GDPR Article 22: Automated Individual Decision-Making and Profiling

Introduction

Article 22 GDPR is one of the most complex provisions within the GDPR because it regulates the circumstances in which organisations may make decisions about individuals using solely automated processing, including profiling, where those decisions produce legal effects or similarly significant effects.

Rather, it establishes:

Default Right

A default right not to be subject to certain automated decisions.

Narrow Exceptions

Narrow exceptions permitting such automated decisions.

Mandatory Safeguards

Mandatory safeguards when exceptions apply.

Article 22 Is Particularly Relevant To

  • AI systems and machine learning models
  • Credit scoring and insurance underwriting
  • Fraud detection
  • Recruitment automation
  • Employee monitoring
  • Public sector eligibility assessments
  • Online behavioural profiling
  • Dynamic pricing
  • Healthcare triage systems

Core Legal Test Under GDPR Article 22

Article 22 applies where ALL three elements exist simultaneously. If any one element is absent, Article 22 generally does not apply.

A Decision Exists

There must be an identifiable decision made about an individual.

Solely Automated Processing

The decision must be based solely on automated processing without meaningful human involvement.

Legal or Significant Effects

The decision must produce legal effects or similarly significant effects on the individual.

What Is a Decision?

Examples That Constitute a Decision

Credit Approval

Automated determination of creditworthiness.

Mortgage Refusal

Automated rejection of a mortgage application.

Insurance Premium Calculation

Automated pricing based on risk profiling.

Employment Screening Outcome

Automated shortlisting or rejection of candidates.

University Admission

Automated determination of academic eligibility.

Welfare Entitlement Assessment

Automated eligibility for public benefits.

Visa Approval

Automated immigration processing outcomes.

Automated Fraud Blocking

Automated account suspension or transaction blocking.

Examples That May NOT Constitute a Decision

Recommendation Engines

Suggesting products or content without material consequence.

Product Suggestions

Personalised shopping recommendations.

Website Personalisation

Adjusting layout or content for user experience.

Non-Material Advertising Targeting

Serving adverts without significant individual impact.

What Is "Solely Automated"?

A decision is solely automated when there is no meaningful human involvement. The threshold is meaningful human involvement, not merely human presence.

Meaningful human involvement requires all of the following:

Actual Review

Genuine Authority to Change Outcomes

Understanding of Decision Rationale

Ability to Override Systems

Independent Assessment

Article 22 Applies

  • AI rejects a loan automatically
  • Applicant is rejected instantly
  • No human reviews the case

Article 22 Does Not Apply

  • AI recommends rejection
  • Underwriter reviews evidence
  • Underwriter can overturn result
  • Underwriter makes final determination

What Is a Legal Effect?

Legal effects are outcomes that directly alter legal rights, obligations or status of an individual. These are generally the clearest cases under Article 22.

Refusal of Employment

Automated rejection from a job application process.

Denial of Insurance

Automated refusal of insurance coverage.

Loan Rejection

Automated refusal of credit or lending products.

Termination of Benefits

Automated cessation of welfare or public entitlements.

Visa Refusal

Automated immigration decision with legal consequences.

Account Closure

Automated termination of banking or service accounts.

Disciplinary Action

Automated initiation of formal disciplinary proceedings.

What Is a Similarly Significant Effect?

Likely Within Scope
  • Recruitment screening
  • Creditworthiness scoring
  • Dynamic insurance pricing
  • Educational progression decisions
  • Housing allocation
  • Automated employee monitoring leading to sanctions
Usually Outside Scope
  • Music recommendations
  • Film recommendations
  • Website layout optimisation
  • Non-material advertising preferences

Assessment Focuses on Impact On:

Economic Circumstances

Financial position and access to credit or services.

Employment Prospects

Career opportunities and professional standing.

Education & Health

Access to educational and healthcare services.

Reputation & Essential Services

Social standing and access to fundamental services.

Profiling and Article 22

Not Article 22

Customer segmented as "sports enthusiast" for marketing purposes. No decision with significant effects follows from the segmentation alone.

Article 22 Applies

Customer classified as high-risk through profiling, and mortgage is automatically refused without meaningful human review.

Article 22 Exceptions

Automated decisions may occur lawfully only where one of three narrow exceptions applies. These exceptions are interpreted strictly by supervisory authorities.

Contract Necessity

Necessary for entering into or performing a contract with the data subject.

Explicit Consent

Based on the data subject's explicit consent, freely given and fully informed.

Authorised by Law

Authorised by Union or Member State law with appropriate safeguards.

Contract Necessity & Explicit Consent Exceptions

Contract Necessity Exception

The necessity threshold is interpreted narrowly. Convenience or cost savings alone are insufficient.

May Apply
  • Instant online lending decisions
  • Real-time fraud prevention
  • Immediate insurance quotation
May Not Apply
  • Employer convenience
  • Cost savings alone
  • Business efficiency

Explicit Consent Exception

Consent must meet all five requirements simultaneously:

01

Freely Given

02

Specific

03

Informed

04

Unambiguous

05

Explicit

May apply: Consumer opts into AI-driven investment recommendations affecting transactions.

May not apply: Hidden consent clauses, bundled consent, or pre-ticked boxes.

Authorised by Law Exception & Mandatory Safeguards

Authorised by Law Exception

Automated decisions may be authorised by Union or Member State law. Such laws must themselves include appropriate safeguards.

Tax Administration

Social Security Systems

Anti-Money Laundering Controls

Border Security Processing

Mandatory Safeguards

Where any Article 22 exception applies, organisations must provide all four safeguards:

Human Intervention

A human must be able to intervene in the decision-making process.

Ability to Express Views

The data subject must be able to express their point of view.

Ability to Challenge

The data subject must be able to challenge the decision.

Reconsideration Process

A formal process for reconsidering the decision must exist.

GDPR Articles Intersecting with Article 22

Article 22 does not operate in isolation. It intersects with a broad range of GDPR provisions that practitioners must consider holistically.

Twenty Cross-Cutting Technical and Organisational Controls

Large enterprises typically implement the following controls to operationalise Article 22 compliance across their organisations.

Inventory & Registration

  • Automated decision inventory
  • Enterprise AI register
  • Article 22 applicability assessment

Governance

  • Algorithm governance committee
  • AI risk classification framework
  • Board-level AI governance reporting

Human Oversight

  • Human-in-the-loop controls
  • Human override capability
  • Contestability process

Model Controls

  • Decision explainability controls
  • Model transparency documentation
  • Training data governance
  • Independent model validation

Monitoring

  • Bias testing programme
  • Fairness monitoring
  • Drift monitoring
  • Automated outcome monitoring

Process & Audit

  • Mandatory DPIA workflow
  • Individual rights management workflow
  • Audit trail logging

Large Enterprise Operationalisation Model: Stages 1–3

Large enterprises typically implement a structured multi-stage operationalisation model. The first three stages establish the foundation for compliant automated decision-making.

1

Stage 1 – Use Case Identification

Business proposes automation. Use case registered. AI register updated. Risk owner assigned.

Outputs: Initial risk profile, data inventory, stakeholder mapping.

2

Stage 2 – Article 22 Screening

Is a decision being made? Is profiling involved? Is automation involved? Is human review meaningful? Are legal or similarly significant effects present?

Outputs: Article 22 applicability decision, legal opinion, compliance assessment.

3

Stage 3 – Data Mapping

Identify personal data, special category data, source systems, data lineage, and data quality risks.

Outputs: Record of processing activities, data flow diagrams.

Large Enterprise Operationalisation Model: Stages 4–6

Stage 4 – DPIA

Evaluate necessity, proportionality, fairness, explainability, bias, and human oversight.

Outputs: Approved DPIA, mitigation plan.

Stage 5 – Model Development Controls

Training data review, feature engineering review, protected characteristic testing, fairness testing, explainability testing, validation testing.

Outputs: Validation reports, approval recommendations.

Stage 6 – Governance Approval

Approvals obtained from Legal, Privacy, Risk, Compliance, Security, and the AI governance committee.

Large Enterprise Operationalisation Model: Stages 7–9

Stage 7 – Human Oversight Design

Design must specify:

  • Review triggers
  • Escalation thresholds
  • Override authority
  • Appeal mechanisms
  • Reconsideration procedures

Stage 8 – Transparency Controls

Privacy notices must explain:

  • Use of automation
  • Decision logic
  • Consequences
  • Rights available
  • Challenge process

Stage 9 – Go-Live Approval

Requirements:

  • DPIA complete
  • Security sign-off
  • Model validation
  • Legal approval
  • Operational readiness

Large Enterprise Operationalisation Model: Stages 10–11

Stage 10 – Ongoing Monitoring

Continuous monitoring must cover:

  • Bias
  • Drift
  • Error rates
  • Complaint volumes
  • Override frequency
  • Regulatory developments

Stage 11 – Individual Challenge Process

01

Receipt

Challenge submitted by data subject.

02

Validation

Identity verified.

03

Review

Human reviewer assigned.

04

Investigation

Inputs, model outputs, and context reviewed.

05

Outcome

Decision upheld, amended, or reversed.

06

Communication

Written explanation issued to data subject.

07

Audit

Record retained for accountability purposes.

Necessity, Proportionality, Exclusions & Monitoring

Proportionality Assessment

Large organisations apply a structured proportionality assessment. Key questions include:

  • Is automation necessary?
  • Could humans reasonably perform the task?
  • Is impact proportionate?
  • Is there a less intrusive method?
  • Is automation fair?
  • Are safeguards sufficient?
  • Is explainability achievable?
  • Is review possible?

Evidence typically includes: Cost-benefit analysis, operational necessity, error analysis, human review studies, fairness testing.

Reasons Article 22 May Not Apply

Advisory Only

Decision is advisory only with no binding effect.

No Decision Exists

Processing does not result in a decision.

Human Final Decision

Human makes the final determination.

Effect Not Significant

Impact on individual is not material.

Aggregate Reporting

Statistical or aggregate data only.

Monitoring Compliance

Mature organisations establish:

  • Quarterly Article 22 audits
  • AI governance committees
  • Continuous fairness monitoring
  • Model drift reviews
  • Internal audit testing
  • Regulatory horizon scanning
  • Annual DPIA refresh
  • Complaint trend analysis
  • Challenge outcome reviews
  • Executive reporting

Impact of the UK Data (Use and Access) Act 2025

The Fundamental Shift

The previous regime was largely prohibition-based; the new regime is safeguard-based. Organisations may use solely automated significant decisions more broadly, provided safeguards are implemented. Special category data remains subject to stronger restrictions.

Key Changes Under DUAA

  • Wider use of automated decision-making
  • Broader lawful basis options
  • Increased reliance on organisational safeguards
  • Formal challenge rights
  • Human intervention rights
  • Representation rights
  • Contestability rights
  • Stronger focus on governance and accountability

Now in Scope Under DUAA (With Safeguards)

  • AI recruitment shortlisting
  • Automated employee screening
  • Automated promotion recommendations
  • Automated insurance underwriting
  • Automated pricing decisions
  • Automated customer onboarding
  • Automated account opening decisions
  • Automated fraud decisions
  • AI-driven credit assessments
  • Automated lending approvals
  • Automated eligibility screening
  • Automated telecommunications risk scoring
  • Automated customer trust scoring
  • AI-based claims triage
  • Automated mortgage pre-screening

Required safeguards: Notice, human intervention, challenge rights, ability to make representations, review process.

Advanced Points

Article 22 is not fundamentally an AI law; it is a decision-making law. The central compliance question is not "Are we using AI?" but "Are we making significant decisions solely through automation?"

Where Enforcement Failures Occur

Most enforcement failures occur because organisations cannot demonstrate meaningful human involvement. The burden of proof rests with the organisation.

The Strongest Evidence of Compliance

Compliance is demonstrated through operational evidence: override records, review logs, appeal outcomes, challenge handling, bias monitoring, and governance approvals.

Modern Regulatory Focus

Modern regulators increasingly focus on reviewability, accountability and contestability rather than purely technical explainability. End-to-end reviewability is the gold standard.

The Enterprise Governance Framework View

For advanced practitioners, Article 22 should be viewed as an enterprise governance framework spanning privacy, AI governance, model risk management, consumer protection, employment law, financial regulation, ethics, and operational accountability — not merely as a privacy compliance obligation.

Datari Home