Automated decision-making
Under Article 22 GDPR, automated decision-making means a decision based solely on automated processing that produces legal effects or similarly significantly affects a person.
Automated decision-making under Article 22 GDPR concerns a decision made solely on the basis of automated processing, including profiling, where the decision produces legal effects or similarly significantly affects a natural person. A fully automated rejection of a credit application or an automated selection decision in recruitment can therefore raise questions under this provision.
Not every decision supported by software is covered. The key question is whether a person actually and meaningfully intervenes in the decision process. Article 22 GDPR provides exceptions, including where the decision is necessary for a contract, expressly authorised by EU or Member State law, or based on the person’s explicit consent. Where an exception applies, suitable safeguards are required. These include at least the possibility of human intervention, presenting the person’s point of view and contesting the decision. Additional conditions apply when special categories of personal data are involved.
Businesses should therefore document the purpose, data, decision criteria, human oversight and information provided before deploying such a system. The privacy compliance and governance topic supports the organisational assessment. Decisions concerning employees should also be reviewed through employee data protection. The overview of data subject rights and access helps organise communication with affected persons.
Learn more
Legal framework
General orientation, not individual advice.
Discuss your data protection matter
Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.
Clarify a data protection question
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000