In one sentence. GDPR Article 22 grants data subjects the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them — with three narrow exceptions: (a) necessary for contract performance, (b) authorized by law, © based on explicit consent. Article 22(3) expressly requires human intervention, an opportunity to express a view and to contest the decision for the contract and explicit-consent exceptions. The law authorising paragraph (2)(b) processing must provide suitable safeguards.
Article 22 requires separate analysis of the decision, automation and effect on a person. In SCHUFA (C-634/21), the CJEU held that automated scoring can itself constitute the relevant decision where a third party draws strongly on the score in establishing, implementing or terminating a contractual relationship. Do not treat every use of scoring as automatically equivalent.
For related rights: right of access (Article 15), right to object (Article 21). For DPIA obligations triggered by automated decision-making, Article 35 RGPD AIPD.
Key takeaways
- Article 22(1): right not to be subject to decisions based solely on automated processing with legal or similarly significant effects.
- Three exceptions in Article 22(2): contract performance, law, explicit consent.
- Safeguards depend on the exception: paragraph (3) governs contract and consent; paragraph (2)(b) requires safeguards in the authorising law.
- Article 22(4): exceptions don’t apply to special category data (Article 9) unless explicit consent OR substantial public interest.
- SCHUFA (2023) addresses automated scoring that plays a determining role in another party’s contractual decision; assess that role on the actual facts.
1. Article 22(1) — the prohibition
Start with the decision and these scope questions:
- The decision is based solely on automated processing (including profiling)
- It produces legal effects concerning the data subject OR similarly significantly affects them
- Assess separately whether one of the Article 22(2) exceptions permits the decision; it is not a third condition that triggers paragraph (1).
“Based solely on” — the SCHUFA clarification
A nominal human sign-off does not by itself establish meaningful intervention. Examine the whole decision process. SCHUFA addresses a score that plays a determining role in another party’s contractual decision, rather than creating a rule that every score or human-supported decision is within Article 22.
Practical test:
- Does the human make an independent assessment?
- Does the human have the authority to overturn the automated outcome?
- Does the human do so in non-trivial cases?
These questions help investigate meaningful human involvement; they are not a mechanical legal test based on the number of decisions overturned. On what qualifies as processing by “automated means” in the first place, see our GDPR automated means definition.
“Legal or similarly significant effects”
| Decisions that may have significant effects | Uses often less significant, depending on context |
|---|---|
| Loan approval/denial | Personalized product recommendations |
| Insurance premium calculation | Search result ordering |
| Job application screening | Movie suggestions |
| Visa/immigration decisions | Newsletter content selection |
| Welfare benefit eligibility | A/B test variant assignment |
| Employment performance scoring | UI customization |
| Credit scoring (SCHUFA) | Generic ad targeting (debated) |
| University admission | — |
The threshold is significant impact on the data subject’s circumstances, behavior, or choices.
(a) Contract performance
The decision is necessary for entering or performing a contract between the data subject and the controller.
Necessity is strict — the EDPB (Guidelines on Article 22) requires:
- The processing must be necessary, not merely useful or efficient
- Less invasive alternatives must have been considered
A lender or employer must demonstrate necessity in the actual context. Automated credit checks and recruitment screening are not categorically accepted or rejected exceptions merely because of their sector. Consider realistic alternatives and the impact of the proposed decision.
(b) Authorized by EU/Member State law
Specific law authorizes the automated decision and provides safeguards. Examples: tax authority automated assessments, social security automated decisions.
© Explicit consent
The data subject has given explicit consent. Subject to Article 7 conditions + must be unambiguous + freely given. Highly disputed in employment and consumer contexts where power imbalance exists.
3. Required safeguards (Article 22(3))
For the contract and explicit-consent exceptions, Article 22(3) requires suitable measures including at least:
- Right to obtain human intervention (a real human, with authority to overturn)
- Right to express their point of view
- Right to contest the decision
These rights must be easy to exercise — not buried in legalese, not behind paywalls, not requiring postal mail.
4. Special category data (Article 22(4))
Automated decisions involving special category data (Article 9: health, biometrics, etc.) are permitted only if:
- Explicit consent (Article 9(2)(a)), OR
- Substantial public interest under EU/Member State law (Article 9(2)(g))
AND suitable measures to safeguard the data subject’s rights and freedoms are in place.
These conditions apply to decisions covered by Article 22(2); an Article 9 exception alone does not resolve the other requirements.
5. Information obligations interaction
Articles 13(2)(f) and 14(2)(g) require the controller to inform the data subject of:
- The existence of automated decision-making (including profiling)
- Meaningful information about the logic involved
- The significance and envisaged consequences of such processing for the data subject
In Dun & Bradstreet Austria, C-203/22, the CJEU addressed meaningful information about the logic involved. The explanation must allow the person to understand and challenge the decision; simply disclosing a complex algorithm or source code is not the same as an intelligible explanation.
6. AI Act intersection
The EU AI Act (Regulation 2024/1689) classifies many automated decision systems as “high-risk AI” requiring conformity assessment, technical documentation, and human oversight. The GDPR Article 22 obligations are cumulative with AI Act obligations:
- Article 22 protects individual data subjects
- AI Act regulates the AI system itself
For an AI system meeting both sets of conditions, the obligations apply cumulatively. See EU AI Act compliance guide and AI Act vs GDPR.
7. DPIA obligation
Article 35(3)(a) makes DPIA mandatory for “systematic and extensive evaluation of personal aspects relating to natural persons based on automated processing, including profiling, and on which decisions are based that produce legal effects.”
Assess Article 35(1), the specific Article 35(3)(a) condition and applicable authority lists. Systematic and extensive evaluation producing legal or similarly significant effects is expressly covered. Record the DPIA assessment rather than replacing its conditions with an assertion that every automated decision requires one.
8. Keep the judgment and the operational finding separate
SCHUFA, C-634/21, is a preliminary ruling on interpretation, not a fine imposed on every scoring provider. Record the proposition a judgment supports and the facts relevant to your own process. Do not convert a court’s legal test into an invented sector-wide enforcement statistic.
A useful review asks where the outcome is produced, how another party uses it and whether a human can assess relevant additional information before the significant decision. Keep evidence of the actual process, including instructions, user permissions and sample decisions.
9. Implementation checklist
For an automated decision system, assess each item’s applicability:
- ☐ DPIA trigger assessed and DPIA completed where required
- ☐ Article 6 basis documented separately from the Article 22 exception
- ☐ For special category data: Article 9 exception identified
- ☐ Article 22 exception applicable: documented
- ☐ Human intervention mechanism implemented and tested (real human, real authority)
- ☐ Mechanism for data subject to express their view documented
- ☐ Mechanism to contest decisions documented (with response SLA)
- ☐ Privacy notice (Articles 13/14) discloses: existence, logic, significance, consequences
- ☐ Algorithm explainability documented (for response to access requests)
- ☐ AI Act conformity assessment if high-risk
Related implementation guides
For related deep-dives: Article 35 RGPD AIPD, right to object, right of access, EU AI Act compliance guide, AI Act vs GDPR.
Official sources: Article 22 (automated individual decision-making) of Regulation (EU) 2016/679 on EUR-Lex, the EDPB guidelines, recommendations and best practices register, and the ICO guidance.
Conclusion
An Article 22 review should identify the decision and its effects, establish how it is made, assess any exception and implement the appropriate safeguards. Keep the AI Act classification separate: related technology does not make the two legal tests identical.
When does GDPR Article 22 apply?
Article 22(1) concerns solely automated decisions with legal or similarly significant effects. A loan, hiring or insurance workflow can meet that test, but its sector alone does not establish the conditions. Assess actual automation, human involvement and effects; targeting can also require careful contextual assessment.
What does “based solely on automated processing” mean after SCHUFA?
SCHUFA addresses automated scoring that plays a determining role in a third party’s contractual decision. Separately, genuine human assessment must be distinguished from a rubber stamp. Review the actual authority, information and conduct of the human decision maker.
Can I use automated decisions for hiring?
First assess whether the hiring decision is solely automated and has the relevant effects. If Article 22(1) applies, identify an exception under paragraph (2) and the corresponding safeguards. Necessity and freely given explicit consent require careful assessment in this context; do not assume an exception from the label recruitment.
What information must I provide about the algorithm?
Provide meaningful information about the logic, significance and envisaged consequences where the provisions apply. The explanation should allow the person to understand and challenge the outcome. Dun & Bradstreet Austria clarifies this; handing over an unexplained formula is insufficient.
Does the AI Act replace Article 22?
The AI Act does not replace GDPR Article 22. Each has its own scope, roles and conditions. Assess both where relevant; classification as high-risk AI does not by itself establish that a decision is solely automated for Article 22.