Data Governance Atlas

Automated decisions, profiling and AI

For both sides

When a decision is "solely automated", why meaningful information about the logic is not the source code, and where model training sits in the framework.

NIST PF ID-PCM-P
ISO 27701 A.7.3.10
GDPR family Art 4(4)Art 13(2)(f)Art 15(1)(h)Art 21Art 22Art 35

Automated processing of personal dataPersonal dataAny information relating to an identified or identifiable person: names, IDs, location, online identifiers, and combinations that single someone out. is ordinary and mostly unremarkable. A narrow slice of it attracts specific rules, and the boundary is where the arguments are.

Profiling and automated decisions are different things

Profiling is any automated processing that evaluates personal aspects of someone — to analyse or predict performance at work, economic situation, health, preferences, reliability, behaviour, location or movements. ProfilingProfilingUpdate: UK automated-decision rules moved from an Art 22 prohibition to a safeguards regime (Arts 22A-22D) in force 2026-02-05. by itself is lawful with a basis; it does not require anything special.

Art 22 is narrower. It engages only where a decision is based solely on automated processing, including profiling, and produces legal effects or similarly significantly affects the person. Both limbs must be met.

“Solely” and the human-in-the-loop problem

A human who reviews and can genuinely change the outcome takes the decision outside Art 22. A human who clicks approve on whatever the system produced does not.

The distinction turns on authority and capability: does the reviewer have the standing to overrule, the information to form a view, and enough time to use it? A caseworker processing three hundred a day against a model output is a rubber stamp, and describing them as human oversight in a policy document does not change that.

This matters practically because organisations frequently believe they are outside Art 22 on the strength of a review step that would not survive being examined.

“Significantly affects”

Legal effects are clear enough: entitlement lost, contract terminated, benefit refused. “Similarly significantly affects” is broader and covers decisions with a comparable impact — credit refusal, exclusion from a service, materially different pricing, employment screening.

Ordinary personalisation usually falls short. It can cross the line where it exploits vulnerability, targets people in a way that affects their real choices, or determines access rather than presentation.

Where it is permitted, and what must follow

Solely automated significant decisions are permitted only where necessary for a contract, authorised by law, or based on explicit consent — and in the contract and consent cases you must provide safeguards: at minimum the right to obtain human intervention, to express a point of view, and to contest the decision. Special category dataSpecial category dataHealth, biometrics, racial or ethnic origin, beliefs, sexual orientation, trade-union membership — processing needs an extra condition. narrows the gate further.

Meaningful information about the logic

You must tell people, both proactively and on request, that this is happening, with meaningful information about the logic involved and the significance and envisaged consequences.

This is not the source code, the weights, or the training set. Nor is it a sentence saying “an algorithm decides”. What is required is an explanation the person can act on: what factors are used, roughly how they matter, what would change the outcome, and how to challenge it. Explaining the logic is not the same as disclosing the model, and commercial sensitivity does not remove the obligation — it shapes how you meet it.

Where model training sits

Training a model on personal data is processing and needs its own basis, its own purpose assessment, and its own place in the record. Points that recur:

  • Purpose limitation. Data collected to deliver a service and later used to train is reuse. Assess compatibility; do not assume it.
  • Minimisation. Training rarely needs full identifiers; whether the training set is personal data after processing is a question to answer, not to assert.
  • Rights still attach. If the training data is personal data, people retain rights over it, and “it is already in the model” is a design problem rather than an exemption.
  • Impact assessment. Large-scale profiling, novel technology and systematic evaluation are precisely the triggers that make one mandatory. See impact assessment methodology.

For someone on the receiving end

Ask three questions, in this order: was this decision made solely by automated means; what factors were used and what would change the outcome; and how do I obtain human review. The first determines which rules apply, the second is the logic obligation, and the third is the safeguard. An organisation that cannot answer the first has not assessed its own process.

How this differs elsewhere

The page above is written from a GDPR-family default. These are the recorded departures — family entries apply to every jurisdiction in that family at once.

US state privacy acts Works differently Applies to the whole US state acts

Framed as opt-out rights over profiling in furtherance of significant decisions, rather than a prohibition on solely automated decisions with safeguards.

The GDPR-family structure — prohibited unless one of three gateways applies, plus a right to human intervention — is not the model. States generally give a right to opt out of profiling in furtherance of decisions producing legal or similarly significant effects, with rulemaking filling in the detail. "Solely automated" is therefore not the pivotal question it is under the GDPR family.

United Kingdom Works differently This jurisdiction only

Reformed to permit more solely automated significant decisions, with safeguards, rather than prohibiting them subject to three gateways.

The DUAA reworks the automated decision-making provisions. The direction of travel is permissive relative to the EU position, with the protection shifted onto safeguards rather than onto the gateway. Confirm which provisions are in force before advising — this is the single most commonly overstated UK divergence.

Where this connects

Sources

Never independently verified.