10 to the 23 AI logo

Domain Atlas / Public benefits & eligibility

Case fileNetherlandslarge deployment

SyRI (Netherlands)

On 5 February 2020 the District Court of The Hague ruled that the legislation authorising SyRI, the Dutch state's secret cross-database welfare-fraud risk-profiling system, violated Article 8 of the European Convention on Human Rights, and it ordered the system's use stopped; the State did not appeal. The ruling is widely described as one of the first times a court anywhere halted a digital welfare-fraud technology on human-rights grounds. Across its two executed neighbourhood projects SyRI was reported to have produced no confirmed fraud cases, and in one municipality 62 of 113 risk notifications were reported to be false positives.[6]

What happened

SyRI (Systeem Risico Indicatie, or System Risk Indication) was a Dutch state instrument for detecting welfare, tax and labour-law fraud, given a statutory basis in 2014 through articles 64-65 of the SUWI Act. Participating administrative bodies and the Ministry of Social Affairs first defined a secret "risk model" of undisclosed indicators; a third-party foundation, the Inlichtingenbureau, then pseudonymised and linked records drawn from a wide range of government databases — employment, income, benefits, taxes, fines, property, housing, education, pensions, debts, permits, and more, reaching in principle to special-category data — and compared them against the model. Matching cases were de-pseudonymised into binary "risk notifications" and held in a register for up to two years. One disclosed example indicator was unusually low running-water usage, taken to suggest a benefits recipient was living elsewhere. Crucially, the legislation imposed no duty to notify people that their data had been processed or that a risk report had been filed, so a flagged person generally could not know about, access, or contest the notification.

SyRI was deployed only in specific low-income, high-migrant neighbourhoods — Eindhoven, Haarlem, Capelle aan den IJssel, and Rotterdam-Zuid. Its results were meagre: across 2014-2019 five municipalities requested analyses but only two projects were actually executed, and in June 2019 De Volkskrant reported that SyRI had not detected a single fraud case since its introduction. In one Capelle aan den IJssel project, 62 of 113 risk notifications were reported to be false positives; after the analysis effectively yielded nothing, participating parties independently re-linked their own files. The Rotterdam-Zuid project in Bloemhof and Hillesluis was halted by the municipality in mid-2019 over an unresolved dispute about its legal basis, before planned home visits took place.

A coalition of civil-society organisations — among them NJCM, Platform Bescherming Burgerrechten, Privacy First, Stichting KDVP, the FNV trade-union confederation, and the Landelijke Clientenraad, joined by the authors Tommy Wieringa and Maxim Februari, with the litigation coordinated by PILP — sued the Dutch State. The UN Special Rapporteur on extreme poverty and human rights, Philip Alston, submitted an amicus intervention (dated 26 September 2019, ahead of the 29 October main hearing) calling dragnet systems like SyRI "the digital equivalent of fraud inspectors knocking on every door in a certain area." SyRI received the Big Brother Award on 29 November 2019.

On 5 February 2020 the District Court of The Hague (ECLI:NL:RBDHA:2020:865, with the official English translation at ECLI:NL:RBDHA:2020:1878) ruled that the SyRI legislation violated Article 8 of the European Convention on Human Rights. The court held that the scheme failed the proportionality or "fair balance" test, lacked transparency (a secret model and indicators, and no notice to those affected), and breached the GDPR's purpose-limitation and data-minimisation principles; it found the State bears a "special responsibility" when applying new technologies, and flagged risks of discrimination, stereotyping and stigmatisation, noting that a risk notification carried "significant effect" for a person even though it lacked formal legal effect. The legislation was declared to have no binding effect and its use ordered stopped. The government announced on 23 April 2020 that it would not appeal. The ruling is widely described as one of the first times a court anywhere halted a digital welfare-fraud technology on human-rights grounds. A broader successor data-sharing law, the WGS — dubbed "Super SyRI" by critics and opposed by a civil-rights coalition — entered into force on 1 March 2025.

Whether the executed SyRI model used machine learning or data mining is not established in the public record; the court noted the legislation permitted such methods, but no confirmation of the deployed model's method, and no AI model identifier, is documented.

The sociotechnical reading

SyRI is the Atlas's pre-harm case. The control that bound the system arrived before its individual harms were ever tallied, and it arrived on transparency and privacy grounds rather than on any measurement of who was wrongly flagged. That sets it apart from its two nearest neighbours here. Rotterdam's control came from an audit that pried open a live model and measured its bias; the Dutch childcare-benefits scandal's reckoning came from a parliamentary inquiry years into the damage. SyRI's came from a court that could see the defect on the statute's face — a secret model, no notice to the people it flagged, cross-silo data reaching far beyond its stated purpose — and stopped it under Article 8 of the European Convention on Human Rights. In Rotterdam-Zuid the planned home visits never took place at all; the municipality had already shelved that project months earlier over a dispute about its legal basis.

In map terms, the defining feature is an absence: there was no subject-facing correction channel at all. A risk notification was written into a two-year register and could be re-linked into other agencies' files, but the person flagged had no duty-of-notice, no access, and no way to contest — so a false positive (62 of 113 in one municipality, against no confirmed fraud across the executed projects, as reported) could persist unchallenged wherever it spread. The lesson the map draws is that transparency is not a reporting nicety downstream of accuracy; it is the precondition for correction to exist at all. A system no one can see is a system no one can fix, and the court treated the invisibility itself — not a proven error rate — as the harm. That is also why the Lab's sharpest levers here are the transparency and record-reconciliation ones rather than a better classifier: when the flag cannot be seen, refining it changes nothing a person can act on. The sequel underlines the point. The broader successor data-sharing law critics call "Super SyRI" took effect in 2025, so the governance question SyRI posed — on what published basis may a state link everyone's records and score the poor? — is live, not historical.

The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.

Grounding sources for this case

The same sources that ground this model organization in the PAN library: evaluations, government documents, investigative reporting, and advocacy documentation, each labeled by tier.

vanbekkum2021GroundingAcademicSave

van Bekkum, Marvin and Zuiderveen Borgesius, Frederik, Digital welfare fraud detection and the Dutch SyRI judgment, European Journal of Social Security 23(4):323-340 (2021) https://journals.sagepub.com/doi/10.1177/13882627211031257

https://journals.sagepub.com/doi/10.1177/13882627211031257

Grounds: model org: nl_syri

algorithmwatch2020aGroundingInvestigativeSave

AlgorithmWatch, How Dutch activists got an invasive fraud detection algorithm banned (Automating Society Report 2020: Netherlands) (2020) https://algorithmwatch.org/en/syri-netherlands-algorithm/

https://algorithmwatch.org/en/syri-netherlands-algorithm/

Grounds: model org: nl_syri

privacyfirst2022GroundingAdvocacySave

Privacy First, Burgerrechtencoalitie: Eerste Kamer moet datasurveillancewet 'Super SyRI' afwijzen (Civil-rights coalition: the Senate must reject the 'Super SyRI' data-surveillance law) (2022) https://privacyfirst.nl/aandachtsvelden/wetgeving/item/1244-burgerrechtencoalitie-eerste-kamer-moet-datasurveillancewet-super-syri-afwijzen.html

https://privacyfirst.nl/aandachtsvelden/wetgeving/item/1244-burgerrechtencoalitie-eerste-kamer-moet-datasurveillancewet-super-syri-afwijzen.html

Grounds: model org: nl_syri

Topics: privacy-security

privacynieuwsnl2024GroundingTrade pressSave

PrivacyNieuws.nl, Controversiele gegevensuitwisselingswet WGS treedt op 1 maart 2025 in werking (Controversial WGS data-sharing law enters into force 1 March 2025) (2024) https://privacynieuws.nl/nieuwsoverzicht/binnenlands-nieuws/politiek-en-overheid/controversi%C3%ABle-gegevensuitwisselingswet-wgs-treedt-op-1-maart-2025-in-werking.html

https://privacynieuws.nl/nieuwsoverzicht/binnenlands-nieuws/politiek-en-overheid/controversi%C3%ABle-gegevensuitwisselingswet-wgs-treedt-op-1-maart-2025-in-werking.html

Grounds: model org: nl_syri

Topics: privacy-security

Seeing your organization in this case file?

The histories here are documented after the harm. Mapping a live deployment's pathways and pressures, before the incident report, is engagement work: intake, diagnosis, prescription, and monitoring, with every limitation stated.

Sources & Evidence

Claims made on this page and what supports them. The full registry lives in Evidence.

EmpiricalOn 5 February 2020 the District Court of The Hague ruled that the legislation authorising SyRI, the Dutch stat…

On 5 February 2020 the District Court of The Hague ruled that the legislation authorising SyRI, the Dutch state's secret cross-database welfare-fraud risk-profiling system, violated Article 8 of the European Convention on Human Rights, and it ordered the system's use stopped; the State did not appeal. The ruling is widely described as one of the first times a court anywhere halted a digital welfare-fraud technology on human-rights grounds. Across its two executed neighbourhood projects SyRI was reported to have produced no confirmed fraud cases, and in one municipality 62 of 113 risk notifications were reported to be false positives.

vanbekkum2021GroundingAcademicSave

van Bekkum, Marvin and Zuiderveen Borgesius, Frederik, Digital welfare fraud detection and the Dutch SyRI judgment, European Journal of Social Security 23(4):323-340 (2021) https://journals.sagepub.com/doi/10.1177/13882627211031257

https://journals.sagepub.com/doi/10.1177/13882627211031257

Grounds: model org: nl_syri

algorithmwatch2020aGroundingInvestigativeSave

AlgorithmWatch, How Dutch activists got an invasive fraud detection algorithm banned (Automating Society Report 2020: Netherlands) (2020) https://algorithmwatch.org/en/syri-netherlands-algorithm/

https://algorithmwatch.org/en/syri-netherlands-algorithm/

Grounds: model org: nl_syri

EmpiricalThe District Court of The Hague found that the SyRI framework provided no duty to notify people that their dat…

The District Court of The Hague found that the SyRI framework provided no duty to notify people that their data had been processed or that a risk report had been filed, so a flagged person generally could not know about, access, or contest the notification; notifications were retained in a register for up to two years. The court held that a risk notification carried significant effect for the person even though it lacked formal legal effect, and it faulted the scheme for a lack of transparency and for breaching data-minimisation and purpose-limitation principles.

vanbekkum2021GroundingAcademicSave

van Bekkum, Marvin and Zuiderveen Borgesius, Frederik, Digital welfare fraud detection and the Dutch SyRI judgment, European Journal of Social Security 23(4):323-340 (2021) https://journals.sagepub.com/doi/10.1177/13882627211031257

https://journals.sagepub.com/doi/10.1177/13882627211031257

Grounds: model org: nl_syri