Skip to main content
Category: Data Subject Rights

Right Not to Be Subject to Automated Decision-Making

Also known as: Rights related to automated decision-making including profiling, Automated individual decision-making, Right regarding solely automated decisions
Simply put

This is a right that generally allows an individual to object to having a significant decision about them made purely by a computer or algorithm, with no meaningful human involvement. It typically applies where such a decision has a legal effect on the person or similarly significant consequences, and often includes profiling. There are exceptions, so the right is not absolute and depends on the circumstances and applicable safeguards.

Formal definition

Under the UK GDPR (and its EU GDPR counterpart, generally associated with Article 22, which readers should verify against the current official text), a data subject generally has the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them. 'Solely' automated processing typically refers to processing carried out without meaningful human involvement in the decision. The right is subject to exceptions and conditions; for example, in a law enforcement processing context, a significant decision based solely on automated processing may generally not be taken unless required or authorised by law. Where the right does not apply because an exception is engaged, controllers are typically still required to implement safeguards. The precise conditions, exceptions, and required safeguards depend on the applicable legal regime and any national implementing law or member state derogations, and should be assessed case by case.

Why it matters

Automated decision-making increasingly shapes outcomes that carry real consequences for individuals, from access to credit and employment screening to eligibility determinations. Where a decision is made solely by an algorithm with no meaningful human involvement and produces legal effects or similarly significant effects, the individual can be affected without any opportunity to explain their circumstances or challenge a flawed result. This right, generally associated with Article 22 of the UK and EU GDPR (which readers should verify against the current official text), exists to place limits on that dynamic and to require safeguards where such processing is permitted.

For organisations, the right matters because it constrains when purely automated significant decisions may lawfully be taken and typically requires safeguards even where an exception is engaged. In a law enforcement processing context, for example, a significant decision based solely on automated processing generally may not be taken unless required or authorised by law. Misclassifying a process as involving meaningful human review when the human role is only nominal can expose a controller to compliance risk.

The right also connects to broader accountability and transparency expectations around automated systems. Commentary in this area, including work discussing a so-called right to explanation, frames such mechanisms as ways to enhance the accountability and transparency of automated decision-making. The precise contours of any explanation obligation are subject to ongoing debate and guidance, and the position can vary between regulators and under national implementing law, so organisations should assess their obligations case by case rather than assume a single settled interpretation.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams need to identify where processing involves solely automated significant decisions, confirm whether an exception applies, and ensure appropriate safeguards are in place. This includes assessing whether any human involvement in a decision is genuinely meaningful rather than nominal, and documenting the legal basis and conditions relied upon, subject to the applicable regime and any national derogations.
Engineers and Product Teams Building Automated Systems
Teams designing profiling or automated decision systems should understand that a decision made without meaningful human involvement may trigger this right where it produces legal or similarly significant effects. Design choices around where and how humans review or influence outcomes can determine whether a process is treated as 'solely' automated, and safeguards may be required even where an exception is engaged.
Lawyers Advising on Automated Processing
Legal advisers assess whether the right is engaged, which exceptions may apply, and what safeguards are required in a given context, including law enforcement processing where such decisions generally may not be taken unless required or authorised by law. Advisers should account for divergence between regulators, evolving guidance on transparency and explanation, and national implementing law, and verify article references and conditions against the current official text.
Individuals Subject to Automated Decisions
Individuals affected by decisions made solely by automated means, including profiling, that carry legal or similarly significant effects may generally be able to invoke this right, subject to applicable exceptions. Related transparency and accountability mechanisms are often discussed as ways to help individuals understand and challenge such decisions, though their precise scope depends on the applicable framework.

Inside Right Not to Be Subject to Automated Decision-Making

Article 22 core right
The right for a data subject generally not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. The right derives from Article 22 of the GDPR.
Solely automated processing
The provision typically applies where there is no meaningful human involvement in the decision. According to regulatory guidance, human involvement must be substantive rather than a token gesture; nominal or rubber-stamp review may not remove a decision from the scope of Article 22.
Legal or similarly significant effects
The right is generally engaged only where the decision produces legal effects (such as affecting legal rights or status) or similarly significantly affects the individual. What crosses this threshold is subject to assessment and has been the subject of regulatory guidance; the boundary can be uncertain in some cases.
Profiling
Automated processing of personal data to evaluate certain personal aspects of an individual. Profiling may fall within the scope of this right where it forms the basis of a qualifying solely automated decision, though not all profiling triggers Article 22.
Exceptions to the prohibition
Article 22 sets out situations where such decision-making may nonetheless be permitted, generally including where it is necessary for entering into or performing a contract, is authorised by Union or Member State law, or is based on the data subject's explicit consent. Member state law can vary the position for the law-based exception.
Safeguards where an exception applies
Where a permitted exception is relied upon, the controller must generally implement suitable safeguards, which typically include at least the right to obtain human intervention, to express one's point of view, and to contest the decision.
Special category data constraints
Where a qualifying automated decision is based on special category data under Article 9, additional conditions generally apply, and the available exceptions are typically narrower than for other personal data.
Related transparency obligations
Separate provisions on information to be provided to data subjects generally require meaningful information about the logic involved and the significance and envisaged consequences of such processing, though these transparency duties are distinct from the Article 22 right itself.

Common questions

Answers to the questions practitioners most commonly ask about Right Not to Be Subject to Automated Decision-Making.

Does this right mean an organization can never make decisions about individuals using automated processing?
No. The right addresses a specific category of processing: decisions based solely on automated processing, including profiling, that produce legal effects concerning the individual or similarly significantly affect them. It is not a blanket prohibition on all automated processing. Many forms of automated processing fall outside its scope, for example where there is meaningful human involvement in the decision, or where the decision does not have a legal or similarly significant effect. The precise boundary of what counts as 'solely' automated and 'similarly significantly affects' is subject to regulatory guidance and interpretation, so each use case should be assessed on its facts.
Is consent always required before carrying out automated decision-making that falls within this right?
Not necessarily. Consent is only one of the recognized grounds on which such decision-making may be permitted. Automated decisions of the relevant kind are generally restricted unless an applicable exception applies, which typically includes where the decision is necessary for entering into or performing a contract, where it is authorized by Union or Member State law with suitable safeguards, or where it is based on the individual's explicit consent. Because Member State law and additional conditions can vary the position, and because special category data attracts further requirements, the correct ground should be identified for each specific decision rather than defaulting to consent.
How can an organization determine whether a decision is 'solely' automated or involves meaningful human involvement?
The distinction generally turns on whether a human exercises genuine, meaningful oversight rather than a token or rubber-stamp review. Regulatory guidance has indicated that human involvement should be carried out by someone with the authority and competence to change the decision, taking into account all relevant information. Where a person merely applies an automated output without real assessment, the processing may still be treated as solely automated. Organizations should document how and where human judgment is exercised, and be aware that the assessment is fact-specific and continues to be shaped by guidance and case law; verify against current official sources.
What safeguards should typically be put in place where permitted automated decision-making is used?
Where such decision-making is carried out on a permitted ground, suitable safeguards for the individual's rights, freedoms, and legitimate interests are generally expected. These typically include, at minimum, the ability to obtain human intervention, to express one's point of view, and to contest the decision. Organizations commonly also consider measures such as testing for accuracy and bias, providing meaningful information about the logic involved, and reviewing outcomes. The specific safeguards required can depend on the legal ground relied upon and on applicable national law, so these should be mapped to the relevant provisions rather than applied uniformly.
How does this right interact with transparency and information obligations?
Where automated decision-making of the relevant kind takes place, individuals are generally entitled to be informed about its existence and to receive meaningful information about the logic involved, as well as the significance and envisaged consequences of the processing. This information is typically provided through privacy notices and can also arise in response to an access request. The level of detail considered 'meaningful' is a matter of ongoing guidance and interpretation, and does not generally require disclosing the full underlying algorithm or trade secrets; the appropriate balance should be assessed case by case.
What additional considerations apply when automated decision-making involves special category data?
Automated decisions of the restricted kind that are based on special category data are generally subject to tighter constraints. Such decisions typically may only be carried out where a relevant condition for processing special category data applies, alongside the ground permitting the automated decision itself, and where suitable measures to safeguard the individual's rights and interests are in place. Because the conditions for special category data and the availability of Member State derogations can vary, organizations should confirm that both the general and the additional requirements are satisfied and verify the current position against official texts.

Common misconceptions

Article 22 bans all automated decision-making.
It is generally understood as a qualified right rather than an absolute prohibition. It typically applies only to decisions based solely on automated processing that produce legal or similarly significant effects, and recognised exceptions (such as contractual necessity, authorising law, or explicit consent) may permit such processing subject to safeguards.
Adding any human to the process removes the decision from Article 22.
Regulatory guidance indicates the human involvement must be meaningful and substantive. A token or rubber-stamp review that does not genuinely influence the outcome may not take the decision outside the scope of the right; this is subject to assessment of the facts.
Consent is always the required basis for automated decision-making.
Explicit consent is only one of the routes that may permit a qualifying automated decision. Contractual necessity or authorising Union or Member State law can also apply, and the appropriate route depends on the context rather than a universal consent requirement.

Best practices

Map and inventory processing activities to identify where decisions are based solely on automated processing and could produce legal or similarly significant effects, documenting the assessment of that threshold.
Where an exception is relied upon, document which route applies (contractual necessity, authorising law, or explicit consent) and confirm any applicable Member State law conditions, rather than defaulting to consent.
Implement and evidence the required safeguards, generally including a route to obtain meaningful human intervention, to express a point of view, and to contest the decision.
Ensure human review is substantive by empowering reviewers with authority and information to change outcomes, and avoid processes that amount to a token or rubber-stamp check.
Apply heightened scrutiny where special category data is involved, verifying that a narrower Article 9 condition is met before relying on any exception.
Provide clear transparency information about the logic involved and the significance and envisaged consequences, and verify current regulatory guidance as interpretation of thresholds and safeguards continues to evolve.