Automated decision-making and profiling constitute personal data processing that may have a significant impact particularly on the rights of the data subject. As such, they require special attention and care with regard to data protection practices, and the EU’s General Data Protection Regulation (“GDPR”) includes special provisions regarding their use, which controllers must observe.
Profiling refers to the automated processing of personal data that involves evaluation of personal aspects relating to a data subject
Profiling involves prediction and analysis pertaining, in particular, to performance at work, economic situations, health, personal preferences or interests, reliability or behavior, and location or movements. Profiling is automated or partially automated by nature, performed on personal data and specifically aimed at evaluating or attempting to predict personal aspects of a data subject. In contrast, simple classification of data subjects based on their age, gender and municipality of residence, for example, is not necessarily considered to be profiling.
The key is the purpose of classification.
For instance, classification of a company’s customers, an educational institution’s students or the participants in a training provider’s courses based on their age and gender for statistical purposes with the intention of establishing an overall picture of the customers without predictions or conclusions concerning personal aspects relating to individual customers or students is considered to be classification. This is because it is not aimed at evaluating personal aspects relating to an individual.
If the purpose, however, is to evaluate a data subject’s personal aspects in order to, for example, target advertising based on a subject´s purchase history or courses taken at a school, the definition of profiling is fulfilled.
Automated decision-making happens without human intervention in the decision and the decision significantly affects the subject
Decision-making is automated when decision-making is based purely on the automated processing of personal data without the intervention of a natural person and the resulting decisions have legal effects on the subject of the automated decision-making or the decisions otherwise significantly affect the subject.
The data used as the basis of automated decision-making may have been obtained from the data subject directly or based on observation (e.g. location data, IP address), or it may be based on data that is extrapolated or deduced from other data using, for example, a profile (previously) generated on the data subject (e.g. credit rating).
It is important to understand that automated decision-making may be carried out without profiling, and profiling may be carried out without automated decision-making. The same personal data processing activity may also aspect which would be considered profiling and other aspects which do not, depending on how the data is used.
Automated decision-making is only allowed if the decision involves at least one of the following:
In data protection practices, pay special attention to informing the data subject, implementing the rights of the data subject and conducting an impact assessment
The key to compliance with GDPR is to inform data subjects as clearly and intelligibly as possible regarding the processing of personal data they are subject to and the effects thereof.
Whenever automated decision-making or profiling is involved, make sure that at least the following conditions are met:
When the case involves only automated decision-making or profiling, it is important that the following conditions are also met:
- contractual;
-specific consent, for which it is possible to demonstrate when and how the consent was obtained, and that the data subjects have been informed of how they can withdraw their consent and they can do so in a simple manner; or
- a legal obligation.