Home/Resources/Articles/Automated Decision-Making and Profiling: KVKK Scope and Data Subject Rights
Back to Articles
Yapay Zeka Yönetişimi10 min read

Automated Decision-Making and Profiling: KVKK Scope and Data Subject Rights

From credit scoring to hiring filters, many decisions are now made by algorithms. We explain the right to object to automated decisions under KVKK Art. 11, the risks of profiling, and the measures organisations should take.

JUS. Hukuk Ekibi
Uyum ve Veri Koruma
September 6, 2026
Automated Decision-Making and Profiling: KVKK Scope and Data Subject Rights

A loan application rejected within seconds, a job application filtered out by the system, or an insurance premium set by an algorithm... Today many decisions are made by software alone, without a human touch. Such fully automated decisions and the profiling that underpins them require special attention under the KVKK.

In this article we cover what automated decision-making and profiling are, the right to object that the KVKK grants to data subjects, the risks of profiling, and the governance framework organisations should build.

What Are Automated Decision-Making and Profiling?

Automated decision-making is the making of a decision solely by automated systems (algorithms, models) without human intervention. What matters here is whether a meaningful human assessment exists at the end of the process.

Profiling is the automated processing of personal data to analyse or predict aspects of an individual such as performance, economic situation, health, preferences, reliability or behaviour. Profiling often forms the input to automated decisions.

Not every instance of profiling ends in an automated decision; but fully automated decisions producing an adverse outcome require particular care.

KVKK Art. 11 and the Right to Object

Article 11 of the KVKK sets out the rights granted to data subjects. One of these is the right to object to an outcome against the person that arises from the exclusively automated analysis of the processed data.

Three elements are assessed together for this right to apply:

  1. The analysis must be carried out by exclusively automated systems.
  2. This analysis must produce a result.
  3. The result must be against the data subject.

When these conditions coincide, the data subject may object to the decision. This does not mean automated decisions are entirely prohibited; it means organisations must design such decisions to be accountable and reviewable.

The Risks of Profiling

As powerful as it is, profiling also carries risks. The main risk areas are:

  • Discrimination: If the historical data fed into the model is biased, the output can be discriminatory too.
  • Lack of transparency: The individual may not understand how a decision about them was made (the "black box" effect).
  • Inaccurate or incomplete data: Wrong input produces wrong predictions and unfair results.
  • Purpose creep: Reusing data collected for one purpose for profiling.
  • Disproportionality: An imbalance between the impact of the decision and the amount of data used.

These risks are not only a compliance issue but also a matter of reputation and trust.

Measures Organisations Should Take

The core governance measures to make automated decision and profiling processes lawful and trustworthy are:

  • Human oversight: A meaningful human assessment should be in the loop for critical decisions.
  • Transparency and information: The data subject should be informed that an automated decision is made, the outline of its logic, and its potential consequences.
  • Objection mechanism: A channel should be established where the individual can easily object and request a re-assessment.
  • Data quality: The data entering the model should be accurate, up to date and limited to the purpose.
  • Impact assessment: For high-impact models, risks should be analysed in advance.
  • Logging and traceability: How decisions are produced should be documented and auditable.

Comparing Automated and Semi-Automated Decisions

The table below summarises the risk profile and expected measures by process type.

DimensionFully Automated DecisionHuman-Supervised Decision
Art. 11 objection riskHighLow
Transparency needVery highHigh
Recommended measureObjection + reviewProcess and logging discipline
ExampleAutomated pre-screeningExpert-approved final decision

Implementation Steps

Practical steps an organisation can follow to bring its automated decision processes into compliance:

  1. Build an inventory. Identify which processes use automated decisions or profiling.
  2. Classify the degree of automation. Determine whether the decision is fully automated or human-supervised.
  3. Update your notices. Add clear information about automated decisions and profiling.
  4. Set up an objection channel. Define a clear route for the individual to object to the decision.
  5. Add human oversight. Introduce a meaningful review step for high-impact decisions.
  6. Monitor the model. Run regular checks for discrimination, error and data quality.

Example Scenario

An e-commerce company uses a model that scores orders in real time to prevent payment fraud. The model automatically rejects orders above a certain threshold, and the customer immediately receives a "your payment could not be approved" message.

A customer notices being repeatedly rejected despite a valid card and queries the situation. At this point the company sees that the decision is exclusively automated and produces an adverse outcome for the customer. For a compliant approach the company does the following: it adds a note to its privacy notice that an automated assessment is performed; it creates a human review queue for rejected transactions; and it offers the customer the option to "request a review of the decision".

As a result, fraud protection is preserved while a meaningful route for objection and correction is opened for false-positive decisions.

Frequently Asked Questions

Is every automated decision prohibited?

No. The KVKK does not ban automated decisions wholesale. It grants the data subject a right to object when an exclusively automated analysis produces a result against them. Organisations are expected to make such decisions transparent, supervised and open to objection.

If I carry out profiling, must I inform the data subject?

Yes. Transparency and information are core obligations. Giving the individual understandable information that profiling is carried out, its main logic and its likely consequences is critical for both compliance and trust.

For "human oversight", is it enough for a person to approve the decision?

The oversight must be meaningful. A step that merely rubber-stamps the system's output is not genuine oversight. The reviewer must have the authority and the data to change the decision.

Is using an AI model contrary to the KVKK?

No. Using AI is not itself unlawful. What matters is running the model within a governance framework that observes a legal basis, data quality, transparency, human oversight and data subject rights.

This content is for general informational purposes only and does not constitute legal advice.

With JUS. you can inventory your automated decision and profiling processes and standardise your information and objection flows; request a demo to see how it works.

Share this article

Need Help?

JUS. can help you implement best practices for compliance.

Book a Demo
Request Demo