Profiling
In a data protection context, profiling generally means using personal data to automatically analyze or predict things about a person, such as their behavior, preferences, interests, or likely future actions. It can help organizations tailor services, but it can also affect individuals in significant ways, which is why data protection regimes pay particular attention to it. The term is also used in unrelated fields such as software engineering and criminal investigation, where it means something different.
Within data protection frameworks, profiling typically refers to any form of automated processing of personal data that evaluates certain personal aspects relating to an individual, in particular to analyze or predict attributes such as behavior, interests, economic situation, health, preferences, reliability, location, or movements. The specific statutory definition and the associated obligations, including any rules concerning solely automated decision-making with legal or similarly significant effects, are set by the applicable instrument and are framed most prominently under the EU GDPR and, in materially similar but separately enacted terms, the UK GDPR; treatment differs under other regimes such as the CCPA/CPRA, HIPAA, ISO/IEC 27701, and the NIST Privacy Framework, and the evidence provided does not establish a uniform cross-regime definition. Profiling as understood here should not be conflated with the same word as used in software engineering (measuring the runtime behavior of a program) or in criminal or psychological investigative methodologies, which are distinct concepts. This entry defines the term only; it does not address the specific lawfulness conditions, rights of the data subject, safeguards, transparency requirements, or any restrictions on automated decision-making, all of which depend on the governing instrument, jurisdiction, and implementation.
Why it matters
Profiling matters because it shifts the way organizations relate to individuals: rather than acting on information a person has knowingly provided, an organization draws automated inferences and predictions about that person's behavior, preferences, economic situation, health, reliability, location, or movements. Those inferences can shape decisions that individuals never see and cannot easily contest, which is why data protection regimes give profiling particular attention. Under the EU GDPR and the separately enacted UK GDPR, profiling is defined in specific statutory terms and is closely associated with rules concerning solely automated decision-making that produces legal or similarly significant effects. Treatment differs under other regimes such as the CCPA/CPRA, HIPAA, ISO/IEC 27701, and the NIST Privacy Framework, and there is no single uniform cross-regime definition to rely on.
Who it's relevant to
Inside Profiling
Common questions
Answers to the questions practitioners most commonly ask about Profiling.