# Profiling (Article 4(4) GDPR)

Profiling means any automated processing of personal data used to evaluate personal aspects relating to a natural person, in particular to analyze or predict behavior, economic situation, or health.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/begriffe-und-definitionen/1.2.4-profiling
> Sprache: en



[Article 4(4) GDPR](https://dsgvo-gesetz.de/art-4-dsgvo/) defines profiling as any form of automated processing of personal data consisting of the use of that data to evaluate certain personal aspects relating to a natural person. The term is broad and covers both the analysis of existing characteristics and the prediction of future behavior or future states.

<Callout type="info">
  **Key takeaways**

  * Profiling is any automated evaluation of personal data aimed at evaluating personal aspects relating to a natural person.
  * Three statutory criteria must be met cumulatively: automated processing, evaluation of personal aspects, and a reference to an identifiable natural person.
  * Scoring (e.g., creditworthiness assessment) is the most practically significant subcase; the CJEU has classified SCHUFA scoring as profiling under Article 4(4) GDPR.
  * Profiling and automated individual decision-making are distinct categories: Article 22 GDPR applies only where the profiling directly forms the basis of a decision with significant effects.
  * Transparency obligation: controllers must provide information about the existence of profiling and its envisaged consequences (Articles 13 and 14 GDPR).
</Callout>

## 1. Overview [#1-overview]

Profiling requires three statutory criteria: automated processing, an evaluation of personal aspects, and a reference to an identifiable natural person (cf. [Article 4(1) GDPR](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.1-personenbezogene-daten)).

<Callout type="info">
  Profiling is not a separate category of processing but a subcase of automated processing. It is initially subject to the general requirements of the GDPR: a legal basis under [Article 6(1) GDPR](https://dsgvo-gesetz.de/art-6-dsgvo/) and compliance with all the principles under [Article 5 GDPR](https://dsgvo-gesetz.de/art-5-dsgvo/). Special, additional rules apply only where the profiling becomes the basis of an automated individual decision under Article 22 GDPR.
</Callout>

## 2. Statutory criteria [#2-statutory-criteria]

### 2.1 Automated processing [#21-automated-processing]

The processing must be carried out in an automated manner, that is, without material human involvement in the actual evaluation operation. Typical implementations are algorithmic evaluations, machine learning, and rule-based systems. The purely manual review and assessment of data records by individuals does not fall within the term.

### 2.2 Evaluation of personal aspects [#22-evaluation-of-personal-aspects]

The core criterion is the evaluation. The processing must be directed at obtaining statements about a person, whether these are current states (analysis) or predictions. [Recital 71 GDPR](https://dsgvo-gesetz.de/erwaegungsgruende/nr-71/) lists the following as standard examples of personal aspects that may be evaluated:

| Aspect                             | Practical example                                                     |
| ---------------------------------- | --------------------------------------------------------------------- |
| Performance at work                | Automated evaluation of productivity data in a home office setting    |
| Economic situation                 | Credit score based on account activity and payment data               |
| Health                             | Evaluation of fitness-tracker data to estimate disease risk           |
| Personal preferences and interests | Recommendation algorithm based on click and purchase behavior         |
| Reliability                        | Assessment of delivery compliance or return rates among online buyers |
| Behavior                           | Analysis of browsing behavior to classify fraud risk                  |
| Location or movements              | Mobility profile derived from location data for targeted advertising  |

The list is not exhaustive; what is decisive is that the processing aims to obtain insights into personal characteristics, not object-related evaluations without a reference to a person.

**Scoring** is a particularly significant subcase in practice: a probability value is calculated from existing data, making a statement about future behavior, such as creditworthiness or payment reliability. The CJEU has confirmed that automated scoring by credit reference agencies falls under Article 4(4) GDPR and, insofar as the score directly forms the basis of a credit decision, under Article 22 GDPR ([CJEU, judgment of 7 December 2023, C-634/21, SCHUFA Holding (Scoring)](/docs/dsgvo-hub/rechtsprechung/1.4.32-eugh-schufa-scoring)).

### 2.3 Reference to a natural person [#23-reference-to-a-natural-person]

The profiling must relate to a specific or identifiable natural person. Purely aggregated statistics that cannot be traced back to individuals do not satisfy the criterion. Where re-identification is possible with proportionate effort, the reference to a person persists.

## 3. Relationship to Article 22 GDPR [#3-relationship-to-article-22-gdpr]

[Article 22(1) GDPR](https://dsgvo-gesetz.de/art-22-dsgvo/) protects data subjects from being subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

Profiling and [automated individual decision-making](/docs/dsgvo-hub/einzelthemen/1.3.14-automatisierte-einzelentscheidung) are two distinct matters. Profiling may be a preliminary stage, a component, or an instrument of such a decision, but it is not identical to it. Profiling without a subsequent individual decision is not subject to Article 22 GDPR; in that case, only the general requirements of the GDPR apply, in particular the principles under [Article 5 GDPR](https://dsgvo-gesetz.de/art-5-dsgvo/) and the obligation to have a legal basis under Article 6(1) GDPR.

Recital 71 GDPR explains that the scope of protection of Article 22 GDPR covers profiling insofar as it produces legal effects or similarly significantly affects the data subject ([Recital 71 GDPR](https://dsgvo-gesetz.de/erwaegungsgruende/nr-71/)). It also identifies the monitoring of employees' behavior and performance as a relevant area of application.

## 4. Profiling based on special categories of data [#4-profiling-based-on-special-categories-of-data]

Where data under Article 9(1) GDPR feed into the profiling, for example health data, data concerning ethnic origin, political opinions, or religious beliefs, the heightened requirements of that provision apply. Such processing is permissible only under the narrow conditions of Article 9(2) GDPR. Recital 71 GDPR expressly emphasizes that profiling based on special categories requires special safeguards (cf. [Sensitive data categories](/docs/dsgvo-hub/einzelthemen/besondere-kategorien-personenbezogener-daten/1.3.12.1-sensible-datenkategorien)).

<Callout type="warn">
  In practice, profiling may also touch upon special categories of data even where such data are not processed directly: if health status, religious affiliation, or political views are inferred from neutral data (purchasing behavior, location data, browsing history), this may de facto constitute processing of special categories. Controllers should examine this at an early stage when designing profiling procedures.
</Callout>

## 5. Transparency and information obligation [#5-transparency-and-information-obligation]

The controller must inform the data subject that profiling is taking place and provide information about the envisaged consequences of this processing. Recital 60 GDPR gives concrete expression to this principle: the information forms part of fair and transparent processing and is part of the information obligations under Articles 13 and 14 GDPR ([Recital 60 GDPR](https://dsgvo-gesetz.de/erwaegungsgruende/nr-60/)). Where an automated individual decision within the meaning of Article 22 GDPR occurs, further specific rights to information and objection are added.

The accuracy of the data processed for the profiling is of particular importance: erroneous input data can lead to inaccurate profiling results and violate the principle of accuracy under Article 5(1)(d) GDPR (cf. [Accuracy](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.6-richtigkeit)).

## 6. Guidelines of the European Data Protection Board [#6-guidelines-of-the-european-data-protection-board]

Recital 72 GDPR states that the EDPB (European Data Protection Board) may issue guidelines on profiling ([Recital 72 GDPR](https://dsgvo-gesetz.de/erwaegungsgruende/nr-72/)). Of particular practical relevance are the EDPB guidelines (formerly the Article 29 Data Protection Working Party) on automated decision-making and profiling, which give concrete expression to the requirements regarding legal basis, transparency, data minimization, and data subject rights in profiling procedures.

<Cards>
  <Card title="Personal data" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.1-personenbezogene-daten" description="Prerequisite of profiling: a reference to an identifiable natural person." />

  <Card title="Sensitive data categories" href="/docs/dsgvo-hub/einzelthemen/besondere-kategorien-personenbezogener-daten/1.3.12.1-sensible-datenkategorien" description="Article 9 GDPR: heightened requirements for profiling based on sensitive data." />

  <Card title="Accuracy" href="/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.6-richtigkeit" description="Article 5(1)(d) GDPR: correct input data as a prerequisite for valid profiling results." />

  <Card title="Automated individual decision-making" href="/docs/dsgvo-hub/einzelthemen/1.3.14-automatisierte-einzelentscheidung" description="Article 22 GDPR: when profiling becomes the basis of a prohibited individual decision." />

  <Card title="CJEU SCHUFA Scoring" href="/docs/dsgvo-hub/rechtsprechung/1.4.32-eugh-schufa-scoring" description="CJEU C-634/21: scoring as profiling and its relationship to Article 22 GDPR." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.