Art. 22 GDPR: Limits on Automated Decisions

Art. 22 GDPR: when automated decisions and AI profiling are lawful – covering obligations, exceptions and typical compliance gaps in practice.

What Art. 22 GDPR requires

Art. 22(1) GDPR gives data subjects the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. This covers classic use cases such as automated creditworthiness checks, algorithmic candidate scoring or automated pricing – in other words, any case where a system reaches a decision without human involvement that has a noticeable impact on the person concerned.

The key word is “solely”. As soon as a human actually reviews the decision and takes it independently, Art. 22(1) does not apply. A merely formal intermediate step – an employee clicking through the system’s suggestions without any substantive review – is not enough. This is precisely where the first common misconception arises in practice: many organisations assume that a “four-eyes principle” is automatically sufficient, without the human review being substantively meaningful.

When the prohibition applies – and when it doesn’t

Art. 22(2) GDPR sets out three exceptions under which a decision based solely on automated processing is permitted:

  • it is necessary for entering into, or the performance of, a contract (point a),
  • it is authorised by Union or Member State law which lays down suitable safeguards (point b), or
  • it is based on the data subject’s explicit consent (point c).

In practice, these exceptions are often interpreted too generously. “Necessary for the performance of a contract”, for instance, is not a blanket justification for every scoring model – it requires genuine necessity, not mere convenience or cost-efficiency. For consent under point c, the strict GDPR standard of explicitness also applies: a hidden clause buried in the terms and conditions is not sufficient.

Suitable measures: the concrete obligation

Art. 22(3) GDPR obliges controllers, in the cases referred to in points a and c, to implement suitable measures to safeguard the data subject’s rights and freedoms. The law sets out a minimum programme: the right to obtain human intervention, to express one’s point of view and to contest the decision.

In practice, this means there needs to be a defined, genuinely functioning process through which data subjects can contest an automated decision, and a body that then reviews the decision with the relevant expertise and actual discretion – not merely rubber-stamping it. If this process is missing, or exists only on paper, that constitutes a breach of paragraph 3, even where the exception under paragraph 2 would otherwise apply.

Art. 22(4) GDPR further tightens the requirements where special categories of personal data under Art. 9(1) GDPR are involved – for example, health data used in an automated risk-scoring model. Such decisions are only permitted if Art. 9(2), point (a) or (g), is additionally satisfied and suitable safeguards are in place.

Interface with the EU AI Act

Many systems falling under Art. 22 GDPR – such as credit scoring, candidate pre-selection or risk assessment – are also listed as high-risk use cases in Annex III of the AI Act. Under the current timetable, as amended by the Digital Omnibus, the corresponding high-risk obligations under Annex III apply from 2 December 2027. Anyone operating such a system therefore needs to keep an eye on GDPR and AI Act requirements in parallel – the GDPR obligation to provide a means of contesting a decision does not replace an AI Act conformity assessment, and vice versa.

Separately, the transparency obligations under Art. 50 AI Act already apply from 2 August 2026, with a grace period until 2 December 2026 for systems placed on the market beforehand. Anyone required to inform data subjects about the use of AI in the context of automated decisions should align this information duty with the access and contestation logic under Art. 22 GDPR, rather than running two separate, potentially contradictory processes.

Common gaps in practice

Three patterns keep recurring in audits: first, the “solely automated” threshold is underestimated – systems that de facto pre-determine decisions get labelled as merely “supportive”. Second, a robust contestation process under paragraph 3 is missing, even though an exception under paragraph 2 is being relied on in theory. Third, special categories of data under Art. 9 are processed within automated models without the heightened requirements of paragraph 4 having been assessed.

Whether your automated decision-making processes fall under Art. 22 GDPR, and what additional obligations arise from the EU AI Act as a result, can be assessed in a few minutes using our free risk check at /einstufung.

Factual orientation, not legal advice. Citations refer to the named legal acts and were checked against the official EUR-Lex texts.