Skip to main content
Category: Data Subject Rights

Right to Human Review

Also known as: Right to Human Intervention, Right to a Human Decision Maker, Right to Human Involvement in Automated Decisions
Simply put

The right to human review lets an individual ask that a real person, rather than an automated system alone, be involved when a significant decision is made about them. In UK and EU data protection law, this right generally applies only when a decision is based solely on automated processing and produces legal effects or similarly significant effects on the person. Where it applies, the individual can typically request human intervention, express their point of view, and challenge the decision.

Formal definition

The right to human review refers to a data subject's entitlement, in the context of solely automated decision-making, to obtain human intervention, to express their view, and to contest the outcome. Under the UK GDPR and Data Protection Act 2018 (and analogously under the EU GDPR), the ICO indicates this right is engaged where a decision is based solely on automated processing and produces legal effects or similarly significantly affects the individual; requests may be made verbally or in writing. The obligation to inform individuals of, and to give effect to, this right rests with the controller determining the purposes and means of the processing, not the processor. This entry covers the conceptual basis and triggering threshold only; it does not address the specific exceptions permitting solely automated decisions (for example where authorised by law, necessary for a contract, or based on explicit consent), the mechanics of human intervention procedures, provisions concerning special category data, or the differing treatment of automated decision-making under regimes outside the UK/EU, which vary and should be assessed separately. Accountability for compliance requires demonstrable evidence that a meaningful, competent human review is available rather than a nominal rubber-stamp, and no single procedural measure guarantees compliance across contexts.

Why it matters

The right to human review addresses a specific concern in data protection: that individuals should not be subject to consequential decisions determined entirely by automated systems without any avenue to involve a person. Under the UK GDPR and Data Protection Act 2018, and analogously under the EU GDPR, this right is not a general entitlement to human involvement in every automated process. As the ICO indicates, it is engaged only where a decision is based solely on automated processing and produces legal effects or similarly significantly affects the individual. Where that threshold is met, individuals can typically request human intervention, express their point of view, and challenge the outcome.

For controllers, the practical significance lies in accountability. Offering human review in name only, a nominal rubber-stamp rather than a meaningful, competent review, does not generally satisfy the underlying obligation. Demonstrable evidence that a genuine review is available, and that the reviewer has the authority and competence to alter the decision, is what supports a defensible compliance position. The obligation to inform individuals of this right, and to give effect to it, rests with the controller determining the purposes and means of the processing, not the processor.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads need to identify which processing activities involve solely automated decisions producing legal or similarly significant effects, since these are the activities where the right to human review is engaged under the UK/EU regimes. They are typically responsible for ensuring individuals are informed of the right and that meaningful review processes exist. This entry does not cover the exceptions permitting solely automated decisions, which must be assessed separately.
Controllers Deploying Automated Decision Systems
Organisations acting as controllers bear the obligation to inform individuals of, and give effect to, this right. Accountability requires demonstrable evidence that a competent human can meaningfully review and, where appropriate, alter a decision, rather than a rubber-stamp process. Controllers should not rely on any single procedural measure as a guarantee of compliance across contexts.
Compliance and Legal Teams
Legal and compliance professionals advising on automated decision-making should assess whether a given decision crosses the solely-automated and significant-effect threshold before concluding the right applies. They should also treat treatment under regimes outside the UK/EU as distinct, since it varies and is out of scope for this entry.
Privacy Engineers and System Designers
Those building or configuring automated decision systems should design for the possibility of genuine human intervention where the right may be engaged, including mechanisms that allow individuals to contest outcomes and express their view. Design decisions should support demonstrable evidence of meaningful review rather than nominal escalation paths.

Inside Right to Human Review

Solely Automated Decision-Making
The right to human review generally applies, under the EU GDPR and UK GDPR (as supplemented in the UK by the Data Protection Act 2018), to decisions based solely on automated processing without meaningful human involvement. Where a human meaningfully participates in the decision, the specific safeguards attaching to solely-automated decisions typically do not apply in the same way.
Significance Threshold
Under the EU GDPR and UK GDPR, the right is generally triggered only where a solely-automated decision produces legal effects concerning the individual or similarly significantly affects them. Decisions falling below this threshold do not typically attract the same right, though other transparency and fairness obligations may still apply.
Human Intervention Safeguard
Where the right applies, the data subject can generally request that a qualified person review the decision. To be meaningful, the reviewer typically must have the authority and competence to assess and, where appropriate, change the outcome, rather than merely rubber-stamping the automated result.
Ability to Contest and Express a View
The safeguards accompanying this right generally include the individual's ability to express their point of view and to contest the decision, alongside obtaining human intervention. These elements typically operate together rather than in isolation.
Accountability Evidence
Under governance and accountability principles, controllers generally need to demonstrate, through documented procedures, logs, and role assignments, that a genuine human review mechanism exists and functions. Stated intent to provide review is not sufficient; demonstrable evidence is typically required.
Controller Responsibility
The obligation to provide and operationalize human review generally rests with the data controller that determines the purposes and means of the automated processing, not with a processor acting solely on the controller's instructions.

Common questions

Answers to the questions practitioners most commonly ask about Right to Human Review.

Does the right to human review apply to every automated decision an organisation makes?
No. Under the EU GDPR and UK GDPR (as implemented via the DPA 2018), the right generally arises only where a decision is based solely on automated processing and produces legal effects concerning the individual or similarly significantly affects them. Decisions that involve meaningful human involvement, or that do not meet this significance threshold, typically fall outside the specific right, though other transparency and fairness obligations may still apply. Treatment differs in other regimes, so scope should be assessed per applicable law.
Is inserting a person somewhere in the workflow enough to avoid the right being triggered?
Not necessarily. The right generally attaches to decisions based solely on automated processing, and regulators have indicated that human involvement must be meaningful rather than a token or rubber-stamp step. A reviewer who lacks the authority, competence, or actual practice of examining and potentially overriding the output may not remove a decision from the 'solely automated' category. This entry does not set out the full evidentiary standard for demonstrating meaningful involvement, which depends on facts and jurisdiction.
How should an organisation identify which of its processing activities engage this right?
Generally this involves mapping decision-making processes to determine which are based solely on automated processing and which meet the legal-effects-or-similarly-significant-effects threshold. This exercise typically draws on records of processing activities and data flow documentation, though those artefacts serve broader governance purposes and are not themselves a determination of whether the right applies. Legal assessment of the significance threshold is usually required. Cross-border variations in how the threshold is interpreted are out of scope here.
What does a compliant human review process usually need to demonstrate?
In most cases the reviewer should have the authority and competence to assess the decision, consider relevant information provided by the individual, and be able to change the outcome. Under an accountability-based framing, organisations generally need demonstrable evidence of this, such as documented review procedures, reviewer training, and records of individual cases, rather than a stated policy alone. This entry does not prescribe a specific documentation format, which varies by organisation and regime.
What information typically needs to be provided to the individual so they can exercise the right?
Where the right applies, individuals generally need to be able to obtain human intervention, express their point of view, and contest the decision. Related transparency obligations often require meaningful information about the logic involved and the significance and envisaged consequences of the processing. The precise content and timing of such disclosures depend on the applicable regime and implementation, and this entry does not cover the associated notice or transparency requirements in full.
How does the right to human review relate to a data protection impact assessment?
Processing that involves solely automated decision-making with significant effects is commonly the kind of high-risk activity that may call for a data protection impact assessment, but the two are distinct: the right is an individual entitlement, while a DPIA is an organisational risk assessment process. A DPIA is not automatically required for all automated decision-making, and whether one is mandatory depends on the specific processing and jurisdiction. Enforcement consequences and retention of DPIA records are out of scope here.

Common misconceptions

The right to human review applies to every automated decision an organization makes.
Under the EU GDPR and UK GDPR, the specific right generally applies only to decisions based solely on automated processing that produce legal effects or similarly significantly affect the individual. Decisions involving meaningful human input, or those below the significance threshold, typically fall outside this specific right, though other obligations may still apply. Treatment differs across regimes such as the CCPA/CPRA, so scope should be assessed per applicable law.
Inserting any human step into the workflow automatically removes the decision from scope.
A nominal or perfunctory human step does not necessarily make a decision non-solely-automated. For the involvement to be meaningful, the reviewer generally needs the authority and competence to influence or change the outcome. A rubber-stamp does not typically satisfy the standard.
The right to human review is the same as a general right to appeal any organizational decision.
This right is a specific data protection safeguard tied to solely-automated decision-making meeting a defined threshold, generally including human intervention, the ability to express a view, and the ability to contest the decision. It is not a universal appeal right and does not cover all decision types, enforcement penalties, or cross-border transfer mechanics, which are out of scope for this entry.

Best practices

Map which of your processing activities constitute solely-automated decision-making and assess whether each produces legal or similarly significant effects on individuals, since the specific right generally applies only where both conditions are met under the EU GDPR and UK GDPR.
Ensure any human involved in a review has the authority and competence to change the outcome, and avoid relying on nominal or rubber-stamp steps that would not typically qualify as meaningful human intervention.
Provide clear channels for individuals to obtain human intervention, express their point of view, and contest a decision, and document how each of these safeguards is delivered in practice.
Maintain demonstrable evidence, procedures, role assignments, and review logs, so that accountability can be shown, recognizing that stated intent alone is generally insufficient under governance and accountability principles.
Assign clear responsibility for the review mechanism to the data controller and confirm that any processor obligations are reflected in contractual arrangements, since the core obligation generally rests with the controller.
Assess applicable requirements per jurisdiction rather than assuming a single approach, as the treatment of automated decision-making and human review differs across regimes such as the EU GDPR, UK GDPR/DPA 2018, and CCPA/CPRA.