Data Protection HubConcepts and Definitions

Profiling (Article 4(4) GDPR)

Profiling means any automated processing of personal data used to evaluate personal aspects relating to a natural person, in particular to analyze or predict behavior, economic situation, or health.

Article 4(4) GDPR defines profiling as any form of automated processing of personal data consisting of the use of that data to evaluate certain personal aspects relating to a natural person. The term is broad and covers both the analysis of existing characteristics and the prediction of future behavior or future states.

Key takeaways

  • Profiling is any automated evaluation of personal data aimed at evaluating personal aspects relating to a natural person.
  • Three statutory criteria must be met cumulatively: automated processing, evaluation of personal aspects, and a reference to an identifiable natural person.
  • Scoring (e.g., creditworthiness assessment) is the most practically significant subcase; the CJEU has classified SCHUFA scoring as profiling under Article 4(4) GDPR.
  • Profiling and automated individual decision-making are distinct categories: Article 22 GDPR applies only where the profiling directly forms the basis of a decision with significant effects.
  • Transparency obligation: controllers must provide information about the existence of profiling and its envisaged consequences (Articles 13 and 14 GDPR).

1. Overview

Profiling requires three statutory criteria: automated processing, an evaluation of personal aspects, and a reference to an identifiable natural person (cf. Article 4(1) GDPR).

Profiling is not a separate category of processing but a subcase of automated processing. It is initially subject to the general requirements of the GDPR: a legal basis under Article 6(1) GDPR and compliance with all the principles under Article 5 GDPR. Special, additional rules apply only where the profiling becomes the basis of an automated individual decision under Article 22 GDPR.

2. Statutory criteria

2.1 Automated processing

The processing must be carried out in an automated manner, that is, without material human involvement in the actual evaluation operation. Typical implementations are algorithmic evaluations, machine learning, and rule-based systems. The purely manual review and assessment of data records by individuals does not fall within the term.

2.2 Evaluation of personal aspects

The core criterion is the evaluation. The processing must be directed at obtaining statements about a person, whether these are current states (analysis) or predictions. Recital 71 GDPR lists the following as standard examples of personal aspects that may be evaluated:

AspectPractical example
Performance at workAutomated evaluation of productivity data in a home office setting
Economic situationCredit score based on account activity and payment data
HealthEvaluation of fitness-tracker data to estimate disease risk
Personal preferences and interestsRecommendation algorithm based on click and purchase behavior
ReliabilityAssessment of delivery compliance or return rates among online buyers
BehaviorAnalysis of browsing behavior to classify fraud risk
Location or movementsMobility profile derived from location data for targeted advertising

The list is not exhaustive; what is decisive is that the processing aims to obtain insights into personal characteristics, not object-related evaluations without a reference to a person.

Scoring is a particularly significant subcase in practice: a probability value is calculated from existing data, making a statement about future behavior, such as creditworthiness or payment reliability. The CJEU has confirmed that automated scoring by credit reference agencies falls under Article 4(4) GDPR and, insofar as the score directly forms the basis of a credit decision, under Article 22 GDPR (CJEU, judgment of 7 December 2023, C-634/21, SCHUFA Holding (Scoring)).

2.3 Reference to a natural person

The profiling must relate to a specific or identifiable natural person. Purely aggregated statistics that cannot be traced back to individuals do not satisfy the criterion. Where re-identification is possible with proportionate effort, the reference to a person persists.

3. Relationship to Article 22 GDPR

Article 22(1) GDPR protects data subjects from being subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

Profiling and automated individual decision-making are two distinct matters. Profiling may be a preliminary stage, a component, or an instrument of such a decision, but it is not identical to it. Profiling without a subsequent individual decision is not subject to Article 22 GDPR; in that case, only the general requirements of the GDPR apply, in particular the principles under Article 5 GDPR and the obligation to have a legal basis under Article 6(1) GDPR.

Recital 71 GDPR explains that the scope of protection of Article 22 GDPR covers profiling insofar as it produces legal effects or similarly significantly affects the data subject (Recital 71 GDPR). It also identifies the monitoring of employees' behavior and performance as a relevant area of application.

4. Profiling based on special categories of data

Where data under Article 9(1) GDPR feed into the profiling, for example health data, data concerning ethnic origin, political opinions, or religious beliefs, the heightened requirements of that provision apply. Such processing is permissible only under the narrow conditions of Article 9(2) GDPR. Recital 71 GDPR expressly emphasizes that profiling based on special categories requires special safeguards (cf. Sensitive data categories).

In practice, profiling may also touch upon special categories of data even where such data are not processed directly: if health status, religious affiliation, or political views are inferred from neutral data (purchasing behavior, location data, browsing history), this may de facto constitute processing of special categories. Controllers should examine this at an early stage when designing profiling procedures.

5. Transparency and information obligation

The controller must inform the data subject that profiling is taking place and provide information about the envisaged consequences of this processing. Recital 60 GDPR gives concrete expression to this principle: the information forms part of fair and transparent processing and is part of the information obligations under Articles 13 and 14 GDPR (Recital 60 GDPR). Where an automated individual decision within the meaning of Article 22 GDPR occurs, further specific rights to information and objection are added.

The accuracy of the data processed for the profiling is of particular importance: erroneous input data can lead to inaccurate profiling results and violate the principle of accuracy under Article 5(1)(d) GDPR (cf. Accuracy).

6. Guidelines of the European Data Protection Board

Recital 72 GDPR states that the EDPB (European Data Protection Board) may issue guidelines on profiling (Recital 72 GDPR). Of particular practical relevance are the EDPB guidelines (formerly the Article 29 Data Protection Working Party) on automated decision-making and profiling, which give concrete expression to the requirements regarding legal basis, transparency, data minimization, and data subject rights in profiling procedures.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn