating any one of these cases as a direct “AI public-health liability” case.

43. Consolidated Case-Law Table

CaseCourtMain principleRelevance to algorithmic public health
SCHUFA, C-634/21CJEUAutomated scoring can fall within Article 22AI triage/risk scoring
Dun & Bradstreet Austria, C-203/22CJEUMeaningful information concerning automated logicExplainability and challenge
Nowak, C-434/16CJEUBroad concept of personal dataAlgorithm-generated health profiles
Österreichische Post, C-300/21CJEUInfringement, damage and causal link required for GDPR compensationAlgorithmic health-data harm
Lindqvist, C-101/01CJEUHealth information is specially protected personal informationHealth-data processing
Calvelli and Ciglio v ItalyECtHRState must maintain appropriate healthcare/accountability frameworkInstitutional AI safety
Šilih v SloveniaECtHREffective investigation of medical negligenceInvestigation of AI-caused medical harm
Lopes de Sousa Fernandes v PortugalECtHRDistinguishes medical negligence from systemic healthcare failures; procedural accountabilitySystemic algorithmic healthcare failures
Y v TurkeyECtHRHealth information may be shared for legitimate healthcare/public-health purposes with safeguardsAI health-data sharing
Căldărari v MoldovaECtHRInadequate response to arguable medical-negligence claims can engage Convention obligationsModern systemic healthcare-error accountability

44. Key Legal Principles

Principle 1

An algorithm is not a legal person.

Responsibility remains with relevant human or legal actors.

Principle 2

Automation does not automatically eliminate human responsibility.

Principle 3

Health data receive heightened protection.

Principle 4

A person affected by significant automated decision-making may have rights concerning the decision and its logic.

Principle 5

Incorrect data can produce legally significant algorithmic errors.

Principle 6

Algorithmic error alone does not automatically establish civil damages.

Damage and causation generally remain important.

Principle 7

Public-health objectives can justify certain data uses but do not create unlimited authority.

Principle 8

Systemic algorithmic failures can raise broader institutional and State-responsibility questions.

Principle 9

Courts may need both medical and technical expert evidence.

Principle 10

The healthcare institution may remain responsible even when software supplied the recommendation.

45. European Civil-Law Approach

The emerging European approach can therefore be understood as a multi-layered liability model:

Algorithmic error

↓

Data-protection law

  •  

Medical negligence

  •  

Contract/tort law

  •  

Product liability

  •  

Equality law

  •  

Fundamental rights

  •  

Public-authority liability

The exact remedy depends on the Member State, the identity of the defendant, the nature of the algorithm, the type of harm and the legal relationship between the parties.

46. Important Limitation in Current Case Law

There is presently an important distinction between algorithmic decision jurisprudence and algorithmic healthcare jurisprudence.

The leading CJEU cases such as SCHUFA and Dun & Bradstreet Austria concern automated scoring outside healthcare. The ECtHR cases such as Calvelli and Ciglio, Šilih, and Lopes de Sousa Fernandes concern medical negligence rather than AI.

Therefore, it would be legally inaccurate to say that these courts have already created a settled European rule specifically stating:

“AI-generated public-health decisions create civil liability.”

Instead, these authorities provide the legal building blocks from which courts can analyse such disputes.

47. Short Exam Answer

Algorithmic public-health decision errors in Europe arise when AI, automated scoring or predictive systems used by healthcare providers or public authorities produce incorrect or discriminatory decisions causing individual harm. The legal framework combines GDPR, national medical-negligence and civil-liability rules, equality law, EU fundamental rights and the ECHR.

The CJEU's SCHUFA, C-634/21 establishes important principles concerning automated decision-making and scoring, while Dun & Bradstreet Austria, C-203/22 strengthens the importance of meaningful information concerning automated decision logic. Nowak, C-434/16 supports a broad understanding of personal data, while Österreichische Post, C-300/21 establishes the importance of infringement, damage and causation for GDPR compensation. Lindqvist, C-101/01 demonstrates the special character of health information.

Under the ECHR, Calvelli and Ciglio v Italy, Šilih v Slovenia, and Lopes de Sousa Fernandes v Portugal establish important principles concerning healthcare safety, medical negligence and effective investigation. Y v Turkey illustrates the balance between medical confidentiality and public-health interests, while Căldărari v Moldova demonstrates the continuing importance of effective remedies for serious healthcare failures. (HUDOC)

The central legal issue is therefore not simply whether an algorithm made a mistake, but who was responsible for deploying, supervising, validating and acting upon the algorithm, whether the relevant data were lawfully and accurately processed, whether meaningful human oversight existed, and whether the error caused legally compensable harm.

48. Ultra-Short Revision

Algorithmic Public Health Error =

Wrong data + Wrong model + Wrong automated decision + Health harm

Remember:

SCHUFA → automated decisions
Dun & Bradstreet → explanation
Nowak → personal data
Österreichische Post → compensation + causation
Lindqvist → health data
Calvelli → healthcare regulatory framework
Šilih → effective investigation
Lopes de Sousa Fernandes → medical negligence/systemic failure
Y v Turkey → health-data confidentiality/public health
Căldărari → effective healthcare remedy

Core principle:

AI may make the decision technically, but European civil and human-rights law continues to look for responsible human, institutional and public-authority actors behind the system.

LEAVE A COMMENT