Decisions taken by systems without meaningful human involvement; GDPR Art. 22 anchor.
For platform-dependent creators, automated decision-making is the set of machine verdicts that govern income and reach without a human ever looking: copyright matches that claim or block uploads, moderation classifiers that demonetize or remove content, ranking systems that quietly withdraw distribution. It is operationalized through the machinery around those verdicts — strike counts, appeal windows, counter-notification forms — and through the practical literacy of contesting them: knowing which decisions carry a right to human review, preserving evidence of licenses and fair-use grounds, and tracking whether an appeal actually reaches a person or merely another model.
In practice: Identify which platform actions against your content are automated, use the appeal channels that trigger human review, and document rights evidence to contest erroneous machine verdicts.
OmniGloss seed synthesis, 2026 (machine-drafted, pending expert validation)
In established lending compliance, automated decision-making is the final act on a customer executed without human involvement: an application declined, a limit cut, a price set by the system alone, with legal or similarly significant effect. Institutions operationalize the definition through process design: they place trained credit officers as decision checkpoints so outcomes are not 'solely' automated, restrict fully automated approval to contractually necessary flows with safeguards, and provide the mandated rights package — human intervention on request, the customer's ability to state their case, and contestation. On this reading, upstream scores and flags are inputs, not decisions, so Article 22 duties attach at the final act.
In practice: Map where in the credit process a final automated act occurs, insert genuine human decision checkpoints where required, and operate the intervention and contestation rights for affected customers.
Regulation (EU) 2016/679 (GDPR), automated individual decision-making
For data-protection counsel advising after the CJEU's SCHUFA judgment, automated decision-making reaches back into the scoring itself: where a credit bureau's automatically produced score plays a determining role in whether a lender contracts, the score's creation is already the decision within the meaning of Article 22 — not merely preparation for one. Operationally this relocates duties upstream: scoring agencies, not only lenders, must establish a lawful basis, provide transparency about the logic involved, and support intervention and contestation; and a lender's pro-forma human step downstream does not launder a determinative score into mere decision support.
In practice: Assess whether an automatically produced score effectively determines the final outcome; if it does, apply lawful-basis, transparency, and contestation duties to the scoring stage itself.
Regulation (EU) 2016/679 (GDPR), automated individual decision-making
In care delivery, automated decision-making is recognized less by its label than by its effect: whether a system determines access to care before a clinician exercises judgment. Triage scores that auto-schedule, coverage engines that deny prior authorization, staffing algorithms that allocate beds — these are operationally ADM when the pathway executes unless someone intervenes. Clinical practice draws the line at meaningful sign-off: a recommendation a physician genuinely weighs is decision support; a queue that acts on defaults is decision-making. Because vendors label systems 'support' precisely to stay on the safe side of that line, the working task is testing what actually happens when nobody overrides.
In practice: Trace each algorithmic pathway to its default outcome, determine whether care access changes without clinician judgment, and classify and govern such pathways as automated decisions.
OmniGloss seed synthesis, 2026 (machine-drafted, pending expert validation)
For health-sector data-protection officers, automated decision-making is a near-prohibited processing category: decisions based solely on automated processing that produce legal or similarly significant effects are restricted in general, and when they rely on special-category health data they are permissible only on narrow bases such as explicit consent or substantial public interest grounded in law, with suitable safeguards. Operationally this yields a screening question for every algorithmic deployment touching patient data: does it decide anything about an individual without meaningful human involvement, and if so, which lawful basis and safeguard package — human intervention, contestation routes, impact assessment — authorizes it.
In practice: Screen every patient-facing algorithm for solely automated decisions with significant effects, verify a lawful basis where special-category data is involved, and document required safeguards before go-live.
Regulation (EU) 2016/679 (GDPR), automated individual decision-making and special categories of data
In administrative-law practice, automated decision-making is the issuance of an administrative act wholly or partly by machine, and its legitimacy turns on statutory authorization and on whether residual human involvement is real. Some statutes permit fully automated acts only where no discretion is exercised; beyond that, doctrine and oversight bodies examine substance over form: a caseworker who systematically adopts system outputs without the capacity, time, or information to depart from them is not deciding, and the act is functionally automated regardless of the signature on it. Operational tests include override rates, access to underlying reasoning, and whether departing from the machine is organizationally punished.
In practice: Verify statutory authorization for automated administrative acts, and audit whether caseworkers can and do depart from system outputs — measuring override rates, reasoning access, and tolerance for deviation.
OmniGloss seed synthesis, 2026 (machine-drafted, pending expert validation)
Communities disagree about where in an automated pipeline the 'decision' occurs and how much human involvement removes a decision from the automated category. Established lending compliance attaches Art. 22 duties at the final act on the customer, treating upstream scores as inputs and a trained human checkpoint as sufficient de-automation. The post-SCHUFA data-protection reading and administrative-law oversight practice instead look to determinative effect: a score or system output that is systematically followed is itself the decision, and pro-forma human review does not change its automated character.