PAN Lab example
SyRI (Netherlands)
Struck down before the harm was counted: a secret welfare-fraud dragnet
SyRI, a secret Dutch system, linked government records to flag people for fraud investigation. In 2020 a court stopped it on privacy and transparency grounds.
See more
SyRI, short for System Risk Indication, was a Dutch state system for detecting welfare, tax, and labor law fraud. A foundation, the Inlichtingenbureau, linked records from many government databases and compared them against a secret risk model. Matches became risk notifications that the people flagged generally could not know about.
How it worked
The Ministry of Social Affairs and the participating administrative bodies first defined the risk model. Its indicators were kept secret. One disclosed example was unusually low running water use, taken to suggest that a benefits recipient lived elsewhere.
The Inlichtingenbureau pseudonymized the records, putting a code in place of each name, and linked them. The databases covered employment, income, benefits, taxes, fines, property, housing, education, pensions, debts, permits, and more. In principle the linkage could include special-category data, the most sensitive kinds of personal data under European data protection law.
When a person's records matched the model, the code was replaced by the person's name again, and the match became a yes-or-no risk notification. A register held them for up to two years. Before release, the Ministry of Social Affairs screened flagged notifications for obvious false positives: flags on people who were not committing fraud. A released notification could lead to an administrative or criminal investigation, and possibly a home visit.
What the people flagged could know
The law gave no duty to tell people that their data had been processed, or that a risk notification had been filed. So a flagged person generally could not know about, access, or contest a notification. Meanwhile a notification in the register could be re-linked into other agencies' files.
Where it was used
SyRI gained a legal basis in 2014, in articles 64 and 65 of the SUWI Act, the Dutch social security implementation act. From 2014 to 2019, five municipalities requested analyses, SyRI runs over the records of chosen neighborhoods. Only two projects were carried out.
The case file records SyRI's use only in low-income neighborhoods with many migrant residents: in Eindhoven, Haarlem, Capelle aan den IJssel, and Rotterdam-Zuid. It does not say which of these were the two projects carried out. The municipality halted the Rotterdam-Zuid project, in Bloemhof and Hillesluis, in mid-2019. It did so over an unresolved dispute about the project's legal basis, before the planned home visits took place.
What it found
In June 2019, the newspaper De Volkskrant reported that SyRI had not detected a single fraud case since its introduction. In one Capelle aan den IJssel project, 62 of 113 risk notifications were reported to be false positives. After that analysis effectively yielded nothing, the participating parties re-linked their own files independently.
These figures come from court filings and the press, not from an independent government audit.
Who challenged it
A coalition of civil society organizations sued the Dutch State. Among them were the Nederlands Juristen Comite voor de Mensenrechten (NJCM), Platform Bescherming Burgerrechten, Privacy First, Stichting KDVP, the FNV trade union confederation, and the Landelijke Clientenraad. The authors Tommy Wieringa and Maxim Februari joined them. The Public Interest Litigation Project (PILP) coordinated the case.
Philip Alston, the UN Special Rapporteur on extreme poverty and human rights, intervened in the case. His brief to the court was dated September 26, 2019, ahead of the main hearing on October 29. He called dragnet systems like SyRI "the digital equivalent of fraud inspectors knocking on every door in a certain area."
SyRI received the Big Brother Award on November 29, 2019.
What the court ruled
On February 5, 2020, the District Court of The Hague ruled that the SyRI legislation violated Article 8 of the European Convention on Human Rights. Article 8 protects private life. The court held that the scheme failed the test of proportionality, or fair balance. It lacked transparency: the model and its indicators were secret, and the people affected got no notice. It also breached the principles of purpose limitation and data minimization in the GDPR, the EU's data protection law.
The court found that the State bears a special responsibility when it applies new technologies. It flagged risks of discrimination, stereotyping, and stigmatization. It noted that a risk notification had a significant effect on a person, even without formal legal effect.
The court declared the legislation to have no binding effect and ordered its use stopped. On April 23, 2020, the government announced that it would not appeal. The ruling is widely described as one of the first times a court anywhere halted a digital welfare fraud technology on human rights grounds.
What came after
A broader data sharing law, the Wet gegevensverwerking door samenwerkingsverbanden (WGS), entered into force on March 1, 2025. Critics dubbed it "Super SyRI", and a civil rights coalition opposed it. So the question SyRI posed is live, not historical: on what published basis may a state link everyone's records and score the poor?
The question this case asks
SyRI is the pre-harm case in this collection. The control that stopped it came before its individual harms were counted. It came on transparency and privacy grounds, not from measuring who was wrongly flagged.
A court could see the defect on the face of the law. The case file names that defect: a secret model, no notice to the people it flagged, and linked data far beyond SyRI's stated purpose.
Two nearby cases differ. In Rotterdam, an audit opened up a live model and measured its bias. The Dutch childcare benefits scandal was reckoned with through a parliamentary inquiry, years into the damage.
The case file draws a lesson from this. Transparency is not a reporting nicety that comes after accuracy. It is the precondition for correction to exist at all. A system no one can see is a system no one can fix.
What the available tools can and cannot address
A failure pathway is a link between two parts of the network where a mistake made by one part can be passed on to the other. A pathway is closed when mistakes stop passing along it.
Explore (No Targets) sets no targets. Under Service Targets Only, the targets can be met with one tool: Vet connections, for 3 of this case's 12 budget units. It closes four pathways. Two are the linked records and the past notifications compared with the risk model. The others are the notifications copied to agencies and the one indicator set applied to every record.
Service and Safety Targets and All Governance Targets both ask you to close every failure pathway. The targets can be met under both. The cheapest combination costs 11 of the 12 units: Understand the system, Assign a challenger, Escalate checks, Vet connections, and Store less data. While Understand the system is on, three of the others cost less.
Under All Governance Targets, Vet connections and Store less data work at reduced strength unless Understand the system is on.
More tools are not better here. The service target asks that the network keep doing useful work. Every tool at once, ignoring the budget, closes every pathway but misses the service target at all three target levels. Some of the tools take something from the service. Together they take it below its target.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the SyRI-class cross-database risk-flagging engine network: 6 components and 13 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 4 assumed · 3 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
Show all 7 assumptions
- assumed
This example follows the pattern the SyRI case file documents: a secret risk model that flagged people using records linked across government databases. It does not rebuild the actual model or its undisclosed indicators.
- assumed
The example assumes two pathways that spread mistakes. Investigators share suspicion rules of thumb, and one secret set of indicators repeats the same flaw for everyone. It also assumes a check among the people handling flags. The sources do not describe one among investigators. It stands in for the ministry's documented pre-screen for false positives, which is also drawn as its own part.
- baseline
The example draws a loop through the register. Notifications are written into it and kept for up to two years. They are re-linked into agency files and read again on re-investigation. This follows the case file: a register with no way for the person flagged to have a notification corrected.
- assumed
The ministry's pre-screen is drawn as its own part of the network, with its own review of notifications. That follows the documented screening for false positives before release. Screening some false positives did not let the person flagged see or contest a notification.
- baseline
The defining feature is something the deployment lacked: any way for the person flagged to have a notification corrected. So the example includes a check of a notification against its source, which the deployment did not have. The court found no duty to notify people, so a flagged person generally could not know about, access, or contest a notification.
- baseline
The linked records are drawn as a real input to the risk model: pseudonymized records linked across many government databases. What the linkage covered comes from the case file: data far beyond SyRI's stated purpose, in principle including special-category data. The case file is also the source for who was targeted. The example does not compute either.
- assumed
SyRI was used in specific low-income neighborhoods with many migrant residents. The court flagged risks of discrimination, stereotyping, and stigmatization. This example follows how mistakes move through the institution's work, not who the people are. It does not estimate whether harm fell unequally on the people served. The targeting and the individual harms come from the case file, not from this example.
What this example does not show
Show all 2 limitations
- This example does not show the harm to the people SyRI flagged, who are not part of the network. SyRI was used in specific low-income neighborhoods with many migrant residents. The court flagged risks of discrimination, stereotyping, and stigmatization. This example follows how mistakes move through the institution's work, not who the people are. It does not estimate whether harm fell unequally on them. The targeting and the individual harms come from the case file, not from this example.
- The false-positive and no-fraud figures come from court filings and the press, not from an independent government audit. This example follows the case's pattern, not measured rates.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
The District Court of The Hague found that the SyRI framework provided no duty to notify people that their data had been processed or that a risk report had been filed, so a flagged person generally could not know about, access, or contest the notification; notifications were retained in a register for up to two years. The court held that a risk notification carried significant effect for the person even though it lacked formal legal effect, and it faulted the scheme for a lack of transparency and for breaching data-minimisation and purpose-limitation principles.
empirical- Government District Court of The Hague, NJCM and FNV v. The State of the Netherlands (SyRI), ECLI:NL:RBDHA:2020:1878 (English translation; Dutch original ECLI:NL:RBDHA:2020:865) (2020) https://www.escr-net.org/caselaw/2020/nederlands-juristen-comite-voor-mensenrechten-et-al-v-netherlands-eclinlrbdha20201878/
- Academic van Bekkum, Marvin and Zuiderveen Borgesius, Frederik, Digital welfare fraud detection and the Dutch SyRI judgment, European Journal of Social Security 23(4):323-340 (2021) https://journals.sagepub.com/doi/10.1177/13882627211031257
On 5 February 2020 the District Court of The Hague ruled that the legislation authorising SyRI, the Dutch state's secret cross-database welfare-fraud risk-profiling system, violated Article 8 of the European Convention on Human Rights, and it ordered the system's use stopped; the State did not appeal. The ruling is widely described as one of the first times a court anywhere halted a digital welfare-fraud technology on human-rights grounds. Across its two executed neighbourhood projects SyRI was reported to have produced no confirmed fraud cases, and in one municipality 62 of 113 risk notifications were reported to be false positives.
empirical- Government District Court of The Hague, NJCM and FNV v. The State of the Netherlands (SyRI), ECLI:NL:RBDHA:2020:1878 (English translation; Dutch original ECLI:NL:RBDHA:2020:865) (2020) https://www.escr-net.org/caselaw/2020/nederlands-juristen-comite-voor-mensenrechten-et-al-v-netherlands-eclinlrbdha20201878/
- Academic van Bekkum, Marvin and Zuiderveen Borgesius, Frederik, Digital welfare fraud detection and the Dutch SyRI judgment, European Journal of Social Security 23(4):323-340 (2021) https://journals.sagepub.com/doi/10.1177/13882627211031257
- Government UN Office of the High Commissioner for Human Rights, Landmark ruling by Dutch court stops government attempts to spy on the poor - UN expert (2020) https://www.ohchr.org/en/press-releases/2020/02/landmark-ruling-dutch-court-stops-government-attempts-spy-poor-un-expert
- Investigative AlgorithmWatch, How Dutch activists got an invasive fraud detection algorithm banned (Automating Society Report 2020: Netherlands) (2020) https://algorithmwatch.org/en/syri-netherlands-algorithm/
- Trade press PONT Data&Privacy (privacy-web.nl), SyRI: Algorithm that identifies citizens as high fraud risk (2019) https://privacy-web.nl/en/artikelen/syri-algoritme-dat-burgers-aanmerkt-als-hoog-frauderisico/
- Advocacy Public Interest Litigation Project (PILP-NJCM), System Risk Indication (SyRI) - dossier (2020) https://pilp.nu/en/dossier/system-risk-indication-syri/
Where this connects
Institutional pressures in this domain
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
All of them in context on the Public benefits & eligibility domain page.
Levers available here and the patterns behind them
- Require sign-off — Conformity assessment gate
- Mark AI-written records — Provenance labeling
- Store less data — Data minimization
- Check copied records — Reconcile copied records
- Vet connections — Connection authorization
- Understand the system — Understand the system
- Review on schedule — Oversight cadence & retrospectives
- Assign a challenger — Structured dissent
- Upgrade model — Improve the model
- Peer sharing rules — Peer-edge governance
- Escalate checks — State-feedback vigilance
Documented case histories
- SyRI (Netherlands)
- Michigan MiDAS
- Robodebt (Australia)
- Indiana / IBM eligibility modernization
- Rotterdam welfare-fraud risk model
- Arkansas ARChoices / ARIA
- Netherlands childcare-benefits scandal (Toeslagenaffaire)
- CNAF benefit-fraud risk score (France)
- Forsakringskassan VAB fraud-selection profile (Sweden)
- Udbetaling Danmark data-driven control (Denmark)
- BOSCO (Spain)
- Serbia Social Card (Socijalna karta)
- UK DWP Universal Credit Advances fraud model
- ID.me identity verification as an unemployment eligibility gate
- Medicaid unwinding: automated ex parte renewal at population scale
- INSS auto-analysis: when the productivity metric makes denial the fastest way out
- Samagra Vedika
- Workforce Australia Targeted Compliance Framework: automated payment sanctioning after Robodebt
- NYC MyCity business chatbot
- Nevada DETR generative-AI unemployment appeals
- Tennessee TennCare TEDS