Article 22 GDPR
Legal Text
1. The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
2. Paragraph 1 shall not apply if the decision:
(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller;
(b) is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or
(c) is based on the data subject's explicit consent.
3. In the cases referred to in points (a) and (c) of paragraph 2, the data controller shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.
4. Decisions referred to in paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1), unless point (a) or (g) of Article 9(2) applies and suitable measures to safeguard the data subject's rights and freedoms and legitimate interests are in place.
Relevant Recitals
The data subject should have the right not to be subject to a decision, which may include a measure, evaluating personal aspects relating to him or her which is based solely on automated processing and which produces legal effects concerning him or her or similarly significantly affects him or her, such as automatic refusal of an online credit application or e-recruiting practices without any human intervention. Such processing includes ‘profiling’ that consists of any form of automated processing of personal data evaluating the personal aspects relating to a natural person, in particular to analyse or predict aspects concerning the data subject's performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, where it produces legal effects concerning him or her or similarly significantly affects him or her. However, decision-making based on such processing, including profiling, should be allowed where expressly authorised by Union or Member State law to which the controller is subject, including for fraud and tax-evasion monitoring and prevention purposes conducted in accordance with the regulations, standards and recommendations of Union institutions or national oversight bodies and to ensure the security and reliability of a service provided by the controller, or necessary for the entering or performance of a contract between the data subject and a controller, or when the data subject has given his or her explicit consent. In any case, such processing should be subject to suitable safeguards, which should include specific information to the data subject and the right to obtain human intervention, to express his or her point of view, to obtain an explanation of the decision reached after such assessment and to challenge the decision. Such measure should not concern a child.
In order to ensure fair and transparent processing in respect of the data subject, taking into account the specific circumstances and context in which the personal data are processed, the controller should use appropriate mathematical or statistical procedures for the profiling, implement technical and organisational measures appropriate to ensure, in particular, that factors which result in inaccuracies in personal data are corrected and the risk of errors is minimised, secure personal data in a manner that takes account of the potential risks involved for the interests and rights of the data subject and that prevents, inter alia, discriminatory effects on natural persons on the basis of racial or ethnic origin, political opinion, religion or beliefs, trade union membership, genetic or health status or sexual orientation, or that result in measures having such an effect. Automated decision-making and profiling based on special categories of personal data should be allowed only under specific conditions.Commentary
Article 22 GDPR regulates so called automated individual decision-making (ADM). ADM refers to a decision made by the controller solely on automated processing (i.e. no meaningful human intervention) which produces either some legal effect concerning a data subject or similarly significantly affects them. This is a process that is widely used in an increasing area of situations, both in the public and private sector. E.g. ADM is widely used in Banking and Finance, healthcare, taxation, insurance, marketing and advertising.[1]
Article 22(1) GDPR provides for a description of a ADM as well as for the general prohibition of ADM.
Article 22(2) GDPR provides for three exemptions from this general prohibition. Namely, where ADM is necessary for entering into, or performance of, a contract between the data subject and a data controller; where it is authorised by EU or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests; or where it is based on the data subject’s explicit consent.
Article 22(3) GDPR requires controllers to implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests in case the ADM is based on the necessity to enter into, or perform a contract, or with the data subject's explicit consent. In case ADM is based on Union or Member State law to which the controller is subject, such law already must lay down such suitable measures. This Paragraph also specifies that the safeguards implemented by the controller must at least provide for the data subject's right to obtain human intervention on the part of the controller, to express their point of view and to contest the decision.
Finally, Article 22(4) GDPR sets further requirements for ADM based on special categories of personal data (Article 9(1) GDPR). Such ADM is only permissible, in case the data subject explicitly consented to the ADM or it is necessary for reasons of substantial public interest, on the basis of Union or Member State law, and suitable measures to safeguard the data subject's rights and freedoms and legitimate interests are in place.
WP29 Guidelines: see WP29, ‘Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679’, 17/EN WP251 rev.01, 6 February 2018, (available here).
(1) Prohibition on automated decision-making
Article 22(1) GDPR defines the scope of ADM as any decision based solely on automated processing, including profiling, which produces legal effects concerning a data subject or similarly significantly affects them. At the same time, this provision provides for a general prohibition of ADM. On the first glance, the wording of the provision ("shall have the right") indicates a mere data subject's right; however, the provision has to be understood as a prohibition in principle, which does not need to be invoked by the data subject to have an effect on the controller.[2]
"Article 22(1) of the GDPR confers on the data subject the ‘right’ not to be the subject of a decision solely based on automated processing, including profiling. That provision lays down a prohibition in principle, the infringement of which does not need to be invoked individually by such a person."
CJEU - C‑634/21 - SCHUFA Holding (Scoring), margin number 52.
The term “right” in the provision does not mean that Article 22(1) applies only when actively invoked by the data subject. Article 22(1) establishes a general prohibition for decision-making based solely on automated processing. This prohibition applies whether or not the data subject takes an action regarding the processing of their personal data.
Scope
Article 22(1) GDPR clarifies that ADM is any decision based solely on automated processing, including profiling, which produces legal effects concerning a data subject or similarly significantly affects them. Therefore, 3 cumulative conditions have to be met in order for a processing activity to constitute ADM:
- The controller must make a decision;
- The decision must be based solely on automated processing, including profiling; and
- The decision must produce legal effects concerning the data subject or similarly significantly affect them.
The applicability of [Article 22(1) GDPR] is therefore subject to three cumulative conditions, namely, first, that there must be a ‘decision’, secondly, that that decision must be ‘based solely on automated processing, including profiling’, and, thirdly, that it must produce ‘legal effects concerning [the interested party]’ or ‘similarly significantly [affect] him or her’."
CJEU - C‑634/21 - SCHUFA Holding (Scoring), margin number 43.
The title of Article 22 GDPR further suggests that the scope is limited to automated individual decision-making, i.e. a decision concerning an individual data subject. This requirement can also be derived from the 3 cumulative conditions mentioned above and requires that the decision is made with regard to an individual, excluding abstract decisions like implementing rules or guidelines subject to numerous data subjects and strategic decisions like the discontinuation of a business segment.[3]
Decision
The first condition required to trigger Article 22 GPDR is the presence of a "decision", which can be interpreted in a broad sense.[4] Examples of a decision can be official acts of public authorities such as decisions on tax returns,[5] as well as automatic refusals of online credit applications or similar decisions in the context of e-recruiting practices.[6] Although there does not seem to be a specific requirement for the decision to be formalised in a particular way, it should at least be distinguishable from other stages of the decision-making process.
"As regards, first, the condition relating to the existence of a decision, it should be noted that the concept of ‘decision’, within the meaning of Article 22(1) of the GDPR, is not defined by that regulation. However, it is apparent from the very wording of that provision that that concept refers not only to acts which produce legal effects concerning the person at issue but also to acts which similarly significantly affect him or her.
The broad scope of the concept of ‘decision’ is confirmed by recital 71 of the GDPR, according to which a decision evaluating personal aspects relating to a person, to which that person should have the right not to be subject, ‘may include a measure’ which either produces ‘legal effects concerning him or her’, or, ‘similarly significantly affects him or her’. Under that recital, the term ‘decision’ covers, for example, the automatic refusal of an online credit application or e-recruiting practices without human intervention.
The concept of ‘decision’ within the meaning of Article 22(1) of the GDPR is thus [...] capable of including a number of acts which may affect the data subject in many ways, since that concept is broad enough to encompass the result of calculating a person’s creditworthiness in the form of a probability value concerning that person’s ability to meet payment commitments in the future."
CJEU - C‑634/21 - SCHUFA Holding (Scoring), margin number 44 et seqq.
Based solely on automated processing, including profiling
The second condition requires that the decision is based solely on automated processing, including profiling.[7]
automated processing
For a processing activity to be based solely on automated processing, there must be no human involvement in the decision process. However, in order for human involvement to prevent the applicability of Article 22(1) GDPR, the involvement has to be meaningful; i.e. the intervention must be meaningful and not just a pretext in order to avoid the consequences of Article 22 GDPR.[8] Human intervention can only be considered meaningful, in case it is carried out by someone who has the authority and competence to change the decision and the human involved exercise this competence by considering all the relevant data and verifying the substance and correctness of the machine-generated decision.[9] Therefore, it should be considered, whether human intervention is even possible from a technical perspective, or whether the decision-making process is constructed in a solely algorithmic way with no room for human involvement.
For example: A online-retailer decides in real time whether it sends goods to customers without prior payment (buy now - pay later) based on the customers profile. If an employee of the retailer screes hundreds of purchases per hour simply "confirming" the automated decision based on the customer's profile, this is not sufficient to be considered meaningful human intervention.
The controller cannot avoid the Article 22 provisions by fabricating human involvement. For example, if someone routinely applies automatically generated profiles to individuals without any actual influence on the result, this would still be a decision based solely on automated processing.
Further, the "automated processing" criterion in Article 22(1) GDPR is related to the final stage of the processing, which results in a solely automated decision based on already existing data. By contrast, the methods of collecting the initial data sources must not necessarily be automated, and can be semi-automated or even manual.[10]
Profiling
Article 4(4) GDPR defines profiling as any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.[11]
For example, automated credit scoring falls under the definition of profiling:
As regards, secondly, the condition according to which the decision, within the meaning of that Article 22(1), must be ‘based solely on automated processing, including profiling’, [...] it is common ground that an activity such as that of SCHUFA meets the definition of ‘profiling’ appearing in Article 4(4) of the GDPR and therefore that that condition is met in the present case, since the wording of the first question referred explicitly refers to the automated establishment of a probability value based on personal data relating to a person and concerning that person’s ability to repay a loan in the future.
CJEU - C‑634/21 - SCHUFA Holding (Scoring), margin number 47.
It should be noted however, that not all profiling leads to ADM; if a decision is based on profiling, but there is meaningful human intervention involved, Article 22 GDPR is not applicable.[12]
Automated decisions can be made with or without profiling; profiling can take place without making automated decisions. However, profiling and automated decision-making are not necessarily separate activities. Something that starts off as a simple automated decision-making process could become one based on profiling, depending upon how the data is used. [...] Decisions that are not solely automated might also include profiling.
Legal or similarly significant effects
Legal Effects
A decision has legal effects on a data subject when it is binding and affects the person’s rights.[13] It is not necessary, that the legal effect is negative for the data subject; a positive legal effect is also a legal effect in accordance with this provision.[14]
A legal effect requires that the decision, which is based on solely automated processing, affects someone’s legal rights, such as the freedom to associate with others, vote in an election, or take legal action. A legal effect may also be something that affects a person’s legal status or their rights under a contract. Examples of this type of effect include automated decisions about an individual that result in:
- cancellation of a contract;
- entitlement to or denial of a particular social benefit granted by law, such as child or housing benefit;
- refused admission to a country or denial of citizenship.
Similarly significant effects
In principle, satisfying this criterion means that the impacts of the decision must be considerable despite not changing the legal position of the individual. While it can be difficult to establish this in practice, according to the WP29 some guiding criteria for similarly significant effects include:
- significantly affects the circumstances, behaviour or choices of the individuals concerned;
- has a prolonged or permanent impact on the data subject; or
- at its most extreme, leads to the exclusion or discrimination of individuals.[15]
The WP29 also gives examples of decisions that can have effects which are similarly significant to legal ones. These include decisions that:
- affect someone’s financial circumstances, such as their eligibility to credit;
- affect someone’s access to health services;
- deny someone an employment opportunity or put them at a serious disadvantage;
- affect someone’s access to education, for example university admissions.[16]
In any case, the decision should have more than just a trivial effect, and impact someone’s position either in relation to other persons, or to access a service or opportunity. For example, Recital 71 GDPR mentions the “automatic refusal of an online credit application or e-recruiting practices without human intervention”.
Similarly, the CJEU found that credit rating performed by an credit information agency can have significant effects on the data subject:
[I]n the event where a loan application is sent by a consumer to a bank, an insufficient probability value leads, in almost all cases, to the refusal of that bank to grant the loan applied for.
In those circumstances, it must be stated that the third condition to which the application of Article 22(1) of the GDPR is subject is also fulfilled, since a probability value such as that at issue in the main proceedings affects, at the very least, the data subject significantly.
It follows that, in circumstances such as those at issue in the main proceedings, in which the probability value established by a credit information agency and communicated to a bank plays a determining role in the granting of credit, the establishment of that value must be qualified in itself as a decision producing vis-à-vis a data subject ‘legal effects concerning him or her or similarly significantly [affecting] him or her’ within the meaning of Article 22(1) of the GDPR."
CJEU - C‑634/21 - SCHUFA Holding (Scoring), margin number 48 et seqq.
Decisions resulting in targeted advertisement based on profiling could also significantly affect individuals, for example, when someone is targeted with high interest loans because they are known to be in financial difficulties and are particularly susceptible to accept such offers. In this context, the WP29 lays down a non-exhaustive list of characteristics that can be decisive in the assessment of each case, such as:
- the intrusiveness of the profiling process, including the tracking of individuals across different websites, devices and services;
- the expectations and wishes of the individuals concerned;
- the way the advert is delivered; or
- using knowledge of the vulnerabilities of the data subjects targeted.[17]
(2) Exceptions
While Article 22(1) GDPR provides for a general prohibition of ADM, Article 22(2) GDPR provides for some exemptions of this prohibitions. In other words, ADM is only permissible, in case one of those conditions is met.
(a) Contract
The first exception from the prohibition laid down in Article 22(1) GDPR applies if the decision is necessary for entering into, or performance of, a contract between the data subject and the controller. For an interpretation of the criterion of necessity see Commentary on Article 6(1) GDPR. This means, that the ADM is not just useful, but necessary for entering into, or the performance of a contract.
"The controller must be able to show that this type of processing is necessary, taking into account whether a less privacy-intrusive method could be adopted. 35 If other effective and less intrusive means to achieve the same goal exist, then it would not be ‘necessary’."
As stated by the WP29, this exemption is also applicable if ADM is necessary for pre-contractual processing.[18]
For example: A online-retailer receives hundreds of purchase orders each minute. An algorithm is utilized in order to filter out existing customers with a trouble-free purchase history and automatically sends out purchase confirmations. The manual screening of each purchase would be unfeasible for the retailer.
In any case, the application of Article 22(2)(a) GDPR is always subjected to the presence of “suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision” (see below on Article 22(3) GDPR).
(b) Authorised by law
Article 22(2)(b) GDPR provides for the second exemption from the prohibition of ADM in case it is authorised by Union or Member State law to which the controller is subject and such law also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests. (Regarding the requirement to provide suitable safeguards, see Commentary on Article 22(3) GDPR below.)
Regarding the suitable measures, these have to include the specific measures mentioned in Article 22(3) GDPR, i.e. the data subject's right to obtain human intervention on the part of the controller, to express their point of view and to contest the decision.[19] While the wording of the provision seems to suggest that such measures do not necessarily need to be the same as those foreseen by Article 22(3) GDPR and leave discretion to the Member States,[20] the CJEU clarified that these also apply to Article 22(2)(b) GDPR:
"With regard, more specifically, to Article 22(2)(b) of the GDPR, to which the referring court refers, it is apparent from the very wording of that provision that the national law which authorises the adoption of an automated individual decision must lay down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests.
In the light of recital 71 of the GDPR, such measures must include, in particular, the obligation for the controller to use appropriate mathematical or statistical procedures, implement technical and organisational measures appropriate to ensure that the risk of errors is minimised and inaccuracies are corrected, and secure personal data in a manner that takes account of the potential risks involved for the interests and rights of the data subject and prevent, inter alia, discriminatory effects on that person. Those measures include, moreover, at least the right for the data subject to obtain human intervention on the part of the controller, to express his or her point of view and to challenge the decision taken in his or her regard."
CJEU - C‑634/21 - SCHUFA Holding (Scoring), margin number 65 et seq.
The CJEU case law suggests, that any Member State law authorising ADM in accordance with Article 22(2)(b) GDPR have to comply with Article 6(3) GDPR, i.e. requirements for national law providing for legal obligations of the controller (Article 6(1)(c) GDPR) or determining a public interest (Article 6(1)(e) GDPR). For now, it remains an rather open question, whether a controller invoking Article 22(2)(b) GDPR has to similarly base the ADM on Article 6(1)(c) GDPR or Article 6(1)(e) GDPR or if also other legal bases (mainly legitimate interest under Article 6(1)(f) GDPR) can be invoked in this case.
"Thus, in the event that the law of a Member State authorises, under Article 22(2)(b) of the GDPR, the adoption of a decision solely based on automated processing, that processing must comply not only with the conditions set out in the latter provision and in Article 22(4) of that regulation, but also with the requirements set out in Articles 5 and 6 of that regulation. Accordingly, Member States cannot adopt, under Article 22(2)(b) of the GDPR, regulations which authorise profiling in disregard of the requirements laid down by those Articles 5 and 6, as interpreted by the case-law of the Court.
With regard in particular to the conditions of lawfulness, provided for in Article 6(1)(a), (b), and (f) of the GDPR, which are likely to apply in a case such as that at issue in the main proceedings, Member States are not empowered to provide additional rules for the implementation of those conditions, such an option being, in accordance with Article 6(3) of that regulation, limited to the reasons referred to in Article 6(1)(c) and (e) of that regulation."
CJEU - C‑634/21 - SCHUFA Holding (Scoring), margin number 68 et seq.
Also, the EDPB pointed out that Article 6(1)(f) GDPR can not be considered a law authorising automated decision making within the meaning of this provision.[21]
(c) Explicit consent
The third and last exemption from the prohibition of ADM in Article 22(1) GDPR applies if it is based on the data subject's explicit consent. The wording of Article 22(2)(c) GDPR (“explicit consent”) results in the same standard for this requirement as Article 9(2)(a) GDPR. Particular attention must be given to consent being freely given in the context of entering into or performance of a contract.[22] For more information on the interpretation of the term "explicit consent" see Commentary on Article 9(2)(a) GDPR.
"Article 22 requires explicit consent. Processing that falls within the definition of Article 22(1) poses significant data protection risks and a high level of individual control over personal data is therefore deemed appropriate."
Any decision based on the data subject's explicit consent is also subjected to the safeguards laid down in Article 22(3) GDPR (see Commentary on Article 22(3) GDPR bellow.)
(3) Safeguards
In case ADM is based on contractual necessity (Article 22(2)(a) GDPR) or the data subject's explicit consent (Article 22(2)(c) GDPR), Article 22(3) requires controllers to implement suitable measures to safeguard data subjects’ rights freedoms and legitimate interests. As mentioned above, in case ADM is authorised by Member or Union State law (Article 22(2)(b) GDPR) such law must also incorporate appropriate safeguarding measures.
Therefore, Article 22(3) GDPR lays down some safeguards which must be available to the data subjects in case of automated decision-making carried out under Article 22(2)(a) and (c) GDPR. I.e. the right to obtain human intervention on the part of the controller, to express the data subject’s point of view and to contest the decision. However, this list is not exhaustive and the controller might have to implement further safeguards.
These rights maintain a unifying element: in order to be exercised, they all require some kind of prior information that only the controller can provide. Take, for example, the right to challenge the decision. In order to do so, it is necessary to know which elements have been taken into account by the algorithm and what its logic is, albeit in summary form. Conversely, it would be logically impossible to challenge the decision. The same applies to the right to obtain human intervention. In order to meaningfully exercise it, it is necessary to know at least what procedure the data subject has to follow and which criteria guide the reviewer’s decision. Otherwise, it would be completely impossible to express one's own point of view.
It should therefore be noted that the controller's information obligation as well as the right of access provides for an obligation to inform data subjects about the ADM, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.[23]
"Furthermore, in the case of automated decision-making, such as that referred to in Article 22(1) of the GDPR, first, the controller is subject to additional information obligations under Article 13(2)(f) and Article 14(2)(g) of that regulation. Secondly, the data subject enjoys, under Article 15(1)(h) of that regulation, the right to obtain from the controller, in particular, ‘meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject’."
CJEU - C‑634/21 - SCHUFA Holding (Scoring), margin number 56.
Pursuant to Article 12(1) GDPR, which expressly refers to Article 22, the controller "shall take appropriate measures" to provide the information required "in a concise, transparent, intelligible and easily accessible form, using clear and plain language". In the light of the above, the controller is obliged to provide an explanation of ADM, enabling data subjects to exercise their rights provided for in Article 22(3) GDPR.[24]
"It is apparent from the examination of the purposes of the GDPR and, in particular, those of Article 15(1)(h) thereof that the right to obtain ‘meaningful information about the logic involved’ in automated decision-making, within the meaning of that provision, must be understood as a right to an explanation of the procedure and principles actually applied in order to use, by automated means, the personal data of the data subject with a view to obtaining a specific result, such as a credit profile. In order to enable the data subject effectively to exercise the rights conferred on him or her by the GDPR and, in particular, Article 22(3) thereof, that explanation must be provided by means of relevant information and in a concise, transparent, intelligible and easily accessible form."
CJEU - C‑203/22 - Dun & Bradstreet Austria, margin number 58.
However, clarifications will still be needed as to how the safeguards already mentioned by Article 22(3) GDPR can be operationalised and what their outcome will be. With regards to the legal consequences of the data subject expressing their point of view or contesting the decision, it is not clear from this provision how or by who contentious issues should be resolved in practice.[25]
In addition, effective implementation of a right to explanation faces both legal and technical issues. On the one hand, the problem arises of how to balance such a data subject's right with intellectual property rights and industrial secrets of the controller. On the other hand, due to the current level of development of machine learning technologies, it may be difficult for the controller to explain in details the logic behind processes partly beyond human understanding. However, from a legal perspective, the controllers should make sure to use algorithms or tools for ADM they understand well enough to explain and influence their functioning and effects in practice.
(4) Qualified prohibition of using special categories of data
Article 22(4) GDPR stipulates that any ADM permissible under Article 22(2) GDPR must not be based on special categories of personal data (Article 9(1) GDPR) unless the data subject has given their explicit consent in accordance with Article 9(2)(a) GDPR or the processing is necessary for reasons of substantial public interest in accordance with Article 9(2)(g) GDPR. In addition, the controller must put in place suitable measures to safeguard the data subject's rights and freedoms and legitimate interests.
This provision is supposed to counteract the particular potential for discrimination in case ADM is based on sensitive data.[26] Explicit consent in the context of Article 22(4) GDPR should be interpreted in a similar manner as to Article 22(2)(c) GDPR. The suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, should depend on the particular sensitivity of the processed data and potential consequences of the ADM.[27]
Decisions
→ You can find all related decisions in Category:Article 22 GDPR
References
- ↑ WP29, ‘Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679’, 17/EN WP251 rev.01, 6 February 2018, p. 5 (available here)
- ↑ CJEU, Case C-634/21, SCHUFA, 7 December 2023, martin number 52 (available here).
- ↑ Scholz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 20 GDPR, margin number 20 (NOMOS 2025, 2nd Edition).
- ↑ Bygrave, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 22 GDPR, p. 532 (Oxford University Press 2020); Buchner, in Kühling, Buchner, DS-GVO BDSG, Article 22 GDPR, margin number 24 (C.H. Beck 2024, 4th Edition).
- ↑ Brkan, Do Algorithms Rule the World? Algorithmic Decision-Making and Data Protection in the Framework of the GDPR and Beyond, in International Journal of Law and Information Technology, 27 (2019), p. 102.
- ↑ Recital 71 GDPR.
- ↑ For the definition of "profiling" see Commentary on Article 4(4) GDPR.
- ↑ WP29, ‘Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679’, 17/EN WP251 rev.01, 6 February 2018, p. 21 (available here).
- ↑ WP29, ‘Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679’, 17/EN WP251 rev.01, 6 February 2018, p. 21 (available here); Bygrave, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 22 GDPR, p. 533 (Oxford University Press 2020); see also Scholz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 22 GDPR, margin number 29 (NOMOS 2025, 2nd Edition).
- ↑ Bygrave, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 22 GDPR, p. 533 (Oxford University Press 2020).
- ↑ See commentary on Article 4(4) GDPR.
- ↑ Scholz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 22 GDPR, margin number 29 (NOMOS 2025, 2nd Edition).
- ↑ WP29, ‘Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679’, 17/EN WP251 rev.01, 6 February 2018, p. 21 (available here); Brkan, Do Algorithms Rule the World? Algorithmic Decision-Making and Data Protection in the Framework of the GDPR and Beyond, in International Journal of Law and Information Technology, 27 (2019), p. 102.
- ↑ Scholz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 22 GDPR, margin number 35 (NOMOS 2025, 2nd Edition); opposing opinion: Buchner, in Kühling, Buchner, DS-GVO BDSG, Article 22 GDPR, margin number 24a (C.H. Beck 2024, 4th Edition).
- ↑ WP29, ‘Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679’, 17/EN WP251 rev.01, 6 February 2018, p. 21 (available here).
- ↑ WP29, ‘Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679’, 17/EN WP251 rev.01, 6 February 2018, p. 22 (available here)
- ↑ WP29, ‘Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679’, 17/EN WP251 rev.01, 6 February 2018, p. 22 (available here)
- ↑ WP29, ‘Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679’, 17/EN WP251 rev.01, 6 February 2018, p. 23 (available here)
- ↑ See Commentary on Article 22(3) GDPR.
- ↑ Scholz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 22 GDPR, margin number 50 (NOMOS 2025, 2nd Edition).
- ↑ EDPB, '1/2024 on processing of personal data based on Article 6(1)(f) GDPR', 8 October 2024 (Version 1), margin number 81 (available here).
- ↑ See also Articles 4(11) and 7(4) GDPR, as well as Recital 43 GDPR.
- ↑ See Commentary on Article 13(2)(f), 14(2)(g) and 15(1)(h) GDPR.
- ↑ See in particular Commentary on Article 15(1)(h) GDPR.
- ↑ Brkan, Do Algorithms Rule the World? Algorithmic Decision-Making and Data Protection in the Framework of the GDPR and Beyond, in International Journal of Law and Information Technology, 27 (2019), p. 106.
- ↑ Buchner, in Kühling, Buchner, DS-GVO BDSG, Article 22 GDPR, margin number 44 (C.H. Beck 2024, 4th Edition).
- ↑ Compare Scholz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 22 GDPR, margin number 73 (NOMOS 2025, 2nd Edition).




