Digital Decisions, Tangible Consequences: Tech Companies’ Responsibility for Harm

Categories:

Date:

Sep 28, 2026

Date:

Sep 28, 2026

Abstract

A tech company’s power does not always take the form of a direct instruction. It may be built into a rule that determines who sees a housing ad, software that rejects a job applicant, a rating that reduces a driver’s chances of receiving rides, or a ranking system that amplifies incitement. In each case, the affected person sees the outcome but may not see the series of decisions that led to it. They may also be unable to tell whether the outcome arose from the system’s design, a client’s use of it, or the work of a supplier involved in delivering the service.

Yet the company retains control over crucial elements of the system that shape that outcome, from the purpose for which it was designed, the data it uses, its performance measures, the contracts that allocate authority, and the records needed to understand what happened. This paper begins with the gap between those who can shape a decision and those who bear its consequences.

The paper proposes a practical standard for accountability. A company’s responsibility to respect human rights grows with its control over design, data, and business relationships; its ability to foresee or limit harm; and its exclusive access to the evidence affected people need to establish the decision’s impact and challenge it.

This standard does not make every harm associated with a product an automatic source of legal liability, or treat a content platform, a work app, and a spyware supplier as though they were the same. It does, however, clarify what should be expected of a company in preventing harm, disclosing information, using its influence, preserving evidence, and providing remedy. It also prevents a company from obscuring the control it exercises by describing itself as an intermediary or supplier, or by attributing decisions to an algorithm.

Methodology and Scope

This paper draws on a review of business and human rights standards, court and regulatory decisions and settlements, independent assessments, human rights reports, and legislation and regulations. Its case examples are used to examine specific ways in which harm occurs, rather than to measure how widespread harm is across an entire sector. Accordingly, the paper distinguishes between facts established by a court, allegations made in a complaint, findings reached by a human rights organization, and assessments conducted at a company’s request. Its methodology does not include field research or interviews with affected people.

The paper focuses on companies that design or operate digital services capable of ranking content, distributing opportunities, managing work, enabling surveillance, or controlling access to a service with tangible consequences. It does not examine every aspect of the tech sector’s responsibility, such as device manufacturing, mineral extraction, or the environmental impact of data centers, except where these issues bear on the analysis of the product life cycle and value chain.

1. Decisions Hidden from Those They Affect

In 2023, the U.S. Equal Employment Opportunity Commission (EEOC) settled a lawsuit against iTutorGroup for $365,000. The EEOC alleged that the company’s hiring software automatically rejected women aged 55 or older and men aged 60 or older. The case involved more than 200 qualified applicants.

The settlement provided for compensation, training, an anti-discrimination policy, and continued monitoring of the company’s compliance. The hiring settlement is particularly instructive because the rule at issue was clear: applicants encountered software applying a criterion built into the system, rather than a manager openly telling them they had been rejected because of their age.

A rejected applicant often does not know whether anyone read their application. Nor do they have a record of the variables the system used, the version applied to their application, or why they met its rejection threshold. Even when an applicant suspects discrimination, the evidence remains with the organization that designed or purchased the tool. This is more than a transparency problem. Control over the records determines who can turn a sense of unfair treatment into an examinable claim, and who is left with a generic automated message that offers no way to understand or correct the decision.

The iTutorGroup case illustrates a pattern this paper examines in other settings: a person may receive an outcome affecting their rights or opportunities without being able to see how the system was designed or access the records explaining the decision. This is particularly apparent in platform work. The number of tasks available to a worker may fall without the worker knowing the score the system assigned them or how declining a particular task affected their priority for future work.

This imbalance in access to information extends beyond work. On a social media platform, a post may be removed or its reach reduced without its author knowing which rule was applied, how much weight an automated classifier carried in the decision, or whether a human reviewed it.

The rights at stake differ across work, expression, and privacy, but the pattern of power is similar. The organization operating the system holds its design and the records needed to understand its decisions, while the individual bears their consequences without the information needed to explain or challenge them.

Accountability therefore begins by identifying the organizational decisions behind the system: the purpose it was designed to serve; the data and thresholds it uses; the benefits the company gains from speed or lower costs; its ability to foresee and prevent harm; and its control over the evidence needed to understand and challenge a decision. This analysis focuses on those who designed the system and set the terms of its operation, rather than treating the technology as an independent decision-maker.

2. Responsibility Proportionate to Power

The UN Guiding Principles on Business and Human Rights distinguish between three levels of responsibility that are often conflated in public debate. States have the primary duty to respect, protect, and fulfill human rights. This includes adopting laws, exercising oversight, and ensuring access to courts. Companies have an independent responsibility to respect human rights wherever they operate, even where local law is weak or selectively enforced. Legal liability, whether it involves compensation, penalties, or the invalidity of a contract, depends on the applicable law, the facts of the case, and the decision of a competent authority. Under the Guiding Principles, the absence of a local prohibition does not justify a company’s harmful conduct.

Recognizing a company’s independent responsibility to respect rights does not, by itself, establish what is expected of it when a client or supplier is also involved in the harm. The OECD Guidelines therefore distinguish between causing an adverse impact, contributing to it, and being directly linked to it through a product, service, or business relationship.

If a company causes or contributes to harm, it is expected to stop the conduct, prevent its recurrence, and participate in remediation. If it is directly linked to harm caused by a client or supplier, the focus is on using its leverage. This may involve changing a contract, imposing restrictions, requesting information, suspending support, or ending the relationship when the harm is severe and less restrictive measures have failed.

A company’s relationship to the harm may shift from direct linkage to contribution if it continues to provide support after obtaining credible information about foreseeable misuse, despite having practical means to prevent it.

In the tech sector, responsibility cannot be assigned solely to the party that took the final action when another company designed the system, set the terms of its operation, and retained significant influence over its outcomes. On an advertising platform, for example, the company may do more than host an ad written by a client: it may also design the algorithm that determines who receives it.

The same pattern appears in app-based work. A worker may have a contract with a local entity, while a parent company sets the rules for ratings, task allocation, speed, and account suspension that govern the worker’s day-to-day experience. The distance between the direct user and the technology supplier is greater still with spyware. A government client decides whom to target, but the supplier can choose its clients, set licensing terms, provide updates, and, in some cases, suspend or terminate the service.

Assessing a company’s responsibility therefore requires examining its control over the system and its relationship to the harm at each stage, rather than looking only at who took the final action. This assessment should not begin only after harm occurs. To identify where it may cause, contribute to, or be directly linked to harm, a company needs a process that begins before a decision is made and continues throughout the system’s use. The UN Human Rights Office’s B-Tech Project offers a practical way to apply this framework to tech companies through human rights due diligence: an ongoing process for identifying, preventing, and addressing their impacts on human rights.

That process begins with defining the need for a product and its permitted purpose. It extends through data collection, testing, launch, marketing, client selection, and supplier contracting, and continues after a sale. Updates, market changes, political crises, and user behavior can turn a product whose risks were considered acceptable at launch into a source of severe harm. Companies therefore need an ongoing system to identify and track impacts, communicate how they are addressed, and make changes when necessary.

Human rights due diligence sets priorities according to risks to people, rather than to the company’s financial or reputational risks. A market may generate little revenue yet pose grave risks to journalists or a linguistic minority. A system may have a low average error rate, yet a single error can lead to detention, expose a source, or permanently deny someone an opportunity. Severity is assessed by the scale and scope of the impact and the difficulty of remedy. Safety resources should therefore not depend solely on market size. Nor should a company accept an apparently reasonable error rate without examining who bears the consequences of those errors and whether they can be remedied.

The paper’s standard for assessing a company’s responsibility for harm can be summarized in five connected factors: how much control it has over a rule, price, ranking, or suspension; how foreseeable the harm is in the relevant sector and context; how much leverage it has over a client, supplier, or user; who holds the data needed to measure and establish the impact; and whether the remedy can remove the source of harm, rather than correcting one person’s case while leaving the system in place. Together, these factors help establish the extent of the company’s power, its relationship to the harm, and what it could have done to prevent or address it.

A company’s power is shaped not only by what it can do technically or contractually, but also by the incentives guiding its internal decisions. Its revenue model influences the measures by which product and sales teams judge success. An advertising platform, for example, benefits from increased use and engagement; a work platform’s revenue is tied to the volume of transactions or tasks; and a surveillance technology company depends on securing high-value client contracts. These incentives affect practical decisions about launch speed, investment in safety, contract terms, and the resources devoted to testing for and addressing harm.

A technical decision can affect several rights at once because the same system may determine access to income, opportunities, or expression. Assessing a company’s responsibility therefore requires considering civil and political rights alongside economic and social rights. Suspending an account may restrict a person’s ability to express themselves and, if they rely on the platform for work, cut off their income.

An advertising system may use personal data to select an audience and then influence who has access to work or housing opportunities. Monitoring a worker affects their privacy and their working relationship when the data is used to assess performance, set pay, or organize working time. People experience these effects together, in ways shaped by their social, economic, and political circumstances. An assessment of corporate responsibility is incomplete if it considers each right in isolation from the wider relationship governed by the system.

3. How Design Shapes Access to Housing and Work

In 2022, the U.S. Department of Justice sued Meta over how housing ads were delivered to Facebook users. The lawsuit examined both the categories advertisers could select when defining their audience and Meta’s algorithm, which determined who actually received an ad after it was published. The ad delivery system relied in part on characteristics protected under the Fair Housing Act, creating a gap between the people eligible to see an ad and those who actually saw it.

The case ended in a court settlement under which Meta stopped using its “Special Ad Audience” tool for housing ads and agreed to develop a new system to reduce disparities in ad delivery, subject to independent review. The case shows that unequal access to housing opportunities can arise from the delivery of an ad itself, even when an advertiser does not explicitly ask to exclude a legally protected group. Exclusion can occur before a person has any chance to apply for housing. If an ad delivery algorithm shows an opportunity to some users but not others, those who never see it may lose the chance to apply without knowing they were excluded.

This makes disparities harder to detect and establish than when someone applies and receives a rejection: a person who never saw the ad has no decision to challenge or explanation to examine. In systems of this kind, a platform’s responsibility therefore extends to how it distributes opportunities, as well as to preventing advertisers from selecting explicitly discriminatory criteria.

The case also showed that an ad delivery algorithm can produce disparities between the groups that receive housing opportunities. Observing a disparity, however, is not enough on its own to establish unlawful discrimination. Ad delivery may be influenced by past usage patterns, data that reflect existing social inequalities, or variables indirectly associated with characteristics protected by law.

Companies therefore need to measure how a system performs across different groups, identify the factors behind differences in access, and compare the results with those that a delivery method less likely to produce such disparities might achieve. This testing matters especially when a system affects essential opportunities such as housing or work. If a company continues to use the system without knowing which groups its delivery methods disadvantage, discrimination becomes harder to detect and correct.

The iTutorGroup case presents a clearer causal relationship. According to the official complaint, which ended in a settlement, the harm arose from an automated rule directly tied to age, rather than complex correlations in historical data. The case illustrates that automation remains shaped by the human decisions that set its criteria. The software applied a criterion chosen by people and adopted by a company as part of its hiring process; it did not independently assess the applicants. The remedy therefore went beyond changing the code to include financial relief, policy changes, training, and oversight.

Together, the Meta and iTutorGroup cases show that discrimination in automated systems can arise in different ways. At iTutorGroup, exclusion was directly tied to an applicant’s age through an explicit rule in the hiring system. In ad delivery systems, disparities may emerge without the direct use of a protected characteristic when an algorithm relies on data associated with that characteristic to varying degrees. A person’s neighborhood, university, purchasing habits, or social connections may function as proxies for characteristics protected by law, even when those characteristics are not included in the model.

A system’s overall accuracy rate is therefore an insufficient measure of its impact. It may perform well on average, while errors that exclude people are concentrated in a single group. An error may also have particularly serious consequences if a person loses a work or housing opportunity before they can challenge and correct the decision.

4. Work Behind the App and the Contract

Digital labor platforms often describe themselves as intermediaries connecting independent workers with clients. That contractual description alone does not establish who controls prices, allocates tasks, imposes penalties, or suspends accounts. In a case brought by Uber drivers, for example, the UK Supreme Court examined how the relationship operated in practice. Its judgment focused on Uber’s control over fares, contractual terms, trip allocation, ratings, and communication with passengers.

The Court held that the drivers in the case had worker status. It also found, within the scope of the case, that working time included periods when a driver was in the relevant area, had the app switched on, and was ready and willing to accept trips.

The judgment matters because it examines actual control rather than accepting the label a platform gives itself. A driver may choose when to open the app, but their income still depends on fares they cannot negotiate, trips allocated through a process they cannot see, ratings that may reduce their opportunities, and the possibility of account suspension. Flexibility over working hours does not remove the platform’s control over these other aspects of the relationship.

The effects of that control extend beyond a worker’s legal classification. They also shape how the costs and risks of work are divided between the company and the worker. Workers may pay for a car or bicycle, phone, connectivity, fuel, and maintenance. They also bear the costs of waiting time, fluctuating demand, and road risks. At the same time, a platform may link incentives to the speed at which trips are completed or the proportion of requests accepted, while workers bear a greater share of the consequences of accidents, fatigue, and low demand.

These issues, from control over fares and time to safety and account suspension, shift the discussion from how the business model is described to the labor standards it provides. ILO Convention No. 193, adopted by the International Labor Conference in June 2026, recognizes that labor platforms use automated decision-making systems to organize work performed on-site or online. It also addresses employment status, pay, safety, social protection, trade union rights, and the explanation and review of algorithmic decisions. At the time of writing, the Convention had not entered into force.

The Convention covers the relationship between labor platforms and the people who work through them. Yet some of the work required to operate tech companies occurs outside that direct relationship. A company may rely on an external supplier to hire workers and manage their pay and contracts while retaining control over the standards and tools that govern their work.

Content moderation is a clear example: a moderator may be employed by an outsourcing company, while the platform sets the moderation rules, performance measures, tools, and volume of work. This arrangement adds another layer to the question of control raised by platform work. It separates the formal employer from the company that may retain significant influence over working conditions.

The lawsuits brought by content moderators in Kenya test this relationship between platforms and outsourcing companies. Moderators have brought claims concerning working conditions, mental health, termination of employment, and freedom of association against Sama and entities linked to Meta.

In 2024, the Court of Appeal addressed whether the Kenyan courts could hear the dispute without deciding the merits of the allegations. In April 2026, the Employment and Labor Relations Court found that an amended petition had been properly filed and that the consolidated matter could proceed to consideration on the merits. The lawsuit helps examine how control and responsibility may be divided between a platform and a staffing supplier, while the final legal responsibility for the alleged harms remains before the courts.

The Kenyan moderators’ case points to a broader issue. Many tech services depend on human work outsourced by companies, while, in some cases, retaining significant power over performance standards, workload, and the tools used. This occurs in content moderation, data labeling, AI model testing, and the review of model outputs.

Outsourcing places part of the workforce outside a company’s direct structure. Still, it does not remove the effects of the company’s decisions about price, speed, and the resources required of its supplier. If a contract demands a high volume of work within a short time or on a limited budget, the result may be greater pressure on workers and less capacity to review content with the necessary accuracy and attention to context.

Working conditions are also linked to the quality of the service users receive. A moderator working under severe time pressure, without adequate mental health support, or with limited language resources is more likely to make mistakes when applying content policies. A company’s assessment of its content moderation suppliers should therefore cover both working conditions and performance measures. This includes pay, working hours, rest, mental health, freedom of association, and the time and resources available for decision-making.

Workers also need access to their performance data and the reasons for measures that affect their work or income. When a platform and a supplier share control over these matters, responsibility should reflect the power each retains. Otherwise, a chain of contracts can make it difficult to identify which company can change the condition causing the harm.

5. Content, Language, and Conflict

The connection between content moderators’ working conditions and users’ rights is especially clear where moderation errors can cause harm beyond the removal or retention of a post. In Myanmar, the UN Fact-Finding Mission documented Facebook’s role in the spread of hate speech during a period of widespread persecution and violence against the Rohingya. It criticized the company’s slow and ineffective response.

Amnesty International attributed a broader responsibility to Meta. Its 2022 report concluded that content ranking systems designed to increase engagement amplified inciting content and substantially contributed to the harms suffered by the Rohingya.

A human rights impact assessment conducted by BSR at Facebook’s request identified risks concerning security, privacy, freedom of expression, and non-discrimination. It recommended greater investment in local resources and expertise, a better understanding of how hate speech spreads, and the preservation of removed content that might serve as evidence. The case shows how a company’s internal decisions about resources, language expertise, and moderation design can affect users’ rights and the communities exposed to harm.

Despite the limits of the available data, these findings provide a basis for assessing the company’s responsibility for decisions within its control. Escalating violence in Myanmar was a known feature of the political and security context. The company could have increased resources for local review, improved detection tools, adjusted its content ranking systems, and established crisis response procedures. Under the standard proposed in this paper, prevention resources should reflect the severity of foreseeable harm and the difficulty of remedying it. Market size and revenue should not be the only factors determining investment in safety.

Determining that more effective action is needed does not settle which action to take. A delayed response to incitement can allow it to spread. Excessive removal, meanwhile, can suppress legitimate content posted by journalists, human rights defenders, or affected communities, and may destroy material documenting violations or crimes.

Content moderation therefore needs clear rules applied in proportion to the type of harm. Measures such as reducing a post’s reach or adding a warning may be appropriate in some cases. Users also need ways to appeal decisions, while procedures for preserving potentially valuable evidence must protect victims’ data. The number of items removed, on its own, is not a measure of a moderation system’s quality or its impact on human rights.

Similar concerns arise in the moderation of Arabic content, where understanding language and context is essential to sound decisions. A BSR assessment of Meta’s impacts during the events surrounding Sheikh Jarrah in Palestine found indications of higher rates of policy enforcement against Arabic content per user. It also identified the possibility that some content was sent to reviewers who did not understand the dialect used, as well as gaps in classification tools and available resources. At the same time, the assessment documented failures to address some content that incited violence or hatred.

Language itself helps explain the difficulty. A phrase can change meaning with dialect, political context, sarcasm, or its use in a journalistic quotation. A reviewer’s decision also depends on what information they receive and how the context is presented. Human review does not automatically correct an automated system’s errors if the reviewer is under time pressure, does not understand the dialect, cannot see the full context, or lacks the authority to reject the system’s recommendation.

Assessing moderation quality, therefore, requires detailed data on removals, appeals, and decision reversals, broken down by language, dialect, and policy category. It also requires information about the proportion of automated and human decisions and the resources and expertise available to review teams. The number of Arabic-speaking reviewers alone does not show whether they can understand the different contexts in which the system operates.

Appeals do more than correct individual decisions. If decisions involving a particular dialect or type of expression are repeatedly overturned, that pattern may reveal flaws in classification tools, policy rules, or reviewer training. Appeals data can prompt a reassessment of the system itself when the findings reach product, policy, and training teams.

The scale of this function is visible under the EU Digital Services Act. Since 2024, users have appealed more than 165 million content moderation decisions through major platforms’ internal mechanisms, with nearly 30 percent overturned. In the first half of 2025, out-of-court dispute settlement bodies reviewed more than 1,800 disputes, and platform decisions were overturned in 52 percent of closed cases.

An appeal against a content moderation decision is effective only if users can learn why their post was removed, its reach reduced, or their account restricted, and can reach a body with the authority to review and change that decision. An appeal loses much of its value if the review takes too long, lacks language and contextual expertise, proceeds without the data explaining the decision, or cannot be implemented once a decision is reached.

Different parties need different information. Users need a clear explanation and the information required to challenge a decision. Regulators need broader records to examine patterns of removal, restriction, and reduced reach. Researchers need appropriate data to assess the wider effects of moderation systems, with safeguards for personal data and legitimate trade secrets.

Notice and appeal protections assume that a person knows a platform has made a decision affecting their content or account. With intrusion and covert surveillance tools, a person may not even know they have been targeted, and the client may be a government agency with coercive powers. For these tools, responsibility rests more heavily on prevention before a sale, client scrutiny, use monitoring, and the ability to suspend the service when misuse comes to light.

6. From Principles to Enforceable Rules

The cases discussed above show the limits of relying on corporate human rights policies and non-binding frameworks alone to govern company conduct. These frameworks include the UN Guiding Principles on Business and Human Rights and the OECD Guidelines, as well as companies’ own due diligence and risk assessment policies. They help establish what is expected of a company in preventing, monitoring, and addressing harm, even when national law provides no detailed rules.

Their ability to change decisions remains limited, however, if the company alone determines the scope of an assessment, what information to publish, and what action to take when harm emerges. The same is true if decisions about launches, sales, and productivity consistently take precedence over the findings of human rights assessments.

These principles become more effective when translated into enforceable rules that empower an independent body to request records and assess compliance, while enabling affected people to understand and challenge decisions and obtain an appropriate remedy.

European legislation offers examples of these regulatory functions. The Digital Services Act gives users certain rights to learn the reasons for content moderation decisions and to challenge them. It also requires the largest platforms to assess certain systemic risks and regulates access to their data for some researchers.

The Platform Work Directive addresses the determination of workers’ employment status and aspects of algorithmic management. It establishes a framework for a legal presumption of an employment relationship under conditions set by national law. The AI Act classifies several uses of AI in recruitment and worker management as high-risk systems. Following amendments in 2026, the application of parts of this framework has been deferred to 2027 and 2028.

For this paper, these pieces of legislation illustrate three functions worth considering in the Egyptian context: enabling affected people to understand a decision, access evidence, and challenge it; placing limits on algorithmic management at work; and requiring additional safeguards before high-risk systems are used.

Examining how these functions might operate in Egypt begins with existing law. In the workplace, for example, Labor Law No. 14 of 2025 provides a starting point for discussing the relationship between a worker and a digital labor platform. Article 96 defines new forms of work as non-traditional work performed for an employer, under the employer’s management or supervision, in exchange for pay. These forms include remote, part-time, flexible, and job-sharing arrangements.

The following articles also extend rights to these forms of work and allow for electronic contracts and multiple forms of evidence. The law does not expressly regulate platform workers as a distinct group, so its application to them depends on establishing, in practice, that a management or supervisory relationship exists. That relationship can be examined through the platform’s control over working conditions: how it sets pay and commissions, allocates tasks, treats rejected requests when offering future work, applies ratings, and suspends accounts. Other relevant factors include workers’ ability to negotiate terms or build an independent client base, and the degree to which they depend economically on the platform. Together, these factors can help assess whether the app creates a relationship of subordination even without a human manager directly overseeing the work.

Assessing those factors requires access to information about how the platform actually manages work. A worker may know what they were paid or that their account was suspended, but may not have the records showing how tasks were allocated, whether declining a task affected later opportunities, how their rating was calculated, or why their account was suspended. The platform holds much of this information as data linked to the worker and their activity on the app.

In this context, Personal Data Protection Law No. 151 of 2020 and its executive regulations, issued under Decree No. 816 of 2025, may provide a means of accessing some of that data. They also set rules governing the lawful collection, use, and security of personal data, as well as the rights of the person concerned. Data protection law may thus help workers or competent authorities obtain information needed to examine these questions under labor law and other relevant rules.

The level of access required depends on how the information will be used. Workers and users need data connected to decisions that affected them, presented in a form they can understand and use to raise an objection. Courts and regulators need a wider range of records when a dispute concerns a recurring pattern or a rule applied to many people. Researchers also need appropriate data to assess a system’s collective effects, subject to safeguards for personal data.

A right to access data or challenge a decision is insufficient if it is unclear which company must provide the records, if the data and responsible entities are spread across countries, or if an individual cannot make effective use of the information against a platform with greater bargaining and litigation power. Different parts of the same dispute may also fall to labor, data protection, and competition authorities, as well as the courts, without any one of them seeing the entire relationship.

Enforcing these rules, therefore, depends on addressing three interconnected problems: identifying an entity that can be held accountable across borders; strengthening workers’ and users’ collective ability to use information; and establishing an institution capable of bringing together questions of work, data, contracts, and system design in a single accountability process.

6.1 Cross-Border Remedy

The first problem arises when the company, worker, data, and contracts are spread across countries. A parent company may be based in one country, a supplier may perform part of the work in another, and the worker or user may be in a third, while some data is stored elsewhere. When harm occurs, affected people may struggle to identify who made the decision or holds the records needed to establish what happened. Contractual terms may also direct disputes to foreign law or courts, increasing the cost of asserting rights.

The lawsuits brought by content moderators in Kenya illustrate this obstacle. Considerable time was spent resolving whether the Kenyan courts could hear the disputes before the claims concerning working conditions and responsibility for them could be examined. Identifying an entity that can be held accountable, and obtaining its records, are therefore part of gaining access to remedy.

National rules and contracts can reduce this obstacle by requiring a company that organizes work or provides a service in a country to identify a legally contactable entity, preserve records concerning local workers and users, and cooperate with courts and regulators. Choice-of-law, jurisdiction, and arbitration clauses should not make it practically impossible to pursue a claim because of the cost or distance involved.

Cooperation among regulators becomes especially important when harm results from a rule or update applied to many people across countries. Yet identifying an accountable entity and obtaining its records does not, by itself, correct the imbalance of power in the relationship. A worker or user may receive information about their own case without knowing whether the same system affects others in the same way.

6.2 Collective Organization and Data

The limits of an individual right to information become apparent when a system applies the same rule to an entire group of workers. A worker may receive an explanation for the suspension of their account, but their own records cannot show whether rejecting a particular type of task reduces the number of requests offered to all workers. Nor can those records show whether workers who raise safety concerns or take part in trade union activity face a recurring pattern of suspensions or fewer work opportunities. Detecting such patterns requires information that extends beyond any one person’s file.

Trade unions, workers’ associations, and their representatives therefore need access to appropriate data on pay, working time, ratings, and account suspensions. They also need to be consulted when new monitoring or algorithmic management systems are introduced. The ILO’s Convention No. 193 addresses the use of algorithmic systems to manage work alongside fundamental rights at work. The EU Platform Work Directive also provides for certain rights of workers and their representatives to information about these systems.

Access to information alone will not change working conditions if each worker must deal with the platform individually. A platform can change pay, rating, or task allocation rules for many workers at once, while an individual worker has limited power to negotiate those rules.

Collective rights to data are therefore connected to the rights to organize and be represented, and to protection from retaliation for collective activity. Giving workers’ representatives access to information allows them to use it in negotiations over pay, safety, and algorithmic management, rather than leaving data solely in the platform’s hands as a tool for monitoring and managing workers.

These protections also matter for workers classified under contract as independent when, in practice, they lack the market power to negotiate individually. Their effect will remain limited, however, without an authority that can require the platform to provide information, verify that it is complete, and protect workers from account suspensions or reduced work opportunities for organizing.

6.3 An Institution That Sees the Whole Relationship

Enforcing rights to information and representation raises a broader institutional problem in Egypt. A dispute over pay or worker status may be referred to a labor office, while a data protection authority examines how the worker’s data is collected and used. A court may consider the contract and terms of service, and the competition authority may become involved if the issue concerns the platform’s market power.

The platform, meanwhile, may treat the same event as a technical decision or an account support matter. With responsibility divided this way, each authority sees only part of the relationship, even though harm may arise from the interaction among system design, data, contracts, and working conditions.

Addressing this fragmentation does not necessarily require a new regulator with broad powers. An authority or coordinated process could receive complaints about automated decisions with significant consequences, request the records needed to understand them, and refer labor, data protection, or competition issues to the relevant bodies, all while maintaining a single case file.

Such a process could cover decisions to reject a job applicant, reduce a worker’s income, suspend an account on which someone relies for work, or deny access to an essential service. It would require the company to provide the reason for the decision, the relevant data, and a record showing which rule was applied. If the company failed to provide a record it was required to keep, or destroyed it, the law could attach an appropriate procedural consequence or sanction instead of requiring affected people to prove facts for which the company alone holds the information.

Integrated oversight is also needed when the state purchases a system. In public procurement, a body independent of the agency using the system should be able to examine the contract, records, and data-processing terms, review any changes in the system’s intended use, and suspend the service if harm emerges.

Rules on transparency, record preservation, and access to records can help reveal harm and identify who is responsible. They do not, on their own, ensure that affected people can have a decision corrected, receive compensation, or see the rule that caused the harm changed. The analysis therefore turns from detecting and establishing a decision to whether the remedy available can undo its effects and address the source of harm.

Conclusion

This paper began with a person receiving an outcome that affects their rights without being able to see the rule that produced it or access the records needed to understand it. The cases examined show that this information gap reflects how power is distributed within the relationship. A company that sets the rules for hiring, task allocation, content ranking, or the use of a high-risk product may also hold the data needed to measure and establish the effects of those rules. Its responsibility should therefore be assessed by the control it exercises, its ability to foresee and prevent harm, its leverage over other parties, the evidence it holds, and its ability to address the outcome, not by its contractual description or the fact that a decision was automated.

The importance of this standard becomes clear when harm occurs. Correcting an individual decision is insufficient if the rule that produced it continues to affect others in the same way. An affected person may need the restoration of an opportunity, lost income, or removed content.

Remedy also requires examining and changing the cause of the harm when it lies in the system’s design, data, or operating rules. Complaints and appeals can therefore have value beyond individual cases when they reveal a recurring pattern, bring it to the attention of product, contracting, risk, and management teams, and lead to changes whose effects on affected people can later be measured.

The examples in this paper show that many corrective measures followed litigation, investigations, regulatory interventions, or external reviews. This exposes the limits of an accountability system that acts only after affected people have borne the cost of discovering and establishing the harm. Under the standard proposed here, safeguards must begin earlier. Companies need to test a rule’s impact before applying it, preserve the records needed to review it, and be subject to intervention by an independent body. They must also change the system when signs of recurring harm emerge.

Responsibility should thus be distributed in proportion to actual power. Those able to design and operate a system that produces decisions should bear part of the cost of preventing harm and correcting its effects, rather than leaving that cost to people who could not see how the decisions were made.