Article 22 GDPR is one of the most complex provisions within the GDPR because it regulates the circumstances in which organisations may make decisions about individuals using solely automated processing, including profiling, where those decisions produce legal effects or similarly significant effects.
Rather, it establishes:
A default right not to be subject to certain automated decisions.
Narrow exceptions permitting such automated decisions.
Mandatory safeguards when exceptions apply.
Article 22 applies where ALL three elements exist simultaneously. If any one element is absent, Article 22 generally does not apply.
There must be an identifiable decision made about an individual.
The decision must be based solely on automated processing without meaningful human involvement.
The decision must produce legal effects or similarly significant effects on the individual.
Automated determination of creditworthiness.
Automated rejection of a mortgage application.
Automated pricing based on risk profiling.
Automated shortlisting or rejection of candidates.
Automated determination of academic eligibility.
Automated eligibility for public benefits.
Automated immigration processing outcomes.
Automated account suspension or transaction blocking.
Suggesting products or content without material consequence.
Personalised shopping recommendations.
Adjusting layout or content for user experience.
Serving adverts without significant individual impact.
A decision is solely automated when there is no meaningful human involvement. The threshold is meaningful human involvement, not merely human presence.
Meaningful human involvement requires all of the following:
Legal effects are outcomes that directly alter legal rights, obligations or status of an individual. These are generally the clearest cases under Article 22.
Automated rejection from a job application process.
Automated refusal of insurance coverage.
Automated refusal of credit or lending products.
Automated cessation of welfare or public entitlements.
Automated immigration decision with legal consequences.
Automated termination of banking or service accounts.
Automated initiation of formal disciplinary proceedings.
Financial position and access to credit or services.
Career opportunities and professional standing.
Access to educational and healthcare services.
Social standing and access to fundamental services.
Customer segmented as "sports enthusiast" for marketing purposes. No decision with significant effects follows from the segmentation alone.
Customer classified as high-risk through profiling, and mortgage is automatically refused without meaningful human review.
Automated decisions may occur lawfully only where one of three narrow exceptions applies. These exceptions are interpreted strictly by supervisory authorities.
Necessary for entering into or performing a contract with the data subject.
Based on the data subject's explicit consent, freely given and fully informed.
Authorised by Union or Member State law with appropriate safeguards.
The necessity threshold is interpreted narrowly. Convenience or cost savings alone are insufficient.
Consent must meet all five requirements simultaneously:
May apply: Consumer opts into AI-driven investment recommendations affecting transactions.
May not apply: Hidden consent clauses, bundled consent, or pre-ticked boxes.
Automated decisions may be authorised by Union or Member State law. Such laws must themselves include appropriate safeguards.
Where any Article 22 exception applies, organisations must provide all four safeguards:
A human must be able to intervene in the decision-making process.
The data subject must be able to express their point of view.
The data subject must be able to challenge the decision.
A formal process for reconsidering the decision must exist.
Article 22 does not operate in isolation. It intersects with a broad range of GDPR provisions that practitioners must consider holistically.

Large enterprises typically implement the following controls to operationalise Article 22 compliance across their organisations.
Large enterprises typically implement a structured multi-stage operationalisation model. The first three stages establish the foundation for compliant automated decision-making.
Business proposes automation. Use case registered. AI register updated. Risk owner assigned.
Outputs: Initial risk profile, data inventory, stakeholder mapping.
Is a decision being made? Is profiling involved? Is automation involved? Is human review meaningful? Are legal or similarly significant effects present?
Outputs: Article 22 applicability decision, legal opinion, compliance assessment.
Identify personal data, special category data, source systems, data lineage, and data quality risks.
Outputs: Record of processing activities, data flow diagrams.
Evaluate necessity, proportionality, fairness, explainability, bias, and human oversight.
Outputs: Approved DPIA, mitigation plan.
Training data review, feature engineering review, protected characteristic testing, fairness testing, explainability testing, validation testing.
Outputs: Validation reports, approval recommendations.
Approvals obtained from Legal, Privacy, Risk, Compliance, Security, and the AI governance committee.
Design must specify:
Privacy notices must explain:
Requirements:
Continuous monitoring must cover:
Challenge submitted by data subject.
Identity verified.
Human reviewer assigned.
Inputs, model outputs, and context reviewed.
Decision upheld, amended, or reversed.
Written explanation issued to data subject.
Record retained for accountability purposes.
Large organisations apply a structured proportionality assessment. Key questions include:
Evidence typically includes: Cost-benefit analysis, operational necessity, error analysis, human review studies, fairness testing.
Decision is advisory only with no binding effect.
Processing does not result in a decision.
Human makes the final determination.
Impact on individual is not material.
Statistical or aggregate data only.
Mature organisations establish:
The previous regime was largely prohibition-based; the new regime is safeguard-based. Organisations may use solely automated significant decisions more broadly, provided safeguards are implemented. Special category data remains subject to stronger restrictions.
Required safeguards: Notice, human intervention, challenge rights, ability to make representations, review process.
Article 22 is not fundamentally an AI law; it is a decision-making law. The central compliance question is not "Are we using AI?" but "Are we making significant decisions solely through automation?"
Most enforcement failures occur because organisations cannot demonstrate meaningful human involvement. The burden of proof rests with the organisation.
Compliance is demonstrated through operational evidence: override records, review logs, appeal outcomes, challenge handling, bias monitoring, and governance approvals.
Modern regulators increasingly focus on reviewability, accountability and contestability rather than purely technical explainability. End-to-end reviewability is the gold standard.
For advanced practitioners, Article 22 should be viewed as an enterprise governance framework spanning privacy, AI governance, model risk management, consumer protection, employment law, financial regulation, ethics, and operational accountability — not merely as a privacy compliance obligation.
GDPR Article 22: Automated Individual Decision-Making and Profiling