Automated individual decision-making, including profiling
18.(1) The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or similarly significantly affects him.
(2) Subsection (1) shall not apply where the automated processing or profiling of personal data is
(a) necessary for entering into, or performance of, a contract between the data subject and a data controller;
(b) authorised by any enactment to which the data controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or
(c) based on the data subject's consent.
(3) In the cases referred to in subsection (2)(a) and (c), the data controller shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests.
(4) Subsection (2) shall not apply to sensitive personal data unless it is in the public interest and suitable measures to safeguard the data subject's rights and freedoms and legitimate interests are in place.