Practical guide
GDPR Article 22: A Guide to Automated Decisions
Learn when EU GDPR Article 22 applies to AI-assisted decisions, which exceptions exist, and what safeguards and records an SME may need.
Key takeaways
- EU GDPR Article 22 concerns decisions based solely on automated processing that produce legal or similarly significant effects. Profiling can be involved, but it is not a separate condition.
- Real human judgment can take a decision outside Article 22. A nominal reviewer who routinely accepts a score may not provide meaningful involvement.
- The three Article 22 exceptions are contractual necessity, authorisation by EU or member-state law, and explicit consent. A separate Article 6 lawful basis is still required for the processing.
- Article 22 is not the only GDPR issue. Transparency, fairness, accuracy, processor contracts, records, security, and DPIA duties can apply even when a human makes the final decision.
- The UK replaced its version of Article 22 in February 2026. This guide concerns EU GDPR, not UK GDPR.
AI can recommend which applicant to interview, whether to extend credit, or which customer receives an offer. EU GDPR Article 22 matters only for a narrower group of decisions, but getting that boundary wrong can leave a business without the notice, safeguards, or legal authority it needs.
The right first step is to map the decision process, not to label the software “automated.”
The Article 22 test
EU GDPR Article 22 applies when all three elements below are present.
1. There is a decision about a person
The system must do more than generate general content or organise internal information. Examples can include rejecting an applicant, setting a person's credit limit, cancelling a service, or determining access to a significant benefit.
2. The decision is based solely on automated processing
There is no meaningful human involvement before the decision takes effect. A human reviewer can change the result, but only if the reviewer has enough information, authority, time, and independence to assess the case rather than rubber-stamp the output.
Document the real workflow. If the process says “manager review” but the manager sees only a score and approves every recommendation, the label alone is weak evidence of human involvement.
3. It has a legal or similarly significant effect
A legal effect changes a person's legal rights or status. A similarly significant effect materially affects their circumstances, behaviour, opportunities, or access to a service.
Recruitment rejection and credit decisions are common examples. Personalised advertising or pricing requires a fact-specific assessment: not every tailored offer is significant, but a substantial financial effect or exclusion from an essential service may be.
Profiling is not a fourth requirement. Article 22 says automated processing “including profiling.” A decision can fall within Article 22 without profiling, and profiling can occur without a significant automated decision.
When a solely automated significant decision is allowed
Article 22(2) provides three routes:
- Necessary for a contract. The decision must be objectively necessary to enter into or perform a contract with the person, not merely cheaper or more convenient.
- Authorised by law. EU or member-state law must authorise the decision and provide suitable measures to protect the person's rights, freedoms, and legitimate interests.
- Based on explicit consent. Consent must be specific, informed, freely given, demonstrable, and capable of withdrawal. An ordinary privacy-policy acceptance is not enough.
These are Article 22 permissions, not substitutes for the rest of GDPR. Identify a lawful basis under Article 6 and, where special-category data is processed, a condition under Article 9. Article 22(4) also sharply limits decisions based on special-category data.
If no Article 22(2) route applies, do not make the decision solely by automated means. Introduce meaningful human decision-making or change the process.
Safeguards and information duties
For contract-necessity and explicit-consent cases, Article 22(3) requires at least the ability to:
- obtain human intervention from the controller;
- express a point of view; and
- contest the decision.
Where law authorises the processing, that law must provide suitable safeguards. Build a process that routes requests to a person who can inspect relevant inputs, consider additional information, and alter the result.
Articles 13 and 14 require information about the existence of Article 22 decision-making, meaningful information about the logic involved, and the significance and envisaged consequences for the person. Article 15 provides related access rights.
Avoid pretending that one generic explanation suits every model. Tell people what decision is being made, the main categories of information and factors used, how the outcome affects them, and how to seek review or contest it. Do not claim that GDPR always requires disclosure of source code, model weights, or every technical detail.
DPIAs: Article 22 and Article 35 are different tests
A Data Protection Impact Assessment is required before processing likely to result in high risk to people's rights and freedoms.
Article 35(3)(a) expressly covers a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based. Other mandatory cases include large-scale processing of special-category or criminal-conviction data and large-scale systematic monitoring of a publicly accessible area.
AI, profiling, or sensitive data does not automatically make every use a mandatory DPIA. Assess the combination of scale, novelty, vulnerability, monitoring, data type, decision effect, and other risk factors. Check the relevant supervisory authority's published list as well as Article 35.
Where the DPIA identifies a high residual risk that you cannot mitigate, Article 36 requires prior consultation with the competent supervisory authority.
Common SME scenarios
Recruitment
An applicant-screening tool rejects candidates automatically. If the rejection is significant and no person meaningfully reviews it, Article 22 applies. If a recruiter receives a recommendation but independently reviews the application and can depart from it, Article 22 may not apply—although fairness, transparency, accuracy, DPIA, and employment-law duties still can. The AI Output Review Process gives a practical starting point for designing a real review step.
Recruitment AI may also fall within Annex III of the EU AI Act. Most Annex III high-risk duties now apply from 2 December 2027, so keep the GDPR and AI Act analyses separate and date them.
Credit or eligibility
An automated credit refusal is a classic Article 22 scenario. Record the Article 6 lawful basis, Article 22(2) route, information given, review process, retention, and any relevant special-category-data restriction.
Marketing and churn scoring
A score used only to choose which general email to send may not create a significant effect. The same score used automatically to suspend an account or deny a material benefit might. Trace what the score actually triggers.
General productivity tools
Using AI to draft an email or summarise notes is usually not an Article 22 decision. GDPR can still apply if personal data enters the system. Review the lawful basis, vendor's processor terms, international transfers, security, retention, and use of prompts for training. Start with the AI vendor data-terms guide before reviewing the contract itself.
A practical review process
For each AI-assisted decision:
- Describe the decision and its effect on the person.
- Draw the workflow from input to final outcome, including every human step.
- Test whether human involvement is meaningful in practice.
- If Article 22 applies, document the Article 22(2) route and separate Article 6 basis.
- Check special-category data and Article 22(4).
- Prepare the required notices and a usable human-review and contest process.
- Complete the DPIA screen and, where required, the DPIA before deployment.
- Record the system under Article 30 where applicable and review it when the model, purpose, or workflow changes.
Tools that help
The GDPR AI Data Processing Register records the processing purpose, Article 6 basis, data categories, retention, recipients, transfers, and Article 22 position. The DPIA Trigger Checklist supports the separate Article 35 screen, while the EU AI Act Risk Classification Worksheet handles the additional AI Act analysis.
The free AI Vendor Review can structure an initial review of data handling and access controls. It does not replace a processor-contract, transfer, or legal assessment.
For jurisdiction-neutral policies and employee rules that sit underneath this EU-specific layer, see the AI Governance Starter Pack.
This article describes EU GDPR Article 22 and related provisions in plain language for SME owners. It is not legal advice and does not guarantee compliance. The result depends on the decision, data, human involvement, member-state law, sector, and other facts. Obtain qualified advice for significant decisions about people.