Automated Decision-Making Rights
Automated decision-making rights are protections that let individuals object to, or avoid being subject to, decisions made about them purely by computers without meaningful human involvement, particularly where those decisions have significant effects on them. In the EU and UK, these rights generally give people the ability not to be subject to such solely automated decisions in certain circumstances, while many US state privacy laws instead tend to offer a right to opt out of profiling based on automated processing. The precise scope and how these rights apply depend on the applicable law and the facts of each case.
Under the EU GDPR and the UK GDPR (notably Article 22), a data subject generally has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, subject to exceptions and safeguards set out in law. Processing is considered 'solely' automated where it is carried out without meaningful human involvement in the decision. These EU and UK rights differ in structure from many US state privacy frameworks, which, according to the evidence, commonly provide consumers with a right to opt out of processing (profiling) based on automated decisions rather than a general prohibition. This entry addresses the existence and general character of these rights only; the specific conditions, exemptions, required safeguards, thresholds for what constitutes a 'legal' or 'similarly significant' effect, and the interaction with emerging AI-specific regulation are jurisdiction-dependent, subject to evolving regulatory guidance, and outside the scope of this definition. Note also that these rights concern the processing and decision-making stage rather than the placing of or access to cookies and similar technologies on a device, which is governed by separate rules.
Why it matters
Automated decision-making rights address a growing reality: organizations increasingly rely on algorithms and profiling to make or shape decisions about individuals, sometimes without meaningful human involvement. Where those decisions carry legal effects or similarly significant consequences for a person, the individual's ability to understand, contest, or avoid a purely automated outcome becomes a central data protection concern. For compliance teams, these rights matter because they determine when an organization must build in human oversight, provide transparency about automated logic, or offer individuals a route to challenge outcomes.
The rights also matter because their structure differs across jurisdictions. In the EU and UK, the framework (notably Article 22 of the GDPR and UK GDPR) generally gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to exceptions and safeguards. By contrast, many US state privacy laws instead tend to provide consumers with a right to opt out of profiling based on automated decisions rather than a general prohibition. An organization operating across these regimes cannot assume that satisfying one framework satisfies the others, and the practical obligations may vary considerably by facts and location.
Because automated decision-making is emerging as an early focus of AI-specific regulation as well, the compliance landscape here is evolving. The precise thresholds for what counts as a 'legal' or 'similarly significant' effect, the exemptions that apply, and the interaction between data protection rules and newer AI frameworks remain jurisdiction-dependent and subject to changing regulatory guidance. Organizations that treat these rights as settled risk misjudging their obligations as interpretation develops.
Who it's relevant to
Inside ADM Rights
Common questions
Answers to the questions practitioners most commonly ask about ADM Rights.
