Public authorities that decide by algorithm: what transparency the BOSCO case requires
The progressive automation of administrative action has brought to the fore the question of how decisions taken by means of algorithms are to be explained and reviewed. Judgment 1119/2025 of 11 September of the Third Chamber of the “Tribunal Supremo”, Spain's Supreme Court, known as the BOSCO case and highlighted in the Third Chamber's official case-law report for 2025–2026, marks a landmark in this field by recognising that, where public authorities use automated systems to grant rights or social benefits, the right of access to public information may require, in certain circumstances, that even the source code of the program be disclosed. The decision rests on article 105 b) of the Spanish Constitution, on Law 19/2013 on transparency, access to public information and good governance, on the rules governing automated administrative action in Law 40/2015 and on the European data protection framework of Regulation (EU) 2016/679 —the GDPR—. Algorithmic transparency ceases to be a technical question and becomes a structural requirement of the digital rule of law.
1.Automated administrative action and the responsibility of the competent body
The “Ley 40/2015, de 1 de octubre, de Régimen Jurídico del Sector Público” —Law 40/2015 of 1 October on the legal regime of the public sector— defines in its article 41 automated administrative action as any act or action carried out entirely by electronic means by a public authority within an administrative procedure and in which no public employee has taken any direct part. Paragraph 2 requires that, in the case of automated administrative action, the body or bodies competent for the definition of the specifications, the programming, the maintenance, the supervision and the quality control and, where appropriate, the audit of the information system and of its source code be established in advance, as well as the body to be regarded as responsible for the purposes of any challenge. That provision is key: although the decision is produced by an algorithm, legal responsibility lies with an identifiable body, which must be able to explain and defend the logic of the system.
Article 42 of the same Act governs the signature systems for automated administrative action, allowing the use of electronic seals of an authority, body, public agency or public-law entity, based on recognised or qualified certificates, and of secure verification codes linked to the authority or body concerned, which make it possible to check the integrity of the document by accessing its electronic office, the “sede electrónica”. Article 40 lays down the identification systems of the public authorities, including the use of electronic seals and the identification of the information published on the internet portal as the authority's own. All of this shapes a framework in which the automated decision must be attributable, verifiable and auditable.
2.Transparency and the right of access to public information
The right of access to public information is recognised in article 105 b) of the Spanish Constitution, which directs that the law is to govern citizens' access to administrative files and registers, save as regards the security and defence of the State, the investigation of offences and the privacy of individuals. The “Ley 19/2013, de 9 de diciembre, de transparencia, acceso a la información pública y buen gobierno” —Law 19/2013 of 9 December on transparency, access to public information and good governance— gives effect to that right. Article 5 lays down the general principles of proactive disclosure, imposing on the bodies within its scope the obligation to publish, periodically and in updated form, the information relevant to ensuring the transparency of their activity, with particular reference to the economic, budgetary and statistical information of article 8, which includes contracts, agreements, subsidies, budgets and annual accounts.
The right of access is set out in articles 17 to 22. Article 18 lists the grounds for refusing to admit a request, among them requests concerning information in the course of preparation, ancillary or supporting information, or information requiring prior reworking, requests addressed to a body lacking competence and requests that are manifestly repetitive or abusive. Article 20 governs the decision, requiring that it be issued and notified within a maximum period of one month, extendable by a further month on grounds of volume or complexity, and that decisions refusing access, granting partial access or granting access in a form other than that requested be reasoned, stating the remedies available. Article 14 sets out the limits on the right of access, including national security, defence, external relations, public safety, the prevention and investigation of unlawful acts, the equality of the parties in judicial proceedings, supervisory and inspection functions, economic and commercial interests, economic and monetary policy, professional secrecy and intellectual and industrial property, confidentiality in decision-making processes and protection of the environment. Paragraph 2 requires the application of those limits to be justified and proportionate, having regard to the circumstances of the case and to the presence of an overriding public or private interest justifying access. Article 16 provides for partial access where the application of a limit does not affect all the information, allowing the affected part to be omitted, provided that the meaning is not distorted.
Article 15 deals specifically with the protection of personal data, distinguishing between specially protected data, which require express consent or a statutory basis, and merely identifying data relating to the organisation, operation or public activity of the body, in respect of which access is as a general rule granted unless data protection or other constitutional rights prevail. Paragraph 3 requires a reasoned balancing of the public interest in disclosure against the rights of those affected, taking into account criteria such as the lesser harm resulting from the passage of time, the applicants' status as researchers, the merely identifying character of the data, or the impact on privacy or safety, particularly that of minors.
3.The BOSCO case: access to the source code and algorithmic transparency
In the BOSCO case, the Fundación Ciudadana Civio asked the “Ministerio para la Transición Ecológica”, the Ministry for the Ecological Transition, for information about the software used to verify whether applicants for the “bono social eléctrico”, Spain's subsidised electricity tariff, met the requirements to be treated as vulnerable consumers. The information requested included the source code of the program. The “Consejo de Transparencia y Buen Gobierno”, Spain's transparency and good governance council, partially upheld the complaint, ordering the disclosure of technical specifications and test results, but refused access to the source code, relying on the intellectual property limit in article 14.1 j) of Law 19/2013. The “Juzgado Central de lo Contencioso‑Administrativo”, the central administrative court, and the “Audiencia Nacional”, Spain's national high court, upheld the refusal, adding arguments based on public safety and data protection.
Judgment 1119/2025 of the Supreme Court quashes those decisions and recognises Civio's right of access to the source code. The Chamber stresses that the right of access to public information takes on particular importance in the context of automated administrative decisions affecting social rights. The use of algorithms to grant benefits such as the bono social eléctrico calls for enhanced transparency, making it possible to verify that the system applies the rules correctly and does not introduce bias or errors affecting citizens' rights.
The Court examines the limits relied on. As regards intellectual property, it recalls that computer programs are protected by the “Texto Refundido de la Ley de Propiedad Intelectual”, Spain's consolidated Intellectual Property Act, article 96 of which defines the subject matter of protection and requires originality, but it insists that the application of the limit in article 14.1 j) of Law 19/2013 is not automatic: it calls for a balancing exercise under article 14.2. In the BOSCO case, the public interest in verifying the correct application of the law for the recognition of a social right prevails over the authority's proprietary interest in protecting the code, all the more so where the purpose of the program is not commercial but the administration of a public benefit.
As regards public safety, the Chamber rejects the contention that the risk of vulnerabilities in the code justifies an outright refusal. It reasons that the risk that disclosure of the code will facilitate attacks is inherent in any system, and that accepting it as a general proposition would deprive the right of access to algorithms of any content. It further notes that transparency may improve security by allowing wider scrutiny to identify and correct flaws. The opacity of the program, which issues decisions without comprehensible reasons, hampers review and the detection of errors, which justifies giving precedence to the public interest in access.
As regards data protection, the Court makes clear that the source code does not in itself contain personal data of the applicants, so that the limit in article 15 does not apply. Information about the logic of the algorithm and its implementation does not directly affect individuals' privacy, although it may call for safeguards to prevent sensitive data from being inferred through the code.
4.What citizens and organisations may request: beyond the source code
The BOSCO case is not confined to access to the source code; it opens the door to a broader concept of algorithmic transparency. Citizens and organisations may request, under Law 19/2013 and article 105 b) CE, information about the automated systems used by public authorities, including functional specifications, decision criteria, the variables used, their weightings, operational tests, audits and impact assessments. Academic commentary and the judgment itself stress that transparency is not exhausted by the code: it is also relevant to know who designed the system, which body is responsible for supervising it, what quality controls have been applied and how the algorithm fits into the administrative procedure.
Article 41 of Law 40/2015 requires the body responsible for the definition, programming, maintenance, supervision and audit of the system and of its source code to be identified. That identification is public information open to access. Article 88 of the “Ley 39/2015”, Spain's Common Administrative Procedure Act, governs the content of administrative decisions, requiring them to determine all the questions raised and to state reasons in the cases provided for in article 35, indicating the remedies available. The reasons given for an automated decision must include, at the very least, a comprehensible explanation of the logic applied, in line with article 22 of Regulation (EU) 2016/679, which confers on the data subject the right not to be subject to a decision based solely on automated processing which produces legal effects or significantly affects him or her, save for certain exceptions, and requires that, in such cases, measures be adopted to safeguard the data subject's rights, including the right to obtain human intervention, to express his or her point of view and to contest the decision.
5.How refusals of access must be reasoned
Refusals of access to information about algorithms must state reasons in accordance with article 20 of Law 19/2013, indicating the limit applied, the balancing carried out and, where appropriate, the possibility of partial access. Article 20.2 requires reasons to be given for decisions refusing access, for those granting partial access or access in a form other than that requested, and for those allowing access notwithstanding the objection of third parties. Article 14.2 requires the application of the limits to be justified and proportionate, having regard to the circumstances of the case and to the presence of an overriding public or private interest.
In the context of algorithms, a refusal based on intellectual property must explain why the protection of the code prevails over the interest in transparency, what specific harm would flow from disclosure and whether it is possible to provide alternative information enabling the logic of the system to be understood without revealing details that would compromise that protection. A refusal based on public safety must identify specific risks, not merely generic ones, and justify why disclosure of the code or of particular specifications would materially increase the vulnerability of the system, without its being capable of mitigation by technical measures or by restricted access.
Article 16 of Law 19/2013 offers the tool of partial access: where the application of a limit does not affect all the information, access may be granted to the part not affected, omitting the protected information, provided that the meaning is not distorted. In the case of algorithms, this may mean supplying functional documentation, decision criteria, tests and audits, while withholding part of the code or of the configuration on grounds of security or intellectual property, provided that the withholding is justified and does not deprive the right of access of its content.
6.Safeguards for an administrative decision based on algorithms
An administrative decision based on algorithms requires specific safeguards if it is to be compatible with the principles of legality, the prohibition of arbitrariness and effective judicial protection laid down in article 106 of the Spanish Constitution, which entrusts the courts with reviewing the power to make regulations and the lawfulness of administrative action, as well as its subjection to the purposes that justify it. Article 3 of Law 40/2015 recalls that public authorities serve the general interest with objectivity and act in accordance with the principles of effectiveness, transparency, good faith, legitimate expectations and accountability for public management. Automation does not dispense with compliance with those principles.
In concrete terms, an algorithmic decision must rest on a clear legal basis determining the purposes and means of the processing of data, in accordance with article 6 of Regulation (EU) 2016/679, and must respect the rights of data subjects, including the right of access to their data and to information about the processing, governed by articles 13, 14 and 15 of the Regulation. Article 22 of the Regulation requires that, where decisions are taken based solely on automated processing, the data subject be afforded the right to obtain human intervention, to express his or her point of view and to contest the decision, and it prohibits such decisions from being based on special categories of data save for certain exceptions.
From the standpoint of administrative procedure, the decision must be reasoned in comprehensible terms, enabling the party concerned to understand why a right or benefit is granted or refused. The reasons may rest on technical reports or opinions which, under article 88.6 of Law 39/2015, serve as the statement of reasons where they are incorporated into the text of the decision. In the case of algorithms, such reports may describe the logic of the system, the variables used and the tests carried out.
There must also be a possibility of challenging the decision before the administrative courts which, under article 106 CE, review the lawfulness of administrative action. Algorithmic transparency is the condition that makes such review possible: without access to the logic of the system, the judge cannot verify whether the decision conforms to the law and to the purposes that justify it.
7.Conclusion: from source code to digital constitutionalism
The BOSCO case marks a turning point in the building of a digital constitutionalism in which algorithmic transparency forms part of the core of the safeguards of the rule of law. Judgment 1119/2025 recognises that, where public authorities use automated systems to grant rights or social benefits, the right of access to public information may require that even the source code be disclosed, on a specific balancing of intellectual property and security. Citizens and organisations may request information about the logic of the algorithms, the technical specifications, the tests and audits, and the bodies responsible for their design and supervision. Refusals of access must be reasoned with rigour, applying the limits of Law 19/2013 in a justified and proportionate manner, and granting partial access where that is possible.
Administrative decisions based on algorithms require additional safeguards: identification of the responsible body under Law 40/2015, comprehensible reasons under Law 39/2015, respect for the rights of data subjects under Regulation (EU) 2016/679 and the possibility of judicial review under article 106 CE. Algorithmic transparency is not a technical luxury but a legal requirement that allows automation to operate within the framework of legality, responsibility and effective judicial protection. In a context in which automated administration is spreading to sensitive fields such as social benefits, penalties and authorisations, the BOSCO case offers clear guidance on what transparency the law requires and how it must be organised so that algorithms serve citizens and not the other way round.