Skip to main content
Promotional banner for the pentest readiness checklist
Category: Consumer Privacy Rights

Automated Decision-Making Rights

Also known as: ADM Rights, Rights related to automated decision-making, Automated individual decision-making rights, Article 22 rights, Rights against solely automated decisions
Simply put

Automated decision-making rights are protections that let individuals object to, or avoid being subject to, decisions made about them purely by computers without meaningful human involvement, particularly where those decisions have significant effects on them. In the EU and UK, these rights generally give people the ability not to be subject to such solely automated decisions in certain circumstances, while many US state privacy laws instead tend to offer a right to opt out of profiling based on automated processing. The precise scope and how these rights apply depend on the applicable law and the facts of each case.

Formal definition

Under the EU GDPR and the UK GDPR (notably Article 22), a data subject generally has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, subject to exceptions and safeguards set out in law. Processing is considered 'solely' automated where it is carried out without meaningful human involvement in the decision. These EU and UK rights differ in structure from many US state privacy frameworks, which, according to the evidence, commonly provide consumers with a right to opt out of processing (profiling) based on automated decisions rather than a general prohibition. This entry addresses the existence and general character of these rights only; the specific conditions, exemptions, required safeguards, thresholds for what constitutes a 'legal' or 'similarly significant' effect, and the interaction with emerging AI-specific regulation are jurisdiction-dependent, subject to evolving regulatory guidance, and outside the scope of this definition. Note also that these rights concern the processing and decision-making stage rather than the placing of or access to cookies and similar technologies on a device, which is governed by separate rules.

Why it matters

Automated decision-making rights address a growing reality: organizations increasingly rely on algorithms and profiling to make or shape decisions about individuals, sometimes without meaningful human involvement. Where those decisions carry legal effects or similarly significant consequences for a person, the individual's ability to understand, contest, or avoid a purely automated outcome becomes a central data protection concern. For compliance teams, these rights matter because they determine when an organization must build in human oversight, provide transparency about automated logic, or offer individuals a route to challenge outcomes.

The rights also matter because their structure differs across jurisdictions. In the EU and UK, the framework (notably Article 22 of the GDPR and UK GDPR) generally gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to exceptions and safeguards. By contrast, many US state privacy laws instead tend to provide consumers with a right to opt out of profiling based on automated decisions rather than a general prohibition. An organization operating across these regimes cannot assume that satisfying one framework satisfies the others, and the practical obligations may vary considerably by facts and location.

Because automated decision-making is emerging as an early focus of AI-specific regulation as well, the compliance landscape here is evolving. The precise thresholds for what counts as a 'legal' or 'similarly significant' effect, the exemptions that apply, and the interaction between data protection rules and newer AI frameworks remain jurisdiction-dependent and subject to changing regulatory guidance. Organizations that treat these rights as settled risk misjudging their obligations as interpretation develops.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for data subject rights need to identify where processing involves solely automated decisions with legal or similarly significant effects, and to design procedures for handling requests, providing safeguards, and documenting how human involvement is (or is not) built into decisions. They should account for the structural differences between EU/UK rights and the opt-out approach common in many US state laws.
Legal counsel and compliance teams
Counsel advising on cross-border operations must assess how automated decision-making obligations differ across the EU, UK, and individual US states, including exemptions, safeguards, and effect thresholds that are jurisdiction-dependent. They also need to track the interaction with emerging AI-specific regulation, which is evolving and may change the analysis.
Marketing and profiling teams
Teams that use profiling and automated processing to target or segment individuals should understand when such profiling triggers these rights, particularly where decisions could produce significant effects. In many US states, individuals may have a right to opt out of profiling based on automated decisions, which affects how such activities are configured and disclosed.
Developers and engineers building automated systems
Those implementing algorithmic or profiling systems may need to support meaningful human involvement in decisions, provide mechanisms for individuals to contest outcomes, and ensure transparency about automated logic where required. The precise technical requirements depend on the applicable law and the facts of each deployment.

Inside ADM Rights

Right not to be subject to solely automated decisions
Under the GDPR (notably Article 22), data subjects in the EU generally have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them. This right is subject to exceptions and is distinct from cookie consent obligations, though profiling driven by cookies and similar technologies can intersect with it.
Profiling as a linked concept
Profiling involves the automated processing of personal data to evaluate, analyse, or predict aspects about an individual. Cookies, pixels, SDKs, and fingerprinting techniques can feed profiling activities, which is where automated decision-making rights become relevant to consent management. The placing of and access to such technologies is governed by the ePrivacy regime, while the subsequent profiling of personal data is governed by the GDPR.
Applicable exceptions
The GDPR permits certain solely automated decisions where they are necessary for a contract, authorised by EU or Member State law, or based on the data subject's explicit consent. Where an exception applies, suitable safeguards typically remain required, such as the ability to obtain human intervention, to express one's point of view, and to contest the decision.
Transparency and information obligations
Controllers relying on automated decision-making are generally expected to inform individuals about the existence of such processing and to provide meaningful information about the logic involved and the significance and envisaged consequences. The precise scope of what must be disclosed remains subject to regulatory interpretation.
Jurisdictional scope
Detailed automated decision-making rights as described here derive from the EU GDPR and, in materially similar form, the UK GDPR. Other regimes, including individual US state privacy laws such as the CCPA and CPRA in California, address automated processing and profiling differently, and their requirements and opt-out mechanisms should not be assumed to mirror the EU approach.

Common questions

Answers to the questions practitioners most commonly ask about ADM Rights.

Does the right against automated decision-making apply to all cookie-based profiling and targeting?
Not necessarily. The specific right under Article 22 of the GDPR concerns decisions based solely on automated processing that produce legal effects or similarly significantly affect the individual. Much everyday cookie-based profiling and ad targeting may not meet that threshold, and where it does not, Article 22 in its restrictive sense may not be engaged. However, other GDPR obligations, such as transparency, lawful basis, and the general rights to object and to be informed, can still apply to profiling activities. Whether a particular targeting practice crosses into the Article 22 threshold is a fact-specific assessment, and interpretations among EU data protection authorities can differ.
If a user consents to cookies, does that mean they have waived their automated decision-making rights?
No. Consent to the placing of or access to cookies under the ePrivacy rules, and consent as a lawful basis for processing personal data under the GDPR, are distinct from the safeguards that attach to qualifying automated decisions. Even where a lawful basis exists for the processing, individuals may retain rights connected to solely automated decision-making, and controllers relying on the exceptions in Article 22 (such as explicit consent) are generally still expected to provide safeguards like meaningful human intervention and the ability to contest a decision. Obtaining cookie consent does not by itself extinguish these separate protections.
How do we determine whether our cookie-driven processing triggers automated decision-making obligations?
Assess whether the processing results in a decision based solely on automated means and whether that decision produces legal effects or similarly significant effects on the individual. This typically involves mapping what decisions your systems make from cookie or tracking data, whether any human meaningfully reviews them, and how those decisions affect users. Because the threshold is interpretive and enforcement positions can evolve, many organizations document this analysis and seek legal input rather than relying on a technical assessment alone. This entry describes the concept and does not substitute for a jurisdiction-specific legal review.
What information should we disclose to users when qualifying automated decisions rely on cookie data?
Where the GDPR's provisions on automated decision-making apply, controllers are generally expected to inform individuals about the existence of such processing and to provide meaningful information about the logic involved, as well as the significance and envisaged consequences for the individual. In practice this information often appears in the privacy notice rather than in the cookie banner itself. The precise level of detail required is a matter of ongoing interpretation, and organizations should confirm current expectations with applicable data protection authority guidance for their jurisdiction.
How can a consent management platform support compliance with automated decision-making requirements?
A CMP can help capture and log consent, manage user choices, and record the technologies deployed, which supports the transparency and record-keeping aspects of compliance. However, a CMP does not itself determine whether processing qualifies as solely automated decision-making, nor does it provide the human intervention, contestability, or safeguards that may be required for such decisions. These elements typically sit in operational processes and system design rather than in the consent tool. No CMP guarantees compliance; it supports but does not replace legal judgment.
What should we do if a user objects to or contests an automated decision derived from tracking data?
Where the relevant GDPR safeguards apply, controllers are generally expected to enable individuals to obtain human intervention, to express their point of view, and to contest the decision. Operationally this usually means establishing a channel to receive such requests, a process for a person with appropriate authority to review the decision, and records demonstrating how the request was handled. The scope of these obligations depends on whether the decision falls within the qualifying category and on the applicable jurisdiction, so the handling process should be aligned with current legal advice and regulatory guidance.

Common misconceptions

Obtaining cookie consent automatically satisfies automated decision-making requirements.
Consent to the placing of cookies under the ePrivacy regime does not by itself satisfy the separate GDPR conditions for solely automated decisions or profiling. Where Article 22 applies, a specific lawful basis (such as explicit consent, contractual necessity, or legal authorisation) and additional safeguards are generally needed, and these are distinct from cookie consent.
All profiling based on cookies triggers the automated decision-making right.
The GDPR right primarily concerns decisions based solely on automated processing that produce legal or similarly significant effects. Much cookie-based profiling may not reach that threshold, though it can still require a lawful basis and, in most EU jurisdictions, prior consent for non-essential cookies. Whether a given activity crosses the significance threshold is fact-specific and can be contested.
These rights apply the same way everywhere.
Automated decision-making rights as framed under the EU and UK GDPR do not translate uniformly to other jurisdictions. US state laws such as the CCPA and CPRA address profiling and automated processing through different mechanisms, often opt-out based, so obligations vary by geographic and legal scope.

Best practices

Map where cookies, pixels, SDKs, and fingerprinting feed profiling or automated decisions, and assess separately whether the GDPR's automated decision-making provisions may apply, rather than relying on cookie consent alone.
Identify a specific GDPR lawful basis for any profiling or solely automated decision-making, and treat this analysis as distinct from ePrivacy consent for placing or accessing information on a device.
Where solely automated decisions with legal or similarly significant effects are involved, implement safeguards such as human intervention, the ability for individuals to express their view, and a means to contest the decision.
Provide clear, layered transparency about the existence and logic of automated processing, and integrate this disclosure with your consent notices and privacy information rather than duplicating or contradicting it.
Scope obligations by jurisdiction, distinguishing EU and UK GDPR requirements from opt-out oriented US state law regimes such as the CCPA and CPRA, and document the geographic assumptions behind your approach.
Record consent and configuration decisions and revisit them as data protection authority guidance evolves, recognising that CMPs and related tools support but do not replace legal judgment on automated decision-making.
Promotional banner for the Penetration Report Template Kit