General Data Protection Regulation (automated decision-making)
Article 22 gives individuals the right not to be subject to solely automated decisions producing legal or similarly significant effects, plus rights to information, human review and to contest. It is a key constraint on AI-driven decisioning.
Overview
Article 22 functions as a prohibition with three gateways rather than as a general opt-out: a solely automated decision producing legal effects or similarly significant effects is barred unless it is necessary for entering into or performing a contract, authorised by Union or Member State law with safeguards, or based on explicit consent (Art. 22(1), (2)). Where a controller relies on the contract or consent gateway, it must implement safeguards that include, at a minimum, human intervention, the chance for the individual to express a point of view, and the ability to contest the decision (Art. 22(3)). Special category data cannot underpin such a decision unless explicit consent or a substantial public interest basis applies alongside safeguards (Art. 22(4)). Transparency is delivered through separate provisions requiring notice of the existence of automated decision-making plus meaningful information about the logic involved and the significance and envisaged consequences (Art. 13(2)(f), Art. 14(2)(g), Art. 15(1)(h)). Court of Justice rulings have widened the practical reach: C-634/21 SCHUFA treated a credit reference agency's probability score as itself a decision where the lender draws strongly on it, and C-203/22 Dun and Bradstreet Austria held that the logic explanation must set out the procedure and principles actually applied, with any trade secret conflict resolved by the supervisory authority or a court rather than by simply withholding.
Key dates
- Apr 27, 2016Adopted
- May 25, 2018Became applicable & enforceable
Risk areas addressed
Who it applies to
Any controller using solely automated processing to reach decisions about individuals in the Union is caught, whatever the sector: employers screening applicants, lenders and credit reference agencies, insurers, healthcare providers, and platforms that price, suspend or terminate accounts. GDPR sets no headcount or turnover threshold, so a small firm running one scoring model is as exposed as a large one, and Art. 3(2) extends the reach to controllers and processors outside the Union whose processing relates to offering goods or services to, or monitoring the behaviour of, people in the Union. Excluded is processing outside the scope of Union law, purely personal or household processing, and law-enforcement processing under the Law Enforcement Directive rather than GDPR (Art. 2(2)); the SCHUFA ruling also means an upstream scoring intermediary can be the Art. 22 controller in its own right rather than a mere supplier.
Key obligations
- Identify every decision reached solely by automated means that produces legal effects or similarly significant effects, and stop it unless you can rest it on contractual necessity, Union or Member State law, or explicit consent (Art. 22(1), (2)).
- Where you rely on contractual necessity or explicit consent, provide a route to human intervention, let the individual state their point of view, and give them a workable way to contest the outcome (Art. 22(3)).
- Keep special categories of personal data out of the decision logic unless you hold explicit consent or a substantial public interest basis and have safeguarding measures in place (Art. 22(4), Art. 9(2)(a) and (g)).
- Tell individuals, at collection or when data is obtained indirectly, that automated decision-making is taking place, and give meaningful information about the logic involved plus the significance and envisaged consequences (Art. 13(2)(f), Art. 14(2)(g)).
- Answer access requests with an account of the procedure and principles actually applied to that person's data, and where disclosure would expose a trade secret, put the information to the supervisory authority or court to balance rather than refusing outright (Art. 15(1)(h)).
- Carry out a data protection impact assessment before any systematic and extensive evaluation of personal aspects based on automated processing on which such decisions are based, and take the DPO's advice (Art. 35(1), (2), (3)(a)).
- Where the processing rests on public task or legitimate interests, honour objections to profiling and cease processing unless you can demonstrate compelling legitimate grounds that override the individual's interests (Art. 21(1)).
- Act on Art. 15 to 22 requests without undue delay and within one month, extending by up to two further months only for complex or numerous requests and telling the individual why within the first month (Art. 12(3)).
How to prepare
- Map every point where a model, score or rule set produces a determination about a person, and record for each whether a reviewer has genuine authority to depart from the output or merely rubber-stamps it.
- For each decision that is solely automated and legally or similarly significantly effective, select and document the Art. 22(2) gateway, then redesign or retire anything with no gateway available.
- Write the explanation layer twice over: a privacy notice passage covering logic, significance and consequences, and an access-request template that sets out the factors and procedure actually applied to that individual.
- Build the safeguard workflow so a contest routes to a person empowered to change the outcome, and log the reviewer, the evidence considered, the reasoning and the result.
- Complete a DPIA on the profiling, consult the DPO, and screen model inputs for special category data and for proxies that reconstruct it.
- Set response-time and retention controls so rights requests are met inside one month and the safeguard records survive long enough to evidence compliance to a supervisory authority.
Penalties & enforcement
Up to €20M or 4% of global annual turnover.
Enforced by: European Data Protection Board & national data protection authorities
Enforcement under EU GDPR (Art. 22)
National data protection authorities (DPAs) are applying data protection rules to AI-related practices, initiating investigations and adopting corrective measures regarding AI-enabled technologies such as biometric identification and facial recognition.
Italy's Garante is treating large-model training data and chatbot personalisation under the same legal-basis lens it has applied to ad tech for years.
Cumulative GDPR fines exceeded €5 billion, with DPAs increasingly targeting mid-size companies for practical failures such as inadequate DPIAs and insufficient legal bases for AI-driven profiling.
The Dutch DPA imposed a fine of €3.75 million on the Dutch Tax and Customs Administration for processing nationality data through an ML algorithm in a discriminatory manner.
Clearview AI was fined for untargeted facial image scraping to build a commercial recognition database.
EU GDPR (Art. 22) is enforced by European Data Protection Board & national data protection authorities. Its obligations are already live, so a gap is a present exposure rather than a future one. In practice that means knowing which of your AI systems fall in scope across every sector you operate in, holding assessments that speak to privacy, automated decisions and transparency, and being able to produce that evidence on request, including for systems built outside the jurisdiction.