European Union · Legislation

EU GDPR Automated Decision-Making Rules

The GDPR sets legal-basis, transparency and safeguard requirements for profiling and solely automated decisions that produce legal or similarly significant effects.

Current status
In force
Published or updated
27 April 2016
Effective date
25 May 2018
Last verified
19 August 2026

Prepared by Longan Bay Area AI Legal Research Center based on official public materials.

01

Scope of application & addressees

  • Organisations using personal data for scoring, profiling, recommendation or automated approval
  • Controllers making solely automated decisions with legal or similarly significant effects
  • Non-EU businesses offering goods or services to, or monitoring, people in the European Union

02

Core regulatory mandates & key requirements

01Significant solely automated decisions require a permitted basis, such as contractual necessity, legal authorisation or explicit consent.

02Privacy information should explain the use, meaningful logic and expected consequences.

03Applicable safeguards include human intervention, an opportunity to state a position and a route to contest the decision.

03

Enforcement & compliance timeline

The GDPR was adopted.

The GDPR became applicable.

Primary text

Statutory & regulatory text

PROJECT ENQUIRY

Need to evaluate this regulation against your system architecture?

Consult with our regulatory team →