What safeguards does Article 22 require for solely automated decisions?
Answered
You may only take a solely automated decision with legal or similarly significant effects if it is necessary for a contract, authorised by law, or based on explicit consent. Then you must tell people about the processing, give them simple ways to request human intervention or challenge the decision, and run regular checks that the system works as intended. Meaningful human review usually happens after the automated decision and must relate to the actual outcome. If the tool is in ATRS scope, complete the Article 22 field on the record.
From the guidance
Primary (how) ICO: Article 22 of the UK GDPR and fairness
Section: What is the purpose of Article 22?
Read this in ICO: Article 22 of the UK GDPR and fairness (opens in new tab)
Secondary (normative) ICO: Article 22 of the UK GDPR and fairness
Section: What is the purpose of Article 22?
Read this in ICO: Article 22 of the UK GDPR and fairness (opens in new tab)
Secondary (normative) ICO: Article 22 of the UK GDPR and fairness
Section: When does the human-determined decision take place?
Read this in ICO: Article 22 of the UK GDPR and fairness (opens in new tab)
Secondary (normative) ATRS: Guidance for public sector bodies
Section: Deployment Context (Tier 2)
Read this in ATRS: Guidance for public sector bodies (opens in new tab)
Related questions
- Can AI make automated decisions that affect people?
- Do significant automated decisions need ministerial agreement?
- Can I use proxy or generalised social datasets for automated decisions about individuals?
- When should I use the Ethics, Transparency and Accountability Framework for Automated Decision-Making?
- What does data-protection fairness require of an AI system?