GDPR
Chapter III - Rights of the Data Subject

GDPR GDPR-Art.22: Automated individual decision-making, including profiling

Do not subject a data subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the decision is necessary for entering into or performing a contract between the data subject and the controller, is authorised by Union or Member State law that lays down suitable safeguards, or is based on the data subject's explicit consent. Where the contract or explicit consent route is used, implement suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express a point of view and to contest the decision. Such decisions must not be based on special categories of personal data unless explicit consent or substantial public interest applies and suitable safeguards are in place.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 30 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • s31 s 31 Use scores for contract decisions only on the statutory conditions
  • s37 s 37 Insurance: automated decisions only where the request is met or with human review rights
  • s54 s 54 Automated individual decisions only when authorised by law, never discriminatory
  • 3.1.3 3.1.3 No decision based solely on automated evaluation of work performance without a permitted ground
  • 5.6 5.6 Video monitoring: no video analytics of expressions or movements, no facial recognition

EU AI Act · 2 controls

  • AL-DPA-9 Right to Object and Automated Decisions
  • AM-DPA-14 Automated Decision-Making Safeguards

Bahrain PDPL · 1 control

  • BB-DPA-15 Section 18 - Automated Decision-Making Including Profiling

CCPA/CPRA · 1 control

  • CAYDPA-s12 Rights in Relation to Automated Decision-Making (s.12)
  • PIPL-Art24 Automated Decision-Making
  • UAE-PDPL-Art.11_12_13_14_15_16 Data subject rights (UAE PDPL Articles 11-16)
  • 5.5 5.5 No decisions solely by automated processing

ISO 27701:2019 · 1 control

  • 7.3.10 Automated decision making
  • 40 Art. 40 Apply automated decisions under the statutory exception only with human intervention, a hearing and a challenge route
  • RO-LAW190-001 Lawful Basis for Processing Genetic, Biometric and Health Data
  • CIA-AUTOM-18 Automated decision making in credit assessment
  • ZDPA-13 Automated Decision Making and Profiling

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter III - Rights of the Data Subject

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.22 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 30 it maps to, and the evidence behind each claim, over MCP and REST.