The general data protection regulation and automated decision-making: Will it deliver
Dreyer, S., Schulz, W.
S Dreyer, W Schulz - Bertelsmann Stiftung, 2019 - reframetech.de
Abstract
The General Data Protection Regulation (GDPR) includes provisions that deal with automated decision-making (ADM). These provisions have the potential to prevent damage to the rights and freedoms of individuals. However, the requirements specified in the GDPR may not be sufficient to safeguard the interests of groups and society as a whole. The present study investigates the potentials and limitations of the GDPR with regard to ADM systems. It looks at possible risks arising from the use of ADM systems and at counter-measures that could safeguard the interests of individuals, groups and society as a whole. The study also examines the requirements imposed by the GDPR concerning ADM systems, as well as relevant provisions of data protection law. Finally, it analyzes where the GDPR brings benefits and where it falls short, and discusses possible data protection approaches and instruments for the remaining risk potentials. The study concludes that the GDPR offers a good starting point for safeguarding individual rights and freedoms in the age of ADM systems. However, the GDPR also has some weak spots concerning group-related and societal interests. In order to address these weak spots, the study recommends a number of measures, including: - Co-regulation: Certified codes of conduct as a support for commercial initiatives - GDPR: Expanding data protection authorities regulatory options - Opening clauses: More restrictive national law requirements - Alternative regulatory tools not covered by data protection law, such as explainability of automated decisions, enhanced transparency and accountability provisions, and options for application of consumer protection and competition law.