Skip to content

PAN Lab example

SyRI (Netherlands)

Struck down before the harm was counted: a secret welfare-fraud dragnet

A secret model links records across many government databases and flags people for fraud investigation, and the flags land in a two-year register that other agencies re-read and re-link — but the people flagged are never told, so they cannot see or contest a flag. Modeled on the Netherlands' SyRI. Watch where the control comes from: not from measuring who was wrongly flagged, but from the transparency and privacy defect an outside authority could see before any of that harm was counted.

Stylized model of a documented deploymentPublic benefits & eligibility

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the SyRI-class cross-database risk-flagging engine network: 6 components and 13 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 4 assumed · 3 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

  • assumed

    This models the secret cross-database risk-flagging pattern documented in the SyRI case file — not a reconstruction of the actual model or its undisclosed indicators.

  • assumed

    Peer pathways are authored on both signs: shared suspicion heuristics and one secret indicator set's systematic skew reinforce, while the operator-side ministry pre-screen — the documented false-positive filter — is a present but light inhibiting check.

  • baseline

    The register loop — notifications written into a two-year register, re-linked into agency files, and re-read on re-investigation — is present at baseline, reflecting the case documentation's account of a two-year register held with no subject-facing correction.

  • assumed

    The ministry pre-screen node carries a real, lighter review pathway of its own — the documented operator-side screening of notifications for false positives before release — so it enters the dynamics rather than sitting on a pathway. That it screened some false positives does not mean the person flagged could see or contest the notification.

  • baseline

    The defining feature is an absence: there was no subject-facing correction channel, so the record-side reconciliation edge starts closed at baseline. The court found no duty to notify data subjects, so a flagged person generally could not know about, access, or contest a notification.

  • baseline

    The cross-database-linkage node carries a real inflow into the model — pseudonymised records linked across many government databases — so it enters the dynamics. What that linkage reached (data collected for other purposes, up to special-category data) and whom it targeted are documented in the case file, not computed here.

  • assumed

    SyRI was deployed in specific low-income, high-migrant neighbourhoods, a targeting the court flagged as risking discrimination and stigmatisation. This Lab models institutional workflow propagation, not demographics, and estimates no differential harm to served people; that targeting and the individual harms are documented in the case file and measured outside any diagram like this one.

What this example does not show

  • SyRI was deployed in specific low-income, high-migrant neighbourhoods, a targeting the court flagged as risking discrimination and stigmatisation. The Lab models institutional workflow propagation, not demographics, and estimates no differential harm to served people; that targeting and the individual harms are documented in the case file and measured outside any diagram like this one.
  • The false-positive and zero-fraud figures reached the record through litigation pleadings and press, not an independent government audit; the Lab uses the case's shape, not calibrated rates.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • The District Court of The Hague found that the SyRI framework provided no duty to notify people that their data had been processed or that a risk report had been filed, so a flagged person generally could not know about, access, or contest the notification; notifications were retained in a register for up to two years. The court held that a risk notification carried significant effect for the person even though it lacked formal legal effect, and it faulted the scheme for a lack of transparency and for breaching data-minimisation and purpose-limitation principles.

    empirical
    • Government District Court of The Hague, NJCM and FNV v. The State of the Netherlands (SyRI), ECLI:NL:RBDHA:2020:1878 (English translation; Dutch original ECLI:NL:RBDHA:2020:865) (2020) https://www.escr-net.org/caselaw/2020/nederlands-juristen-comite-voor-mensenrechten-et-al-v-netherlands-eclinlrbdha20201878/
    • Academic van Bekkum, Marvin and Zuiderveen Borgesius, Frederik, Digital welfare fraud detection and the Dutch SyRI judgment, European Journal of Social Security 23(4):323-340 (2021) https://journals.sagepub.com/doi/10.1177/13882627211031257
  • On 5 February 2020 the District Court of The Hague ruled that the legislation authorising SyRI, the Dutch state's secret cross-database welfare-fraud risk-profiling system, violated Article 8 of the European Convention on Human Rights, and it ordered the system's use stopped; the State did not appeal. The ruling is widely described as one of the first times a court anywhere halted a digital welfare-fraud technology on human-rights grounds. Across its two executed neighbourhood projects SyRI was reported to have produced no confirmed fraud cases, and in one municipality 62 of 113 risk notifications were reported to be false positives.

    empirical
    • Government District Court of The Hague, NJCM and FNV v. The State of the Netherlands (SyRI), ECLI:NL:RBDHA:2020:1878 (English translation; Dutch original ECLI:NL:RBDHA:2020:865) (2020) https://www.escr-net.org/caselaw/2020/nederlands-juristen-comite-voor-mensenrechten-et-al-v-netherlands-eclinlrbdha20201878/
    • Academic van Bekkum, Marvin and Zuiderveen Borgesius, Frederik, Digital welfare fraud detection and the Dutch SyRI judgment, European Journal of Social Security 23(4):323-340 (2021) https://journals.sagepub.com/doi/10.1177/13882627211031257
    • Government UN Office of the High Commissioner for Human Rights, Landmark ruling by Dutch court stops government attempts to spy on the poor - UN expert (2020) https://www.ohchr.org/en/press-releases/2020/02/landmark-ruling-dutch-court-stops-government-attempts-spy-poor-un-expert
    • Investigative AlgorithmWatch, How Dutch activists got an invasive fraud detection algorithm banned (Automating Society Report 2020: Netherlands) (2020) https://algorithmwatch.org/en/syri-netherlands-algorithm/
    • Trade press PONT Data&Privacy (privacy-web.nl), SyRI: Algorithm that identifies citizens as high fraud risk (2019) https://privacy-web.nl/en/artikelen/syri-algoritme-dat-burgers-aanmerkt-als-hoog-frauderisico/
    • Advocacy Public Interest Litigation Project (PILP-NJCM), System Risk Indication (SyRI) - dossier (2020) https://pilp.nu/en/dossier/system-risk-indication-syri/

Where this connects

Institutional pressures in this domain

  • Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.

All of them in context on the Public benefits & eligibility domain page.

Levers available here and the patterns behind them

Documented case histories