CHAPTER IIIRIGHTS OF THE DATA SUBJECT

Article 22Automated individual decision-making, including profiling

Official text

(1)The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

(2)Paragraph 1 shall not apply if the decision:

(a)is necessary for entering into, or performance of, a contract between the data subject and a data controller;

(b)is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests; or

(c)is based on the data subject’s explicit consent.

(3)In the cases referred to in points (a) and (c) of paragraph 2, the data controller shall implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.

(4)Decisions referred to in paragraph 2 shall not be based on special categories of personal data referred to in Article 9 (1), unless point (a) or (g) of Article 9 (2) applies and suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests are in place.

Commentary

1. Introduction: The Democratic Challenge of Algorithmic Decision-Making

Article 22 of the General Data Protection Regulation (GDPR) represents one of the most technologically significant provisions within the Regulation because it addresses one of the central challenges of modern digital societies: the increasing delegation of decisions affecting individuals to algorithms and automated systems.

Contemporary organisations increasingly rely on automated tools to evaluate, classify, predict, rank, and make decisions concerning individuals. Financial institutions use automated systems to assess creditworthiness; employers use algorithmic recruitment tools to screen candidates; insurers use predictive models to calculate premiums; healthcare providers employ artificial intelligence systems to support diagnosis and treatment decisions; online platforms use recommendation algorithms to determine visibility and access to information.

While automated processing offers substantial benefits, including efficiency, consistency, scalability, and reduction of human error, it also creates serious risks for fundamental rights. Algorithmic decisions may reproduce historical biases, rely on inaccurate assumptions, operate without meaningful transparency, and create situations where individuals are affected by decisions they cannot understand or challenge.

Article 22 GDPR seeks to preserve human autonomy and prevent individuals from becoming subjects of decisions made exclusively by opaque technological systems. It establishes limitations on purely automated decision-making where such decisions have serious consequences for individuals.

The provision reflects a fundamental principle underlying European data protection law: individuals should not lose control over their lives merely because decisions affecting them are increasingly mediated by technology.

2. Structure and Purpose of Article 22 GDPR

Article 22 contains four interconnected elements:

Article 22(1): General prohibition on solely automated decisions

Article 22(1) provides:

“The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.”

This paragraph defines the scope of prohibited automated decision-making.

Three cumulative requirements must exist:

  1. There must be a decision;

  2. The decision must be based solely on automated processing, including profiling;

  3. The decision must produce legal effects or similarly significant effects.

Only when all three elements are satisfied does Article 22 apply.

Article 22(2): Exceptions

The prohibition is not absolute.

Automated decision-making may nevertheless occur where:

(a) it is necessary for entering into or performing a contract;

(b) it is authorised by Union or Member State law with appropriate safeguards; or

(c) it is based on the data subject's explicit consent.

Article 22(3): Safeguards

Where automated decision-making is permitted under Article 22(2)(a) or (c), controllers must introduce safeguards, including:

  • the right to obtain human intervention;

  • the right to express one's viewpoint;

  • the right to contest the decision.

Article 22(4): Special categories of personal data

Automated decisions based on sensitive personal data under Article 9(1) GDPR are subject to stricter restrictions.

Such processing is allowed only where:

  • explicit consent exists; or

  • processing is necessary for substantial public interest under Article 9(2)(g),

and appropriate safeguards are implemented.

3. Article 22 as a Prohibition Rather Than Merely an Individual Right

One of the most debated questions concerning Article 22 is whether it establishes merely an individual right that must be actively exercised by the data subject or whether it creates a general prohibition binding controllers.

The wording of Article 22(1) states:

“The data subject shall have the right not to be subject to a decision…”

At first glance, this appears to create a subjective right that requires invocation by the individual.

However, European regulatory authorities and judicial interpretation have confirmed that Article 22 establishes a general prohibition in principle.

The Court of Justice of the European Union (CJEU) clarified this position in:

SCHUFA Holding (Scoring) C-634/21

The Court held that Article 22(1):

“lays down a prohibition in principle, the infringement of which does not need to be invoked individually by such a person.”

Therefore, controllers cannot argue that Article 22 applies only after a data subject submits a request.

The obligation exists proactively.

A controller using a purely automated system producing significant effects must assess Article 22 applicability before deployment.

4. Relationship Between Article 22 and Artificial Intelligence

Article 22 has become particularly important because of the rapid expansion of artificial intelligence systems.

Modern AI systems often perform tasks traditionally undertaken by humans:

  • evaluating job applicants;

  • predicting consumer behaviour;

  • identifying fraud;

  • determining insurance risks;

  • recommending medical treatments;

  • detecting suspicious activities;

  • assigning credit scores.

These systems frequently rely on:

  • machine learning models;

  • statistical correlations;

  • behavioural analysis;

  • large-scale datasets;

  • predictive algorithms.

The central concern is that algorithmic outputs may appear objective while embedding hidden assumptions.

For example:

A recruitment algorithm trained on historical hiring data may learn that successful employees historically shared certain characteristics. If historical recruitment practices disadvantaged certain groups, the algorithm may reproduce those patterns.

Similarly, an automated credit scoring system may use indirect indicators such as:

  • postcode;

  • shopping behaviour;

  • browsing patterns;

  • employment history;

to generate predictions that disproportionately affect particular communities.

Article 22 seeks to ensure that individuals affected by such decisions retain meaningful procedural rights.

5. The Three Cumulative Conditions of Article 22(1)

The applicability of Article 22 depends on three cumulative conditions.

The CJEU confirmed this approach in SCHUFA:

“The applicability of Article 22(1) of the GDPR is subject to three cumulative conditions…”

These are:

  1. Existence of a decision;

  2. Decision based solely on automated processing;

  3. Decision producing legal effects or similarly significant effects.

Each element requires separate analysis.

6. First Requirement: Existence of a Decision

6.1 Meaning of “Decision”

The GDPR does not define the term “decision”.

However, Article 22 must be interpreted broadly.

A decision is not limited to formal administrative acts.

It includes any determination that evaluates an individual and produces consequences affecting them.

Examples

include:

  • automatic refusal of credit applications;
  • automated rejection of job candidates;
  • automatic denial of insurance coverage;
  • automated eligibility assessments for social benefits. Recital 71 expressly recognises:
  • automatic refusal of online credit applications;
  • e-recruitment practices without human intervention.

6.2 SCHUFA and Broad Interpretation of Decision

In SCHUFA, the issue concerned credit scoring.

A credit information agency calculated a probability value predicting whether a person would repay a loan.

Although SCHUFA argued that it merely provided information to banks and did not itself make the final lending decision, the CJEU rejected this narrow interpretation.

The Court held that the generation of the score itself could constitute a decision because:

  • banks relied heavily on the score;

  • an unfavourable score almost inevitably resulted in loan refusal;

  • the score therefore determined the individual's practical outcome.

The judgment demonstrates that Article 22 cannot be avoided through formal separation between algorithmic assessment and final decision.

A controller cannot escape Article 22 simply by claiming:

“the algorithm does not decide; a human merely follows the algorithm.”

The practical reality of decision-making is what matters.

7. Individual Nature of the Decision

Article 22 applies only to decisions concerning individuals.

Therefore, general organisational decisions are outside its scope.

Examples

Not covered:

  • a company deciding to change its pricing strategy;
  • a platform adopting a general recommendation algorithm;
  • a government introducing broad policy rules. Covered:
  • rejecting a specific person's loan application;
  • ranking a specific applicant;

  • assigning a risk score to an individual.

The provision protects individuals against automated judgments about them personally.

8. Automated Decision-Making and Profiling Relationship

Article 22 expressly includes:

“automated processing, including profiling”

This wording reflects the close relationship between automated decision-making and profiling.

Under Article 4(4) GDPR:

Profiling means:

“any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person.”

Examples

include evaluation of:

  • work performance;
  • economic situation;
  • health;
  • personal preferences;
  • interests;
  • reliability;
  • behaviour;
  • location;
  • movements.

9. “Based Solely on Automated Processing”

The second cumulative condition under Article 22(1) is that the decision must be “based solely on automated processing”.

This is the critical dividing line between ordinary algorithm-assisted decision-making and automated individual decision-making regulated by Article 22.

The provision does not prohibit every use of algorithms in decision-making. Organisations may use algorithms to assist human decision-makers. The stronger protection under Article 22 is triggered where the final decision is effectively made by the machine, without meaningful human involvement.

This distinction is particularly important in artificial intelligence systems.

A bank might use an AI system to analyse a loan application and identify potential risks. If a qualified employee genuinely examines the application, considers the AI's recommendation, evaluates relevant circumstances and has authority to depart from the recommendation, the final decision may not be “solely automated”.

By contrast, if an employee merely clicks “approve” after receiving an algorithmically generated recommendation, the existence of a human being somewhere in the workflow does not necessarily remove the decision from Article 22.

The relevant question is therefore not:

“Was a human technically involved?”

The relevant question is:

“Did a human genuinely intervene in the decision-making process?”

10. Meaningful Human Intervention

The concept of meaningful human intervention is central to Article 22.

A controller cannot circumvent Article 22 simply by placing a human being at the end of an automated workflow.

Suppose an employer uses an AI recruitment system to rank 10,000 candidates.

The system automatically identifies the top 100 applicants.

A recruiter then reviews the list but:

  • has only a few seconds per candidate;

  • normally follows the algorithmic ranking;

  • has no authority to override the system;

  • does not examine the underlying information;

  • has no independent decision-making criteria.

Calling this “human review” does not necessarily make the process genuinely human.

The European regulatory approach requires the intervention to be substantive rather than cosmetic.

10.1 Characteristics of Meaningful Human Intervention

A meaningful human intervention should generally involve a person who:

  1. has the authority to change the automated outcome;

  2. has sufficient competence to understand the decision;

  3. has access to relevant information;

  4. actually reviews the circumstances of the individual;

  5. does not merely rubber-stamp the algorithmic result.

The human reviewer should be capable of exercising independent judgment.

This is particularly important because automation bias can cause human decision-makers to place excessive confidence in machine-generated recommendations.

A human may technically possess the power to reject an AI recommendation but practically never exercise that power.

In such circumstances, the “human” component may be largely fictional.

11. The Importance of the Human Decision-Maker's Competence

Human intervention must also be undertaken by someone capable of understanding the consequences of the automated system.

A controller cannot meaningfully rely on human intervention where the reviewer:

  • does not understand the system's output;

  • lacks access to the relevant data;

  • lacks authority to alter the outcome;

  • cannot identify errors;

  • lacks sufficient training.

This creates an important governance obligation for organisations deploying AI.

It is insufficient to appoint a nominal human reviewer.

The organisation should establish:

  • who reviews automated decisions;

  • what information they receive;

  • what authority they possess;

  • when intervention is mandatory;

  • how disagreements with the algorithm are handled;

  • how decisions are documented.

12. Profiling and Article 22

Article 22 expressly mentions profiling because profiling is one of the most important mechanisms through which automated decisions are produced.

Under Article 4(4), profiling involves automated processing used to evaluate personal aspects of an individual.

Example

an organisation may construct a profile predicting:

“This person has a 78% probability of defaulting on a loan.”

That prediction may then be used to determine whether the individual receives credit.

The profile itself is not necessarily an Article 22 decision.

The crucial question is what happens because of the profile.

12.1 Profiling Does Not Automatically Mean Article 22 Applies

This distinction is extremely important.

There are three possibilities:

Situation 1 - Profiling without a decision

A company analyses customer behaviour to understand market trends.

This may constitute profiling but not Article 22 automated decision-making.

Situation 2 - Profiling followed by meaningful human decision-making

An insurer generates an automated risk assessment, but a qualified employee independently evaluates the individual and can depart from the algorithm.

Article 22 may not apply because the final decision is not solely automated.

Situation 3 - Profiling produces an automated significant decision

An algorithm generates a credit score and automatically rejects the individual's application.

This can fall squarely within Article 22.

Therefore:

Profiling ≠ automatically Article 22.

Instead:

==Profiling + solely automated decision + legal/significant effect = Article 22.==

13. Automated Decision-Making Without Profiling

The relationship also works in the opposite direction.

Not every automated decision necessarily involves profiling.

Example

a system may automatically cancel an account because a predetermined contractual condition has been triggered.

If the decision has legal or similarly significant effects and is made solely through automated processing, Article 22 may apply even if there is no sophisticated profiling.

Thus:

  • profiling can exist without Article 22;

  • Article 22 can exist without profiling;

  • profiling can form part of an Article 22 decision.

The third requirement under Article 22(1) is that the decision must:

  1. produce legal effects concerning the individual; or

  2. similarly significantly affect the individual.

This requirement prevents Article 22 from applying to every insignificant automated decision.

A website recommending a movie is generally not equivalent to an algorithm automatically rejecting someone's mortgage application.

The effects must therefore cross a meaningful threshold.

A legal effect generally exists where the decision affects the legal rights or legal status of an individual.

Examples

include:

  • cancellation of a contract;
  • denial of a statutory benefit;
  • denial of citizenship;
  • refusal of entry into a country;
  • termination of a legally protected entitlement;
  • automatic contractual consequences. A legal effect does not necessarily have to be negative. An automated decision granting a legal entitlement may also produce a legal effect. The crucial factor is the impact upon the individual's legal position.

16. Similarly Significant Effects

The second limb is deliberately broader.

The GDPR recognises that modern technology can seriously affect individuals even where no formal legal right changes.

For example:

An individual may not lose a legal entitlement when an algorithm rejects their employment application, but the rejection can profoundly affect their economic and professional circumstances.

Similarly:

  • denial of access to education;

  • refusal of credit;

  • exclusion from housing opportunities;

  • denial of health services;

  • significant insurance consequences;

may substantially affect an individual even without changing their formal legal status.

The phrase “similarly significantly affects” therefore ensures that organisations cannot avoid Article 22 simply because their algorithmic decision does not technically alter a legal right.

17. Criteria for Determining Significant Effects

The assessment is contextual.

Relevant factors may include whether the decision:

17.1 Significantly affects circumstances

Example

a decision that determines whether someone receives financing for a home can substantially affect their life.

17.2 Significantly affects behaviour

An automated system that controls access to employment, financial services or healthcare may substantially influence how an individual lives.

17.3 Has a prolonged effect

A decision with consequences lasting several years is more likely to be significant than a temporary inconvenience.

17.4 Has a permanent effect

Permanent or difficult-to-reverse consequences are particularly important.

17.5 Excludes or discriminates against individuals

Algorithmic exclusion is especially significant.

For example:

  • systematically excluding certain applicants from employment;

  • assigning higher insurance risk to particular individuals;

  • automatically denying access to financial products.

18. SCHUFA: The Importance of Algorithmic Credit Scoring

The CJEU's decision in SCHUFA Holding (Scoring), C-634/21 represents a major development in Article 22 jurisprudence.

The case concerned automated credit scoring.

A credit information agency generated a probability value concerning an individual's ability to repay a loan.

The agency argued that it did not make the final lending decision. Banks received the score and made their own decisions.

The CJEU nevertheless recognised that the score could itself constitute a decision for Article 22 purposes.

Why?

Because the score had a decisive practical effect.

If the score fell below a particular threshold, banks would generally reject the loan.

Therefore, the algorithmic score was not merely an insignificant piece of background information.

It played a determining role in the ultimate decision.

19. The Anti-Circumvention Principle in SCHUFA

SCHUFA is important because it prevents controllers from artificially separating algorithmic assessment from the ultimate decision.

Consider the following structure:

AI system → risk score → bank employee → automatic acceptance/rejection

A controller might argue:

“The AI does not decide. The bank decides.”

But if the bank's employee simply follows the AI score, the distinction becomes artificial.

The GDPR must be interpreted according to the substantive reality of decision-making, not merely contractual or organisational labels.

Otherwise, Article 22 could easily be defeated.

Every organisation could simply say:

“Our algorithm only makes recommendations.”

The question would then become whether that recommendation is actually determinative.

20. SCHUFA and the Right to Explanation

SCHUFA also illustrates the connection between Article 22 and transparency rights under Articles 13, 14 and 15.

Article 15(1)(h) gives the data subject the right to obtain:

“meaningful information about the logic involved”

in relevant automated decision-making.

This does not necessarily mean disclosure of the source code.

Rather, the individual must receive information sufficient to understand:

  • what factors were considered;

  • how those factors were used;

  • what role the algorithm played;

  • why the resulting decision was reached;

  • what significance the processing had.

This information is essential because procedural rights are meaningless if the person cannot understand what happened.

21. Dun & Bradstreet Austria

The CJEU subsequently developed the explanation dimension in:

Dun & Bradstreet Austria C-203/22

The Court emphasised that meaningful information about the logic involved should allow the data subject to understand the procedure and principles actually applied to their personal data in producing the result.

This is particularly significant for AI systems.

An organisation should not simply tell an individual:

“The algorithm determined that you were high risk.”

That provides almost no meaningful information.

A more useful explanation might identify that the assessment considered:

  • payment history;

  • outstanding debts;

  • income;

  • previous defaults;

  • relevant financial indicators;

and explain how these categories contributed to the result.

The objective is not necessarily to provide the individual with the complete mathematical architecture of the system.

The objective is to provide enough meaningful information to make the rights under Article 22 effective.

22. Article 22 and the Right to an Explanation

A common misconception is that Article 22 creates an unlimited and independent “right to explanation” of every algorithm.

The legal position is more nuanced.

The GDPR establishes transparency requirements through:

  • Articles 13 and 14;

  • Article 15;

  • Article 22;

  • Recital 71.

The information must be sufficiently meaningful to allow the data subject to understand and challenge the decision.

The CJEU's recent case law therefore strengthens the practical significance of explanation.

23. Intellectual Property and Trade Secrets

A difficult issue arises when an organisation argues that detailed explanations could reveal:

  • trade secrets;

  • proprietary algorithms;

  • source code;

  • confidential business information.

The GDPR does not automatically require disclosure of an entire algorithm or source code.

However, intellectual property cannot simply be invoked as a blanket justification for refusing meaningful information.

The controller must reconcile competing interests.

The essential question is:

What information must be disclosed to make the data subject's GDPR rights effective?

A controller should therefore seek to explain the relevant logic without unnecessarily disclosing protected proprietary information.

24. Article 22 and AI “Black Boxes”

The emergence of complex machine learning systems creates particular challenges.

Some AI systems are difficult even for their developers to interpret fully.

This creates a fundamental governance problem.

If a controller cannot adequately understand how a system produces significant decisions, it may struggle to comply with:

  • transparency obligations;

  • Article 22 safeguards;

  • accuracy obligations under Article 5(1)(d);

  • fairness obligations under Article 5(1)(a);

  • accountability under Article 5(2).

The fact that a technology is technically complex does not eliminate the controller's legal obligations.

A controller should therefore carefully assess whether it can deploy an AI model for high-impact decisions while still providing meaningful oversight and explanations.

25. Article 22(2): Exceptions to the Prohibition

Article 22(1) establishes the general prohibition.

Article 22(2) creates three exceptions:

Exception 1

The decision is necessary for entering into or performing a contract.

Exception 2

The decision is authorised by Union or Member State law.

Exception 3

The decision is based on the data subject's explicit consent.

These exceptions should not be interpreted as a general licence for automated decision-making.

Each requires satisfaction of specific conditions.

26. Article 22(2)(a): Contractual Necessity

The first exception applies where automated decision-making is:

“necessary for entering into, or performance of, a contract between the data subject and a data controller.”

The critical word is:

necessary.

Necessity is stronger than convenience.

A controller cannot rely on Article 22(2)(a) merely because automation:

  • saves money;

  • is faster;

  • is more convenient;

  • reduces staffing costs;

  • increases efficiency.

The controller should demonstrate that the automated decision-making is genuinely necessary for the contractual relationship.

27. Necessity and Less Intrusive Alternatives

Suppose a company claims:

“We need AI to automatically evaluate every customer's creditworthiness.”

The company should consider whether there are less intrusive alternatives.

For example:

  • human assessment;

  • a narrower algorithm;

  • fewer categories of personal data;

  • manual review for borderline cases;

  • a hybrid decision-making model.

If an equally effective and less intrusive alternative exists, relying on contractual necessity becomes more difficult.

The assessment should therefore involve proportionality.

28. Pre-Contractual Situations

Article 22(2)(a) may also be relevant to certain pre-contractual activities.

Example

a financial institution may use automated processing during an application process before the contract is concluded.

However, the controller must still demonstrate genuine necessity.

The fact that the individual has submitted an application does not automatically permit unrestricted automated decision-making.

29. Contractual Necessity Does Not Eliminate Safeguards

Even where Article 22(2)(a) applies, the controller must implement the safeguards required by Article 22(3).

Therefore:

Contractual necessity ≠ unrestricted automation.

The individual must still be able to:

  • obtain human intervention;

  • express their viewpoint;

  • contest the decision.

This reflects the fundamental purpose of Article 22.

30. Article 22(2)(b): Authorisation by Union or Member State Law

The second exception applies where automated decision-making is:

“authorised by Union or Member State law”

to which the controller is subject.

But the law must also establish:

“suitable measures to safeguard the data subject's rights and freedoms and legitimate interests.”

This is an important limitation.

A Member State cannot simply pass a law saying:

“Government agencies may make automated decisions.”

The legislation must contain meaningful safeguards.

30. Article 22(2)(b): Authorisation by Union or Member State Law

The second exception applies where automated decision-making is:

“authorised by Union or Member State law”

to which the controller is subject.

But the law must also establish:

“suitable measures to safeguard the data subject's rights and freedoms and legitimate interests.”

This is an important limitation.

A Member State cannot simply pass a law saying:

“Government agencies may make automated decisions.”

The legislation must contain meaningful safeguards.

31. What Must Authorising Legislation Contain?

The safeguards should address matters such as:

  • accuracy;

  • fairness;

  • security;

  • human intervention;

  • error correction;

  • discrimination;

  • transparency;

  • ability to challenge decisions.

The CJEU in SCHUFA emphasised the importance of:

  • appropriate mathematical or statistical procedures;

  • technical and organisational measures;

  • minimising errors;

  • correcting inaccuracies;

  • preventing discriminatory effects;

  • ensuring appropriate security;

  • human intervention;

  • ability to express a viewpoint;

  • ability to challenge the decision.

Thus, Article 22(2)(b) is not simply about legislative permission.

It is about legislatively authorised automation accompanied by fundamental-rights safeguards.

32. Relationship with Articles 5 and 6

The CJEU's reasoning in SCHUFA is particularly important here.

Authorisation under Article 22(2)(b) does not remove the other GDPR requirements.

Automated processing must still comply with the broader GDPR framework.

This means the controller must consider:

Article 5

  • lawfulness;

  • fairness;

  • transparency;

  • purpose limitation;

  • data minimisation;

  • accuracy;

  • storage limitation;

  • integrity and confidentiality;

  • accountability.

Article 6

The processing must have an appropriate legal basis.

Therefore:

Article 22 is not an independent legal basis for processing personal data.

This is one of the most important points for compliance analysis.

A controller cannot say:

“Article 22 allows automated decision-making, therefore we can process whatever data the algorithm needs.”

That is incorrect.

Article 22 regulates the decision-making mechanism; it does not replace the underlying lawfulness requirements.

33. Article 22(2)(c): Explicit Consent

The third exception is where the automated decision is:

“based on the data subject's explicit consent.”

This is a particularly strong form of consent.

The controller must satisfy the GDPR requirements governing valid consent.

Consent must be:

  • freely given;

  • specific;

  • informed;

  • unambiguous;

  • explicit where Article 22 requires explicit consent;

  • capable of being withdrawn.

The controller should therefore not bury consent to significant automated decision-making within lengthy terms and conditions.

The requirement of explicit consent becomes particularly important where there is a power imbalance.

For example:

  • employer and employee;

  • public authority and citizen;

  • dominant platform and user.

A controller cannot simply assume that consent is freely given merely because an individual clicked “I agree”.

The practical ability to refuse should be considered.

This is especially relevant where the automated decision determines access to an essential service or opportunity.

Article 22(2)(c) is expressly linked to Article 22(3).

Therefore, even where an individual has given explicit consent, the controller must implement appropriate safeguards.

This includes at least:

  1. human intervention;

  2. expression of viewpoint;

  3. contesting the decision.

Consent therefore does not transform an opaque algorithm into an unrestricted decision-maker.

36. Article 22(3): Human Intervention

Article 22(3) requires the controller to provide:

“the right to obtain human intervention on the part of the controller”

This is one of the most important protections in Article 22.

Human intervention provides an escape route from an automated outcome.

However, it must be genuine.

A controller should have a documented process allowing an individual to request human review.

The reviewer should:

  • understand the automated decision;

  • examine the relevant facts;

  • consider the individual's arguments;

  • have authority to change the result;

  • independently assess whether the algorithm was correct.

37. Right to Express a Point of View

The second safeguard is the right:

“to express his or her point of view”

This recognises that algorithms may not have access to the complete context of an individual's circumstances.

Example

an automated credit model might interpret:

  • a missed payment;

  • unusual spending;

  • employment interruption;

as evidence of increased financial risk.

The individual may have an explanation that the algorithm cannot know.

The right to express a viewpoint ensures that the individual can provide relevant contextual information.

38. Right to Contest the Decision

The third explicit safeguard is:

“the right to contest the decision.”

This goes beyond merely allowing the person to complain.

The controller should provide a meaningful mechanism for challenging the outcome.

The process should explain:

  • where the challenge can be submitted;

  • what information may be provided;

  • who reviews it;

  • how the review is conducted;

  • how the outcome is communicated.

A meaningless complaint mailbox is insufficient if challenges are never genuinely evaluated.

39. Article 22 Safeguards as a Procedural Framework

The three safeguards work together.

Consider:

Automated decision

Information about decision

Human review

Data subject explains circumstances

Controller reassesses decision

Decision confirmed or modified

This structure creates procedural accountability around automated systems.

Article 22 therefore does not simply regulate technology.

It regulates the relationship between algorithmic power and individual autonomy.

40. Article 22(4): Special Categories of Personal Data

Article 22 becomes even stricter where special categories of personal data are involved.

Article 9(1) protects information such as:

  • racial or ethnic origin;

  • political opinions;

  • religious or philosophical beliefs;

  • trade union membership;

  • genetic data;

  • biometric data used for uniquely identifying an individual;

  • health data;

  • sex life or sexual orientation.

Automated decisions involving such information create particularly serious risks of discrimination and harm.

Therefore, Article 22(4) imposes a qualified prohibition.

41. Exceptions Under Article 22(4)

An automated decision under Article 22 may not be based on Article 9 special-category data unless:

First

The data subject has given explicit consent under Article 9(2)(a);

or

Second

Processing is necessary for substantial public interest under Article 9(2)(g).

And in either case:

suitable safeguards must be in place.

42. Why Special Categories Receive Stronger Protection

Imagine an automated recruitment system using:

  • health information;

  • religious information;

  • ethnicity;

  • genetic information.

Even if the system claims that such information improves predictive accuracy, using it can produce serious discriminatory consequences.

Article 22(4) therefore reflects a precautionary approach.

The more sensitive the data and the more consequential the decision, the stronger the legal safeguards must be.

43. Indirect Use of Special Category Data

An important practical issue is that discrimination can occur even when the algorithm does not explicitly receive sensitive data.

Example

an AI model may not contain an individual's ethnicity field but may infer characteristics from:

  • postcode;

  • language;

  • names;

  • behavioural patterns;

  • social networks;

  • purchasing behaviour.

Similarly, health status may sometimes be inferred from:

  • search history;

  • wearable data;

  • medication purchases;

  • browsing behaviour.

Therefore, organisations should not focus exclusively on whether an explicit “health” or “religion” field exists.

They should examine whether sensitive characteristics can be inferred or used indirectly.

44. Article 22 and the Principle of Fairness

Article 22 must be interpreted alongside Article 5(1)(a), which requires processing to be lawful, fair and transparent.

An automated system can technically satisfy Article 22 while still raising serious fairness concerns.

Example

an algorithm may not produce a legally significant decision but may systematically disadvantage particular groups through repeated profiling.

Therefore, Article 22 should not be treated as the only GDPR provision governing algorithmic fairness.

Controllers should consider the entire GDPR framework.

45. Article 22 and Accuracy

Article 5(1)(d) requires personal data to be accurate and kept up to date.

This becomes especially important in automated decision-making.

An incorrect data point can propagate through an algorithm and produce a serious consequence.

For example:

Incorrect data:

“Previous loan default.”

Algorithm:

High-risk customer.

Automated decision:

Loan rejected.

If the original information is incorrect, the entire decision may be unjustified.

Controllers therefore need mechanisms for:

  • correcting inaccurate data;

  • identifying erroneous inputs;

  • updating profiles;

  • reconsidering decisions based on corrected information.

46. Article 22 and Data Minimisation

Article 5(1)(c) requires data minimisation.

AI developers often want to use large datasets because more data may improve predictive performance.

But “more data” does not automatically mean “lawful processing”.

The controller should ask:

  • Is this data necessary?

  • Is it proportionate?

  • Is it relevant?

  • Does it materially improve the decision?

  • Can the same objective be achieved with less personal data?

This is especially important where automated decisions have serious effects.

47. Article 22 and Children

Recital 71 expressly recognises the vulnerability of children.

Children deserve specific protection because they may have:

  • limited understanding of algorithmic systems;

  • reduced ability to recognise manipulation;

  • less capacity to challenge automated decisions;

  • increased susceptibility to behavioural profiling.

Automated decisions involving children therefore require particularly careful scrutiny.

Example

an algorithm determining educational opportunities, advertising exposure or access to services may have long-term consequences for a child.

Controllers should therefore consider whether automated decision-making is appropriate at all and whether additional safeguards are necessary.

48. Article 22 and Data Protection Impact Assessments

Article 35 GDPR requires a Data Protection Impact Assessment (DPIA) in situations likely to result in a high risk to individuals.

Systematic and extensive evaluation of personal aspects based on automated processing, including profiling, where decisions produce legal effects or similarly significant effects, is specifically relevant to DPIA requirements.

Therefore, Article 22 systems often warrant a DPIA before deployment.

A proper DPIA should examine:

  • purpose of the system;

  • data sources;

  • legal basis;

  • categories of individuals;

  • algorithmic logic;

  • accuracy;

  • bias;

  • discrimination;

  • foreseeable harms;

  • human oversight;

  • explanation mechanisms;

  • challenge mechanisms;

  • security;

  • retention;

  • mitigation measures.

49. Article 22 and Algorithmic Bias

Algorithmic bias is one of the principal practical concerns surrounding Article 22.

Bias can arise from:

Historical data

The training data may reflect discriminatory historical practices.

Sampling bias

Certain populations may be underrepresented.

Measurement bias

The system may use imperfect proxies.

Label bias

The target variable may reflect subjective or discriminatory judgments.

Deployment bias

A model developed for one population may perform poorly when used for another.

Article 22 therefore operates within a broader ecosystem of anti-discrimination and fairness obligations.

50. Example: Automated Recruitment

Consider an employer deploying an AI recruitment system.

The system:

  1. analyses CVs;

  2. assigns candidates a score;

  3. automatically rejects candidates below 60%;

  4. automatically advances candidates above 60%;

  5. no recruiter independently reviews rejected candidates.

If the rejection significantly affects employment opportunities, Article 22 may apply.

The employer must then ask:

  • Is the decision solely automated?

  • Is the effect sufficiently significant?

  • Is one of Article 22(2)'s exceptions applicable?

  • What human intervention is available?

  • Can candidates challenge the decision?

  • Is the model discriminatory?

  • Are the data accurate?

  • Was a DPIA required?

  • Is meaningful information about the logic provided?

51. Example: Automated Credit Scoring

Consider:

Applicant submits loan application

Algorithm analyses financial history

Algorithm calculates probability of default

System automatically rejects application

No meaningful human review

This is a classic Article 22 scenario.

The fact that the algorithm is statistically accurate does not eliminate Article 22.

Accuracy and legality are separate questions.

A highly accurate algorithm can still violate Article 22 if the conditions for automated decision-making are not satisfied.

52. Example: Healthcare AI

Suppose an AI system automatically determines that a patient is low priority and therefore delays access to treatment.

The decision could potentially produce a significant effect.

The organisation must therefore consider:

  • whether the decision is solely automated;

  • whether meaningful human review exists;

  • whether the decision is necessary under an Article 22(2) exception;

  • whether health data under Article 9 is being processed;

  • whether Article 22(4) applies;

  • whether the system satisfies accuracy and fairness requirements.

The stakes become especially high because errors may affect physical health and potentially life.

53. Example: Insurance

An insurer may use automated systems to determine:

  • whether an applicant receives coverage;

  • premium levels;

  • risk classifications;

  • claim eligibility.

If the decision significantly affects the individual's economic circumstances and is made solely through automated processing, Article 22 may be relevant.

The insurer must carefully examine whether its system actually produces significant effects and whether an Article 22(2) exception applies.

54. Article 22 Is Not a General Ban on AI

An important misconception must be avoided.

Article 22 does not prohibit artificial intelligence generally.

It does not prohibit:

  • machine learning;

  • predictive analytics;

  • recommendation engines;

  • automated customer segmentation;

  • AI-assisted decision-making.

The provision targets a particular category:

solely automated individual decisions producing legal or similarly significant effects.

Therefore, AI can be used lawfully in many circumstances.

The legal issue is not simply:

“Is AI being used?”

The question is:

“What role does AI play in the decision, how significant is the effect, and what safeguards exist?”

55. AI-Assisted Versus AI-Decided

This distinction is likely to become increasingly important.

AI-assisted

Human → AI analysis → human evaluation → decision

Potentially outside Article 22 if the human intervention is genuine.

AI-decided

Data → AI → decision

Potentially within Article 22.

Human rubber stamp

Data → AI → nominal human approval → decision

Potentially still within Article 22.

Therefore, organisations should map the actual decision-making architecture rather than relying on labels such as:

“human in the loop.”

56. Article 22 and the EU AI Act

Article 22 GDPR should now also be considered alongside the EU AI Act.

The two regimes have different purposes.

The GDPR focuses principally on:

  • personal data processing;

  • data subject rights;

  • lawful processing;

  • automated individual decision-making;

  • privacy and fundamental rights.

The AI Act establishes a broader regulatory framework for AI systems, including:

  • prohibited AI practices;

  • high-risk AI systems;

  • transparency requirements;

  • governance obligations;

  • risk-management requirements.

A system can therefore be subject to both regimes.

Compliance with one does not automatically mean compliance with the other.

Example

a high-risk AI system used in recruitment may trigger obligations under the AI Act while also engaging:

  • GDPR Article 22;

  • Article 5;

  • Article 6;

  • Article 9;

  • Article 13/14;

  • Article 15;

  • Article 35.

The organisation should therefore perform an integrated AI and data protection assessment.

57. Article 22 as a Human Autonomy Provision

At its deepest level, Article 22 is not merely about privacy.

It is about human autonomy.

The concern is not simply that an organisation possesses personal information.

The more serious concern is that an algorithm may use information about an individual to make consequential decisions without giving that individual meaningful participation in the process.

Article 22 therefore protects a principle that can be described as:

human control over consequential decisions.

This is particularly important as AI systems become increasingly capable of making predictions and recommendations that humans may be inclined to trust automatically.