What is the "Right to an Explanation" under the GDPR?

The GDPR gives individuals important rights when organizations rely on automated decision-making and profiling. Learn when Article 22 applies, the safeguards organizations must implement, and how individuals can challenge automated decisions.

What is the "Right to an Explanation" under the GDPR?
Key points: (1) The GDPR regulates profiling and solely automated decision-making, but they are not the same thing. (2) Profiling means using automated processing of personal data to evaluate or predict aspects of an individual, such as their behavior, preferences, performance, reliability, or interests. Profiling may or may not result in a decision. (3) Solely automated decision-making refers to decisions made without any meaningful human involvement. (4) Article 22 GDPR only applies where a decision is both: made solely by automated means; and produces legal effects or similarly significant effects on the individual. (5) Such decisions are generally prohibited unless one of the limited exceptions under Article 22 applies. (6) When an exception permits solely automated decision-making, organizations must provide additional safeguards, including information about the processing, a way to obtain human intervention, the opportunity to express a point of view and challenge the decision, and measures to ensure the automated system functions fairly and accurately. (7) The GDPR imposes even stricter rules where the decision involves special category personal data, and additional protections apply when processing concerns children.

Artificial intelligence, algorithms, and automated decision-making are increasingly used to make decisions that affect individuals, from approving loans and screening job applicants to detecting fraud and determining insurance premiums. This has led many people to ask whether the GDPR provides a "right to an explanation" of how these automated decisions are made.

Although the GDPR does not explicitly create a standalone "right to an explanation," it does give individuals important rights when organizations rely on certain forms of automated decision-making. These rights are primarily found in Article 22 GDPR (Automated individual decision-making, including profiling), together with the transparency obligations in Articles 13 (Information to be provided where personal data are collected from the data subject), Article 14 (Information to be provided where personal data have not been obtained from the data subject), and Article 15 (right to access) and further explained in guidance from the European Data Protection Board (EDPB). This article focuses mainly on Article 22. For a discussion of the transparency obligations under Articles 13 and 14, see "What Is the 'Right to Be Informed' under the GDPR?" For more information about the right of access under Article 15, see "What Is the 'Right of Access' under the GDPR?"

Before examining those rights, it is important to understand the difference between profiling and solely automated decision-making, as the GDPR regulates these concepts differently.

What is automated decision-making and profiling?

The GDPR distinguishes between automated decision-making and profiling. Although the two concepts are closely related and often occur together, they are not the same.

Automated decision-making

Automated decision-making occurs when a decision is made entirely by automated means, without any meaningful human involvement.

Examples include:

  • An online system that automatically approves or rejects a loan application.
  • A recruitment system that automatically accepts or rejects job applicants based on pre-programmed criteria or algorithms.

Automated decision-making does not have to involve profiling, although in practice it frequently does.

Profiling

Article 4(4) of the GDPR defines profiling as:

"any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;" 

In simple terms, profiling involves using automated technologies to analyze personal data in order to evaluate or predict characteristics, preferences, or behaviors about an individual.

Organizations may collect personal data from a wide variety of sources, including:

  • websites and online searches;
  • purchasing history;
  • mobile apps and connected devices;
  • social media platforms;
  • video surveillance systems; and
  • Internet of Things (IoT) devices.

Organizations then use algorithms, artificial intelligence, and machine learning to analyze this information, identify patterns, and group individuals with similar characteristics. These profiles may be used to:

  • identify an individual's interests or preferences;
  • predict future behavior or choices; or
  • support or make decisions about that individual.

Profiling has many legitimate and beneficial uses. For example, it may be used to detect fraud, personalize online services, recommend products, improve healthcare outcomes, assess financial risk, or tailor educational services. However, because profiling can also significantly affect individuals' rights and freedoms, Article 22 of the GDPR imposes additional safeguards when it is used as part of solely automated decision-making that produces legal or similarly significant effects.

When is Automated Decision Making (ADMT) Subject to Article 22?

Automated individual decision-making and profiling can lead to faster, more consistent, and more efficient decisions when used responsibly. However, if used improperly, they can also result in unfair, inaccurate, or discriminatory outcomes that may significantly affect an individual's rights and opportunities.

To address these risks, Article 22 GDPR gives individuals the right not to be subject to certain decisions made solely by automated means, including decisions based on profiling, where those decisions produce legal effects or similarly significant effects on the individual. Article 22 GDPR does not prohibit all automated decision-making. Instead, it restricts decisions that meet all of the following conditions:

  • the decision is made solely by automated means, with no meaningful human involvement;
  • the decision produces legal effects or similarly significant effects on the individual; and
  • no exception under Article 22 applies.

Each of these requirements is discussed below.

What does "solely automated" mean?

A decision is solely automated when it is made entirely by technology, without any meaningful human involvement in reviewing or making the final decision.

Simply having a person involved somewhere in the process is not enough. The human reviewer must genuinely assess the relevant information, have the authority to change the outcome, and not merely rubber-stamp the automated result.

The GDPR does not define these terms, but they generally refer to decisions that have a substantial impact on an individual's rights, opportunities, or circumstances.

  • legal effect is one that affects an individual's legal rights or obligations. Examples include decisions that determine eligibility for benefits or the approval of a contract.
  • similarly significant effect is one that has a comparable impact on an individual's life, even if it does not directly change their legal rights. Examples include: (1) automatically rejecting an online loan or credit application; (2) automatically screening out a job applicant during recruitment; (3) refusing insurance coverage or significantly affecting insurance premiums based solely on an automated assessment; or (4) making decisions that substantially affect an individual's access to education, healthcare, housing, or employment.

By contrast, decisions with only a minor or temporary impact—such as recommending products on an online shopping site or displaying personalized advertisements—will generally not meet this threshold.

When are solely automated decisions permitted under Article 22?

Although the GDPR generally prohibits solely automated decisions that have legal or similarly significant effects, Article 22 permits this type of processing in three limited circumstances.

1. The decision is necessary for entering into or performing a contract: An organization may rely on solely automated decision-making where it is necessary to enter into or perform a contract with the individual.

This exception is interpreted narrowly. The automated decision must be genuinely necessary to provide the requested product or service, not merely more convenient, faster, or less expensive for the organization.

Example: A bank uses an automated system to determine whether an online loan application satisfies objective lending criteria where immediate approval is necessary to provide the requested service.

2. The decision is authorized by European Union or Member State law: Solely automated decision-making is also permitted where it is expressly authorized by European Union or Member State law that applies to the controller.

The law must also include appropriate safeguards to protect the individual's rights, freedoms, and legitimate interests.

Example: National legislation authorizing automated processing to detect tax fraud or prevent certain types of financial crime.

An organization may rely on solely automated decision-making where the individual has provided explicit consent.

Explicit consent requires a clear, specific, and affirmative statement of agreement. It cannot be implied from silence, inactivity, or pre-ticked boxes, and the individual must be free to withdraw consent at any time.

Do safeguards apply?

Yes. Even when an organization relies on one of these exceptions, Article 22 requires it to implement appropriate safeguards to protect the individual.

At a minimum, individuals must be able to:

  • request human intervention;
  • express their point of view; and
  • challenge or contest the decision.

Organizations must also comply with the GDPR's transparency obligations by informing individuals about the automated decision-making and providing meaningful information about the logic involved, as well as the significance and envisaged consequences of the processing. They must also take appropriate steps to ensure that automated systems function accurately, fairly, and without unlawful discrimination. Among other things, organizations must:

  • Provide meaningful information about the automated decision-making process, including the logic involved, the significance of the processing, and its likely consequences for the individual.
  • Use appropriate mathematical and statistical methods to help ensure that automated systems produce reliable and accurate results.
  • Take reasonable steps to prevent inaccuracies, bias, and discrimination, including implementing technical and organizational measures to detect and correct errors and reduce the risk of unfair outcomes.
  • Protect the personal data used in the automated decision-making process through appropriate security measures that are proportionate to the risks involved.

These safeguards help ensure that automated decision-making remains subject to human oversight and accountability, reducing the risk that important decisions are based on inaccurate, biased, or unfair automated processing.

Additional protections for special category personal data and children: The GDPR imposes even stricter requirements when solely automated decisions are based on special category personal data, such as information revealing racial or ethnic origin, political opinions, religious beliefs, health, biometric data, or sexual orientation (see also, What are Special Categories of Data under the GDPR?).

Under Article 22(4) of GDPR solely automated decisions based on special category personal data are generally prohibited unless both of the following conditions are met:

  • the individual has given explicit consentor the processing is necessary for reasons of substantial public interest and is authorized by European Union or Member State law; and
  • appropriate safeguards are in place to protect the individual's rights and freedoms.

Additional care is also expected when automated decision-making involves children, given their particular vulnerability.

Challenging Decisions based on ADMT: Under Article 22, organizations must provide a way for individuals to challenge the decision, including the right to:

    • obtain human intervention;
    • express their point of view; and
    • contest the decision and request that it be reviewed by a person rather than solely by an automated system.

Is a Data Protection Impact Assessment (DPIA) required? Because solely automated decision-making with legal or similarly significant effects presents a high risk to individuals' rights and freedoms, organizations will often be required to conduct a Data Protection Impact Assessment (DPIA) before carrying out the processing.

A DPIA helps organizations identify the risks posed by the automated decision-making, assess whether the processing is necessary and proportionate, and implement measures to reduce or eliminate those risks. It is an important accountability tool that demonstrates compliance with the GDPR.

What if Article 22 Does Not Apply?

As explained above, Article 22 applies only to a narrow category of automated processing. However, this does not mean that other forms of automated processing are unregulated. Organizations must still comply with the GDPR's general requirements, including:

  • complying with the data protection principles set out in Article 5 GDPR;
  • identifying and documenting a lawful basis for the processing under Article 6 GDPR;
  • providing individuals with the required privacy information;
  • implementing appropriate technical and organizational measures to ensure the security of personal data and demonstrate accountability; and
  • ensuring that individuals can exercise their GDPR rights, including the rights of access, rectification, erasure, restriction of processing, and, where applicable, the right to object.

In particular, individuals have the right to object to profiling in certain circumstances. Where that right applies, organizations must specifically inform individuals of this right and make it easy for them to exercise it.  (see also, What is the "Right to Object" under the GDPR?.)

Accordingly, even where Article 22 does not apply, organizations using profiling or other forms of automated processing must ensure that their processing complies with the GDPR and respects individuals' rights.

Additional Resources

Article 22 of the GDPR

Suitable Recitals (71) Profiling (72) Guidance of the European Data Protection Board Regarding Profiling (91) Necessity of a Data Protection Impact Assessment

Articles

Books

Ethically Aligned Design, First Edition (downloadable Book) by the Institute of Electrical and Electronics Engineers (IEEE).

Papers

Counterfactual explanations without opening the black box: automated decisions and the GDPR by Sandra Wachter, Brent Mittelstadt, and Chris Russel (2018) ( There has been much discussion of the “right to explanation” in the EU General Data Protection Regulation, and its existence, merits, and disadvantages. Implementing a right to explanation that opens the ‘black box’ of algorithmic decision-making faces major legal and technical barriers. Explaining the functionality of complex algorithmic decisionmaking systems and their rationale in specific cases is a technically challenging problem. Some explanations may offer little meaningful information…)

The Ethical Machine: The Ethical Machine is an anthology of essays on the ethics of artificial intelligence, bias, and what they mean for the future of technology and society.

From dignity to security protocols: a scientometric analysis of digital ethics by René Mahieu, Nees Jan van Eck, David van Putten, and Jeroen van den Hoven

Accountable Algorithms JOSHUA A. KROLL, JOANNA HUEY, SOLON B AROCAS, EDWARD W. FELTEN, JOEL R. REIDENBERG, DAVID G. ROBINSON & HARLAN YU [V165:633 Pennsylvania law review] V.2

Access to Algorithms SSRN Hannah Bloch-Wehba / Drexel University Thomas R. Kline School of Law; Yale University — Yale Information Society Project

Guidelines from regulators

European Data Protection Board (EDPB):

European Data Protection Supervisor (EDPS)

UK

CoE

Reports (US)

Other

This video is quite technical but useful in breaking down the issues of fairness and bias in algorithmic decision-making.

From the New York Times: “The Secretive Company That May End Privacy As We Know It,” about a facial recognition app that can help a user identify strangers and has been embraced by law enforcement.

Worried About Privacy at Home? There’s an AI for That (on Edge AI) by Clive Thomson for Wire Jan. 2020.

How machine learning powers Facebook’s News Feed ranking algorithm(Facebook engineering page)

What is an algorithm? It depends on who you ask. For better accountability, we should shift the focus from the design of these systems to their impact. By Kristian Lum and Rumman Chowdhury for MIT Technology Review. February 26, 2021

Can Auditing Eliminate Bias fromAlgorithms? By Alfred Ng for the Markup. February 23, 2021 08:00 ET

NFTs and the Law: An “Explain it Like I’m Five” Overview by the Harris County Law Library. March 9, 2021

OSU Program on Data and Governance Final Report on Business Data Ethics

OSU Program on Data and Governance recordings of Webinar series on Business Data Ethics

Markulla Center for Applied Ethics, An Ethical Toolkit for Engineering/Design Practice.

Microsoft Research-Carnegie Mellon, Co-Designing Checklists to Understand Organizational Challenges and Opportunities around Fairness in AI.

Proposed EU AI Regulation.


Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe