Skip to main content
Category: Privacy Principles

Profiling

Also known as: automated profiling, data subject profiling
Simply put

In a data protection context, profiling generally means using personal data to automatically analyze or predict things about a person, such as their behavior, preferences, interests, or likely future actions. It can help organizations tailor services, but it can also affect individuals in significant ways, which is why data protection regimes pay particular attention to it. The term is also used in unrelated fields such as software engineering and criminal investigation, where it means something different.

Formal definition

Within data protection frameworks, profiling typically refers to any form of automated processing of personal data that evaluates certain personal aspects relating to an individual, in particular to analyze or predict attributes such as behavior, interests, economic situation, health, preferences, reliability, location, or movements. The specific statutory definition and the associated obligations, including any rules concerning solely automated decision-making with legal or similarly significant effects, are set by the applicable instrument and are framed most prominently under the EU GDPR and, in materially similar but separately enacted terms, the UK GDPR; treatment differs under other regimes such as the CCPA/CPRA, HIPAA, ISO/IEC 27701, and the NIST Privacy Framework, and the evidence provided does not establish a uniform cross-regime definition. Profiling as understood here should not be conflated with the same word as used in software engineering (measuring the runtime behavior of a program) or in criminal or psychological investigative methodologies, which are distinct concepts. This entry defines the term only; it does not address the specific lawfulness conditions, rights of the data subject, safeguards, transparency requirements, or any restrictions on automated decision-making, all of which depend on the governing instrument, jurisdiction, and implementation.

Why it matters

Profiling matters because it shifts the way organizations relate to individuals: rather than acting on information a person has knowingly provided, an organization draws automated inferences and predictions about that person's behavior, preferences, economic situation, health, reliability, location, or movements. Those inferences can shape decisions that individuals never see and cannot easily contest, which is why data protection regimes give profiling particular attention. Under the EU GDPR and the separately enacted UK GDPR, profiling is defined in specific statutory terms and is closely associated with rules concerning solely automated decision-making that produces legal or similarly significant effects. Treatment differs under other regimes such as the CCPA/CPRA, HIPAA, ISO/IEC 27701, and the NIST Privacy Framework, and there is no single uniform cross-regime definition to rely on.

Who it's relevant to

Data protection officers and privacy leads
Those advising on processing activities need to recognize when automated analysis of personal data amounts to profiling under the governing instrument, because the applicable definition and any related rules on automated decision-making are set by that instrument. Because the EU GDPR and UK GDPR frame profiling in materially similar but separately enacted terms, and other regimes treat it differently, the correct starting point is identifying which instrument governs.
Legal and compliance professionals
Legal teams should scope any assessment to the specific instrument in play rather than assuming a uniform cross-regime definition. This entry defines the term only and does not address lawfulness conditions, data subject rights, safeguards, transparency requirements, or restrictions on automated decision-making, all of which depend on jurisdiction and implementation.
Privacy engineers and system designers
Engineers implementing systems that infer or predict attributes about individuals should be careful not to conflate data-protection profiling with the unrelated software-engineering sense of profiling, which measures the runtime behavior of a program. The two share a name but are distinct concepts, and only the former triggers data protection considerations.

Inside Profiling

Automated evaluation of personal data
Profiling generally involves any form of automated processing of personal data to evaluate certain personal aspects relating to an individual, such as analyzing or predicting aspects concerning performance at work, economic situation, health, preferences, interests, reliability, behavior, location, or movements. This framing derives primarily from the EU GDPR and the UK GDPR; other regimes such as the CCPA and CPRA address related concepts under different terminology and scope.
Analysis or prediction component
Profiling typically requires an element of evaluation, analysis, or prediction about an individual, not merely the collection or classification of data. This analytical dimension distinguishes profiling from simple record-keeping.
Relationship to automated decision-making
Profiling and solely automated decision-making are related but distinct under the EU and UK GDPR. Profiling can occur without producing a decision, and automated decisions can be based on profiling. Specific provisions apply where decisions based solely on automated processing, including profiling, produce legal or similarly significant effects, but the precise conditions and exceptions are set out in the applicable regulation and are out of scope for this general definition.
Personal data as input
Profiling operates on personal data. Where inputs are pseudonymized, the data generally remains personal data and profiling obligations continue to apply. Truly anonymized data, if irreversibly and effectively anonymized, would typically fall outside these obligations, though achieving genuine anonymization is difficult to demonstrate.
Lawful basis and transparency requirements
Profiling as a processing activity generally requires an identified lawful basis and, in most jurisdictions applying the GDPR framework, appropriate transparency to data subjects. This entry does not cover the mechanics of selecting a lawful basis, cross-border transfer implications, retention rules, or enforcement penalties.
Accountability of the controller
The party determining the purposes and means of profiling generally acts as the data controller and bears the primary accountability obligation, which typically requires demonstrable evidence of compliance rather than stated intent. A processor carrying out profiling on documented instructions bears the obligations applicable to processors under the relevant instrument.

Common questions

Answers to the questions practitioners most commonly ask about Profiling.

Is profiling the same as automated decision-making?
No. Under the EU GDPR and UK GDPR, profiling refers to any automated processing of personal data used to evaluate, analyze, or predict aspects of a person, such as their behavior, preferences, or performance. Automated decision-making is a related but distinct concept: it concerns decisions produced without meaningful human involvement. Profiling may feed into automated decisions, but it can also inform decisions that involve human judgment, and automated decisions do not always rely on profiling. The two overlap most notably where a decision based solely on automated processing, including profiling, produces legal or similarly significant effects, which is subject to specific restrictions. This entry does not cover those restrictions in detail or how they are applied in other regimes such as the CCPA and CPRA.
Does profiling always require explicit consent from the individual?
Not necessarily. Consent is only one of several lawful bases that may apply under the EU GDPR and UK GDPR, and treating it as the default requirement is a common error. Depending on context, profiling may rely on other lawful bases, such as legitimate interests or performance of a contract, subject to the applicable safeguards and balancing tests. However, certain forms of profiling, particularly those involving special category data or automated decisions with legal or similarly significant effects, are subject to stricter conditions where consent or another specified basis may be required. Determining the appropriate lawful basis is context-dependent, and no single basis guarantees compliance. This entry does not resolve which basis applies to any specific profiling activity.
How do we determine whether a given processing activity qualifies as profiling?
Assess whether the activity involves automated processing of personal data and whether it is used to evaluate, analyze, or predict something about an individual. Both elements generally need to be present under the EU GDPR and UK GDPR framing. Purely manual analysis, or automated processing that does not evaluate personal aspects of a person, typically falls outside the definition. Because the classification affects which obligations and individual rights apply, this determination should be documented as part of your accountability evidence rather than asserted informally. This entry does not provide a jurisdiction-by-jurisdiction test.
When should we consider a data protection impact assessment for profiling activities?
A data protection impact assessment is not automatically required for all profiling. It is generally indicated where profiling is likely to result in a high risk to individuals, for example systematic and extensive evaluation based on automated processing that produces significant effects. The presence of profiling is a signal to evaluate risk, not an automatic trigger. The decision should be based on the specific nature, scope, context, and purposes of the processing, and the reasoning should be documented. This entry does not enumerate the full criteria for when an assessment is mandatory in each jurisdiction.
What transparency information should we typically provide to individuals subject to profiling?
In most cases under the EU GDPR and UK GDPR, individuals should be informed that profiling takes place and given information appropriate to the context. Where profiling supports certain automated decisions with legal or similarly significant effects, additional information may be expected, such as meaningful information about the logic involved and the significance and envisaged consequences. Transparency is a governance and accountability requirement, and stated intent alone is insufficient; the disclosures and their basis should be demonstrable. This entry does not specify the exact wording, format, or timing required, which depend on context and jurisdiction.
How do we document profiling to support accountability?
Accountability generally requires demonstrable evidence rather than a statement of intent. For profiling, this typically includes recording the purpose of the processing, the categories of personal data involved, the lawful basis relied upon, any risk assessment performed, and the safeguards and individual rights mechanisms in place. Where profiling forms part of processing activities, it may also be reflected in your records of processing activities; note that maintaining such records is an obligation and is not the same as deploying a data inventory tool. This entry does not prescribe a specific documentation format or cover retention rules for that documentation.

Common misconceptions

Profiling and solely automated decision-making are the same thing.
Under the EU and UK GDPR they are distinct concepts. Profiling is the automated evaluation of personal aspects and can exist without any decision being made, while solely automated decision-making refers to decisions produced without meaningful human involvement. Specific rules for decisions with legal or similarly significant effects apply to a subset of cases and should not be assumed to apply to all profiling.
Pseudonymizing or tokenizing the data means the activity is no longer profiling of personal data.
Pseudonymization is reversible and the data generally remains personal data, so profiling obligations continue to apply. Encryption and tokenization likewise do not render data non-personal. Only genuine, irreversible anonymization would typically remove data from scope, and that is difficult to achieve and demonstrate.
Profiling always requires consent from the individual.
Consent is only one of several possible lawful bases and should not be conflated with the others. Depending on context and jurisdiction, profiling may rest on a different lawful basis. No single lawful basis or consent mechanism guarantees compliance, which depends on purpose, context, and implementation. This entry does not determine which basis is appropriate for a given case.

Best practices

Document the specific purposes of any profiling activity and identify and record an appropriate lawful basis for it, rather than assuming consent is required or sufficient.
Distinguish in your records whether an activity is profiling alone or profiling that feeds a solely automated decision with legal or similarly significant effects, because different provisions of the applicable GDPR framework may apply.
Provide transparency to data subjects about profiling in line with the requirements of the relevant regime, and retain demonstrable evidence of compliance to satisfy accountability obligations.
Do not treat pseudonymized, encrypted, or tokenized inputs as outside scope; continue applying profiling and personal data obligations unless genuine, irreversible anonymization can be demonstrated.
Clarify controller and processor roles for the profiling activity and ensure processor instructions and obligations are documented where profiling is outsourced.
Assess whether a data protection impact assessment is warranted for the profiling in question based on the criteria in the applicable regulation, rather than assuming it is either always or never mandatory.