Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Data Subject Rights

Automated Individual Decision-Making and Profiling

Also known as: ADM, Automated Decision-Making, Automated Individual Decision-Making, Profiling, Article 22 Automated Decision-Making
Simply put

Automated individual decision-making refers to decisions made about a person by a computer system without meaningful human involvement, sometimes based on profiles built from their personal data. Profiling is the automated analysis of personal data to evaluate or predict aspects of an individual, such as their behaviour, preferences, or circumstances. Under EU and UK data protection law, individuals generally have the right not to be subject to certain decisions based solely on automated processing that significantly affect them, subject to specific exceptions.

Formal definition

Under Article 22 of the GDPR (and the corresponding provisions of the UK GDPR), a data subject generally has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. "Solely" automated processing means there is no meaningful human involvement in the decision; where a human meaningfully reviews and can override the outcome, Article 22's core prohibition typically does not apply, though other data protection obligations still do. Profiling, as a related but distinct concept, refers to any form of automated processing of personal data consisting of the use of that data to evaluate certain personal aspects of an individual—such as analysing or predicting performance, economic situation, health, preferences, interests, reliability, behaviour, location, or movements. Profiling may occur without triggering Article 22 (for example, where it does not lead to a solely automated decision with legal or similarly significant effects), and Article 22 decisions may occur without profiling. Where Article 22 applies, processing is permissible only under limited grounds (broadly, contractual necessity, authorisation by Union or Member State law, or explicit consent), and controllers must generally implement safeguards, including a lawful basis for the underlying processing that should be documented in a data protection policy. Additional restrictions typically apply to decisions based on special category data. This entry describes the EU/UK framework and its terminology; scope, exceptions, and enforcement interpretation continue to evolve, and readers should verify obligations against the current official text and applicable supervisory authority guidance.

Why it matters

Automated individual decision-making sits at the intersection of data protection, fairness, and the growing use of algorithmic systems to make consequential judgements about people—decisions that may affect access to credit, employment, insurance, or essential services. Under Article 22 of the GDPR and the corresponding UK GDPR provisions, individuals generally have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them. For organisations, this means that deploying a system that decides without meaningful human involvement is not simply a technical or commercial choice; it engages a specific legal restriction and a set of accompanying safeguards.

The practical significance lies in the distinction between a decision that is 'solely' automated and one that involves meaningful human review. Where a human meaningfully reviews and can override an outcome, the core Article 22 prohibition typically does not apply—though other data protection obligations continue to apply throughout. Getting this distinction wrong exposes organisations to compliance risk, because a nominal or rubber-stamp human 'review' that cannot realistically alter the outcome may not remove processing from the scope of Article 22. The related concept of profiling adds further complexity: profiling can occur without triggering Article 22, and an Article 22 decision can occur without profiling, so the two must be assessed separately.

Because scope, exceptions, and enforcement interpretation in this area continue to evolve—including how supervisory authorities and courts read terms such as 'solely' and 'similarly significant effect'—organisations cannot treat a one-time assessment as durable. The framework described here reflects the EU and UK position; obligations differ in other jurisdictions, and readers should verify against the current official text and applicable supervisory authority guidance rather than relying on a fixed interpretation.

Who it's relevant to

Data Protection Officers and Privacy Teams
DPOs and privacy professionals are responsible for assessing whether a given processing activity constitutes solely automated decision-making, profiling, or both, and for determining whether Article 22 applies. This includes evaluating whether any human involvement in a decision is genuinely meaningful, identifying and documenting the lawful basis in the data protection policy, and ensuring that any required safeguards are in place—particularly where special category data is involved.
Product and Engineering Teams Building Decision Systems
Teams designing systems that score, rank, or decide about individuals need to understand where meaningful human involvement sits within the workflow, because that design choice affects whether the core Article 22 restriction is engaged. A review step that cannot realistically alter the outcome may not take a decision outside 'solely' automated processing, so system architecture and human-in-the-loop design should be assessed with data protection input rather than treated as a purely technical decision.
Legal Counsel and Compliance Officers
Legal and compliance functions assess which of the limited Article 22 grounds—contractual necessity, authorisation by Union or Member State law, or explicit consent—can support a proposed use, and how obligations differ between the EU and UK frameworks and other jurisdictions. Because interpretation of terms such as 'solely' and 'similarly significant effect' continues to evolve, counsel should monitor supervisory authority guidance and relevant case law rather than relying on a static reading.
Auditors and Assessors
Those reviewing an organisation's data protection posture examine whether automated decision-making and profiling activities have been identified, whether a lawful basis has been documented, and whether appropriate safeguards exist. An audit or assessment in this area typically tests the reality of human oversight against its documented description, since the presence of a nominal review step does not by itself demonstrate that processing falls outside Article 22.

Inside ADM

Automated Individual Decision-Making
Decisions made solely by automated means, without meaningful human involvement, that produce legal effects concerning an individual or similarly significantly affect them. Under the GDPR, such solely automated decisions are generally restricted unless a specific legal basis applies. Note that not all automated processing falls within scope; the concept centers on decisions lacking meaningful human oversight.
Profiling
Any form of automated processing of personal data used to evaluate certain personal aspects of an individual, such as analyzing or predicting performance, economic situation, health, preferences, or behavior. Profiling may occur with or without an automated decision, and it can be a component of automated decision-making but is a distinct concept in its own right.
Meaningful Human Involvement
The threshold that distinguishes solely automated decisions from those subject to human oversight. Involvement is generally considered meaningful where a person with appropriate authority and competence actively reviews the decision rather than routinely rubber-stamping the automated output. Interpretation of what qualifies as meaningful continues to evolve through guidance and enforcement practice.
Legal or Similarly Significant Effect
The impact threshold that brings a solely automated decision within the restricted category. This generally covers effects on legal rights or effects that significantly influence an individual's circumstances, such as access to credit, employment, or essential services. Whether a given effect meets this threshold is fact-specific.
Permitted Grounds and Safeguards
The limited conditions under which solely automated decision-making producing significant effects may generally proceed, together with associated protective measures. These typically include the ability to obtain human intervention, to express one's point of view, and to contest the decision. Specific conditions and any additional protections for special category data should be verified against the current official text.
Transparency and Information Obligations
Requirements to inform individuals about the existence of automated decision-making and profiling and to provide meaningful information about the logic involved and the significance and envisaged consequences. The precise scope of what constitutes meaningful information about the logic remains a developing area.

Common questions

Answers to the questions practitioners most commonly ask about ADM.

Does the GDPR ban all automated decision-making outright?
No. This is a common misconception. The GDPR does not impose a blanket prohibition on automated processing or profiling generally. Rather, it establishes a specific right for data subjects concerning decisions based solely on automated processing (including profiling) that produce legal effects or similarly significantly affect them. Decisions involving meaningful human intervention, or automated decisions that do not reach the relevant threshold of significant effect, fall outside this particular restriction, though other GDPR obligations continue to apply. The precise scope depends on the facts, and readers should verify against the current official text.
Is profiling the same thing as automated decision-making?
No, the two concepts are distinct and should not be conflated. Profiling refers to automated processing used to evaluate, analyze, or predict aspects of a person, such as their behavior, preferences, or circumstances. Automated individual decision-making refers to reaching a decision by automated means. Profiling may feed into an automated decision, but profiling can occur without any resulting decision, and an automated decision may in some cases be made without profiling. The specific safeguards attach primarily to solely automated decisions producing legal or similarly significant effects, which is a narrower category than profiling as a whole.
How can we determine whether a decision is based 'solely' on automated processing?
The 'solely' criterion generally turns on whether there is meaningful human involvement in the decision, rather than a token or rubber-stamp review. In most cases, a human reviewer must have genuine authority and competence to alter the outcome and must actually consider the relevant factors for the processing to fall outside the 'solely automated' category. Nominal oversight that does not substantively influence the result may not be sufficient. Because interpretation continues to evolve and depends heavily on the facts, organizations should document their human-involvement processes and verify their approach against current regulatory guidance and their own professional judgment.
What safeguards are generally expected when relying on a permitted basis for solely automated decisions?
Where solely automated decisions with legal or similarly significant effects are permitted under one of the recognized bases, the GDPR generally expects suitable measures to protect the data subject's rights, freedoms, and legitimate interests. These typically include the ability to obtain human intervention, to express one's point of view, and to contest the decision. Transparency about the existence of such processing is also generally required. The exact measures appropriate in a given case depend on the risk and context, and their design is a fact-specific exercise.
How should automated decision-making be addressed in transparency notices?
Where the relevant provisions apply, controllers are generally expected to inform data subjects about the existence of solely automated decision-making, including profiling that meets the threshold, and to provide meaningful information about the logic involved as well as the significance and envisaged consequences of the processing. 'Meaningful information about the logic' does not necessarily require disclosing proprietary algorithms in full, but does generally call for an intelligible explanation. The appropriate level of detail is fact-specific, and organizations should verify their disclosures against current authoritative guidance.
Does a data protection impact assessment need to be carried out for automated decision-making?
In many cases, systematic and extensive automated evaluation or profiling that forms the basis of decisions with legal or similarly significant effects is treated as high-risk processing that may trigger a data protection impact assessment under the GDPR. Whether an assessment is required depends on the nature, scope, context, and purposes of the processing, and supervisory authorities may publish lists of operations that do or do not require one. Organizations should assess the specific processing against current regulatory criteria and applicable authority guidance rather than assuming a fixed rule.

Common misconceptions

Profiling and automated decision-making are the same thing.
They are related but distinct. Profiling is the automated evaluation of personal aspects and can occur without any decision being made, while automated decision-making refers to reaching a decision. A decision may rely on profiling, but profiling on its own does not necessarily constitute a solely automated decision with significant effects.
Any use of algorithms or automation in a decision triggers the GDPR's restrictions.
The restrictions apply chiefly to decisions made solely by automated means that produce legal or similarly significant effects. Where there is meaningful human involvement, or where the effect does not meet the significance threshold, the specific restriction generally does not apply, though other data protection obligations may still be relevant.
These rules apply uniformly worldwide.
The provisions described here derive from the EU GDPR and govern processing within its territorial and material scope, including certain extraterritorial reach. Other jurisdictions, such as the United States and the United Kingdom, address automated decision-making differently, and the UK regime, while closely aligned, is subject to its own evolution. Requirements should be verified against the applicable jurisdiction's current law.

Best practices

Map and inventory where solely automated decisions and profiling occur, and assess for each whether the decision produces a legal or similarly significant effect that brings it within the restricted category.
Where relying on human involvement to fall outside the solely automated category, ensure that involvement is genuinely meaningful, carried out by someone with the authority and competence to alter the outcome, rather than a nominal review.
Provide clear, accessible information to individuals about the existence of automated decision-making and profiling, including meaningful information about the logic and the envisaged consequences, and keep such notices current.
Implement mechanisms that allow individuals to obtain human intervention, express their views, and contest decisions, and document how these safeguards operate in practice.
Consider conducting a data protection impact assessment where automated decision-making or profiling is likely to result in high risk, and treat special category data with additional caution.
Verify the specific conditions, permitted grounds, and safeguards against the current official text of the applicable regulation and relevant regulatory guidance, and seek professional judgment for application to particular circumstances, since interpretation and enforcement practice continue to evolve.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide