Permissible Conditions for Solely Automated Decision-Making, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 22(2).

Assessment Step

1
Permissible Conditions for Solely Automated Decision-Making (PermissibleConditionsforSolelyAutomatedDecision-Making)
If the entity subjects a data subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning the data subject or similarly significantly affects the data subject, does the entity ensure that the decision is either necessary for entering into or performance of a contract with the data subject; authorized by Union or Member State law which includes suitable safeguards; or based on the data subject's explicit consent?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Permissible Conditions for Solely Automated Decision-Making
If the data controller subjects a data subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning the data subject or similarly significantly affects the data subject, then the controller must ensure that the decision is either necessary for entering into or performance of a contract between the data subject and the controller, authorized by Union or Member State law which lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, or based on the data subject's explicit consent.
Citation
GDPR
Art. 22(2), Recital 71