01
Scope of application & addressees
- Organisations using personal data for scoring, profiling, recommendation or automated approval
- Controllers making solely automated decisions with legal or similarly significant effects
- Non-EU businesses offering goods or services to, or monitoring, people in the European Union
02
Core regulatory mandates & key requirements
01Significant solely automated decisions require a permitted basis, such as contractual necessity, legal authorisation or explicit consent.
02Privacy information should explain the use, meaningful logic and expected consequences.
03Applicable safeguards include human intervention, an opportunity to state a position and a route to contest the decision.
03
Enforcement & compliance timeline
The GDPR was adopted.
The GDPR became applicable.