GDPR art. 22(1) does not apply to automated individual decision-making, other than on the basis of profiling, that is necessary to comply with a legal obligation on the controller or to perform a task in the public interest (40(1)); the controller then takes suitable measures to protect the person's rights, freedoms and legitimate interests (40(2)); a controller that is not an administrative body has taken them at least where the right to human intervention, to express one's point of view and to contest the decision are guaranteed (40(3)). Automated decisions based on profiling (for example algorithmic performance scoring leading to dismissal) are not covered and fall under GDPR art. 22 in full.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.