TwinEthosRequest access

Control

Algorithmic recommendation with no opt-out or non-personalized option

Users must be able to conveniently turn off algorithmic recommendation or choose a non-personalized option, and select/delete the tags used to target them.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: People cannot opt out of automated decision-making, profiling, or personalization · control id cond.algorithmic-recommendation-no-optout

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in China (CN).

The guard to add

Give users a setting that turns off personalized recommendation (or picks a non-personalized feed) and controls to view and delete their targeting tags, enforced in the feed service.

A per-user personalization_enabled preference stored server-side and read by the feed or search service before it calls the personalized recommender (get_recommendations, recommend_for_user); when it is off, the service immediately serves a non-personalized feed (latest, popular, editorial) not keyed to user features, including on cached responses. The interest tags or labels that drive targeting are listed to the user with select and delete controls (GET and DELETE /me/tags/{id}), and the recommender excludes deleted tags on the next request. A notice in settings or next to the feed says that recommendations are algorithmic and why.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.

What reviewers look for: a settings toggle that writes a stored preference; a branch in the feed handler that reads it before the recommend call and returns a non-personalized result; tag list and delete endpoints whose effect reaches the recommender inputs; no cached personalized feed served after the user turns personalization off.

Example (FastAPI feed service), before:

@app.get('/feed')
def feed(user=Depends(current_user)):
    return get_recommendations(user_id=user.id, k=50)

After:

@app.get('/feed')
def feed(user=Depends(current_user)):
    if not prefs.get(user.id, 'personalization_enabled', default=True):
        return non_personalized_feed(k=50)       # latest/popular, no user features
    return get_recommendations(user_id=user.id, k=50, exclude_tags=tags.deleted(user.id))

@app.delete('/me/tags/{tag_id}')
def delete_tag(tag_id: str, user=Depends(current_user)):
    tags.delete(user.id, tag_id)
    feed_cache.invalidate(user.id)

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)