SUNDAY 20 SEPTEMBER· STOCKHOLM · THE DAY IN 5 STORIES

When a fully automated decision changes your future, GDPR gives you a right to understand and challenge it

GDPR generally prohibits fully automated decisions with major effects. Exceptions do not erase the right to understand and challenge.

A person uses a card reader beside a laptop for an online financial transaction.
REINER SCT / Pexels License

A credit application can be rejected in seconds without a human reading it. Under GDPR, that is not simply an efficient workflow when the result has legal or similarly significant effects.

Sweden's privacy regulator explains that fully automated individual decision-making is generally prohibited. Exceptions exist when it is necessary for a contract, authorised by law or based on explicit consent. A system used only to support a decision made by a person normally falls outside this specific rule.

When the rule does apply, the organisation must tell the person automation occurred and provide meaningful information about the logic, importance and expected consequences. If an AI model produced the result, the explanation must be sufficient to show how it reached that outcome and what the person can do to change the decision.

The law does not require every line of a “black box” to be exposed. It requires an explanation useful enough for rights to be exercised.

That distinction matters as scoring systems spread across credit, insurance, work and public services. A technically accurate model can still create an unchallengeable power if the affected person cannot identify the input, error or route to review.

Automation can accelerate a decision. It cannot be allowed to remove the person from the process of contesting what the decision does to their life.

DailySweden logo

DailySweden

DailySweden's desk of editors, reporters, researchers and investigative journalists. We bring readers factual, truthful and objective reporting on the issues that matter to them.

Contact the editorial desk ›