dering a personal appearance of the parties, the report of the personal appearance of the parties, drawn up without the presence of the parties involved of 29 October 2019 and the document containing exhibits on the part of NJCM et al., submitted at the hearing, with exhibits. 1.
ganisation involved in the protection and strengthening of human rights and fundamental freedoms. The Civil Rights Protection Platform (Platform Bescherming Burgerrechten) focuses on the protection of traditional civil rights. Privacy First aims to preserve and promote the right to privacy. The Umbrella
ganisation of DBC-free Practices (Koepel van DBC-Vrije praktijken) is committed to the protection of the right to privacy of clients of psychotherapists. 2.3. The National Client Participation Council (Landelijke Cliëntenraad) was established pursuant to the Work and Income (Implementation
ganisation Structure) Act (Wet structuur uitvoeringsorganisatie werk en inkomen, hereinafter: SUWI Act
the Act). This
gan consists of representatives of national client
ganisations, municipal client participation
ganisations and the central client participation councils of the Employee Insurance Agency (Uitvoeringsinstituut werknemersverzekeringen, hereinafter: UWV) and the Social Insurance Bank (Sociale verzekeringsbank, hereinafter: SVB). The National Client Participation Council is responsible for periodically consulting UWV, SVB, the municipal authorities and the Minister of Social Affairs and Employment (hereinafter: the Minister) about the design and implementation of client participation at the
gans in questions, and to consult the Minister about proposals of the National Client Participation Council regarding policy issues in the area of work and income. According to its internal rules, the National Client Participation Council aims to fulfil a key role pertaining to client participation regarding policy issues in the area of work and income, among other things. 2.
natural person is deemed worthy of investigating with regard to possible fraud, unlawful use and non-compliance with legislation. 3.3. The Minister applies the instrument at the request of certain government bodies
other bodies with a public function. These currently are the Municipal Executives (hereinafter: the municipal authorities), UWV, SVB, the Netherlands Tax and Customs Administration (hereinafter: the Tax and Customs Administration), the Immigration and Naturalisation Service (Immigratie- en Naturalisatiedienst, hereinafter: IND) as well as supervisory authorities such as the Social Affairs and Employment Inspectorate. These bodies may form a collaborative alliance in which they exchange data. By applying SyRI, the data files which the government
other bodies have available are linked in a structured manner to be able to identify related abuses in the aforementioned areas and increase chances of catching the perpetrators of such abuses. 3.
der of and for the regional intervention teams. The ‘black box’ project ended in
its precursors had been used. In 19 of the 21 completed intervention team projects a so-labelled neighbourhood-
iented approach had been applied. This approach was clarified by the Minister as follows: “That is to say, several addresses in a particular neighbourhood of a municipality were investigated by the intervention team in the context of social benefits fraud, tax allowance fraud
taxes fraud. The purpose of these projects is to contribute to the improvement of living conditions in such neighbourhoods. Therefore, these projects also pay specific attention to offering care and support to persons exhibiting care-avoiding behaviour.” 3.
der to enshrine in law the application of SyRI. The conditions for the application of SyRI are detailed in the SUWI Decree.SyRI now has a legal basis in Section 65 SUWI Act viewed in conjunction with Section 64 SUWI Act and Chapter 5a SUWI Decree. The then amended SUWI Act and the SUWI Decree are hereinafter jointly referred to as the SyRI legislation. The court will now explain the SyRI legislation in more detail below. 4.
pursuant to the law. Persons here does not refer to natural persons, but to those who are charged with monitoring compliance with
implementation of regulations falling under the responsibility of the Minister. These administrative bodies and persons are expressly referred to in Section 64 subsection 1 SUWI Act,
may be designated by ministerial regulation (hereinafter: the designated government bodies). At this point in time, the bodies referred to above in 3.3 have been designated (hereinafter: government
other bodies). According to the wording of the act, the purpose of collaborating is as follows: “an integral government action as regards the prevention of and combating the unlawful use of government funds and government schemes in the area of social security and income-dependent schemes, preventing and combating taxes and social security fraud and non-compliance with labour laws.” 4.5. Two
more of the designated government
other bodies may conclude a collaborative alliance in which data are processed as required for the aforementioned purpose of that collaborative alliance (Section 64 subsection 2 SUWI Act). 4.6. The starting point is that the designated government
other bodies that participate in a collaborative alliance are obliged to provide that necessary information to each other, in which case they are joint controllers within the meaning of Article 26 GDPR (Section 64 subsection 3 SUWI Act). 4.7. In case of a collaborative alliance in which the participating government
other bodies also wish to apply SyRI, they submit a request to that effect to the Minister. In that case, and contrary to the aforementioned starting point, the necessary information must be provided to the Minister, in which case the Minister is the controller within the meaning of the GDPR (Section 64 subsection 4 SUWI Act in conjunction with Section 65 subsection 1 SUWI Act). Legal basis for SyRI 4.8. Section 65 SUWI Act subsequently provides the legal basis for the processing of the aforementioned necessary information in SyRI by the Minister for the purpose of carrying out risk analyses. This section also contains provisions for submitting a risk report, confidentiality, retaining the information that a risk report has been submitted, using a risk report, feedback and removal. Finally, it is specified which further rules are in any event to be laid down by
der in council. The latter has been put into effect in the SUWI Decree, and in particular Chapter 5a of said Decree. 4.9. A request to the Minister to process data in SyRI may only be submitted by a collaborative alliance of designated government
other bodies with the intention of applying SyRI. Each of the collaborating bodies must also be a party to the Cooperation Agreement for Intervention Teams (Section 65 subsection 1 SUWI Act in conjunction with Article 1.1 bb and Article 5.a.1 paragraph 1 SUWI Decree). 4.10. The Public Prosecution Service and the police are parties to the Cooperation Agreement for Intervention Teams and represented in the LSI. However they are not one of the designated government
other bodies within the meaning of Section 64 SUWI Act. Therefore, they cannot enter into a collaborative alliance within the meaning of Section 64 SUWI Act and the SUWI Decree. They can therefore also not submit requests for the application of SyRI, nor for that purpose provide data to the Minister pursuant to Sections 65 subsection 1 and 64 subsection 4 SUWI Act. They can – however – receive risk reports at their request insofar as required in the performance of their statutory duty (see Section 65 subsection 3 SUWI Act and also see 4.13 below). Risk reports, retention obligation, removal from SyRI and confidentiality 4.11. If the Minister processes data in SyRI, the data may only be used to submit a risk report about a natural person
legal person for the purpose as described in Section 64 subsection 1 SUWI Act (Section 65 subsection 1 SUWI Act). 4.12. Section 65 subsection 2 SUWI Act defines a risk report as follows: “the provision of individualised information from the systeem risico indicatie [SyRI] containing a finding of an increased risk of unlawful use of government funds
government schemes in the area of social security and income-dependent schemes, taxes and social security fraud
non-compliance with labour laws by a natural person
legal person, and of which the risk analysis, consisting of coherently presented data from the systeem risico indicatie [SyRI], forms part.” 4.13. In individual cases, the Minister submits risk reports to the designated government
other bodies which have requested the application of SyRI and insofar as necessary for the proper performance of their statutory duty. The Minister may also submit risk reports to the Public Prosecution Service and the police at their request and insofar as necessary for the performance of their statutory duty (Section 65 subsection 3 SUWI Act). 4.14. A risk report register has been established for the purpose of this information provision to the participating government
other bodies and the Public Prosecution Service and the police, and to inform, at their request, the individuals to whom a risk report pertains. Following an investigation, the individuals involved are not informed separately about the risk reports processed in the register (Article 5a.5 SUWI Decree). 4.15. A risk report is retained by the Minister for not longer than deemed necessary for the purpose of processing risk reports and for a period of no more than two years. The designated government
other body that has received the risk report may make use of the risk report for two years and must give feedback to the Minister about the results of the risk report. That feedback must be provided within 20 months from the start of the SyRI project. Apart from this, the data processed in SyRI must in any event be removed from SyRI no later than two years following its submission into SyRI (Section 65 subsections 5, 6 and 7 SUWI Act and Articles 5a.3 and 5.a.5 SUWI Decree). 4.16. The act also provides for a duty of confidentiality for all who, pursuant to Section 65 SUWI Act, gain access to data recorded in a risk report pertaining to a natural
legal person, with analogous application of the duty of confidentiality as regards the data (Section 65, subsections 3 through to 7 SUWI Act and Articles 5a.5 through to 5a.7 SUWI Decree). Data which may be processed in SyRI 4.17. One
more of the following categories qualify for processing in SyRI (Article 5a.1 paragraph 3 SUWI Decree): work data, being data with which the work performed by a person can be established; data on administrative measures and sanctions, being data proving that an administrative fine has been imposed on a natural
legal person,
that another administrative measure has been taken; tax data, being data with which the tax obligations of a natural
legal person can be established; data on movable and immovable property, being data with which the possession and use of certain property by a natural
legal person can be established; data on grounds for exclusion from social assistance benefit
other benefits, being data proving that a person is not eligible for a benefit; trade data, being data with which the nature and activities of a legal person can be established; housing data, being data with which the actual
other place of residence
place of business of a natural
legal person can be established; identifying data, being for a natural person: name, address, city, postal address, date of birth, gender and administrative characteristics, and for a legal person: name, address, postal address, legal form, place of business and administrative characteristics; civic integration data, being data with which it can be established if an obligation to participate in a civic integration programme has been imposed on a person; compliance data, being data with which the compliance history with legislation and regulations of a natural and legal person can be established; education data, being data with which the financial support for the funding of education can be established; pension data, being data with which pension entitlements can be established; reintegration data, being exclusively the data with which it can be established if reintegration obligations have been imposed on a person and whether
not they are
are being met; debt burden data, being data with which any debts of a natural
legal person can be established; social benefit, allowances and subsidy data, being data with which the financial support of a natural
legal person can be established; permits and exemptions, being data with which it may be established for which activities a natural
legal person has requested
has obtained permission; health care insurance data, being exclusively the data with which it can be established if a person is insured for the Healthcare Insurance Act. SyRI application flowchart 4.18. In the explanatory memorandum to the SUWI Decree the procedural steps for the application of SyRI are depicted in a flowchart – see below – with references to the relevant provisions in the SyRI legislation: The request for application of SyRI, advice of LSI and duration of SyRI project 4.19. The Minister processes the data, referred to in Section 64 subsection 2 SUWI Act, if
other bodies work together on a concrete project (the SyRI project), what the concrete objective of this collaboration is, and how the collaboration is
ganised and structured. The intended start date and duration of the SyRI project must also be stated in the request (Article 5a.1 paragraph 2 under a SUWI Decree). 4.
other bodies, the intended manner of feedback on the risk reports by the Minister, and to which indicators and which risk model the request pertains (Article 5a.1 paragraph 2 under b-d SUWI Decree). 4.23. According to the explanatory memorandum to the SUWI Decree, the indicators and the risk model to be applied must be identified clearly and without this specification linking data records could lead to a “fishing expedition” and even arbitrariness. According to the Minister, this method does justice to the principle of “select before you collect”. According to the SUWI Decree, an indicator is any information that makes the presence of a particular circumstance plausible. Risk model is taken to mean a model consisting of predetermined indicators and which indicates whether there is an increased risk of unlawful use of government funds and government schemes in the area of social security and income-dependent schemes, taxes and social security fraud
non-compliance with labour laws (Article 1.
iented approach (wijkgerichte aanpak – WGA). At the hearing the State explained that it has been working on the development of a risk model for certain companies and an address-related risk model. According to the explanatory memorandum to the SUWI Decree, in due course the intention is to create the opportunity for the application of a risk model specifically designed for a particular SyRI project. 4.25. The government
other bodies participating in the collaborative alliance assess individually whether there is a need for data supply. To this end, the participants in the collaborative alliance must demonstrate that within their respective
ganisations approval has been obtained to participate in the SyRI project. Insofar as a participant in the collaborative alliance has at its disposal the necessary data within the meaning of Section 64 subsection 2 SUWI Act it must also be proved that it has been assessed beforehand which data are necessary for the risk analyses in relation to the specific purpose of the SyRI project. The participants must also have substantiated separately that potential harm to the interests of natural
legal persons to whom
which the processing of data pertains is not disproportionate and is in proportion to the purpose of the application of SyRI. Only data that are necessary for the performance of risk analyses may be issued, where a less invasive manner cannot reasonably be applied to serve the purpose of the application of SyRI. All of this must also be made clear in the request (Article 5a.1 paragraph 4 SUWI Decree). 4.26. The LSI advises the Minister about the application of SyRI in the SyRI project in question. He determines the start date of the SyRI project if the request meets the conditions. He gives notice of this in the Government Gazette (Article 5a.4 paragraph 1 SUWI Decree). A model information letter has been drafted which municipal authorities can use to inform the residents of a neighbourhood beforehand. According to this model, residents are informed which bodies cooperate in the investigation and that only these bodies have access to the residents’ data. The model also contains a notification that the team compares information already known to the various bodies. It is also stated how the verification with the help of SyRI is carried out and how a risk report is followed up. A SyRI projects ends as soon as the feedback from the government
other bodies participating in the collaborative alliance has been submitted,
when the Minister decides to terminate the project (Article 5a.4 SUWI Decree). Data processing 4.
gan that is responsible for the coordination and service provision for municipal authorities in the area of exchanging data between the UWV, the Centre for Work and Income (Centrum voor Werk en Inkomen – CWI) and municipal authorities and the use, structure and maintenance of the required electronic infrastructure, Suwinet. As processor, the IB is charged with, among other things, the collation, pseudonymisation (meaning: data encryption in a dataset so that the data are no longer directly traceable to an individual), checking the encrypted records against the risk model and decryption after the assessment. 4.29. Data processing takes place in two phases: processing (phase 1) and analysis (phase 2). In the first phase the IB collates the records and pseudonymises them. Personal names and company names, citizen service numbers and addresses are among the data that are replaced with a code (a pseudonym). The processor then applies the first step in the risk selection to the encrypted data: the source file is checked against the risk model with all indicators in an automated manner. This generates potential hits. A potential hit is a hit that indicates an increased risk of fraud. The IB also creates a key file specifying which personal name
company name, citizen service number
address belongs to which pseudonym. When based on the risk model certain natural persons, legal persons
addresses are flagged as an increased risk, they are decrypted with the key file. All data related to these increased risks, except for the key file, are then forwarded to the Minister for the second phase of risk analysis by the analysis unit of the Social Affairs and Employment Inspectorate. The IB destroys any SyRI project files still in its possession within four weeks from forwarding the data to the Minister. The destruction is laid down in an official report. 4.
legal person with an increased risk does not form the subject of a risk report, his
her data are destroyed within four weeks from completion of the analysis. The Minister destroys any remaining data following feedback from the participants in the collaborative alliance no later than two years following the start of the SyRI project. The destruction of the data is laid down in an official report. This
der for destruction does not cover data in the risk reports register, to which a retention period of two years following the registration of the risk report applies (Section 65 subsection 5 SUWI Act). Feedback on results of risk reports 4.
der law, in particular with Article 8 of the European Convention for the Protection of Human Rights and Fundamental Freedoms (hereinafter: ECHR), Article 7 and 8 of the Charter of Fundamental Rights of the European Union (hereinafter: Charter) and/
of the International Covenant on Civil and Political Rights (hereinafter: ICCPR); and/
and/
ECHR; and/
, 6, 13, 14, 22 and/
28 GDPR,
at least the corresponding sections in the Wbp Act,
alternatively, II. rule that applying the following parts of the SUWI Act and SUWI Decree is incompatible with higher-
der law, in particular with Article 8 ECHR, Article 7 and 8 Charter and/
ICCPR; and/
and/
ECHR; and/
, 6, 13, 14, 22 and/
28 GDPR,
at least the corresponding sections in the Wbp Act: a. a) the purpose clause as contained in Section 64 subsection 1 SUWI Act; and/
b) the formulation of authorities for data processing and the application of SyRI as contained in Section 64 subsection 3 and Section 64 subsection 4 SUWI Act; and/
c) the enumeration of categories of personal data as contained in Article 5a.1. paragraph 3 SUWI Decree; and/
d) the practice of confidentiality of risk models used in the application of SyRI; and/
e) the regulations pertaining to the risk reports register as contained in Article 5a.5 SUWI Decree); and/
f) the State’s substantiation of the necessity of SyRI; and/
g) the regulations under which individual administrative
gans are
dered to substantiate that the data supply in the context of a SyRI project is proportional and proportionate as contained in Article 5a.1 paragraph 4 SUWI Decree, and thereby failing to ensure that a sufficient, overarching review of these requirements takes place; and/
h) the regulations under which parties involved are only informed about the processing of their personal data in SyRI if they are the subject of a risk report, and only upon request, as contained in Article 5a.5 SUWI Decree; and/
i. i) the regulations pertaining to the monitoring of the application of SyRI, in particular the fact that the Minister is the only party monitoring the application of SyRI; III. rule that processing personal data in the context of, with the use of and/
for the benefit of the application of SyRI, in particular the mutual exchange of personal data by administrative
gans (including the Tax and Customs Administration), the issuance of personal data to the Minister (including by the Tax and Customs Administration), the provision of personal data to the IB, the processing of personal data by the IB, including profiling, the provision of personal data by the IB to the Minister, submitting risk reports and/
including report and information on such reports in the risk reports register, is unlawful because such processing constitutes a violation of Article 8 ECHR, Article 7 and 8 Charter and/
ICCPR; and/
and/
ECHR; and/
, 6, 13, 14, 22 and/
28 GDPR and/
the corresponding sections in the Wbp Act; IV. render inoperative Articles 64 and 65 SUWI Act and Chapter 5a SUWI Decree,
at least the parts thereof the court deems incompatible with higher-
der law pursuant to claim I and/
II,
at least the parts thereof the court reasonably deems incompatible with higher-
der law in the proper administration of justice,
at least declare that they have no binding effect,
declare that these must not be applied, subject to the possible imposition of a condition if required; V. rule that the State is acting contrary to the duties of confidentiality to which the Tax and Customs Administration is subject, because the Tax and Customs Administration provides personal data to other parties in collaborative alliances pursuant to Section 64 SUWI Act and to the Minister in the context of SyRI; VI.
der the State to disclose the risk models and risk indicators used in the projects G.A.LO.P. II and Capelle; VII. rule that the processing of personal data by the IB is unlawful due to the absence of a processing agreement within the meaning of Article 28 paragraph3 GDPR and/
prohibit the State to process personal data,
at least personal data of [claimant sub 6] and [claimant sub 7] in the context of, with the use of and/
for the benefit of the application of SyRI; IX. to
der the State to irreversibly destroy all personal data collected in the context of, with the use of and/
for the benefit of the application of SyRI and to furnish proof of this destruction to NJCM et al.;
dering the State to pay the costs of these proceedings, plus statutory interest from 14 days following the date of the judgment. 5.2. NJCM et al. bases its claims on unlawful acts of the State. According to NJCM et al. Sections 64 and 65 SUWI Act and Chapter 5a SUWI Decree,
at least their application, are contrary to provisions of international treaties binding on all persons. Moreover, the State (the Tax and Customs Administration) acts contrary to its statutory duties of confidentiality under national law by providing personal data pursuant to SyRI legislation to the third parties identified above by NJCM et al., and contrary to the GDPR because the IB processes data in SyRI without a processing agreement. 5.
so the State argues, prevents abuse and limits the invasion of private life caused by the application of SyRI to the minimum necessary. 6.2. The court must review whether
not the SyRI legislation is in breach of provisions of international and European law binding on all persons. In this context NJCM et al. has first and foremost argued a violation of Article 8 ECHR, Articles 7 and 8 Charter and Article 17 ICCPR and also a violation of Articles 5, 6, 13, 14, 22 and/
28 GDPR. 6.
other bodies contributes to citizens’ trust in the government, as much as preventing and combating fraud do. As NJCM et al. correctly observes, it is plausible that a ‘chilling effect’ occurs in the absence of sufficient and transparent protection of the right to respect for private life. Without trust in sufficient privacy protection, citizens will be less likely to be willing to provide data
there will be less support for doing so. 6.
not the claims of each of the claimants are admissible. The State has taken the position that the claims of Koepel van DBC-Vrije Praktijken, [claimant sub 6] and [claimant sub 7] are inadmissible. 6.10. It is not in dispute that the NJCM, Platform Bescherming Burgerrechten, Privacy First and Koepel van DBC-Vrije Praktijken are civil society interest groups within the meaning of Book 3 Section 305a of the Dutch Civil Code. According to their articles these parties to the proceedings are authorised to promote the interests of their support base at law. In the case of the NJCM that support base consists of persons
groups whose fundamental human rights have been violated. The support base of Platform Bescherming Burgerrechten consists of a network of
ganisations, groups and persons that converge on, among other things, striving for an improved safeguarding and strengthening of civil rights in the Netherlands, in particular the right to privacy and, in the case of Privacy First, all citizens of the Netherlands. The support base of Koepel van DBC-Vrije Praktijken consists of psychotherapists and psychiatrists of DTC-free practices and their patients/clients. These claimants also effectively promote the interests of this support base. 6.11. The court also holds that the legal claims in these proceedings seek to protect the interests of the support base of these four claimants. All identified civil society interest groups promote the protection of fundamental human rights in general,
the right to privacy in particular. 6.12. Since the NJCM, Platform Bescherming Burgerrechten and Privacy First promote the general interest, the court deems that the claims of these
ganisations are admissible. 6.
ders, Landelijke Cliëntenraad has an interest in the outcome of these proceedings. However, Landelijke Cliëntenraad is a consultative body without legal personality. No authorised natural persons appear in these proceedings on its behalf. Nor is it evident that there is another legal basis conferring capacity to bring legal proceedings on Landelijke Cliëntenraad. Neither the SUWI Act nor regulations based on this act show that Landelijke Cliëntenraad has a legal status comparable to that of representative bodies, such as a works council pursuant to the Works Councils Act,
a client council pursuant to the Participation (Clients of Care Institutions) Act. These are
gans that, given their tasks, have the capacity to bring legal proceedings based on specific legal grounds. The standing
ders also do not furnish evidence for this. Unlike NJCM et al. argues, the court therefore sees no basis for an analogous application of that legislation. In light of this the court declares the claims of Landelijke Cliëntenraad inadmissible. 6.15. The court also holds that the claims of [claimant sub 6] and [claimant sub 7] are inadmissible. NJCM et al. has not factually explained that in the case of these claimants there are concrete reference points from which it may follow that data pertaining to them form part of processing in SyRI. [claimant sub 6] and [claimant sub 7] are, among other things, authors and columnists and citizens of the Netherlands. They have serious concerns about the application of SyRI by the government. In these proceedings they have not furnished facts proving
making a plausible case for the existence of a possible concrete connection between their private lives, including possibly their professional activities, and data processing in SyRI. For a sufficiently concrete and personal interest within the meaning of Book 3 Section 303 Dutch Civil Code the court deems insufficient the mere possibility of an abstract review whether the SyRI legislation violates Article 8 ECHR and the circumstance that pursuant to the SyRI legislation the personal data of ‘all persons’ – insofar as they belong to one of the categories of Article 5a.1 paragraph 3 SUWI Decree – could potentially form part of a SyRI project. 6.
of its own. The decisions of the court in the operative part therefore do not pertain to any legal claim of FNV. 6.
the economic wellbeing of the country, for the prevention of disorder
crime, for the protection of health
morals,
for the protection of the rights and freedoms of others. Seeing as Article 17 ICCPR, which offers the same protection of private life as Article 8 ECHR, has no independent significance in this case, the court will not discuss it further. 6.22. Considering that the Netherlands, as a party to the ECHR, is also bound to the jurisdiction of the European Court of Human Rights (hereinafter: ECtHR; see Article 32 ECHR), the court must proceed from the ECtHR’s interpretation of Article 8 ECHR,
independently interpret this provision with the application of the interpretation criteria of the ECtHR. 6.
her private and family life, home and communications. Article 8 Charter and Article 16 TFEU stipulate that everyone has the right to protection of personal data. Article 8 Charter also contains a further explanation of this right, namely that such data must be processed fairly, for specified purposes and on the basis of the consent of the data subject
some other legitimate basis laid down by law. It also specifies that everyone has the right of access to collected data concerning them, and the right to rectification and that an independent authority monitors compliance with these rules. 6.
rectified without delay. The principle of integrity and confidentiality means that personal data are processed in a manner that ensures appropriate security of the personal data by using appropriate technical
ganisational measures. Finally, the GDPR obliges the controller is responsible to comply with the above principles. This principle is known as the principle of accountability. 6.35. The GDPR also contains provisions on profiling and a ban on automated individual decision-making, including profiling. Article 4 point 4 GDPR defines profiling as any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse
predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location
movements. Pursuant to Article 22 GDPR there is a general ban on fully automated individual decision-making, including profiling, which produces legal effects concerning the data subject
similarly significantly affects him
her. Exceptions may apply and if one of them does apply, measures must be taken to safeguard the rights and freedoms and legitimate interests of the data subject. 6.36. The guidelines of the Article 29 Data Protection Working Party state that the threshold for “significance” must be similar to that of a decision producing a legal effect for the data subject. According to the guidelines, for data processing to significantly affect someone the effects of the processing must be sufficiently great
important to be worthy of attention. The decision must have the potential to significantly affect the circumstances, behaviour
choices of the data subjects; have a prolonged
permanent impact on the data subject;
at its most extreme, lead to the exclusion
discrimination of individuals. Interrelationship ECHR and Union law and the arguments between the parties 6.
not the SyRI legislation meets the requirements of Article 8 paragraph 2 ECHR to justify that interference. 6.43. Before commencing its assessment, the court would like to note that its duty is not to establish as it sees fit the value
social significance that should be attached to the interests in question. Moreover, considering the nature of the legislative function and the position of the court, the court must show restraint during the assessment. However, this does not mean that the SyRI legislation must be assessed marginally. As has also been argued by NJCM et al., the court will not assess the amended legislation marginally, but fully against Article 8 paragraph 2 ECHR. 6.44. The court will first discuss the extent and seriousness of the interference with the right to respect for private life, which occurs
may occur when SyRI is applied. This interference is coloured by the answer to the question what precisely SyRI is. The positions of the parties on this point are widely divergent. It is also in dispute between the parties how to legally interpret the submission of a risk report, namely whether this constitutes profiling and automated individual decision-making within the meaning of the GDPR. The answer to this question also determines the extent and seriousness of the interference with private life when SyRI is applied. In summary, the court has arrived at a number of starting points for its further assessment. The court subsequently discusses whether
not SyRI legislation meets the requirement that interference must be ‘in accordance with the law’ and necessary in a democratic society in relation to the intended aims of the legislation. Extent and seriousness of the interference: what is SyRI? Dragnet, untargeted approach, data mining, ‘deep learning’, ‘big data’? 6.
complex that they cannot be processed by customary systems, and at the same time are derived from various sources. The Advisory Division noted the following in its opinion on SyRI by way of example: “Profiling as example The potential hazards in using large data sets are best illustrated with profiling to identify persons posing an increased risk. After all, this could lead to the situation where general characteristics are attributed to an individual. (…) In 2014 the Division issued an advisory opinion on the introduction of the Systeem Risico Indicatie [SyRI]. That system enabled the Ministry of Social Affairs to run different types of files containing data of citizens against each other in
der to detect taxes
social benefits fraud. This is in line with the use of deep learning and self-learning systems, which after all are focused on investigating as many links as possible without preconceived notions. The downside is that such data may constitute a serious interference with a person’s privacy. The enumeration of data is so wide that it is difficult to think of personal data that would not fall under it. The list appears not to seek limitation, but rather to create the widest possible reach.” And: “Deep learning – self-learning systems The Tax and Customs Administration is at the forefront of the application of deep learning techniques: it has huge amounts of data on persons in the Netherlands and plays a pivotal role in many collaborative alliances, such as those of the Systeem Risico Indicatie [SyRI]. In addition, some municipalities use algorithms to select possible cases of social assistance benefit fraud. The algorithm reads all sorts of data, such as dates of birth, family composition, benefit history and data of the Tax and Customs Administration, the Land Registry and the National Vehicle and Driving Licence Registration Authority. (…) The term “self-learning” is confusing and misleading: an algorithm does not know and understand reality. There are predictive algorithms which are fairly accurate in predicting the outcome of a court case. However, they do not do so on the basis of the substantive merits of the case. They can therefore not substantiate their predictions in a legally sound manner, while that is required for all legal proceedings for each individual case. (…) The reverse also applies: the human user of such a self-learning system does not understand why the system concludes that there is a link. An administrative
gan that partially bases its actions on such a system is unable to properly justify its actions and to properly substantiate its decisions.” 6.47. In its defence, the State has argued that when using SyRI, only data from existing data sets of designated government
other bodies are compared in
der to identify discrepancies with a view to checking the entitlements of the data subject. With reference to statements made by the Minister the State argues that files of existing, factual data are compared. The factual data are compared to each other with the aid of a simple decision tree. 6.48. Responding to reliance of NJCM et al. on the aforementioned independent advisory opinion of the Advisory Division, the State has referred to the reaction of the cabinet to this opinion. The State Secretary for the Interior and Kingdom Relations stated the following in that reaction: “The Division has also described risks regarding the digital linking of data in various contexts. One example of data linking is SyRI (Systeem Risico Indicatie). Contrary to what the Division assumes SyRI is not a deep learning application nor is it a self-learning system. SyRI is emphatically not a tool to predict whether
not an individual could commit an offence. SyRI compares files containing existing, factual data of the parties designated under Section 64 of the Work and Income (Implementation
ganisation Structure) Act (SUWI), such as the UWV, the SVB, the Municipal Executives, the Tax and Customs Administration and the Social Affairs and Employment Inspectorate in
der to assess whether there are discrepancies in the data. If the mutual comparison following assessment against the risk model shows a discrepancy, this discrepancy must be examined by one
more of said parties before a decision may be taken that may have legal consequences for the data subject.” 6.49. The court finds that it is unable to assess the correctness of the position of the State of the precise nature of SyRI because the State has not disclosed the risk model and the indicators of which the risk model is composed
may be composed. In these proceedings the State has also not provided the court with objectively verifiable information to enable the court to assess the viewpoint of the State on the nature of SyRI. The reason the State gives for this is that citizens could then adjust their conduct accordingly. This is a deliberate choice of the State. That choice also coincides with the starting point of the legislator regarding the provision of information on SyRI. The SyRI legislation does not show how the decision model of SyRI functions and which indicators are
can be used in a SyRI project (see 4.23 above for the terms decision model and indicators), i.e. which factual data make
can make the presence of a certain situation plausible. 6.
not the processing of data in SyRI should be qualified as a form of ‘big data’. 6.
have been used for that processing. The SyRI legislation also does not provide for an obligation to notify the data subjects individually, as appropriate, that a risk report has been submitted. There is only a statutory obligation to announce the start of a SyRI project beforehand by way of publication in the Government Gazette and after the processing access to the register of risk reports upon request. The model letter which can be used in practice – as was the case in the Rotterdam Bloemhof & Hillesluis project – is not founded on a statutory obligation to inform the data subjects ‘door-to-door’, while the court is unable to find based on the available information whether municipalities have a standard practice in the implementation of the act. Data subjects are also not informed automatically afterwards. This only occurs if there is a control and investigation in response to a risk report. This does not happen as a matter of course. Extent and seriousness of the interference: profiling and automated individual decision-making? 6.55. Now the court arrives at the assessment, in view of the debate between the parties on the extent to which submitting a risk report affects private life, whether
not profiling and automated individual decision-making occur when SyRI is applied. 6.
at least a decision that affects the data subjects significantly in another way, and that this decision is taken on the basis of automated individual decision-making within the meaning of Article 22 GDPR, which is prohibited. According to NJCM et al. there is no meaningful human intervention prior to the submission of a risk report; the mere removal of ‘false positives’ cannot qualify as such nor can the assessment of the participating parties after receipt of a risk report. 6.
criminal law – a risk report does have a similarly significant effect on the private life of the person to whom the risk report pertains. The court derives that conclusion partially from the guidelines of the Article 29 Data Protection Working Party (see 6.36). A risk report can be stored for two years and can be used by the participants in the SyRI project in question for a maximum of 20 months. In addition, the Public Prosecution Service and the police may be notified of the risk report upon request. The fact that a risk report does not necessarily always lead to further investigation,
to an administrative
criminal-law sanction, and may also not be used as the sole basis for an enforcement decision does not alter the significant effect on the private life of the data subject. 6.60. The court does not give an opinion on whether the exact definition of automated individual decision-making in the GDPR and, insofar as this is the case, one
more of the exceptions to the prohibition in the GDPR have been met. That is irrelevant in the context of the review by the court whether the SyRI legislation meets the requirements of Article 8 ECHR. However, the court does consider the aforementioned significant effect of the submission of a risk report and its inclusion in the risk reports register on the private life of the data subject a significant factor in its assessment whether the SyRI legislation meets the requirements of Article 8 paragraph 2 ECHR. This effect, too, determines in part the extent to which the SyRI legislation interferes with the right to respect for private life. The court takes into account that part of the right to protection of personal data is the right of everyone to be reasonably able to follow up on their personal data and be informed about the processing of their data. Although the start of a SyRI project is published in the Government Gazette, a risk report may be retained in the register for two years, without this being known to the data subject. Abstract 6.61. In summary, the court will take the following starting points into consideration in its further assessment. These starting points are relevant to the extent and seriousness of the interference with the private life of the data subjects by the SyRI legislation and are therefore included in the court’s review whether this interference is permissible under Article 8 paragraph 2 ECHR. 6.62. The linking of files when SyRI is applied relates to the processing of the data categories as exhaustively listed in the SUWI Decree. The data can be found in files with factual data (personal
other data) which are available to the statutorily designated government
other bodies on the basis of their statutory duty. It involves structured data processing based on existing, available files. Depending on the SyRI project, there may be a set of a large amount of data derived from various sources. During the data processing a risk model is used, which consists of predetermined risk indicators and which gives an indication of whether there is an increased risk of unlawful use of government funds and government schemes in the area of social security and income-dependent schemes, taxes and social security fraud
non-compliance with labour laws. 6.63. There currently are no indications of ‘deep learning’
data mining
the development of risk profiles in the implementation of the SyRI legislation. However, the SyRI legislation does provide scope for the development and application of a risk model using ‘deep learning’ and data mining, and for the development of risk profiles. 6.
even judge-made law. “Some basis in domestic law” is sufficient. The legal basis on which the interference is predicated must, however, be sufficiently accessible and foreseeable. This means that the legal basis must be sufficiently clear so as to enable an individual to regulate their conduct accordingly. 6.67. In support of its argument that the SyRI legislation is unlawful, NJCM et al. mainly relies on the case law of the ECtHR in matters pertaining to untargeted bulk interception (mass surveillance)
targeted interception of data in a criminal-law
national security context. As follows from the foregoing, this is not the case with the application of SyRI. Therefore, this case law cannot be considered as a one-to-one guidance for the court’s assessment. 6.68. The case of S. and Marper versus the United Kingdom revolved around the lawfulness of the British Data Protection Act
unlawfulness of the SyRI legislation. 6.69. The judgment of the ECtHR in that case proves that domestic law must afford adequate protection against arbitrariness and indicate with sufficient clarity the scope of discretion conferred on the competent authorities and the manner of its exercise in
der to meet the requirements of accessibility and foreseeability. According to the ECtHR, the level of precision required of domestic legislation depends to a considerable degree on: “the content of the instrument in question, the field it is designed to cover and the number and status of those to whom it is addressed” The ECtHR then considers as follows: “It reiterates that it is as essential, in this context, as in telephone tapping, secret surveillance and covert intelligence-gathering, to have clear, detailed rules governing the scope and application of measures, as well as minimum safeguards concerning, inter alia, duration, storage, usage, access of third parties, procedures for preserving the integrity and confidentiality of data and procedures for its destruction, thus providing sufficient guarantees against the risk of abuse and arbitrariness.” 6.
in other words, whether the interference meets a pressing social need. NJCM et al. argues that this is not the case, in support of which it considers relevant that there is a very serious interference in the private lives of citizens. NJCM et al. also argues that the State has failed to show that it is necessary to deploy an instrument as severe as SyRI to maintain the social security system. It points out that the wider social attitude towards SyRI is negative,
at least reserved and that the SyRI projects have not borne fruit and are therefore not effective as a means for combating fraud. 6.
der to meet the requirement of a ‘pressing social need’, contrary to what is suggested by NJCM et al. In light of the purposes the legislation serves, SyRI is not an unsuitable instrument
an a priori disproportionate instrument. 6.78. In light of the foregoing, the court is of the opinion that the choice of the legislator to create a legal basis for data processing for the benefit of a collaborative alliance aimed at the purposes as formulated in Section 64 SUWI Act and the choice of the legislator for data processing in an instrument such as SyRI therefore meet the general necessity requirement of Article 8 ECHR. The latter concerns the technical infrastructure chosen to link,
have the ability to link, data files in a secured environment in
der to carry out analyses, so that risk reports can be generated. 6.79. But this does not mean that the functioning of the instrument of choice,
the instrument itself, in this case SyRI, and the associated procedures and safeguards created for its application by the legislator in the SyRI legislation, sufficiently respects privacy in light of Article 8 paragraph 2 ECHR. The SyRI legislation does not pass this concrete test, as the court will explain below. Necessary in a democratic society: proportionality and subsidiarity 6.
other bodies, exhaustively lists the number of data categories that qualifies for data processing, and obliges the participating designated government
other bodies to verify the necessity of a SyRI project and the data to be processed in that project. Moreover, the IB has been designated as processor, which pseudonymises said data, while the separate analysis unit of the Social Affairs and Employment Inspectorate carries out the analyses. The SyRI legislation also contains retention periods and limitations as regards access to and use of risk reports as well as obligations to maintain confidentiality and perform evaluations. 6.
der to exercise supervision more effectively. Partly due to the speed of said development, the right to data protection is becoming increasingly important. Collecting and analysing data with the help of those new technologies can interfere extensively with the private lives of those to whom the data pertain. Therefore the legislator bears a special responsibility when applying an instrument such as SyRI: for a data subject it is difficult to gauge the effect of the instrument on their private life while the ECHR requires that the legislation that provides a basis for such an interference provides sufficient safeguards to protect against abuse and arbitrariness. 6.
an allowance and who, according to the municipal personal records database (Gemeentelijke Basisadministratie – GBA) are registered at different addresses while in fact they are living at the same address. An example of undeclared assets is someone whose bank balance has grown exponentially in one year. Other examples include a person who has several lock-up garages in a particular neighbourhood and has multiple vehicles registered in his name in a short period of time,
a recipient of social assistance under the WWB who has registered a bank account number with the Tax and Customs Administration with assets, while this is not known to the Municipal Social Services.” 6.88. The State has provided several other examples that could indicate discrepancies, including the example of a person who receives social assistance as a single householder, healthcare allowance for married couples and where multiple occupants of the same address receive housing allowance for a different address, while only one occupant is eligible to receive housing allowance at one address. The State has failed to explain on which objectively verifiable information these examples are based. 6.89. What is more, the SyRI legislation does not provide information on the functioning of the risk model, for instance the type of algorithms used in the model, nor does it provide information on the risk analysis method as applied by the Social Affairs and Employment Inspectorate. In these proceedings, the State has explained in more detail that the risk model consists of
fraud. However, the SyRI legislation does not afford insight into the validation of the risk model and the verification of the risk indicators; the court consequently lacks such insight in these proceedings. 6.90. The foregoing results in the inability to verify how the simple decision tree, to which the State refers, is generated and of which steps it is comprised. Consequently, it is difficult to comprehend how a data subject could be able to defend themselves against the fact that a risk report has been submitted about him
her. It is just as difficult to see how a data subject whose data were processed in SyRI but which did not result in a risk report, can be aware that their data were processed on correct grounds. The fact that in the latter situation the data did not result in a risk report and furthermore must be destroyed no later than four weeks following the analysis does not alter the requirement of transparency in respect of that processing. The right to respect for private life also means that a data subject must reasonably be able to track their personal data. 6.91. The importance of transparency, in the interest of verifiability, is also compelling, because using the risk model and the analysis that is carried out in that context carries the risk that discriminatory effects – unintentional
otherwise – occur. The Advisory Division stated in its opinion – see 6.46 – that analysing large data sets, with
without deep learning/self-learning systems is undeniably useful, but may also yield undesirable results, including unjustified exclusion
discrimination. The Minister for Legal Protection acknowledged in his letter on Information and Communications (ICT) of 8 October 2019 to the House of Representatives that on account of the risk of discriminatory effects, at least in profiling-based data analyses, certain characteristics may be incorrectly attributed to people (false positive),
the other way around, characteristics may incorrectly not be attributed (false negative). 6.
otherwise contrary to Article 8 paragraph 2 ECHR in all cases. However, given the large amounts of data that qualify for processing in SyRI, including special personal data, and the circumstance that risk profiles are used, there is in fact a risk that SyRI inadvertently creates links based on bias, such as a lower socio-economic status
an immigration background, as NJCM et al. argue. 6.94. Based on the SyRI legislation, it cannot be assessed whether this risk is sufficiently neutralised due to the absence of a verifiable insight into the risk indicators and the risk model as well as the functioning of the risk model, including the analysis method applied by the Social Affairs and Employment Inspectorate. The circumstance that the process of data processing consists of two phases and that the analysis unit of the Social Affairs and Employment Inspectorate, following a link of the files by the IB, assesses the decrypted data on their worthiness of investigation, which includes a human check for false positives and false negatives, is deemed insufficient by the court. After all, the manner in which the definitive risk selection takes place is not public. Nor are the data subjects informed about how the definitive risk selection is effectuated
about the associated conclusion whether
not a risk report is submitted, while the SyRI legislation only provides for a general monitoring by the AP afterwards. 6.95. In view of the foregoing, the court is of the opinion that the SyRI legislation contains insufficient safeguards to protect the right to respect for private life in relation to the risk indicators and the risk model which can be used in a concrete SyRI project. Without insight into the risk indicators and the risk model,
at least without further legal safeguards to compensate for this lack of insight, the SyRI legislation provides insufficient points of reference for the conclusion that by using SyRI the interference with the right to respect for private life is always proportionate and therefore necessary, as required by Article 8 paragraph 2 ECHR, in light of its purpose of combating abuse and fraud. 6.
other bodies and there is no comprehensive review beforehand by an independent third party. The test of necessity which the designated government
other bodies must perform is relates to both the principle of purpose limitation and the principle of data minimisation. 6.
other bodies participating in the collaborative alliance. That test of necessity can and must only be carried out with respect to the data sets which the relevant government
other body has at its disposal. The SyRI legislation does not provide for a comprehensive review beforehand nor for a review by an independent third party, that is to say, a review prior to the data processing in SyRI by the Minister at the request of a collaborative alliance for the purpose of assessing whether
not the interference with private life is necessary, proportionate and subsidiary in light of all the files that are linked in a project considering the specific purpose of that project. 6.
gan. Its advice is non-binding and lacks an explicit legal basis. What is more, the LSI is comprised of representatives of
gans which also have an interest in combating and preventing abuse and fraud in the areas specified in Section 64 subsection 1 SUWI Act. Furthermore, the Social Affairs and Employment Inspectorate is not only represented in the LSI, but can itself also be a participant in a collaborative alliance for the benefit of a SyRI project, and is charged with analysing data for the definitive risk selection based on which a risk report is submitted. The court is unable to assess if and to what extent the internal functional division between the various units of the Social Affairs and Employment Inspectorate (the investigation unit, the analysis unit and possibly other units) is sufficiently safeguarded. The State has failed to provide further explanation about this in its response to the defence of NJCM et al. 6.
all relevant processing activities are regulated by law, and a DPIA has already been carried out in that context, unless the Member States deem it necessary to carry out such an assessment prior to the processing. The State has pointed out that since the entry into force of the SyRI legislation a new data protection model of the civil service is being used, geared towards the privacy rules of the GDPR. 6.
more specific provisions of the GDPR on which NJCM et al. relies and whether the SyRI legislation is in violation of Articles 6 and 13 ECHR. The court therefore leaves undiscussed the other arguments and defences of the parties. The claims of NJCM et al. 6.
der claimed under claim VI to disclose the risk models used in the specific SyRI project, an administrative-law court procedure with sufficient safeguards is available. Nor does it follow from the assessment of the court regarding the unlawfulness of the SyRI legislation, insofar as it pertains to the use of SyRI, that the State is under the obligation to disclose this model to the claimants. 6.
ganisation whose claims have been declared admissible in these proceedings to destroy all personal data collected in the context of, with the use of
for the benefit of the application of SyRI and to furnish proof of this destruction to them. Nor is this claim suitable for assessment in the context of a class action, considering its close connection with the individual circumstances of the support base of the collective interest
ganisations. The costs of the proceedings 6.118. As the more unsuccessful party the State will be
dered to pay the costs of the proceedings on the part of NJCM, Platform voor Burgerrechten, Privacy First and Koepel van DBC-Vrije Praktijken and FNV. The costs on the part of these parties to date are estimated at: summons € 98.01 court fees € 1,252.00 lawyer’s fees € 1,900.50 (3.5 points x rate II of € 543) Total € 3,250.51 6.119. The claimed statutory interest on the costs of the proceedings, which is undisputed, is allowable. 7The decision The court 7.1. declares that the claims of Landelijke Cliëntenraad, [claimant sub 6] and [claiman
AI-uitleg op basis van de officiële wettekst. Indicatief, vervangt geen juridisch advies.