1. Introduction: The Democratic Challenge of Algorithmic Decision-Making
Article 22 of the General Data Protection Regulation (GDPR) represents one of the most technologically significant provisions within the Regulation because it addresses one of the central challenges of modern digital societies: the increasing delegation of decisions affecting individuals to algorithms and automated systems.
Contemporary organisations increasingly rely on automated tools to evaluate, classify, predict, rank, and make decisions concerning individuals. Financial institutions use automated systems to assess creditworthiness; employers use algorithmic recruitment tools to screen candidates; insurers use predictive models to calculate premiums; healthcare providers employ artificial intelligence systems to support diagnosis and treatment decisions; online platforms use recommendation algorithms to determine visibility and access to information.
While automated processing offers substantial benefits, including efficiency, consistency, scalability, and reduction of human error, it also creates serious risks for fundamental rights. Algorithmic decisions may reproduce historical biases, rely on inaccurate assumptions, operate without meaningful transparency, and create situations where individuals are affected by decisions they cannot understand or challenge.
Article 22 GDPR seeks to preserve human autonomy and prevent individuals from becoming subjects of decisions made exclusively by opaque technological systems. It establishes limitations on purely automated decision-making where such decisions have serious consequences for individuals.
The provision reflects a fundamental principle underlying European data protection law: individuals should not lose control over their lives merely because decisions affecting them are increasingly mediated by technology.