ADMT Proportionality Scorer | BKX Labs
← Back to All Tools

ADMT Proportionality Scorer

Calculates legal proportionality of AI workplace monitoring under EU ADMT (Automated Decision-Making Technology) regulations and labor law.

2026 Compliance Standard: Proportionality for Automated Decision-Making Technology (ADMT) is now judged by the "Triple Test": Legitimacy, Necessity, and Balancing. Under the EU AI Act, workplace monitoring without meaningful human oversight is classified as a "High Risk" critical failure.

BKX Compliance Lab

ADMT Proportionality Scorer

Workforce AI Auditing · Article 35 DPIA Modeling · 2026 Transparency Standards


1. Legal Foundation

Legitimacy (LIA)5/10
Necessity & Alternatives5/10

2. Impact & Ethics

Transparency (Worker Notice)5/10
Intrusiveness (Invasiveness)5/10

3. Governance (AI Act 2026)

Human Oversight5/10
Data Minimization5/10
Compliance Score50/ 100
Risk BandHigh

Strategic Recommendations

  • Update worker privacy notices with specific 'Algorithm Logic' disclosures.
  • Implement automated purging for raw monitoring logs not tied to valid audits.
  • Formalize a 'Right to Contest' workflow for automated evaluations.

Legal Context

Articles 35 & 22 of the GDPR, combined with EU AI Act High-Risk mandates, require organizations to prove that no "less invasive" method exists before deploying automated monitoring.

What ADMT Is and Why It Triggers Heightened GDPR Obligations

Automated Decision-Making Technology in the workplace — ADMT — refers to any system that monitors, evaluates, or makes decisions about workers through automated means. This includes productivity monitoring software that scores keystrokes or mouse activity, surveillance systems that track physical location or facial expressions, algorithmic scheduling that determines shift allocation without human review, and performance management tools that feed automated scores into appraisal processes. Under GDPR Article 22, individuals have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. For employment decisions — hiring, disciplinary action, termination, promotion — this standard is almost always met. Separately, Article 35 requires a Data Protection Impact Assessment before deploying any processing that is likely to result in high risk to individuals, with the Article 29 Working Party guidance specifically listing systematic monitoring of employees as a presumptive high-risk category requiring DPIA. The EU AI Act 2024, which reached full applicability in August 2026, separately classifies AI systems used for evaluating workers, including monitoring their performance and behaviour, as high-risk AI under Annex III, imposing conformity assessment, technical documentation, and human oversight requirements that operate in parallel with GDPR. Organisations deploying workplace monitoring technology must satisfy both regimes simultaneously.

How the Six Dimensions Map to the GDPR Article 35 Triple Test

The GDPR Article 35 DPIA framework and the Article 29 Working Party guidance on DPIA methodology require assessing necessity, proportionality, and risk mitigation for high-risk processing activities. This tool operationalises that assessment through six weighted dimensions. Legitimacy — the lawful basis and legitimate interest assessment — addresses whether the processing has a valid legal foundation under Article 6 and whether that basis is documented. Necessity and alternatives tests whether less intrusive means could achieve the same objective, a core proportionality requirement under Article 25 data minimisation. Transparency addresses Article 13 and 14 obligations to inform workers about the nature, scope, and purpose of monitoring before it begins. Intrusiveness is weighted inversely — high intrusiveness reduces the score — reflecting the principle that processing which penetrates into private spheres requires correspondingly stronger justification. Human oversight addresses Article 22 requirements that consequential automated decisions involve meaningful human review rather than rubber-stamping. Data minimisation assesses whether the system collects only what is strictly necessary for the stated purpose, implementing Article 5(1)(c). The weighting gives highest combined weight to oversight and intrusiveness at 20 percent each, reflecting that these dimensions generate the most enforcement action — the ICO and CNIL have both issued fines specifically for automated systems with insufficient human review and disproportionate data collection scope.

How to Read Critical Gaps Alongside the Overall Score

A composite score above 80 indicates Low overall risk, but the tool separately flags three critical conditions that represent compliance failures regardless of the aggregate score: oversight below 3, legitimacy below 4, and intrusiveness above 8. These thresholds are calibrated against DPA enforcement precedent. Oversight below 3 reflects rubber-stamping risk — a scenario where nominally human-reviewed decisions are in practice never reversed, which regulators treat as equivalent to fully automated decision-making under Article 22. Legitimacy below 4 reflects a weak or undocumented legal basis, the single most common basis for GDPR enforcement action. Intrusiveness above 8 flags processing that is disproportionate in scope — for example, continuous biometric monitoring of remote workers or real-time keystroke logging at character level. When any critical gap is triggered, the tool sets the overall risk band to Critical regardless of the aggregate score. This matters because an organisation could score 75 in aggregate — Medium risk — while still having a legitimacy score of 3 due to weak LIA documentation, creating a Critical gap that should be remediated before any data collection begins. Read the critical gaps flags first, then use the overall score for prioritising remediation of non-critical dimensions.

Frequently Asked Questions

Commonly Asked Questions

What is the difference between GDPR Article 22 and Article 35 for ADMT compliance?
Article 22 gives individuals a specific right not to be subject to solely automated decisions with significant effects, and requires that where such decisions occur the organisation must implement suitable safeguards including the ability to obtain human intervention, express a point of view, and contest the decision. Article 35 requires a Data Protection Impact Assessment before deploying any high-risk processing activity — including systematic employee monitoring — regardless of whether the decisions are fully automated. An organisation can comply with Article 35 by completing a DPIA that documents and mitigates risks, while separately complying with Article 22 by implementing human review procedures. Both obligations exist in parallel for workplace ADMT deployments.
Does the EU AI Act 2024 create obligations on top of GDPR for workplace monitoring AI?
Yes. The EU AI Act classifies AI systems used to evaluate or score natural persons in the employment context — including performance monitoring, behaviour tracking, and allocation of tasks — as high-risk AI under Annex III category 4. High-risk AI systems must undergo a conformity assessment, maintain technical documentation under Article 11, implement a quality management system under Article 17, register in the EU database under Article 71, and provide workers with meaningful explanations of how the system affects decisions concerning them under Article 86. These obligations apply to both providers placing such systems on the market and deployers operating them in the workplace. They operate alongside GDPR and do not replace the DPIA requirement.
What legitimacy score triggers the critical gap flag and why?
A legitimacy score below 4 out of 10 triggers the critical gap. This threshold reflects cases where the legal basis for processing is absent, undocumented, or implausible. Consent is generally not a valid lawful basis for employee monitoring under GDPR because of the inherent power imbalance between employer and employee — consent is not freely given when refusal has employment consequences. Legitimate interest requires a three-part LIA: establishing a genuine interest, demonstrating necessity, and balancing the interest against worker rights. A score below 4 indicates this assessment has not been completed or documented to a standard that would satisfy a regulatory review.
What human oversight score is sufficient to avoid the Article 22 rubber-stamping risk?
The tool flags oversight below 3 as a critical gap. An oversight score of 5 or above indicates a process where human reviewers demonstrably exercise independent judgment — meaning automated recommendations are regularly modified or reversed based on contextual factors the algorithm does not capture. Regulatory guidance from the ICO and the French CNIL has established that human oversight is not meaningful when reviewers lack the training, time, or authority to override system outputs. A score of 3 or 4 indicates oversight exists formally but may not be substantive, requiring documentation of actual override rates and reviewer training to confirm compliance.
Can this tool's output be used as evidence in a GDPR DPIA?
The tool output — compliance score, risk band, critical gaps, and recommendations — can serve as structured input to a DPIA process. It is not a completed DPIA. A DPIA under Article 35 must also document the specific processing operations and their purposes, assess the necessity and proportionality of those specific operations, identify the specific risks to data subjects, and document consultation with the Data Protection Officer under Article 35(2). The tool's risk band and critical gap analysis is suitable for inclusion as a supporting document in the DPIA record, alongside the full DPIA narrative.
What intrusiveness level represents disproportionate monitoring under GDPR?
An intrusiveness score above 8 is flagged as critical. This corresponds to monitoring that captures intimate or continuous data about workers — real-time biometric data, continuous ambient audio recording, keystroke-level input logging, or facial expression analysis. The Article 29 Working Party guidance and the EDPB's subsequent guidance on the use of tracking technologies both indicate that continuous monitoring of workers in their personal environment (including home office monitoring) requires an exceptionally compelling justification that cannot typically be met by productivity management objectives alone.
What are the most common ADMT compliance failures that lead to regulatory fines?
The three most common enforcement patterns are: first, deploying employee monitoring without a lawful basis or valid legitimate interest assessment — the Swedish DPA fined an employer for using software that tracked which applications employees used without a documented LIA. Second, failing to inform workers about monitoring — multiple national DPAs have fined organisations for deploying tracking software without the Article 13 disclosures required before monitoring began. Third, allowing automated performance scoring to feed consequential employment decisions without meaningful human review — the Amsterdam District Court ruled that Uber's use of algorithmic fraud detection to terminate driver contracts without human review violated Article 22. These three failure modes correspond directly to the legitimacy, transparency, and oversight dimensions this tool assesses.