Safeguards for Automated Decisions
Safeguards for automated decisions are the protections that must be put in place when an organisation makes a decision about someone using only automated processing, without meaningful human involvement, where that decision has a significant effect on them. Under the GDPR framework, individuals generally have a right not to be subject to such decisions unless a specific exception applies, and where those decisions are permitted the individual is typically entitled to protections such as human review. The precise scope depends on how the decision and its effect are assessed in each case.
The term refers to the protective measures attaching to decisions based solely on automated processing, including profiling, that produce legal effects concerning the data subject or similarly significantly affect them, as addressed in Article 22 of the GDPR and the UK GDPR. Article 22 generally establishes a right for the data subject not to be subject to such solely automated decisions, subject to defined exceptions, and where an exception applies the controller must implement suitable safeguards for the data subject's rights, freedoms and legitimate interests. The application of these safeguards is contingent on the decision meeting the definitional threshold of being made solely by automated processing and having the requisite significant effect, and the reader should note that the UK regime has been subject to legislative change (for example provisions described as Article 22C under the DUAA), so the position may differ between the EU GDPR and UK law and should be verified against the current official text and applicable regulatory guidance. Special category data and the interaction with Article 9 conditions, as well as member state or national derogations, may vary the position and are not fully resolved by Article 22 alone.
Why it matters
Automated decision-making increasingly shapes outcomes that carry real consequences for individuals, from access to credit and employment to eligibility for services. Where a decision is made solely by automated processing and has a legal or similarly significant effect, the GDPR framework generally establishes a right for the individual not to be subject to that decision unless a defined exception applies. Safeguards for automated decisions exist to prevent people from being subjected to opaque, unchallengeable outcomes and to preserve their rights, freedoms and legitimate interests when such processing is permitted.
For organisations, these safeguards matter because they mark the difference between lawful and unlawful automated processing. Article 22 of the GDPR and the UK GDPR does not treat all automation the same way: the protections attach only where a decision meets the threshold of being made solely by automated processing and having the requisite significant effect. Misjudging that threshold, or deploying an automated system without the human review and other protections expected where an exception is relied upon, can expose an organisation to regulatory scrutiny and complaints from affected individuals.
The position is also in flux and should be handled with care. The UK regime has been subject to legislative change, including provisions described as Article 22C under the DUAA, meaning the EU GDPR and UK law may diverge. Organisations should verify the applicable rules against the current official text and relevant regulatory guidance, and should not assume that a treatment lawful in one regime is automatically lawful in the other.
Who it's relevant to
Inside Safeguards for Automated Decisions
Common questions
Answers to the questions practitioners most commonly ask about Safeguards for Automated Decisions.