xmlns:atom="http://www.w3.org/2005/Atom" xmlns:atom="http://www.w3.org/2005/Atom"

PART 2 U.K.General processing

CHAPTER 2U.K.[F1 The UK GDPR]

Rights of the data subjectU.K.

14Automated decision-making authorised by law: safeguardsU.K.

(1)This section makes provision for the purposes of Article 22(2)(b) of the [F2UK GDPR] (exception from Article 22(1) of the [F2UK GDPR] for significant decisions based solely on automated processing that are [F3required or authorised under the law of the United Kingdom or a part of the United Kingdom] and subject to safeguards for the data subject's rights, freedoms and legitimate interests).

(2)A decision is a “significant decision” for the purposes of this section if, in relation to a data subject, it—

(a)produces legal effects concerning the data subject, or

(b)similarly significantly affects the data subject.

(3)A decision is a “qualifying significant decision” for the purposes of this section if—

(a)it is a significant decision in relation to a data subject,

(b)it is required or authorised by law, and

(c)it does not fall within Article 22(2)(a) or (c) of the [F4UK GDPR] (decisions necessary to a contract or made with the data subject's consent).

(4)Where a controller takes a qualifying significant decision in relation to a data subject based solely on automated processing—

(a)the controller must, as soon as reasonably practicable, notify the data subject in writing that a decision has been taken based solely on automated processing, and

(b)the data subject may, before the end of the period of 1 month beginning with receipt of the notification, request the controller to—

(i)reconsider the decision, or

(ii)take a new decision that is not based solely on automated processing.

(5)If a request is made to a controller under subsection (4), the controller must, within the period described in Article 12(3) of the [F5UK GDPR]

(a)consider the request, including any information provided by the data subject that is relevant to it,

(b)comply with the request, and

(c)by notice in writing inform the data subject of—

(i)the steps taken to comply with the request, and

(ii)the outcome of complying with the request.

(6)In connection with this section, a controller has the powers and obligations under Article 12 of the [F6UK GDPR] (transparency, procedure for extending time for acting on request, fees, manifestly unfounded or excessive requests etc) that apply in connection with Article 22 of the [F6UK GDPR].

(7)The Secretary of State may by regulations make such further provision as the Secretary of State considers appropriate to provide suitable measures to safeguard a data subject's rights, freedoms and legitimate interests in connection with the taking of qualifying significant decisions based solely on automated processing.

(8)Regulations under subsection (7)—

(a)may amend this section, and

(b)are subject to the affirmative resolution procedure.