Automated Individual Decision-Making and Profiling
Automated individual decision-making refers to decisions made about a person by a computer system without meaningful human involvement, sometimes based on profiles built from their personal data. Profiling is the automated analysis of personal data to evaluate or predict aspects of an individual, such as their behaviour, preferences, or circumstances. Under EU and UK data protection law, individuals generally have the right not to be subject to certain decisions based solely on automated processing that significantly affect them, subject to specific exceptions.
Under Article 22 of the GDPR (and the corresponding provisions of the UK GDPR), a data subject generally has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. "Solely" automated processing means there is no meaningful human involvement in the decision; where a human meaningfully reviews and can override the outcome, Article 22's core prohibition typically does not apply, though other data protection obligations still do. Profiling, as a related but distinct concept, refers to any form of automated processing of personal data consisting of the use of that data to evaluate certain personal aspects of an individual—such as analysing or predicting performance, economic situation, health, preferences, interests, reliability, behaviour, location, or movements. Profiling may occur without triggering Article 22 (for example, where it does not lead to a solely automated decision with legal or similarly significant effects), and Article 22 decisions may occur without profiling. Where Article 22 applies, processing is permissible only under limited grounds (broadly, contractual necessity, authorisation by Union or Member State law, or explicit consent), and controllers must generally implement safeguards, including a lawful basis for the underlying processing that should be documented in a data protection policy. Additional restrictions typically apply to decisions based on special category data. This entry describes the EU/UK framework and its terminology; scope, exceptions, and enforcement interpretation continue to evolve, and readers should verify obligations against the current official text and applicable supervisory authority guidance.
Why it matters
Automated individual decision-making sits at the intersection of data protection, fairness, and the growing use of algorithmic systems to make consequential judgements about people—decisions that may affect access to credit, employment, insurance, or essential services. Under Article 22 of the GDPR and the corresponding UK GDPR provisions, individuals generally have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them. For organisations, this means that deploying a system that decides without meaningful human involvement is not simply a technical or commercial choice; it engages a specific legal restriction and a set of accompanying safeguards.
The practical significance lies in the distinction between a decision that is 'solely' automated and one that involves meaningful human review. Where a human meaningfully reviews and can override an outcome, the core Article 22 prohibition typically does not apply—though other data protection obligations continue to apply throughout. Getting this distinction wrong exposes organisations to compliance risk, because a nominal or rubber-stamp human 'review' that cannot realistically alter the outcome may not remove processing from the scope of Article 22. The related concept of profiling adds further complexity: profiling can occur without triggering Article 22, and an Article 22 decision can occur without profiling, so the two must be assessed separately.
Because scope, exceptions, and enforcement interpretation in this area continue to evolve—including how supervisory authorities and courts read terms such as 'solely' and 'similarly significant effect'—organisations cannot treat a one-time assessment as durable. The framework described here reflects the EU and UK position; obligations differ in other jurisdictions, and readers should verify against the current official text and applicable supervisory authority guidance rather than relying on a fixed interpretation.
Who it's relevant to
Inside ADM
Common questions
Answers to the questions practitioners most commonly ask about ADM.

