TwinEthosRequest access

Control

Profiling for significant-effects decisions with no opt-out

Consumers must be able to opt out of profiling (automated processing) used in furtherance of decisions that produce legal or similarly significant effects.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: People cannot opt out of automated decision-making, profiling, or personalization · control id cond.profiling-significant-effects-no-optout

Reach

1items this one guard addresses
17jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in Colorado (US-CO), Connecticut (US-CT), Delaware (US-DE), Florida (US-FL), Indiana (US-IN), Kentucky (US-KY), Maryland (US-MD), Minnesota (US-MN), Montana (US-MT), Nebraska (US-NE), New Hampshire (US-NH), New Jersey (US-NJ), Oregon (US-OR), Rhode Island (US-RI), Tennessee (US-TN), Texas (US-TX), Virginia (US-VA).

The guard to add

Store a consumer's profiling opt-out (and a Global Privacy Control signal where honored) and check it before profiling outputs feed any significant-effects decision.

An opt-out surface (privacy settings toggle, POST /privacy/opt-out) that persists a do_not_profile preference; request middleware that reads the Sec-GPC header (or navigator.globalPrivacyControl on the client) and sets the same preference for that consumer; and a gate in the decision service before profile features, segments, or propensity scores reach approve, deny, or underwrite. Opted-out consumers are decided without profiling-derived inputs or by a person, and the gate records that the opt-out was applied. The check belongs in the server-side decision path, because that is where the profiling takes effect.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.

What reviewers look for: Sec-GPC or navigator.globalPrivacyControl handling that writes a stored preference; a check such as if user.opted_out_of_profiling or consent.allows('profiling') before propensity_score or segment features reach approve(), deny(), or underwrite(); a reachable opt-out control in the product.

Example (FastAPI middleware + decision route), before:

@app.post('/credit/decision')
def credit_decision(req: CreditRequest):
    feats = behavioral_features(req.user_id) | credit_features(req.user_id)
    return underwrite(req, propensity_score(feats))

After:

@app.middleware('http')
async def honor_gpc(request: Request, call_next):
    uid = current_user_id(request)
    if uid and request.headers.get('Sec-GPC') == '1':
        prefs.set(uid, 'do_not_profile', True)
    return await call_next(request)

@app.post('/credit/decision')
def credit_decision(req: CreditRequest):
    if prefs.get(req.user_id, 'do_not_profile'):
        return route_to_human(req, reason='profiling_opt_out')
    feats = behavioral_features(req.user_id) | credit_features(req.user_id)
    return underwrite(req, propensity_score(feats))

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)