Automated processing

Data protection glossary · 1 minute read

Automated processing is any processing of personal data carried out wholly or partly by means of data processing systems.

Relevance for the scope of the GDPR

The GDPR applies to all processing of personal data carried out wholly or partly by automated means. It covers non-automated processing, for example in paper files, only if the data forms part of a filing system or is intended to do so.

In practice, this means that almost all data processing in a company falls under the GDPR, from emails to spreadsheets.

Automated individual decisions

Special rules apply where a decision with legal or similarly significant effects is taken solely by automated means, for example a system rejecting a loan application. Art. 22 GDPR permits this only in exceptional cases and requires safeguards such as the right to obtain human intervention.

In its judgment of 7 December 2023 (C-634/21, SCHUFA), the CJEU held that the mere calculation of a credit score can itself be such a decision if third parties draw strongly on it in making their own decision.

Art. 2(1) GDPR
Material scope for automated processing and processing in filing systems.
Art. 4(4) GDPR
Definition of profiling.
Art. 22 GDPR
Automated individual decision-making, including profiling.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.