Domain Atlas / Public benefits & eligibility
SyRI (Netherlands)
On 5 February 2020 the District Court of The Hague ruled that the legislation authorising SyRI, the Dutch state's secret cross-database welfare-fraud risk-profiling system, violated Article 8 of the European Convention on Human Rights, and it ordered the system's use stopped; the State did not appeal. The ruling is widely described as one of the first times a court anywhere halted a digital welfare-fraud technology on human-rights grounds. Across its two executed neighbourhood projects SyRI was reported to have produced no confirmed fraud cases, and in one municipality 62 of 113 risk notifications were reported to be false positives.[6]
What happened
SyRI (Systeem Risico Indicatie, or System Risk Indication) was a Dutch state instrument for detecting welfare, tax and labour-law fraud, given a statutory basis in 2014 through articles 64-65 of the SUWI Act. Participating administrative bodies and the Ministry of Social Affairs first defined a secret "risk model" of undisclosed indicators; a third-party foundation, the Inlichtingenbureau, then pseudonymised and linked records drawn from a wide range of government databases — employment, income, benefits, taxes, fines, property, housing, education, pensions, debts, permits, and more, reaching in principle to special-category data — and compared them against the model. Matching cases were de-pseudonymised into binary "risk notifications" and held in a register for up to two years. One disclosed example indicator was unusually low running-water usage, taken to suggest a benefits recipient was living elsewhere. Crucially, the legislation imposed no duty to notify people that their data had been processed or that a risk report had been filed, so a flagged person generally could not know about, access, or contest the notification.
SyRI was deployed only in specific low-income, high-migrant neighbourhoods — Eindhoven, Haarlem, Capelle aan den IJssel, and Rotterdam-Zuid. Its results were meagre: across 2014-2019 five municipalities requested analyses but only two projects were actually executed, and in June 2019 De Volkskrant reported that SyRI had not detected a single fraud case since its introduction. In one Capelle aan den IJssel project, 62 of 113 risk notifications were reported to be false positives; after the analysis effectively yielded nothing, participating parties independently re-linked their own files. The Rotterdam-Zuid project in Bloemhof and Hillesluis was halted by the municipality in mid-2019 over an unresolved dispute about its legal basis, before planned home visits took place.
A coalition of civil-society organisations — among them NJCM, Platform Bescherming Burgerrechten, Privacy First, Stichting KDVP, the FNV trade-union confederation, and the Landelijke Clientenraad, joined by the authors Tommy Wieringa and Maxim Februari, with the litigation coordinated by PILP — sued the Dutch State. The UN Special Rapporteur on extreme poverty and human rights, Philip Alston, submitted an amicus intervention (dated 26 September 2019, ahead of the 29 October main hearing) calling dragnet systems like SyRI "the digital equivalent of fraud inspectors knocking on every door in a certain area." SyRI received the Big Brother Award on 29 November 2019.
On 5 February 2020 the District Court of The Hague (ECLI:NL:RBDHA:2020:865, with the official English translation at ECLI:NL:RBDHA:2020:1878) ruled that the SyRI legislation violated Article 8 of the European Convention on Human Rights. The court held that the scheme failed the proportionality or "fair balance" test, lacked transparency (a secret model and indicators, and no notice to those affected), and breached the GDPR's purpose-limitation and data-minimisation principles; it found the State bears a "special responsibility" when applying new technologies, and flagged risks of discrimination, stereotyping and stigmatisation, noting that a risk notification carried "significant effect" for a person even though it lacked formal legal effect. The legislation was declared to have no binding effect and its use ordered stopped. The government announced on 23 April 2020 that it would not appeal. The ruling is widely described as one of the first times a court anywhere halted a digital welfare-fraud technology on human-rights grounds. A broader successor data-sharing law, the WGS — dubbed "Super SyRI" by critics and opposed by a civil-rights coalition — entered into force on 1 March 2025.
Whether the executed SyRI model used machine learning or data mining is not established in the public record; the court noted the legislation permitted such methods, but no confirmation of the deployed model's method, and no AI model identifier, is documented.
The sociotechnical reading
SyRI is the Atlas's pre-harm case. The control that bound the system arrived before its individual harms were ever tallied, and it arrived on transparency and privacy grounds rather than on any measurement of who was wrongly flagged. That sets it apart from its two nearest neighbours here. Rotterdam's control came from an audit that pried open a live model and measured its bias; the Dutch childcare-benefits scandal's reckoning came from a parliamentary inquiry years into the damage. SyRI's came from a court that could see the defect on the statute's face — a secret model, no notice to the people it flagged, cross-silo data reaching far beyond its stated purpose — and stopped it under Article 8 of the European Convention on Human Rights. In Rotterdam-Zuid the planned home visits never took place at all; the municipality had already shelved that project months earlier over a dispute about its legal basis.
In map terms, the defining feature is an absence: there was no subject-facing correction channel at all. A risk notification was written into a two-year register and could be re-linked into other agencies' files, but the person flagged had no duty-of-notice, no access, and no way to contest — so a false positive (62 of 113 in one municipality, against no confirmed fraud across the executed projects, as reported) could persist unchallenged wherever it spread. The lesson the map draws is that transparency is not a reporting nicety downstream of accuracy; it is the precondition for correction to exist at all. A system no one can see is a system no one can fix, and the court treated the invisibility itself — not a proven error rate — as the harm. That is also why the Lab's sharpest levers here are the transparency and record-reconciliation ones rather than a better classifier: when the flag cannot be seen, refining it changes nothing a person can act on. The sequel underlines the point. The broader successor data-sharing law critics call "Super SyRI" took effect in 2025, so the governance question SyRI posed — on what published basis may a state link everyone's records and score the poor? — is live, not historical.
The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.