GDPR
What is automated decision-making in GDPR?
Automated decision-making uses technology to make decisions about individuals, sometimes using profiling to evaluate their behaviour or characteristics. Article 22 provides specific protection where a decision involves no meaningful human involvement and produces legal or similarly significant effects, such as automatically refusing a loan.
Such decisions are generally prohibited unless they are:
Necessary to enter into or perform a contract.
Authorised by EU or Member State law with suitable safeguards.
Based on the individual’s explicit consent.
The GDPR rules on automated decisions require appropriate safeguards. For decisions relying on contract necessity or explicit consent, these include human intervention, an opportunity to express a viewpoint and the ability to challenge the decision.
Automated processing that falls outside Article 22 must still comply with other applicable GDPR requirements.
Türkçe
English