---
title: "Dutch childcare benefits: nationality as a risk indicator"
description: "The Dutch tax administration used applicants' nationality as a risk indicator for childcare benefits; the data protection authority fined it EUR 2.75 million."
canonical: https://aigovernanceengineer.com/cases/dutch-childcare-benefits
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-26
---

# Dutch childcare benefits: nationality as a risk indicator

> The Dutch tax administration used applicants' nationality as a risk indicator for childcare benefits; the data protection authority fined it EUR 2.75 million.

- Year: 2021
- Jurisdiction: Netherlands
- Sector: Public sector: social benefits
- Evidence base: Primary sources
- Incident record: [AIID 101](https://incidentdatabase.ai/cite/101/)
- Harm: [Unequal treatment of a group by public risk profiling](https://aigovernanceengineer.com/resources/harms#harm-group-risk-profiling) · [Discrimination in consequential decisions](https://aigovernanceengineer.com/resources/harms#harm-discriminatory-decisions) · [Regulatory enforcement and forced suspension](https://aigovernanceengineer.com/resources/harms#harm-regulatory-enforcement)

## In short

The Dutch Tax and Customs Administration used the nationality of childcare-benefit applicants as an indicator in a system that automatically designated certain applications as risky. On 7 Dec 2021 the Dutch data protection authority fined it EUR 2.75 million, finding the processing unlawful and discriminatory under the GDPR. The harm is unequal treatment of a group by public risk profiling: the AI Incident Database records families wrongfully accused of tax fraud. The failure mode is a protected characteristic used as a model input, with no check on whether a feature was lawful for the purpose. A Policy Card listing the permitted inputs, an Eval Gate in CI that blocks prohibited attributes or diverging flag rates, and FRIA-as-Code would have caught it. The case touches GDPR Art. 5(1)(a) and Art. 35, and the EU AI Act, which lists benefit-eligibility systems of public authorities as high-risk (Annex III point 5(a)) and requires a fundamental-rights impact assessment from public deployers (Art. 27).

## What happened

The Dutch Tax and Customs Administration processed the nationality, and the dual nationality, of childcare-benefit applicants for years. It used Dutch or non-Dutch nationality as an indicator in a system that automatically designated certain applications as risky, and processed nationality to combat organised fraud although that data was not necessary for the purpose [1].

On 7 Dec 2021 the Dutch data protection authority (AP) fined the administration EUR 2.75 million, finding the processing unlawful and discriminatory, and therefore improper under the GDPR. It said the dual-nationality data should have been deleted in January 2014, and that nationality had not been used to determine risk since October 2018 [1].

Amnesty International's analysis describes an algorithmic system that built risk profiles of applicants to detect inaccurate and potentially fraudulent applications early, with nationality among the risk factors [2]. The AI Incident Database records the case as families wrongfully accused of tax fraud by a discriminatory algorithm [3].

## Failure mode

A protected characteristic was a model input. Nothing between the data and the decision checked whether a feature was lawful to use for this purpose, so a risk flag could rest on nationality.

Retention failed as well: data that should have been deleted in 2014 was still within reach years later [1]. A risk model can use every attribute it can reach, so deletion is a control on the model too.

## Which control would have caught it

A feature policy enforced in the pipeline catches this before the first score: a policy card listing the inputs permitted for the purpose, and an eval gate that fails the build when a prohibited attribute, or a close proxy for one, enters the feature set, or when flag rates diverge across groups. The fundamental-rights impact assessment is where the purpose, the affected groups and the permitted features are decided and signed.

Patterns: [Policy Card](https://aigovernanceengineer.com/bok/patterns#pattern-policy-card) · [Eval Gate in CI](https://aigovernanceengineer.com/bok/patterns#pattern-eval-gate-in-ci) · [FRIA-as-Code](https://aigovernanceengineer.com/bok/patterns#pattern-fria-as-code)

## The evidence that would have existed

What an auditor could have read, and the stack layer that produces it.

- Layer 1 (Govern-as-Code): Policy card for the risk model listing the permitted input features, with nationality marked prohibited for this purpose
- Layer 1 (Govern-as-Code): Signed FRIA naming the affected groups, the purpose limitation and the outcome metric to monitor
- Layer 3 (Evals & Red Teaming as Evidence): Eval-gate run log in which the feature-policy check and the disaggregated flag-rate test pass or block the release
- Layer 5 (Assurance & Continuous Compliance): Retention-job log showing the dual-nationality data deleted on schedule

## Obligations it touches today

As of 2026-09-24. Mappings are illustrative, not a claim of conformity.

- GDPR Art. 5(1)(a), Art. 35: The AP's finding rests on lawfulness and fairness [1]; a data protection impact assessment is the GDPR artefact that should have surfaced the nationality feature [4].
- EU AI Act Annex III, point 5(a): Systems used by or for public authorities to evaluate eligibility for essential public assistance benefits are high-risk [5]; after the AI Omnibus, Annex III obligations apply from 2 Dec 2027 (as of 2026-09-24) [6].
- EU AI Act [Art. 27](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art27): A public body deploying such a system carries out a fundamental-rights impact assessment before first use [7].
- EU AI Act [Art. 5(1)(c)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5): Social scoring that leads to unjustified or disproportionate detrimental treatment is prohibited [8]. Whether a given risk model meets those conditions is a legal judgement, not an engineering one.

## How to read this case

Each case is an illustrative engineering analysis of public records, not a legal determination, not a finding of fact beyond what the cited sources state, and not a claim of conformity. Mappings to obligations are illustrative.

## Sources

[1] Tax Administration fined for discriminatory and unlawful data processing (EUR 2.75 million fine; nationality used as a risk indicator). Autoriteit Persoonsgegevens (Dutch Data Protection Authority). 2021-12-07. https://www.autoriteitpersoonsgegevens.nl/en/current/tax-administration-fined-for-discriminatory-and-unlawful-data-processing (verified: primary)
[2] Xenophobic machines: discrimination through unregulated use of algorithms in the Dutch childcare benefits scandal (EUR 35/4686/2021). Amnesty International. 2021-10-25. https://www.amnesty.org/en/documents/eur35/4686/2021/en/ (verified: primary)
[3] AI Incident Database, Incident 101: Dutch Families Wrongfully Accused of Tax Fraud Due to Discriminatory Algorithm. Responsible AI Collaborative. 2026. https://incidentdatabase.ai/cite/101/ (verified: primary)
[4] Regulation (EU) 2016/679 (General Data Protection Regulation) (Art. 5 principles, Art. 6 lawfulness, Art. 8 child's consent, Art. 9 special categories, Arts. 12-15 transparency and access, Art. 22 automated individual decision-making, Art. 33 breach notification, Art. 35 DPIA). Official Journal of the European Union (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)
[5] EU AI Act Annex III (high-risk uses; point 3(b) evaluating learning outcomes, 4(a) recruitment and selection, 5(a) eligibility for essential public assistance benefits and services). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#anx_III (verified: primary)
[6] AI Omnibus enters into force (Reg. (EU) 2026/1744, in force 2026-07-27; Annex III high-risk obligations move to 2 Dec 2027). European Commission. 2026-07-27. https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force (verified: primary)
[7] EU AI Act Art. 27 (FRIA before first use by deployers that are bodies governed by public law or private entities providing public services, and by deployers of Annex III point 5(b) and (c) systems; Art. 27(4) cross-reference to a GDPR Art. 35 DPIA). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_27 (verified: primary)
[8] EU AI Act Art. 5 (prohibited AI practices; 5(1)(c) social scoring leading to unjustified or disproportionate detrimental treatment; 5(1)(e) facial recognition databases built by untargeted scraping). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_5 (verified: primary)
