Implementation of Safeguards for Solely Automated Decisions, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 22(3).
Assessment Step
1
Implementation of Safeguards for Solely Automated Decisions (ImplementationofSafeguardsforSolelyAutomatedDecisions)
If the entity lawfully subjects a data subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning the data subject or similarly significantly affects the data subject, does the entity implement suitable safeguards to protect the data subject's rights, freedoms, and legitimate interests, including the right to obtain human intervention, to express their point of view, and to contest the decision?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Implementation of Safeguards for Solely Automated Decisions
If the data controller lawfully subjects a data subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning the data subject or similarly significantly affects the data subject, then the controller must implement suitable measures to safeguard the data subject's rights, freedoms, and legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express their point of view, and to contest the decision.
Citation
GDPR
Art. 22(3), Recital 71
|