This is a part of the GDPR - the language is so generic that I think much of this will come out in future court cases, but check out Article 21 and 22 of the GDPR which I think addresses this (but IANAL)
Belated thanks for the really useful link! I hadn't looked into these opt-out/review requirements before. But, FWIW, I still think there's an important difference between a user-driven opt-out (which I also don't read as a guarantee of explanation) and proactive publication of the personalization criteria. It's still possible for an uninformed individual to never even realize content is being personalized for them, much less pass the threshold of asking how.
https://blog.varonis.com/gdpr-requirements-list-in-plain-eng...
People can object to be profiled and can ask a person for help like: "Why am I seeing this? Please stop"