Profiling And Automated Decisions Flashcards

1
Q

What is the definition of ‘profiling’ according to GDPR, and what are the three elements that are required for a process to be considered profiling?

A

According to GDPR, ‘profiling’ is any form of automated processing of personal data that evaluates certain personal aspects relating to a natural person, and it includes three elements:

  • automated processing,
  • personal data,
  • intended to evaluate certain personal aspects of the natural person
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are automated decisions?

A

made by automated processing of personal data, and

may partially overlap with profiling or be based upon it, and they

can involve any type of personal data

may involve human intervention or not

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Question: What does Article 22 GDPR relate to?

A

Answer: Article 22 GDPR regulates automated individual decision-making, including profiling, with legal effects or similarly significant effects.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the general content of article 22 of GDPR?

A

Answer: Article 22 GDPR provides the right for individuals not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless an exception is available to the controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the limited scope of application of Article 22 GDPR?

A

Article 22 only applies to decisions based solely on automated processing that produce legal effects or similarly significant effects concerning the data subject, with the majority of profiling activities and automated decisions falling outside its scope.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the elements of a decision with legal or similar significant effects?

A

It must have the potential to significantly affect circumstances, behaviour, or choices of the data subject.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are some examples of decisions with significant effects?

A

They include eligibility to credit, access to health services, employment opportunities, and education.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can online advertising targeted to a group significantly affect an individual?

A

Online advertising targeted to a group may not significantly affect an individual, but its effect on the group is uncertain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the exceptions to the general prohibition of automated decisions?

A

Exceptions include necessity for entering into or performing a contract, authorization by law, or explicit consent of the data subject.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the data subject’s rights regarding automated decisions?

A

Data subjects have the right to meaningful information, and controllers must implement suitable measures to safeguard their rights and freedoms.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the consequences of controllers not complying with GDPR?

A

Controllers must respect data protection principles and must ground their processing activities on a lawful base.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Are inferences, assessments, predictions, or correlations considered personal data?

A

Their legal status is uncertain, and there is no clear answer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the data subject’s rights to adequate safeguards?

A

Data subjects have the right to human intervention, express their point of view, and contest the decision.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the general GDPR legal regime for automated decision-making, including profiling?

A

Automated decision-making, including profiling, is allowed but it is subject to certain requirements, including the right for the data subject to

obtain human intervention,

the right to be informed about the existence of automated decision-making, and the

right to object to the decision-making.

The decision-making must also be fair, transparent, and based on appropriate safeguards, such as appropriate data protection impact assessments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are some general problems associated with automated decision-making?

A

Some problems include the uncertain legal status of inferences, assessments, predictions, or correlations, and conflicts of interest.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly