● LIVEECB RATE 2.65%·EUR/USD 1.1460·EUR/GBP 0.8588·BRUSSELS 20°C — CLEAR·EU PROPOSES AGE‑BASED LIMITS ON SOCIAL‑MEDIA USE FOR UNDER‑15S·UKRAINE'S RAPID DEFENCE INNOVATION FORCES EUROPE TO RETHINK PROCUREMENT·RUSSIAN PUSH ON DOBROPILLIA INTENSIFIES AS UKRAINE BRACES FOR AUTUMN FIGHTING·ORBÁN RETURNS TO HUNGARY, CRITICISES NEW CHILD‑PROTECTION LAW AND ASSET‑RECOVERY OFFICE·EU PLANS TO DILUTE GDPR SAFEGUARDS AS ALGORITHMIC SCORING SPREADS ACROSS EVERYDAY LIFE·MERZ FACES MOUNTING PRESSURE AS AFD SURGES AHEAD OF GERMAN STATE POLLS·WEEK 38 · VOL. XV · N°261·● LIVEECB RATE 2.65%·EUR/USD 1.1460·EUR/GBP 0.8588·BRUSSELS 20°C — CLEAR·EU PROPOSES AGE‑BASED LIMITS ON SOCIAL‑MEDIA USE FOR UNDER‑15S·UKRAINE'S RAPID DEFENCE INNOVATION FORCES EUROPE TO RETHINK PROCUREMENT·RUSSIAN PUSH ON DOBROPILLIA INTENSIFIES AS UKRAINE BRACES FOR AUTUMN FIGHTING·ORBÁN RETURNS TO HUNGARY, CRITICISES NEW CHILD‑PROTECTION LAW AND ASSET‑RECOVERY OFFICE·EU PLANS TO DILUTE GDPR SAFEGUARDS AS ALGORITHMIC SCORING SPREADS ACROSS EVERYDAY LIFE·MERZ FACES MOUNTING PRESSURE AS AFD SURGES AHEAD OF GERMAN STATE POLLS·WEEK 38 · VOL. XV · N°261·
Brussels · Est. 2012
Independent European journalism

Unionpress

Vol. XV · N°261
Friday, 18 September 2026
Home/Opinion/computer-says-no-how-brussels-is-letting-algorithmic-social-scoring-in-by-the-backdoor
Opinion17 September 2026

EU plans to dilute GDPR safeguards as algorithmic scoring spreads across everyday life

A draft amendment to the GDPR could let companies justify automated decisions as 'necessary', raising concerns that workers, renters and job seekers will face hidden scores that shape their futures.

EU plans to dilute GDPR safeguards as algorithmic scoring spreads across everyday life

Brussels is preparing a change to the General Data Protection Regulation that would make it easier for firms to rely on fully automated decisions, even when a human could make the same choice. The proposal, part of the Commission's Digital Omnibus package, would rewrite Article 22, the clause that currently protects individuals from decisions that have a significant impact on their lives when those decisions are driven solely by algorithms.

Under the draft, a company could argue that an automated process is "necessary" for the performance of a contract, and the regulator would be obliged to accept that justification unless the firm can prove the decision could not be made by a person. Critics say the move would effectively turn a strong safeguard into a loophole, allowing scores generated by opaque systems to dictate who gets a loan, a rental contract, a job interview or even a border check.

From credit scores to CV rankings: a hidden web of algorithms

Across Europe, a growing number of everyday interactions are already filtered through numerical scores. In Germany, the credit bureau SCHUFA maintains data on roughly 69 million citizens, assigning each a rating that influences whether they can obtain a mortgage, sign a mobile‑phone contract or rent an apartment. In 2023, the Court of Justice of the European Union confirmed that such a score, when used to make a fully automated decision, can have "very real consequences" for the individual concerned.

Yet the power of these scores is not limited to finance. In the Netherlands, the data‑protection authority fined ride‑hailing giant Uber €825 million for automatically deactivating drivers based on algorithmic assessments of alleged fraud. The regulator found that drivers were cut off from the platform, and thus from their earnings, without any prior human review, leaving them to contest a decision that had already taken effect.

Similar systems have been deployed by public authorities. The Dutch tax‑benefit fraud detection tool SyRI was struck down by a Hague court in 2020 for lacking transparency and violating the right to private life. More recently, the education agency DUO used an algorithm to assign "fraud‑risk" scores to students based on age, type of study and the distance between their home and their parents' address. Those with higher scores faced a greater likelihood of investigations and even home visits. The Dutch Data Protection Authority concluded that the system discriminated against students with a non‑European migration background, who were more likely to receive higher risk scores.

Even the European Commission itself is testing the technology. For the latest round of EU staff recruitment, a tool is being developed to rank the 174 922 applicants who applied for a generalist competition. While officials claim that a human will make the final hiring decision, the algorithm will determine which CVs rise to the top of the pile, effectively shaping the shortlist before any person ever looks at the applications.

Why the hidden scores matter for ordinary Europeans

For many citizens, the consequences of an unseen score are stark. A wealthy individual rejected by one bank can simply apply elsewhere, but a low‑income family seeking affordable housing may have no alternative if a credit score or a fraud‑risk rating bars them from the market. Platform workers, such as Uber drivers, cannot wait months for a complaint to be resolved; a sudden deactivation can mean an immediate loss of income.

These systems also tend to amplify existing inequalities. By converting social disadvantage into a numerical variable, algorithms present discrimination as a matter of efficiency. The pattern is evident in the Dutch education case, where students from migrant backgrounds were disproportionately flagged, and in the broader European context where credit scores often reflect historical biases in lending practices.

Legal protections exist, but they are under threat. Article 22 of the GDPR gives individuals a right to not be subject to decisions based solely on automated processing when those decisions produce legal or similarly significant effects. The protection applies even if a human ultimately signs off on the decision, because the algorithm can heavily influence the outcome.

What the Digital Omnibus seeks to do is to reinterpret that safeguard. By allowing companies to claim that an automated decision is "necessary" for contract performance, the amendment would shift the burden of proof onto the individual to demonstrate that a human could have made the same choice. In practice, this could mean that a bank's credit‑scoring algorithm, a landlord's tenant‑screening tool, or a government's fraud‑detection system would no longer need to provide the level of transparency and accountability currently required.

Industry and political reactions

Tech firms and industry groups argue that the change would reduce administrative burdens and foster innovation. They claim that many automated processes are already essential for handling the volume of data generated by modern services, and that the current GDPR framework creates unnecessary friction.

However, consumer‑rights organisations and digital‑rights advocates warn that the amendment would erode a core pillar of European data protection. EDRi, the European Digital Rights network, has repeatedly warned against an "authoritarian‑scoring society" and urged policymakers to keep Article 22 intact.

Trade unions are also voicing concerns. The European Trade Union Confederation (ETUC) notes that algorithmic management is already reshaping labour markets, with workers in gig‑economy platforms facing opaque performance metrics that can lead to sudden deactivation. "When a worker's livelihood is decided by a black‑box algorithm, the power imbalance is extreme," a spokesperson said.

Some member states have already taken steps to curb the use of such systems. Germany's Federal Data Protection Agency has launched investigations into the use of credit scores for housing decisions, while France's CNIL has issued guidelines on algorithmic transparency for public services.

What the amendment could mean for everyday life

If adopted, the amendment would likely lead to a rise in automated decision‑making across sectors that have traditionally relied on human judgment. Banks could more confidently use AI to assess loan applications without offering a clear avenue for appeal. Landlords might employ scoring tools to screen tenants, potentially excluding vulnerable groups without a transparent process.

For workers, the risk is that performance monitoring tools could become more entrenched. Companies could justify using AI to allocate shifts, evaluate productivity or even decide on disciplinary actions, all under the banner of "necessity".

Consumers could see more personalised advertising and recommendation feeds that are fine‑tuned by algorithms, but with less insight into how those choices are made. The "For You" sections on streaming platforms or news sites would continue to be curated by opaque systems, influencing public discourse without accountability.

European context and the way forward

The debate over algorithmic scoring sits alongside broader EU efforts to regulate artificial intelligence. The AI Act, currently under negotiation, aims to set standards for high‑risk AI systems, but critics argue that it does not go far enough in addressing the cumulative impact of low‑risk scoring tools that, taken together, create a pervasive surveillance economy.

Moreover, the timing of the Digital Omnibus proposal is striking. Courts across the continent are beginning to recognise the real‑world effects of automated scores, as seen in the EU Court of Justice ruling on SCHUFA and the Dutch courts' decisions on SyRI and DUO. At the same time, the Commission is moving to make it easier for companies to rely on those very systems.

Stakeholders are calling for a more nuanced approach. Rather than a blanket exemption for "necessary" automation, they suggest a tiered system where the level of human oversight required depends on the potential impact of the decision. For high‑stakes outcomes, such as credit, housing, employment or access to public benefits, a human review should remain mandatory.

Transparency is also a recurring demand. The EU could require that any algorithm used for scoring be subject to an independent audit, with the results made available to the individuals affected. Such measures would align with the principle of "explainability" that many data‑protection advocates champion.

Finally, there is a political dimension. The EU has long positioned itself as a defender of digital rights, contrasting its approach with that of the United States and China. Weakening Article 22 would undermine that narrative and could erode public trust in European institutions at a time when digital sovereignty is a key policy goal.

As the debate unfolds, the question for European citizens is clear: will the promise of efficiency be allowed to override the right to a fair, transparent assessment of one's own data? The answer will shape not only the future of AI in Europe but also the everyday lived experience of millions who already feel the weight of unseen scores.

■ ENDOpinion© UnionPress 2026