AI and GDPR

Long hair man in suit bright patterned shirt

When you can complain about AI

When and how to make a complaint about AI in relation to the GDPRs

This is an interesting guest post by James Bore regarding your rights when it comes to AI, those automated decisions and GDPRs and when you can make a complaint.

Automated Decisions

AI is big in the news at the moment, with ChatGPT and other systems being variously cheered as saviours and cursed as the end of humanity.

I’m going to pick up on one area of the discussion, which has been with us a lot longer than the hype over AI and machine learning. Automated decision making is something which, these days, impacts everyone constantly. It’s even more relevant with current economic events.

Everything from your likelihood of getting a loan to the estimate of your energy bill is based, these days, on automated decisions made by algorithms with no human involvement. This is very efficient for the companies involved, but can have life-changing impacts on individuals who have either somehow upset the algorithm or simply haven’t interacted with the systems to give them enough data to work with.

Where GDPR comes in

There is some good news for those who want to appeal the decisions, in the form of Article 22 of the GDPR. While most people are familiar with the rights granted around getting access to your own data and protection of privacy, Article 22 is less well-known.

Article 22 covers individual’s rights around automated decision-making and profiling, and it is only going to become more essential to understand what it allows you to do.

First we need to look at the difference between automated decision-making and profiling.

Automated decision-making: making a decision based on any data with no human intervention, for example issuing a speeding ticket based purely on the evidence from a speed camera with no human review or automated approval for a credit card based on an online form.

Profiling: evaluating and predicting personal aspects using personal data from any source in a wholly or partially automated way, such as giving someone a credit affordability rating based on their address, or setting insurance risk based on age and gender.

Article 21 and 22 of the UK GDPR are what provide protection against automated decision-making. Article 21 sets out your right to object to both, along with some other aspects which are less relevant. The one worth knowing about is Article 22 which focuses purely on automated decisions and profiling.

“1. The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.”

There are exceptions to this first clause that we’ll look at shortly, but the clause itself is important as it sets out the principle that if a decision is going to apply legal effects or anything with a similar impact, you as an individual have a right not to have that decision be based purely on automated processing.

“Paragraph 1 shall not apply if the decision:

is necessary for entering into, or performance of, a contract between the data subject and a data controller;

is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests; or

is based on the data subject’s explicit consent.”

So decisions can be fully automated if it’s necessary for a contract such as with a credit card approval, authorised by another law as with speeding tickets, or if you explicitly consent. Importantly, explicit consent must be an affirmative action, you must be asked to take some sort of action such as signing. Simply signing an agreement wouldn’t be enough, your consent must be specific to the decision-making.

Even with these exceptions though you need to be very aware of this next bit.

“In the cases referred to in points (a) and (c) of paragraph 2, the data controller shall implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.

Decisions referred to in paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1), unless point (a) or (g) of Article 9(2) applies and suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests are in place.”

What this means is that at the absolute minimum anyone using automated decision making or profiling must provide you a way to have a human intervene. This is not simply the right to having a human review the decision, there must be a way for you to explain your point of view and argue with the decision. Anyone failing to do this, in any circumstance, is in breach of the GDPR.

If you need to complain to the ICO over the way a decision has been handled, you can find their details at https://ico.org.uk/make-a-complaint/.

Bin the Bots – Customer Service Week

Long hair man in suit bright patterned shirt

James Bore Security and technology expert

James is a chartered security professional and has worked in IT and security for over two decades. Founder of Bores.com. He covers everything from consulting for enterprises to awareness training for individuals, and teaching children to stay safe online, pick locks, and use secret codes.

 

 

Where you can find James

X (formerly known as X (formerly known as Twitter)

LinkedIn

Website

More from James on The Complaining Cow website

Unsporting Behaviour in JD Sports data breach

How to shop safely online

James Bore talks AI on The Complaining Cow Consumer Show

 

 

You might also like
Newsletter Sign Up

If this site or a response from me has helped you, please consider buying me some chocolate (don’t like coffee!) to help me continue to provide this free advice. Thank you!

Share:

You must be logged in to post a comment.