Profiling under GDPR: Obligations of Data Controllers and Rights of Data Subjects

31 December 2025

The development of technology and ongoing digitization have led to the widespread use of profiling as a tool employed across various sectors of the economy – from marketing to advanced financial services. Thanks to modern technologies such as artificial intelligence and big data analytics, it has become possible to precisely tailor offers and services to the individual needs of persons. Profiling, being a complex and multidimensional process, brings numerous benefits – it not only increases efficiency but also saves resources. However, it is also associated with serious challenges regarding the protection of personal data.

The risk arising from profiling, including the potential impact of this process on the rights and freedoms of individuals, has been recognized by the EU legislator. In response to these threats, specific provisions regulating profiling and automated decision-making were introduced in the GDPR.

These provisions were clarified by the Article 29 Working Party in its guidelines on automated decision-making in individual cases and profiling for the purposes of Regulation 2016/679/EU. Further details on these issues can also be found in the positions of other European supervisory authorities or inferred from the fines imposed by supervisory bodies.

The aim of the indicated regulations is to ensure a balance between the interests of data controllers and the rights of the individuals whose data is being processed. Key principles in this regard include transparency, purpose limitation, and data minimization, as well as the rights of individuals, such as the right to object to profiling and the right to be informed about decision-making processes.

What is profiling

According to the definition contained in Article 4(4) of the GDPR, profiling means any form of automated processing of personal data intended to evaluate certain personal aspects of an individual. It may involve the analysis or prediction of aspects such as work performance, economic situation, health, interests, reliability, behavior, location, or movement. An extension of this definition can be found in the preamble of the GDPR, in recitals 24, 60, 63, 70–73, 75, and 91.

Profiling thus constitutes a specific form of data processing. Below, we discuss the fundamental elements of this process.

  1. Automated form of processing – actions are carried out without direct human involvement.

The data processing process is considered automated when decisions are made entirely without human involvement. An example is the automatic generation of recommendations by a system. However, if a human has a real influence on the outcome through analysis and consideration of additional factors, the process is not fully automated. A symbolic human involvement, consisting of formally approving a decision without real intervention, does not change the automated nature of the process. For human involvement to be significant, it must have the actual ability to change the outcome based on its own assessment.

  1. Personal data as the basis for analysis – processing operations must relate to information linked to a specific individual.

Automated decision-making can be based on various types of data, such as:

  • data obtained directly from the individual concerned (e.g., data entered into a survey form),
  • data collected as a result of observation (e.g., location data obtained through a mobile application),
  • data deduced or sourced from other sources (e.g., creditworthiness data derived from a profile created based on the individual's activities).
  1. Assessment of personal factors – the purpose of profiling is to draw conclusions or make predictions based on data analysis and to influence the rights of the individual concerned by this process.

Automated decision-making can have legal consequences if it affects the rights of a natural person, such as the right to vote, freedom of association, or the ability to take legal action. Examples of such decisions include, among others:

  • termination of a contract,
  • granting or denying social benefits (e.g., housing allowance, family allowance),
  • refusal to grant citizenship.

Even when a decision does not result in direct legal changes, it can have a significant impact on the individual. Such effects are considered significant if:

  • they significantly affect the choices, behavior, or situation of the individual,
  • they cause long-term consequences,
  • in extreme cases, they lead to discrimination or exclusion.

Examples of significant impact include the automatic rejection of an online credit application or e-recruitment processes conducted without human involvement. Such decisions can permanently affect the situation of individuals whose data is processed.

DPO Role - it transfers well

Examples of profiling

In practice, profiling is widely used in various fields. It enables the customization of offers to customer preferences based on their previous behaviors, optimizes decision-making processes, personalizes content, and increases the effectiveness of actions in various areas. Below we present selected examples of the application of profiling in practice.

  • Marketing profiling – enables precise matching of offers to the needs and preferences of customers. For example, an e-commerce organization may analyze purchase history, viewed products, the time a customer spends on its website or in the application. Based on this information, it creates customer segments, such as "people who regularly purchase electronics" or "people interested in fashion." This approach allows for better targeting of advertisements and offers, which in turn increases the effectiveness of marketing campaigns and contributes to sales growth.
  • Social media profiling – social media platforms, such as Facebook or Instagram, utilize advanced algorithms to monitor user activity. This includes analyzing likes, comments, shares, and interactions within the network of friends. As a result, the algorithms are able to create detailed profiles of user interests. The content personalization offered by these platforms not only keeps users on the site longer but also increases advertising revenue.
  • Recruitment and HR profiling – helps select the best candidates for a given position. Employers and recruitment agencies use psychometric tests, personality assessments, and work experience to create a profile of the ideal candidate. Analyzing data from CVs and professional networks, such as LinkedIn, also allows for quicker identification of individuals who meet the required criteria. Such actions can help reduce recruitment costs and the risk of employee turnover.
  • Banking customer profiling – banks and financial institutions utilize transactional data and information about creditworthiness, demographics, and financial habits of customers to create risk profiles. Based on these profiles, they assess whether a customer may have difficulties repaying a loan or whether they require greater protection against fraud. Profiling allows banks to better manage risk, optimize credit decisions, and effectively prevent financial abuses.
  • Health and medical profiling – is used to identify risk groups for specific diseases, such as diabetes or heart disease. Entities in the medical field analyze data regarding medical history, lifestyle, age, and place of residence. This approach enables early detection of threats, development of preventive programs, and effective planning of health initiatives targeted at the most at-risk groups.

Practical DPO Course
Practical DPO Course
will confirm your high competencies
Prepare to fulfill the role of a Data Protection Officer. We invite you!
CHOOSE A DATE
On the other hand, simple categorization of individuals based on age, gender, or height does not necessarily have to be considered profiling. Its qualification depends on the purpose for which it is applied. For example, a company may classify its customers by age and gender for statistical purposes to obtain a general picture of its customer base, but it will not assess individual personal characteristics. In such a case, the processing of data does not constitute profiling, as it is not aimed at evaluating personal aspects of a given individual. However, if the purpose were to predict or draw conclusions about such characteristics, then the processing could be considered profiling.

At this point, it is worth noting the relationship between profiling and the process of automated decision-making – also regulated under the GDPR (Article 22). Profiling may be part of such a process, but it does not always lead to automated decision-making. This distinction is important as it affects the scope of obligations of the data controller and the rights of individuals whose data is processed. Automated decision-making, especially when based on special categories of data, involves the necessity to meet additional requirements.

Obligations of the data controller related to data profiling

Data profiling is subject to the regulations of the GDPR, which specify detailed principles for the protection of personal data. Data controllers are obliged to comply with these principles, which arise from key rules regarding data processing. One of the key principles mentioned in Article 5(1)(a) of the GDPR is lawfulness, fairness, and transparency of data processing. The data controller must ensure that individuals whose data is being processed are fully informed about the manner, purpose, and scope of such processing. Information should be provided in a clear, transparent, understandable, and easily accessible manner. In cases where data is collected directly from the data subject, the data controller must fulfill the information obligation at the time of data collection – in accordance with Article 13 of the GDPR. Conversely, when data has been obtained indirectly, i.e., from other sources, it is necessary to inform the data subject about this within the timeframes specified in Article 14(3) of the GDPR. For example, the fulfillment of the information obligation regarding profiling may be stated as follows:

„We use your data regarding your use of the loyalty program for profiling, which involves determining your purchasing preferences and tailoring our offers to those preferences. This is done based on Article 22(2)(c) of the GDPR. A prerequisite is obtaining your explicit consent for such action beforehand.”

or

„Your data will not be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant impacts.”

Profiling should be conducted in a fair manner to avoid situations leading to discrimination, such as denying access to financial products based on unclear or unreliable criteria. Banking law emphasizes the obligation of the lender to provide the applicant with detailed information regarding the credit assessment, especially when this process is based on profiling. Lenders (banks, credit unions, or financial institutions granting loans) are able to create advanced credit risk models through profiling, which support decision-making regarding loan approvals. In this process, personal data is crucial, as it allows for precise identification of which information influenced the outcome of the analysis and how it was taken into account. In the case of automated systems, such explanations should also include the methods used in the algorithms on which the assessment was based. This enables the applicant to better understand how their data was processed, thereby enhancing the transparency of the process and protecting their rights.

The principle of purpose limitation, as described in Article 5(1)(b) of the GDPR, requires the data controller to use personal data solely for purposes consistent with those for which it was originally collected. The data controller should assess the compliance of new processing purposes with the original purposes, taking into account factors such as the nature of the data and the technical and organizational measures implemented. Further processing of data for profiling purposes must be justified and consistent with the original information provided to the data subjects.

When was the last time you conducted a risk assessment?

Another obligation of the data controller is to comply with the principle of data minimization, as indicated in Article 5(1)(c) of the GDPR. Data controllers should collect and process only those data that are necessary to achieve specific profiling purposes. Collecting excessive data, even if it may be beneficial from the organization's perspective, is inconsistent with the principles of personal data protection. To minimize the risk of privacy breaches, data controllers should consider using aggregated, anonymized, or pseudonymized data, provided that such an approach does not negatively impact the effectiveness of profiling.

Data controllers are also required to ensure the accuracy of personal data – in accordance with Article 5(1)(d) of the GDPR. In profiling processes, the accuracy of data is crucial, as decisions made based on incorrect, outdated, or misinterpreted data can lead to significant harm to the individuals to whom the data pertains. Data controllers should monitor the accuracy of data at every stage of processing – from collection, through analysis and profiling, to decision-making based on those profiles.

The final significant aspect is compliance with the principle of storage limitation, as described in Article 5(1)(e) of the GDPR. Data controllers should retain personal data only for as long as necessary to fulfill the purposes for which the data was collected. In the context of profiling, this means the necessity of implementing a data retention policy that considers the protection of the rights and freedoms of natural persons. While retaining personal data for a longer period may enhance the capabilities of learning algorithms, it does not exempt the data controller from the obligation to adhere to the principle of proportionality and purpose limitation of processing.

In cases where profiling or automated decision-making is a key element of the data controller's activities, the GDPR imposes the obligation to appoint a Data Protection Officer (DPO).

Technical and Organizational Measures and Data Protection Impact Assessment

The data controller intending to carry out a data profiling process is obliged to implement appropriate technical and organizational measures to ensure the security of data processing both before and during the processing of such data.

Additionally, a controller planning to use profiling in data processing activities is required to conduct a Data Protection Impact Assessment (DPIA) if such actions may significantly affect the rights and freedoms of natural persons. Profiling has been directly included in the updated list of types of personal data processing operations that require a DPIA, published by the President of the Polish Data Protection Authority (UODO) in a communication dated June 17, 2019. This list includes, among other cases, profiling of social media users and other applications for the purpose of sending commercial information, creditworthiness assessment using artificial intelligence algorithms, including situations where confidentiality is required and the disclosure of data not directly related to the credit assessment, as well as the assessment of lifestyle, dietary habits, driving behaviors, or leisure activities of natural persons, e.g., to determine a higher insurance premium.

Conducting a DPIA allows the controller to identify potential risks arising from processing operations and to implement appropriate measures to mitigate these risks. Article 35(3)(a) of the GDPR clearly indicates that the obligation to conduct a DPIA encompasses processing activities based on automated decisions, including profiling, that produce legal effects or significantly affect natural persons. It is worth emphasizing that the provisions refer not only to fully automated processes but also to decisions that are partially supported by automated data processing tools.

If the controller plans to implement systems based on profiling that make decisions significantly affecting natural persons, they should consider the necessity of human intervention. Involving a human in the decision-making process can reduce the risks associated with fully automated processes and enhance compliance with GDPR requirements.

Dr RODO
GDPR Compliance Diagnosis.
Do it yourself
Utilize a flexible tool for inventory, auditing, conducting a DPIA, and risk analysis.
GET TO KNOW DR RODO
The results of the DPIA may indicate the need to implement additional measures to protect the rights of individuals whose data is being processed. Such actions include, among others:

  • informing the data subject about the use of an automated decision-making process and its principles,
  • explaining the significance and anticipated consequences of the processing for that individual,
  • providing them with the opportunity to object to the decision,
  • allowing them to present their own position.

Depending on the nature and scale of the processing, the data controller may also introduce other measures aimed at eliminating risks arising from advanced data processing technologies.

Data controllers should also consider implementing additional protective measures. Furthermore, in cases where profiling constitutes a significant element of the activity, involving systematic monitoring of data on a large scale, data controllers are required to appoint a Data Protection Officer in accordance with Article 37(1)(b) of the GDPR.

Profiling of special categories of data

Profiling personal data poses a serious legal challenge, especially concerning the processing of special categories of data. Data controllers may process such data only in specific cases, provided that the requirements of Article 9(2) of the GDPR are met. Profiling that involves analyzing and combining various data sources may lead to the disclosure of sensitive information that is subject to special protection. An example could be the analysis of grocery purchases in the context of the caloric content of products, which may reveal information about an individual's health status. Such connections may lead to the generation of special categories of data, even if the original data, such as purchase history, did not belong to them. In such cases, the data controller must ensure that the processing of data is lawful and has an appropriate legal basis.

Additionally, the data controller is obliged to ensure that the processing is consistent with the original purpose, meaning that they cannot use the data in a manner inconsistent with the purpose for which it was collected. It is also crucial to ensure transparency in data processing, including informing data subjects about the purpose of processing, the legal basis, and the methods of using their data.

In the context of automated decision-making, special categories of data may only be processed when such processing is permitted by law and is based on the explicit consent of the data subject or in connection with a significant public interest provided for by the law of the Union or a Member State. In the case of automated systems, the data controller should also explain to the data subjects how specific data influenced the outcome of the assessment or decision, as well as inform them about the methods used in the algorithms.

Rights of Data Subjects

Data subjects whose data are processed in profiling processes have a number of rights that protect their personal data and ensure control over it. The aim of the GDPR is to guarantee full transparency regarding the processing of personal data and to enable data subjects to make informed decisions regarding their data.

According to Article 13(2)(f) and Article 14(2)(g) of the GDPR, a data subject whose data are being profiled has the right to obtain detailed information about automated decision-making, including profiling, and the anticipated consequences of this process. Data controllers are obliged to provide this information in a transparent manner, allowing the individual to understand how automated processing affects their rights and freedoms. In particular, individuals subject to automated decision-making must be informed of the existence of such a process, the principles on which the data processing is based, as well as the significance and anticipated consequences of the decisions made.

GDPR. Support is useful!

According to Article 15(1)(h) of the GDPR, a data subject whose data are being profiled has the right to obtain additional information about automated processing that may have legal effects or significantly affect that individual. Data controllers are obliged to provide general information about the decision-making principles, including the criteria used and the anticipated consequences of the processing. Furthermore, the data subject should be informed about the factors considered in the decision-making process and their weight, which enables them to assess the fairness and legitimacy of the decision made.

The right to rectification of data, as specified in Article 16 of the GDPR, allows an individual whose data is being profiled to correct inaccurate or outdated information contained in their profile. Data controllers should enable this individual to access their profile and provide tools, such as privacy panels, that allow for the management of settings, updating personal data, and editing the profile to rectify any errors. Through such solutions, data controllers can also ensure compliance with the obligation to maintain data accuracy. It should be noted that the right to rectification and erasure of data applies to the underlying data on which the profile is based, the profile itself, as well as the assessment assigned to the individual concerned.

An individual whose data is processed based on profiling also has the right to object to such processing in accordance with Article 21(1) and (2) of the GDPR. Data controllers must inform this individual of their right to object clearly, in a manner that is straightforward and easily accessible, both on websites and in other relevant documents. Data controllers are obliged to ensure the visibility of this information and that it is not hidden among other records. This allows individuals whose data is concerned to easily exercise their right.

Risks and Sanctions Related to Profiling

Profiling, as an advanced technique for processing personal data, poses significant risks to the privacy of individuals whose data is being processed. Improper use of this mechanism can lead to serious legal and financial consequences for both data controllers and the individuals concerned. The GDPR imposes numerous obligations on data controllers aimed at ensuring that profiling processes comply with applicable regulations and minimizing the risk associated with violations of the rights of natural persons. Failure to fulfill these obligations may result in the imposition of substantial financial penalties and other administrative sanctions, which aim not only to protect the interests of individuals whose data is being processed but also to ensure accountability of data processors. According to the provisions of the GDPR, the supervisory authority may impose administrative fines of up to €10 million or €20 million, or up to 2% or 4% of the total annual global turnover of the undertaking – depending on the severity of the violation.

Examples of imposed penalties show that supervisory authorities in Europe are taking decisive action in cases of violations resulting from improper profiling:

  • A Spanish company was fined 3 million euros for failing to obtain explicit and informed consent from its customers for profiling their data. The violation concerned a fundamental principle of the GDPR, which is the processing of data based on the consent of the data subject. This represents one of the most significant risks in the context of profiling (more at: https://www.edpb.europa.eu/news/national-news/2022/aepd-fine-eur-3000000-caixabank-payments-consumer-efc-ep-sau-lack-specific_en).
  • In Germany, a company responsible for creating databases concerning individuals was fined 300,000 euros for failing to provide adequate information about automated decision-making, including profiling, and for not granting individuals whose data it processed the right to challenge these decisions. Such a violation can result in a loss of consumer trust and significant penalties, which are fully justified in light of the GDPR provisions regarding the protection of individuals' rights in relation to profiling (more at: https://www.edpb.europa.eu/news/national-news/2023/berlin-sa-imposes-300-000-euro-fine-against-bank-after-lack-transparency_pl).
  • The President of the Polish DPA imposed a financial penalty of 314,302 PLN on Toyota Bank Polska SA for omitting profiling in the records of processing activities and for failing to conduct a Data Protection Impact Assessment regarding the effects of profiling on personal data protection. Profiling, used by the bank to assess customers' creditworthiness, was not included in the documentation, despite having a significant impact on data processing. The President of the Polish DPA noted that the bank should have conducted an assessment of the effects of this process, particularly in the context of personal data protection (more at: https://uodo.gov.pl/pl/138/3519).

Summary

Data profiling, while offering numerous benefits in terms of service personalization and optimization of decision-making processes, poses serious challenges in the context of privacy protection and the rights of individuals whose data is being processed. From the perspective of the GDPR, it is essential to maintain a balance between the use of modern technologies to enhance the efficiency of data controllers' activities and the protection of individuals' fundamental rights. The regulations introduced, including specific rules regarding automated decision-making and profiling, aim to ensure greater transparency and protection of personal data, while simultaneously imposing on data controllers the responsibility for compliance with legal requirements, risk minimization, and ensuring transparency of processes.

Data controllers must adhere to the fundamental principles of the GDPR, such as lawfulness, data minimization, and the protection of the rights of individuals whose data is being processed. Conducting Data Protection Impact Assessments (DPIAs), appointing a Data Protection Officer (DPO), and implementing appropriate technical and organizational measures are key elements ensuring compliance with the regulations. At the same time, due to the increasingly widespread use of profiling, it is important for individuals to be aware of their rights and to have the ability to object to adverse decisions based on automated analysis of their data.

In the face of the dynamic development of technology and the growing role of data in the digital economy, privacy protection takes on particular significance. Data profiling – despite its potential – must be carried out with the highest standards of personal data protection, with full respect for individual rights. Only in this way will it be possible to create a balanced environment in which technological innovations do not conflict with fundamental values related to privacy and data protection.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.