Personal Information Protection Law, automated decisions
PIPL Art. 24, Art. 55(2) and Art. 56 (automated decision-making)
In force since .
A data subject rights rule binding public and private bodies.
- Audit expectation
- none
As of .
What it requires
- Ensure transparency and non-discriminatory treatment in any automated decision made using personal information, and do not use it for unreasonable differential pricing.
- Offer a non-personalized option or a convenient opt-out wherever automated decision-making is used to push marketing or commercial information.
- Provide an explanation and honor an individual's refusal of a decision made solely by automated means where that decision has a major effect on their rights.
- Complete a personal-information-protection impact assessment before deploying automated decision-making, and keep the assessment report and the processing record for at least three years.
What this law does
Article 24's first paragraph requires a personal information processor using personal information for automated decision-making to ensure the decision-making is transparent and its results are fair and impartial, and bars unreasonable differential treatment of individuals in transaction conditions such as price.
Its second paragraph requires a non-personalized option or a convenient way to decline wherever information push or commercial marketing toward an individual is itself carried out by means of automated decision-making. Its third paragraph gives an individual the right to an explanation and the right to refuse a decision made solely through automated decision-making where that decision has a major effect on their rights and interests.
Article 55(2) requires a processor to carry out a personal-information-protection impact assessment in advance, and keep a record of the processing, before using personal information to conduct automated decision-making.
Article 56 requires that assessment to cover whether the purpose and method of the processing are lawful, legitimate and necessary, the impact on individual rights and the security risk, and whether the protective measures taken are lawful, effective and proportionate to the risk, with the assessment report and processing record kept for at least three years.
When LexLint raises it
When your app profile says your app makes high-risk automated decisions or sends automated outreach.