The Right Not to Be Inferred: Profiling, Disinformation, and the Limits of the Right to Data Protection
- 1 Data Protection Officer, Instituto Atlântico, Fortaleza, Brazil
Abstract
Contemporary data protection regimes were designed to regulate the collection and processing of personal data, but increasingly fail to address epistemic and behavioral harms produced by algorithmic inferences. This article argues that profiling and micro-targeting of misinformation exploit a structural gap in frameworks, which prioritize control over inputs (collected data) while leaving inferential outputs (inferred attributes, profiles, models, and predictions) relatively ungoverned. By articulating the political economy of surveillance capitalism, cognitive vulnerabilities, and a legal analysis of the GDPR, LGPD, and Digital Services Act (DSA), it demonstrates how algorithmic inference erodes informational self-determination and, consequently, democratic autonomy. Empirically, 1) the analysis of 856 GDPR fines indicates a predominance of organizational and technical violations centered on early stages of the data lifecycle, with less regulatory traction on profiling and inference harms ( Saemann et al., 2022 ); 2) large-scale evidence shows that fake news spreads faster and reaches more people than true news ( Vosoughi, Roy, & Aral, 2018 ); and 3) political advertising data map the global expansion of microtargeting ( Votta, Kruschinski, & Hove, 2024 ). Finally, it is proposed that a normative limit to inference be recognized, formulated as the right not to be inferred (under specific conditions and categories) as a necessary evolution of data protection law in societies mediated by artificial intelligence.
- Alphabet Inc (2026). Form 10-K 2024 (Annual Report).
- Barocas, S., & Nissenbaum, H. (2014). Big Data’s End Run around Anonymity and Consent. In J. Lane, V. Stodden, S. Bender, & H Nissenbaum (Eds.), Privacy, Big Data, and the Public Good (pp. 44-75). Cambridge University Press. https://doi.org/10.1017/cbo9781107590205.004
- Bioni, B. R. (2019). Personal Data Protection: The Function and Limits of Consent. Forense.
- De Miranda, P. R. (2022). Right to Reasonable Infere nces as a Normative Substrate in the Consolidation of Algorithmic Governance Mechanisms in Automated Decision Sys tems (p. 129). Master’s Thesis, Universidade Federal de Santa Maria.
- EDPB (2021). Guidelines 8/2020 on the Targeting of Social Media Users (Version 2.0).
- European Union (2022). Regulation (EU) 2022/2065 (Digital Services Act).
- Floridi, L. (2014). The Fourth Revolution: How the Infosphere Is Reshaping Human Reality. Oxford University Press.
- Grand View Research (2026). Data Broker Market Size and Share (Industry Report).
- Hildebrandt, M. (2015). Smart Technologies and the End(s) of Law. Edward Elgar Publishing. https://doi.org/10.4337/9781849808774
- Kahneman, D. (2011). Thinking, Fast and Slow. Farrar, Straus and Giroux.
- Leerssen, P., Ausloos, J., Zarouali, B., Helberger, N., & De Vreese, C. (2023). Platform Transparency for the Public Interest: The Case for Public Audits of Social Media Platforms. Internet Policy Review, vol. 12 .
- Lynskey, O. (2015). The Foundations of EU Data Protection Law. Oxford University Press.
- Meta Platforms Inc (2025). Meta Reports Fourth Quarter and Full Year 2024 Results.
- Pasquale, F. (2015). The Black Box Society. Harvard University Press. https://doi.org/10.4159/harvard.9780674736061
- Rouvroy, A., & Poullet, Y. (2009). The Right to Informational Self-Determination and the Value of Self-Development: Reassessing the Importance of Privacy for Democracy. In S. Gutwirth, Y. Poullet, P. De Hert, C. de Terwangne, & S. Nouwt (Eds.), Reinventing Data Protection? (pp. 45-76). Springer. https://doi.org/10.1007/978-1-4020-9498-9_2
- Saemann, M., Theis, D., Urban, T., & Degeling, M. (2022). Investigating GDPR Fines in the Light of Data Flows. Proceedings on Privacy Enhancing Technologies, 2022, 314-331. https://doi.org/10.56553/popets-2022-0111