Prohibition of Solely Automated Decision-Making with Legal or Similarly Significant Effects, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 22(1).

Assessment Step

1
Prohibition of Solely Automated Decision-Making with Legal or Similarly Significant Effects (ProhibitionofSolelyAutomatedDecision-MakingwithLegalorSimilarlySignificantEffects)
Does the entity refrain from subjecting a data subject to a decision based solely on automated processing, including profiling, if the decision produces legal effects concerning the data subject or similarly significantly affects the data subject?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Prohibition of Solely Automated Decision-Making with Legal or Similarly Significant Effects
The data controller must not subject a data subject to a decision based solely on automated processing, including profiling, if that decision produces legal effects concerning the data subject or similarly significantly affects the data subject.
Citation
GDPR
Art. 22(1), Recital 71