Automated Decision Making and Profiling is regulated by the The General Data Protection Regulations (GDPR). These have redefined how organisations handle personal data, refining and reforming rules to protect individuals’ privacy. In an era where automated decision making and profiling are becoming increasingly prevalent, understanding the rules and rights under the GDPR is crucial. Because these types of data processing can significantly impact individuals, they receive stricter oversight to ensure fairness, transparency, and accountability.
Contents
Understanding Automated Decision Making and Profiling
Automated decision making involves decisions made solely by automated means without any meaningful human involvement.
Profiling, on the other hand, refers to the automated processing of personal data to evaluate certain aspects of an individual, such as their behaviour, preferences, or performance. Common examples include credit scoring, targeted advertising, and recruitment algorithms. While these technologies offer efficiency and personalisation, they also pose risks to individual rights and freedoms.
Important Considerations:
-
Transparency: people should be informed that automated decision making or profiling is used and have access to the criteria considered. People should also understand the legal effects that could arise from processing their data in this way.
-
Fairness: The algorithms must be free from bias that could unfairly discriminate against certain groups.
-
Human Oversight: There should be a mechanism for human review of automated decisions, particularly when significant consequences are involved (e.g., loan denial).
-
Right to Explanation: Individuals should have the right to understand why an automated decision was made about them.

Legal Framework Under The GDPR
The GDPR addresses automated decision making and profiling primarily through Article 22, which prohibits decisions based solely on automated processing, including profiling, that produce legal effects or significantly affect individuals. However, there are exceptions to this prohibition, governed by stringent conditions and safeguards to protect data subjects’ rights.
Conditions for Lawful Automated Decision Making
Automated decision making is permissible under GDPR if it is necessary for the performance of a contract, based on the individual’s explicit consent, or otherwise authorised by law. Each condition requires careful adherence to ensure lawful processing:
Necessity for Contract
Automated decisions must be essential to fulfil contractual obligations with the data subject. Here are some examples:
1. Creditworthiness Assessments:
-
Financial institutions often use automated algorithms to assess creditworthiness when evaluating loan applications.
-
The algorithm might analyse factors like income, credit history, and debt-to-income ratio to determine eligibility and interest rates.
This is an important example because the contractual basis for processing personal data includes deciding whether or not to enter into a contract at all.
2. Employment:
-
Increasingly employers are using automated decision making to sift through CVs and employment applications. They will then select a sub-set of applications received for human review.
This example helps to highlight the difference between automated decision making and profiling. It is appropriate to automatically remove applications from people without degrees where having a degree is an essential requirement. It is absolutely not appropriate to remove applicants based on age or gender etc.
Explicit Consent
Individuals must give clear and informed consent, understanding the implications of automated decisions. You can use explicit consent for any kind of automated decision making or profiling but consent is not always the best lawful basis to use because people have the right to withdraw consent at any time.
Also consent must be freely given. That means you cannot deny access to other products or services if people refuse consent for automated decision making or profiling.
Also consent must be granular. That means you must separate out consent for automated decision making from other consent-based processing of personal data.
As with the contractual basis, where automated decision making and profiling are done it must be clearly and separately set out in your privacy statement and captured in your record of processing activity.
Authorisation by Law
Specific laws may explicitly allow automated decision making and profiling in some circumstances. These laws will also typically require appropriate safeguards.
Identity Verification and Fraud Detection
-
During the onboarding process, automated systems can verify a user’s identity using data like government IDs or perform fraud checks based on financial information.
Sign Up Here:
The GDPR empowers individuals with specific rights regarding automated decision making and profiling: As noted above individuals must be informed about the existence of automated decision making, its significance, and consequences. Data subjects can request human intervention to review and potentially alter automated decisions. Individuals have the right to challenge decisions made by automated processes and present their case to a human reviewer. This is an important point to understand. People have the right to challenge the process not the outcome. Organisations must maintain transparency in their automated decision making and profiling activities. This includes providing clear information about the logic involved, the significance, and the consequences of such processing. Accountability is achieved through comprehensive documentation, regular audits, and adherence to GDPR principles, ensuring that individuals’ rights are upheld at every stage. To protect data subjects, organisations must implement technical and organisational measures. These safeguards include: Limiting data collection to what is necessary for the intended purpose is a key GDPR principle. To get this right organisations must plan for the data they need and the purposes they need it for. Protecting personal data by making it less identifiable is an important safeguard. Continuously evaluating automated systems to ensure compliance and address potential issues. Data Privacy Impact Assessments (DPIAs) are almost certainly necessary for identifying and mitigating risks associated with automated decision making and profiling. DPIAs involve: Evaluating whether the processing is necessary and proportionate to the purpose. Systematically assessing potential risks to data subjects’ rights and freedoms. Developing strategies to minimise identified risks. Automated decision-making (ADM) and profiling using personal data offer efficiency and convenience, but they come with inherent risks. Here’s a breakdown of some key concerns: Data Bias: Algorithms can inherit and amplify biases present in the data they’re trained on. This can lead to discriminatory outcomes, denying opportunities or resources to certain groups based on factors like race, gender, or socioeconomic background. Algorithmic Bias: The design and development of ADM systems can introduce unintended biases. For example, facial recognition algorithms have been shown to have higher error rates for certain ethic groups, leading to disproportionate legal effects. “Black Box” Problem: Complex algorithms can be opaque, making it difficult to understand how they arrive at decisions. This lack of transparency can make it challenging to assess fairness and identify potential biases. Right to Explanation: Individuals may have difficulty understanding how their data is used in automated processes, hindering their ability to exercise their right to explanation under regulations like GDPR. Data Quality: The accuracy of outputs depends heavily on the quality of the data used to train and run the algorithms. Errors or inconsistencies in data can lead to unfair or inaccurate decisions. Algorithmic Errors: Algorithms can make mistakes, especially when dealing with complex or nuanced situations. This can have negative consequences for individuals if not properly addressed. Data Collection and Use: ADM often relies on vast datasets, raising concerns about data minimization and potential misuse of personal information. Surveillance and Social Scoring: Extensive use of ADM for profiling can lead to intrusive surveillance and the creation of social scoring systems, impacting individuals’ freedoms and opportunities. By acknowledging these risks and taking proactive steps to mitigate them, organisations can leverage the benefits of automated decision making and profiling while ensuring responsible and ethical use of personal data. The landscape of automated decision making and profiling is rapidly evolving with advancements in AI and machine learning. As technologies advance, GDPR regulations must be understood to address new challenges and opportunities. Emerging trends, such as explainable AI and enhanced transparency mechanisms, offer promising solutions to balance innovation and data protection. To balance this it is likely that there will be an increased emphasis on engagement with people to understand their personal preferences and provide assurance of compliance with their legal rights. Automated decision making and profiling present both opportunities and challenges in the realm of data protection. GDPR provides a comprehensive framework to ensure these practices are conducted fairly and transparently, safeguarding individuals’ rights. By implementing robust safeguards, conducting impact assessments, and maintaining accountability, organizations can harness the benefits of automation while respecting data subjects’ rights. Balancing innovation with privacy protection remains a pivotal goal in the evolving landscape of data processing. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
Rights of Data Subjects
The Right to Be Informed
Right to Obtain Human Intervention
Right to Contest Decisions
Transparency and Accountability
Implementing Safeguards
Data Minimisation
Anonymisation and Pseudonymisation
Regular Monitoring and Assessment
Data Privacy Impact Assessments
Challenges and Risks
Bias and Discrimination:
Transparency and Explainability:
Accuracy and Fairness:
Privacy Concerns:
Future Directions and Technological Advancements
Conclusion
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: