Skip to main content
Category: Data Subject Rights

Rights Related to Automated Decision-Making

Also known as: Rights related to automated decision-making including profiling, Automated individual decision-making rights, Rights relating to automated decision-making and profiling
Simply put

This right generally allows an individual to object to decisions that are made about them entirely by automated systems, with no meaningful human involvement, where those decisions have a significant or legal effect on them. Automated decision-making can include profiling, such as using a computer to evaluate a person for a job, promotion, or similar outcome. The right is designed to give people protection and a say when a machine, rather than a person, decides something important about them.

Formal definition

Under the EU GDPR (and correspondingly the UK GDPR), a data subject generally has the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them. Processing is treated as solely automated where the decision is made without meaningful human intervention; profiling refers to the automated processing of personal data to evaluate certain personal aspects of an individual. This entry describes the existence and scope of the right as framed in the EU/UK GDPR context and does not cover the specific exceptions to the right, the safeguards a controller must implement where such processing is permitted, transparency obligations, or how comparable protections are treated under other regimes such as the CCPA/CPRA, HIPAA, ISO/IEC 27701, or the NIST Privacy Framework; treatment differs outside the GDPR context and readers should consult the applicable instrument. The accountability for lawfully deploying and, where required, restricting solely automated decision-making rests with the data controller.

Why it matters

As organizations increasingly deploy algorithmic systems to make or support decisions about individuals, the right relating to automated decision-making addresses a structural concern: that a person can be significantly affected by an outcome no human meaningfully reviewed. Under the EU GDPR, and correspondingly the UK GDPR, this right generally applies where a decision is based solely on automated processing, including profiling, and produces legal effects concerning the individual or similarly significantly affects them. The stakes are highest in contexts such as employment screening, credit and eligibility assessments, and similar evaluative outcomes, where a machine-driven decision can shape access to work, services, or benefits.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads need to identify where their organization makes decisions based solely on automated processing that could produce legal or similarly significant effects, and to assess whether human involvement in those processes is genuinely meaningful rather than nominal. Because accountability rests with the controller and must be demonstrable, they should ensure the organization can evidence how such systems are governed. Determining whether exceptions apply, and what safeguards or transparency obligations follow, falls outside this entry and requires consulting the applicable GDPR provisions and regulator guidance.
Privacy Engineers and System Designers
Those building or configuring decisioning systems, including profiling and scoring models, should recognize that the point at which a human review ceases to be meaningful is decisive for whether this right is engaged. Design choices, such as whether a human reviewer has authority and capacity to alter an outcome, directly affect whether processing is treated as solely automated. Engineers should surface these characteristics to compliance colleagues rather than assuming a human in the loop by itself removes the processing from scope.
Legal and Compliance Teams
Legal and compliance functions advising on employment screening, eligibility, credit, or similar evaluative processes should treat solely automated decisions with significant effects as engaging a distinct data subject right under the EU/UK GDPR. They should scope advice to the applicable instrument, since protections under regimes such as the CCPA/CPRA or others differ and should not be assumed equivalent. Advice on permitted grounds, required safeguards, and enforcement consequences goes beyond the scope of this definition.
Product and HR Decision Owners
Business owners of processes such as automated candidate evaluation, promotion assessment, or automated eligibility decisions are the operational source of the decisions this right addresses. They should coordinate with data protection colleagues before relying on solely automated outcomes with legal or similarly significant effects, and should be able to describe accurately where and how human judgment enters the process, since that determination drives whether the right applies.

Inside Rights Related to Automated Decision-Making

Scope of automated decision-making
Under the EU GDPR and UK GDPR, the relevant provisions concern decisions based solely on automated processing, including profiling, that produce legal effects concerning the individual or similarly significantly affect them. Processing that involves meaningful human involvement in the decision generally falls outside this specific right, though other data protection obligations still apply. Treatment differs in other regimes such as the CCPA and CPRA, HIPAA, and standards frameworks like ISO/IEC 27701 and the NIST Privacy Framework.
General prohibition with exceptions
In most cases under the EU and UK GDPR, individuals have the right not to be subject to a decision based solely on automated processing that has the described effects. This is generally framed as a qualified prohibition rather than an absolute one, with recognized exceptions typically including where the decision is necessary for a contract, authorized by applicable law, or based on the individual's explicit consent. The specific conditions depend on the applicable instrument.
Safeguards where processing is permitted
Where an exception applies, the controller is generally expected to implement suitable safeguards. These typically include the ability to obtain human intervention, to express one's point of view, and to contest the decision. The controller, not the processor, bears responsibility for establishing these safeguards.
Transparency and information about the logic
Information obligations generally require that individuals be informed about the existence of automated decision-making and provided with meaningful information about the logic involved, as well as the significance and envisaged consequences. This is an accountability-related obligation and, under governance principles, must be demonstrable rather than merely asserted.
Interaction with special category data
Automated decision-making that relies on special category (sensitive) data is generally subject to additional constraints and narrower exceptions than processing of ordinary personal data. Special category data should not be treated as interchangeable with personal data generally.
Roles and accountability
The data controller determines the purposes and means of the automated processing and typically bears the obligations to justify a lawful basis or exception, provide transparency, and offer safeguards. A processor acting on the controller's instructions does not generally bear these accountability obligations directly. Accountability requires demonstrable evidence of compliance, not stated intent alone.

Common questions

Answers to the questions practitioners most commonly ask about Rights Related to Automated Decision-Making.

Does the right related to automated decision-making prohibit all automated processing of personal data?
No. The right addressed here concerns decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect the individual, as framed under the EU GDPR and mirrored in the UK GDPR. Automated processing that involves meaningful human review, or that does not produce such significant effects, generally falls outside this specific right. Treating every use of automation or algorithmic tooling as prohibited is a common misreading. This entry does not cover the separate lawfulness, transparency, or fairness obligations that still apply to automated processing generally.
Is obtaining consent enough to satisfy obligations around solely automated decisions?
Not on its own. While explicit consent is one of the conditions that can permit solely automated decisions with significant effects under the EU and UK GDPR, consent is not interchangeable with the safeguards the framework also expects, such as the ability to obtain human intervention, express a point of view, and contest the decision. Relying on consent while omitting these safeguards would generally leave the obligation incompletely met. Consent should not be conflated with the other permitted conditions, and the correct condition depends on context. Enforcement treatment and interaction with other lawful bases are out of scope for this entry.
How do we determine whether a decision qualifies as solely automated?
The assessment generally turns on whether a human exercises meaningful, rather than token, oversight over the decision. A person who merely rubber-stamps an algorithmic output without authority or capacity to alter it may not constitute genuine human involvement, in which case the decision can still be treated as solely automated. Organisations typically document the point of human intervention, the reviewer's competence and authority, and the criteria applied. This entry does not prescribe a jurisdiction-specific test, and treatment may differ outside the EU and UK GDPR context.
What safeguards should be implemented when a solely automated decision with significant effects is permitted?
Where such processing is permitted under an applicable condition, organisations generally implement measures enabling the individual to obtain human intervention, to express their point of view, and to contest the decision, alongside clear information about the logic involved and the significance and envisaged consequences. Demonstrable evidence of these safeguards, not merely a stated policy, is typically expected under an accountability approach. This entry does not detail specific interface designs, retention periods for related records, or cross-border transfer implications.
Should a data protection impact assessment be carried out for automated decision-making?
Frequently, but not automatically. Automated decision-making involving profiling with significant effects is commonly among the processing activities that may trigger a data protection impact assessment under the EU and UK GDPR, yet a DPIA is not universally mandatory for every automated decision. The determination depends on the likelihood and severity of risk to individuals and applicable regulatory guidance. Assuming a DPIA is always required, or never required, are both errors. This entry does not set out the full DPIA triggering criteria or methodology.
What information about the automated decision logic should typically be provided to individuals?
Individuals are generally entitled to meaningful information about the logic involved and about the significance and envisaged consequences of the processing, rather than disclosure of proprietary source code or exhaustive technical detail. In practice this often means an accessible explanation of the main factors and how they influence outcomes. What is sufficient depends on context and applicable regulatory guidance under the EU and UK GDPR, and treatment may differ under other regimes. This entry does not cover trade-secret balancing or specific disclosure formats.

Common misconceptions

Any use of algorithms or profiling triggers the right related to automated decision-making.
Under the EU and UK GDPR, this specific right generally applies only to decisions based solely on automated processing that produce legal or similarly significant effects. Where there is meaningful human involvement, or where the effects are not significant, this particular provision typically does not apply, although other data protection obligations may still be relevant.
Obtaining the individual's consent is enough to satisfy all obligations for automated decision-making.
Explicit consent is one recognized exception in some instruments, but it is not interchangeable with other bases and does not on its own guarantee compliance. Even where an exception applies, the controller generally must still provide suitable safeguards such as human intervention and the ability to contest the decision, and must meet transparency obligations.
The right and its rules are the same across all privacy regimes.
The framing described here derives primarily from the EU GDPR and UK GDPR. The CCPA and CPRA, HIPAA, ISO/IEC 27701, and the NIST Privacy Framework are not interchangeable, and treatment of automated decision-making differs across jurisdictions and instruments.

Best practices

Determine whether a given decision is based solely on automated processing and whether it produces legal or similarly significant effects before assuming the specific right applies; document this assessment as demonstrable evidence.
Identify and record the specific exception relied upon (such as contractual necessity, legal authorization, or explicit consent) and confirm it is valid under the applicable instrument rather than assuming consent covers all cases.
Implement suitable safeguards where automated decision-making is permitted, including a means for individuals to obtain human intervention, express their point of view, and contest the decision.
Provide meaningful information about the logic, significance, and envisaged consequences of the processing in transparency notices, and retain evidence that this information was made available.
Apply heightened scrutiny and narrower exceptions where special category data is involved, and do not treat sensitive data as equivalent to ordinary personal data.
Confirm which party is the controller and ensure controller accountability obligations are met with demonstrable evidence, and scope any analysis to the applicable regime rather than assuming uniform treatment across jurisdictions.