Contract trap · Privacy policy
Automated profiling, no review
The operator may build profiles, infer sensitive traits, enrich your record from data brokers and 'publicly available sources', repurpose data collected for security, and make automated decisions (pricing, credit, account bans, fraud scores) with no human review.
- Severity
- Serious
- How often it turns up
- Regular
- Holds up?
- Depends where you are
- Clause phrases
- 23
What it looks like in a contract
Redline matches these phrases against your document verbatim. Drafters rarely invent new wording — they copy it, which is why the same sentences turn up across unrelated contracts.
In English-language contracts
- profiling
- we may infer
- automated decision-making
- risk score
- fraud score
- personalized pricing
- information from data brokers and other third-party sources
- publicly available sources
- we combine information we collect with information from third parties
- we may use information collected for security purposes to
- eligibility determinations
- credit decisions
In Russian-language contracts
- профилирование
- автоматизированная обработка персональных данных
- решения, порождающие юридические последствия
- скоринг
- оценка платёжеспособности
- из общедоступных источников
- данные, полученные от третьих лиц (партнёров)
- обогащение данных
- формирование профиля Пользователя
- анализ поведения и предпочтений
- определение индивидуальных предложений и цен
Check your own contract
Paste a clause, a page or the whole document. Nothing leaves your browser: the matching runs here, on this page, against the phrases above.
Why it bites
You are judged by scores you cannot see, built from data you did not provide (broker enrichment), and security data becomes marketing data (Twitter $150M); errors and discrimination are hard to contest without a right to explanation.
Is it enforceable where you are
The same clause can be routine in one country and void in another. What follows is what the law says where you are — not advice on your particular contract.
In the EU and the UK, the GDPR governs the legal basis, the retention period and your right to erasure; in the US, state privacy laws (CCPA/CPRA and its successors) give an opt-out of sale and sharing.
United States
CCPA ADMT/risk-assessment regulations adopted Sept 2025 (opt-out and access rights for significant decisions); FCRA where data feeds credit/insurance/employment (GM data to CRAs); FTC purpose-creep enforcement (Twitter 2022); Colorado AI Act (2026).
- Cited
- CCPA
- FCRA
- FTC
European Union
GDPR Art 22 (no solely automated significant decisions without consent/contract necessity and human review), Art 21 objection to profiling for marketing, Art 14 information when data is obtained from third parties; Meta €265M (2022) over scraping; invisible enrichment breaches transparency.
- Cited
- GDPR Art 22
United Kingdom
UK GDPR Art 22 as amended by the DUA Act 2025 (broader automated decisions with safeguards); ICO enforcement notice v. Experian (2020) over marketing profiles built from data subjects never told; CMA37 on discretionary terms.
- Cited
- CMA37
- DUA Act 2025
- GDPR Art 22
- ICO
Russia
Ст. 16 152-ФЗ: решения на основании исключительно автоматизированной обработки, порождающие юридические последствия, только с письменного согласия субъекта (или по закону), с правом на возражение и разъяснение; ст. 10.1 — use of «общедоступных» data requires the subject's separate consent for distribution; 218-ФЗ for credit histories.
- Cited
- 152-ФЗ
- 218-ФЗ
- ст. 10.1
Where this has actually happened
Regulator actions, court rulings and the contracts they were fought over.
- FTC/DOJ v. Twitter (2022) — $150M, security phone numbers repurposed for ad targeting
- ICO enforcement notice against Experian (Oct 2020) over data-broking marketing profiles
- FTC v. General Motors/OnStar (2025) — driving scores fed to consumer reporting agencies used by insurers
- FTC v. Rite Aid (2023) — automated facial-recognition flags led to false accusations
- California CPPA regulations on ADMT, risk assessments and cybersecurity audits — adopted Sept 2025
What to do
In order, from the thing that takes a minute to the thing that takes a letter.
- Request the logic, categories and sources of profiling (GDPR Art 15(1)(h)
- 152-ФЗ ст. 14)
- Object to profiling for marketing (Art 21(2))
- Demand human review of significant automated decisions (Art 22, 152-ФЗ ст. 16, CCPA ADMT opt-out)
- Check for 'we combine information from third parties' and ask for the broker names.
Traps that travel with it
Drafters who use one of these usually use several.