Skip to main content
Category: Data Subject Rights

Automated Individual Decision-Making

Also known as: ADM, Solely automated decision-making, Automated decision-making
Simply put

Automated individual decision-making refers to a decision made about a person by automated means without any meaningful human involvement. Examples can include an online system deciding whether to grant a loan or an application. Individuals generally have rights concerning such decisions where the decision is based solely on automated processing and produces significant effects.

Formal definition

Automated individual decision-making describes the making of a decision about a data subject based solely on automated processing, meaning without meaningful human intervention in the outcome. Under the GDPR, this concept is addressed in Article 22, which provides that a data subject generally has the right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal effects concerning them or similarly significantly affects them. The prohibition is subject to exceptions (for example, where the decision is necessary for a contract, authorised by law, or based on the data subject's explicit consent), and the position under UK GDPR and law enforcement processing regimes may differ; for instance, in a law enforcement context a significant decision based solely on automated processing generally may not be taken unless required or authorised by law. Automated decision-making is distinct from profiling, though the two often overlap, and practitioners should assess whether human involvement is genuinely meaningful rather than nominal. The precise scope of terms such as 'solely,' 'meaningful human involvement,' and 'similarly significantly affects' is elaborated in regulatory guidance (including EDPB and ICO guidance) rather than solely in the Regulation text, and interpretation may evolve; readers should verify the current official text and applicable guidance.

Why it matters

Automated individual decision-making sits at the intersection of individual rights and the growing use of algorithmic and AI-driven systems in areas such as lending, recruitment, insurance, and access to services. Where a decision is based solely on automated processing and produces legal effects or similarly significantly affects a person, the GDPR affords data subjects specific protections under Article 22. This means organisations cannot treat solely automated significant decisions as a routine operational choice; they must generally be able to point to a lawful exception (such as necessity for a contract, authorisation by law, or the data subject's explicit consent) and put appropriate safeguards in place.

The concept carries practical weight because as automated and AI-based systems become more embedded in decisions that affect people's lives, the risk of opaque, unfair, or discriminatory outcomes rises. Regulatory guidance, including EDPB and ICO materials, emphasises that human involvement must be genuinely meaningful rather than a nominal rubber stamp, so an organisation cannot escape the Article 22 regime simply by inserting a token human step. Getting the assessment wrong can expose an organisation to compliance challenges and undermine individuals' ability to understand and contest decisions made about them.

The boundaries of key terms such as 'solely,' 'meaningful human involvement,' and 'similarly significantly affects' are elaborated largely through regulatory guidance rather than the Regulation text itself, and interpretation may evolve over time. The position also differs across regimes: the law enforcement processing context generally prohibits significant decisions based solely on automated processing unless required or authorised by law, and the UK GDPR position may diverge from the EU position. Practitioners should therefore verify the current official text and applicable guidance rather than rely on a single fixed interpretation.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams need to identify where solely automated significant decisions occur, confirm whether an Article 22 exception is available, and ensure appropriate safeguards are documented. They should pay particular attention to whether any human involvement in the process is genuinely meaningful rather than nominal, as this can be decisive to whether the regime applies.
Engineers and Product Teams
Those designing and building automated or algorithmic systems should understand at the design stage whether an outcome will be treated as a solely automated decision with significant effects. This informs whether to build in meaningful human review, mechanisms for individuals to contest decisions, and transparency features, subject to assessment against current guidance.
Privacy and Technology Lawyers
Lawyers advising on lending, recruitment, insurance, or AI-driven services need to assess the availability of exceptions, the applicable regime (including differences under the law enforcement processing context and potentially UK GDPR), and the evolving interpretation of terms like 'solely' and 'similarly significantly affects' drawn from EDPB and ICO guidance rather than the Regulation text alone.
Business Owners of Affected Processes
Those responsible for services that use automated systems to make decisions about individuals, such as approving applications or awarding outcomes, should be aware that these processes may trigger individual rights and that reliance on automation for significant decisions generally requires a lawful basis for the exception and appropriate safeguards.

Inside ADM

Automated processing
Decision-making conducted without meaningful human involvement, where the outcome is generated by algorithmic or automated means. The degree of human input is central to whether a decision falls within scope, and token or rubber-stamp human review generally does not remove a decision from the automated category.
Legal or similarly significant effects
The relevant provisions typically engage where a decision produces legal effects concerning the individual or similarly significantly affects them. This threshold limits the scope to consequential decisions rather than all automated processing, and its application is subject to assessment on the facts.
Profiling
The automated evaluation of personal aspects relating to an individual, which may feed into automated decisions. Profiling and automated decision-making are related but distinct concepts; profiling can occur without resulting in a solely automated decision.
Permitted grounds
Solely automated decisions with significant effects are generally restricted, but may be permissible where based on recognized grounds such as necessity for a contract, authorization under EU or member state law, or the individual's explicit consent. The exact conditions should be verified against the current official text, and member state derogations may vary the position.
Special category data safeguards
Where automated decisions involve special category data under Article 9, an additional Article 9 condition is generally required alongside suitable safeguards, reflecting the heightened protections for such data.
Safeguards and data subject rights
Where permitted, appropriate safeguards typically include the ability to obtain human intervention, to express a point of view, and to contest the decision. Transparency about the existence of automated decision-making and meaningful information about the logic involved is generally expected.

Common questions

Answers to the questions practitioners most commonly ask about ADM.

Is all automated processing of personal data restricted under the rules on automated individual decision-making?
No. The specific safeguards generally apply to decisions based solely on automated processing, including profiling, that produce legal effects concerning the individual or similarly significantly affect them. Automated processing that involves meaningful human involvement in the decision, or that does not produce such significant effects, typically falls outside this specific category, though it remains subject to the GDPR's general principles and other obligations. The precise boundary depends on assessment of the facts, and you should verify against the current official text and applicable regulatory guidance.
Does an individual always have an absolute right not to be subject to automated individual decision-making?
Not in absolute terms. The relevant provision is generally interpreted, including in regulatory guidance, as a prohibition subject to exceptions rather than a right the individual must actively invoke. Exceptions typically include where the decision is necessary for entering into or performing a contract, is authorised by Union or member state law, or is based on the individual's explicit consent. Where an exception applies, suitable safeguards are generally required. Member state law and guidance can vary the position, so verify against the applicable text.
When explicit consent or contractual necessity is the basis for a solely automated decision, what safeguards are typically expected?
In these situations, suitable measures to safeguard the individual's rights, freedoms, and legitimate interests are generally expected. These typically include, at minimum, the ability to obtain human intervention, to express one's point of view, and to contest the decision. The exact scope of appropriate safeguards is subject to assessment and may be informed by regulatory guidance, so you should confirm the current expectations against the applicable text and guidance.
How does automated individual decision-making interact with special category data?
Where a solely automated decision is based on special category data, additional constraints generally apply. Such processing typically requires that an Article 9 condition is satisfied, and in most cases the available exceptions narrow to explicit consent or substantial public interest grounds, alongside suitable safeguards. The precise conditions and any member state derogations should be verified against the current official text before relying on this basis.
What information about automated decision-making generally needs to be provided to individuals?
In cases involving qualifying automated individual decision-making, transparency obligations generally include informing individuals of the existence of the automated decision-making, providing meaningful information about the logic involved, and explaining the significance and envisaged consequences of the processing for them. The depth of explanation expected is subject to assessment and evolving guidance, so the scope of 'meaningful information about the logic' should be considered in light of current regulatory positions.
How can a Data Protection Impact Assessment relate to automated individual decision-making?
A Data Protection Impact Assessment under Article 35 may be relevant where processing involves a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based. Whether a DPIA is required in a given case is subject to assessment against the applicable criteria and any supervisory authority lists of processing operations that require one. This is distinct from, though may inform, the safeguards specific to automated individual decision-making.

Common misconceptions

All automated decision-making is prohibited under the GDPR.
The restriction generally applies to decisions based solely on automated processing that produce legal or similarly significant effects. Automated processing that involves meaningful human involvement, or that does not meet the significance threshold, is typically not caught by the specific restriction, though other GDPR obligations still apply.
Consent is always the required legal basis for automated decision-making.
Explicit consent is one recognized ground, but not the only one. Necessity for a contract or authorization under EU or member state law can also apply, subject to assessment. Consent should not be treated as a universal requirement, and the applicable ground depends on the specific circumstances.
Adding any human to the process removes a decision from scope.
Human involvement must generally be meaningful, carried out by someone with authority and competence to change the outcome. Nominal or rubber-stamp review typically does not convert a solely automated decision into one with genuine human involvement.

Best practices

Assess whether a given process amounts to a decision based solely on automated processing with legal or similarly significant effects before determining which obligations apply.
Identify and document the specific permitted ground relied upon, and where special category data is involved, confirm an additional Article 9 condition and suitable safeguards, verifying against the current official text.
Implement meaningful human intervention that is carried out by someone with authority and competence to alter the outcome, rather than nominal review.
Provide clear transparency to individuals about the existence of automated decision-making and meaningful information about the logic involved.
Establish accessible mechanisms allowing individuals to express their point of view and to contest decisions, and document how such requests are handled.
Review the position in light of applicable member state derogations and evolving regulatory guidance, noting where interpretation remains uncertain.