Skip to content
Artificial intelligence

Automated decisions and the right to review under the LGPD

Credit refused, candidate rejected, account blocked: when a system decides on its own, the data subject may ask for review and an explanation. What a business needs ready to answer.

By Cesar Augusto Taborda Lima

When a system decides about someone on its own, refusing credit, discarding a job application or blocking an account, Brazil’s General Data Protection Law (LGPD) gives that person the right to ask for the decision to be reviewed and to receive clear information on the criteria and procedures behind it. The law does not require the review to be made by a human being, but it does require a review that is real, and a business able to explain what its system does. Anyone using scoring, screening or fraud detection models in Brazil should have that answer ready before the first request arrives.

Art. 20. The data subject has the right to request the review of decisions taken solely on the basis of automated processing of personal data that affect his or her interests, including decisions intended to define his or her personal, professional, consumer and credit profile or aspects of his or her personality.

§ 1. The controller shall provide, whenever requested, clear and adequate information on the criteria and procedures used for the automated decision, subject to commercial and industrial secrets.

Law 13,709/2018 (LGPD), art. 20, head and § 1 (free translation).

What counts as an automated decision

Article 20 covers decisions taken solely on the basis of automated processing that affect the data subject’s interests, including those that define a personal, professional, consumer or credit profile. Refusing a loan, setting a card limit, pricing insurance, screening CVs and blocking an account on suspicion of fraud all fall within it.

The word “solely” is where the debate lies. As I see it, the formal sign-off of an analyst who merely confirms the system’s output, without the information or the power to change it, does not stop the decision from being automated. In the European Union, the Court of Justice went further and held that a score calculated by a credit agency is itself an automated decision when the third party receiving it draws strongly on it to decide whether to contract with the person (SCHUFA Holding, C-634/21, 7 December 2023). The European reading does not bind Brazil, but it shows where the issue is heading.

Review without a human reviewer requirement

The original text of the LGPD provided for review “by a natural person”. Provisional Measure 869/2018 removed that requirement, and Law 13,853/2019 kept the new wording. Congress added a § 3 requiring review by a natural person under rules to be set by the authority, but it was vetoed on the ground that it would make business models unviable, startups above all, and would harm credit risk analysis (Veto Message 288/2019).

Review may therefore involve new automated processing, but it cannot simply repeat the same calculation. The principles of transparency, non-discrimination and accountability (art. 6, VI, IX and X) require the business to reconsider the case in light of what the data subject says and of any corrected data, and to be able to show that it did so.

The ANPD, Brazil’s National Data Protection Agency, ran a public consultation on regulating article 20, focused on artificial intelligence, between November 2024 and January 2025. It has not yet issued a regulation on the subject.

Explaining without giving away trade secrets

Under § 1, the controller must explain the criteria and procedures of the decision, subject to commercial and industrial secrets. Secrecy is not a licence for silence: if a business withholds information on that ground, the ANPD may audit the automated processing for discriminatory aspects (art. 20, § 2). Access requests must also be answered with a full statement of the origin of the data, the criteria used and the purpose, within fifteen days (art. 19, II).

For credit, Law 12,414/2011, which governs Brazil’s positive credit register, gives individuals the right to know the main elements and criteria considered in the risk analysis and to ask the lender for review of a decision made exclusively by automated means (art. 5, IV and VI). Brazil’s Superior Court of Justice (STJ) had already held that credit scoring does not require the consumer’s consent, the consumer being “entitled to request clarification on the personal information assessed and the sources of the data considered in the calculation” (Precedent 550, free translation). The Consumer Protection Code guarantees access to the data held on a consumer and to its sources (art. 43).

On how much detail is owed, European case law offers a useful benchmark. In Dun & Bradstreet Austria (C-203/22, 27 February 2025), the Court of Justice held that the controller must describe the procedure and principles actually applied, so that the person can understand which data were used and how; handing over the algorithm is not enough. Where trade secrets are at stake, the information goes to the authority or the court, which weighs the interests involved.

Hiring and other sensitive choices

In recruitment, Law 9,029/1995 prohibits discriminatory practices in access to or continuation of employment on grounds of sex, origin, race, colour, marital status, family situation, disability, professional rehabilitation or age, among others (art. 1). A screening tool that penalises these factors, even indirectly through variables that stand in for them, exposes the employer. A choice made by a system is not neutral for that reason.

What to have ready

A business that relies on systems to decide should keep:

  • an inventory of automated decisions, with their purpose, the data used and the effect on the individual;
  • a plain-language description of the criteria and main factors behind each decision, updated whenever the model changes;
  • a review channel staffed by people with the information and authority to change the outcome, with a set response time;
  • a record of requests, reviews and their results;
  • a data protection impact report (art. 38) and periodic bias testing for higher-risk uses such as credit, employment and health;
  • contracts with scoring or screening vendors that guarantee access to explanations, cooperation in reviews and the possibility of audit.

A well-structured review also protects the business: it corrects errors before they become disputes and builds evidence that the system is used with care. A company that cannot explain the decision its system took will find it hard to defend.