GovernanceCore
EnforcedEuropean UnionExtraterritorial reach

General Data Protection Regulation (automated decision-making)

Article 22 gives individuals the right not to be subject to solely automated decisions producing legal or similarly significant effects, plus rights to information, human review and to contest — a key constraint on AI-driven decisioning.

Status
Enforced
Jurisdiction
European Union · Supranational
Adopted
Apr 27, 2016
In force
May 25, 2018
Enforcement date
May 25, 2018
Regulator / body
European Data Protection Board & national data protection authorities
Sectors
Cross-sector
Extraterritorial
Yes

Overview

Article 22 gives individuals the right not to be subject to solely automated decisions producing legal or similarly significant effects, plus rights to information, human review and to contest — a key constraint on AI-driven decisioning.

Key dates

  • Apr 27, 2016
    Adopted
  • May 25, 2018
    Became applicable & enforceable

Risk areas addressed

Privacy & dataAutomated decisionsTransparencyFundamental rights

Who it applies to

Any organisation processing personal data of individuals in the EU/EEA, including AI systems making automated decisions with legal or similarly significant effects.

Penalties & enforcement

Up to €20M or 4% of global annual turnover.

Enforced by: European Data Protection Board & national data protection authorities

Getting ready

Whatever your exposure to EU GDPR (Art. 22), the practical work is the same: inventory the AI systems in scope, map them to concrete obligations, and keep the evidence to show it. A structured AI governance programme — risk assessments, documentation and continuous monitoring — turns a moving regulatory target into a repeatable process.

Official source

Regulation (EU) 2016/679 — EUR-Lex

Related regulations

← All regulations