GDPR: what it asks of an approval matrix
For a company with EU or UK operations: the rule on decisions based solely on automated processing, added on lines that decide something about a person.
Quoted when the company has EU or UK operations.
Named, not quoted, beside it: the UK Corporate Governance Code provision on risk management and internal control.
Approval families anchored here
4GDPR: every clause cited, quoted
3 of the 40 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
GDPR Art. 22 Automated individual decision-making, including profilingDo not subject a data subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the decision is necessary for entering into or performing a contract between the data subject and the controller, is authorised by Union or Member State law that lays down suitable safeguards, or is based on the data subject's explicit consent. Where the contract or explicit consent route is used, implement suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express a point of view and to contest the decision. Such decisions must not be based on special categories of personal data unless explicit consent or substantial public interest applies and suitable safeguards are in place.
Where matrices usually fall short: A rubber stamp reviewer treated as human involvement, which leaves the decision solely automated in substance; Necessity for a contract asserted where a manual or hybrid process would work and is merely more expensive; Special category data entering the model through proxies such as postcode, name or purchase history with no assessment; No route for the data subject to contest the decision, only a route to complain about service
Source: GDPR
GDPR Art. 24 Responsibility of the controllerImplement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that processing is performed in accordance with the Regulation, taking into account the nature, scope, context and purposes of processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons. Review and update those measures where necessary. Where proportionate in relation to the processing activities, the measures must include implementing appropriate data protection policies. Adherence to an approved code of conduct or an approved certification mechanism may be used as one element by which to demonstrate compliance, not as a substitute for it.
Where matrices usually fall short: A policy suite adopted once and never reviewed, so it describes processing the organisation no longer carries out; Measures selected from a generic checklist with no link to the risk this organisation's own processing presents; Accountability documentation that records what should happen with no evidence that it does; Certification or code adherence presented as the whole of compliance rather than as one element of it
Source: GDPR
GDPR Art. 29 Processing under the authority of the controller or processorThe processor, and any person acting under the authority of the controller or of the processor who has access to personal data, must not process that data except on instructions from the controller, unless required to do so by Union or Member State law.
Where matrices usually fall short: Instructions existing only as the original contract, never updated as the processing changed over years of service; Staff holding broad standing access to production personal data far beyond what their instructed tasks require; No means of detecting processing outside instruction, so the obligation is asserted and never tested; Processor use of controller data for its own purposes, such as service improvement or model training, permitted by a clause nobody negotiated
Source: GDPR