Automated Decision-Making and Data Protection: A Systematic Review on Organizational Risk, and Managerial Control
Abstract
The purpose of this paper is to present a systematic review of recent literature regarding the way in which automated processing redefines organizational risk management and internal control practices. It also examines how managers integrate oversight mechanisms, performance monitoring of algorithmic models, and the early detection of operational risks into day-to-day decision workflows. Furthermore, the review explores also the legal context, outlining Article 22 of the GDPR and its interpretation, the rights of data subject and also the boundaries applicable to profiling. Based on more than a decade of European and international research, this paper aims to highlight the way by which managerial and legal perspectives converge through priniciples such as accountability, privacy by design and algorithmic auditing. It also takes into consideration the incorporation of ethical safeguards concerning the automated decision processes. The examination suggests that organizations benefit from integrated methologies skilled of aligning complience requirements with operational objectives while maintaning measures for fundamental rights.
© 2026 Cristina-Mihaela STANCIU, Augustin SEMENESCU, published by Bucharest University of Economic Studies
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.