Privacy
Glossary

Automated decision-making

Under Article 22 GDPR, automated decision-making means a decision based solely on automated processing that produces legal effects or similarly significantly affects a person.

In brief

Automated decision-making under Article 22 GDPR concerns a decision made solely on the basis of automated processing, including profiling, where the decision produces legal effects or similarly significantly affects a natural person. A fully automated rejection of a credit application or an automated selection decision in recruitment can therefore raise questions under this provision.

Not every decision supported by software is covered. The key question is whether a person actually and meaningfully intervenes in the decision process. Article 22 GDPR provides exceptions, including where the decision is necessary for a contract, expressly authorised by EU or Member State law, or based on the person’s explicit consent. Where an exception applies, suitable safeguards are required. These include at least the possibility of human intervention, presenting the person’s point of view and contesting the decision. Additional conditions apply when special categories of personal data are involved.

Businesses should therefore document the purpose, data, decision criteria, human oversight and information provided before deploying such a system. The privacy compliance and governance topic supports the organisational assessment. Decisions concerning employees should also be reviewed through employee data protection. The overview of data subject rights and access helps organise communication with affected persons.

General orientation, not individual advice.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich