GDPR Article 22: the automated-decision backstop

Lesson 1 of 5 in Legal Intersections, Liability, and the Failure Files.

Before there was an AI Act, there was one sentence of EU data-protection law doing most of the work — and for systems processing personal data, it still applies in parallel with everything else you have learned. GDPR Article 22 is the oldest operative constraint on algorithmic decision-making in wide effect, and its anatomy repays close reading because every element has been litigated.

Three load-bearing phrases, three bodies of interpretation:

"Solely automated." The classic evasion was to route the algorithm’s output past a human before it took effect — a "human in the loop" whose loop was a rubber stamp. Regulators closed that door early: involvement must be meaningful, by someone with the authority and competence to change the decision, considering all relevant data — not a token gesture. You will recognize this as the same competence-authority-time-information test from the oversight module, now with legal teeth.

"Legal or similarly significant effects." Legal effects are the easy cases — contract cancellation, benefit denial, visa refusal. "Similarly significant" reaches decisions with serious impact on circumstances, behavior, or choices: credit refusal, e-recruiting without human review, and in some circumstances differential pricing. Showing someone an ad is generally out; deciding their livelihood is in.

The three exceptions. Solely automated significant decisions are permitted only where (a) necessary for a contract (necessity is read narrowly — "cheaper for us" does not qualify), (b) authorized by EU or member-state law with safeguards, or (c) based on explicit consent. And even inside an exception, Article 22(3) mandates safeguards: at minimum the right to obtain human intervention, to express one’s point of view, and to contest the decision. Special-category data raises the bar further.

Then, in December 2023, the CJEU detonated the market’s favorite workaround.

Does Article 22 bite? Walk the logic

Interactive decision tree — outcomes:

  • Outside Article 22

    No personal-data-based individual decisions, no Article 22. Other regimes (the AI Act, sector rules) may still apply — Article 22 is one layer, never the whole analysis.

  • Not "solely automated" — but prove it

    Article 22 does not apply where human involvement is meaningful. The burden of showing that is yours: document reviewer authority, information access, and real disagreement rates. A 99.8% approval rate at four seconds per case is evidence against you — and post-SCHUFA, a determining score cannot hide behind the human at all.

  • Below the significance threshold

    No legal or similarly significant effect, no Article 22(1) prohibition — though GDPR transparency and fairness duties still govern the processing itself.

  • Permitted — with mandatory safeguards

    The decision may proceed, but Article 22(3) safeguards are owed: a route to human intervention, the ability to express a point of view, and a genuine contest channel. Under Articles 13–15 the person is also owed meaningful information about the logic involved, and a DPIA is almost certainly triggered. Exception ≠ exemption.

  • Prohibited as designed

    A solely automated, significantly affecting decision with no applicable exception cannot lawfully run. Redesign options: introduce genuinely meaningful human review, establish a valid exception basis, or reduce the decision’s effect. This is the analysis the toeslagenaffaire’s architects never performed.

Article 22 and the AI Act now operate as a lattice, and mature programs run them as one workflow rather than two. The mappings that matter: the AI Act’s fundamental rights impact assessment and the GDPR DPIA cover overlapping ground (Art 27(4) expressly lets deployers fold one into the other); AI Act transparency duties parallel GDPR notice duties; Art 12 logs feed the accountability evidence GDPR already demanded; and GDPR Articles 13–15 add something the AI Act mostly does not — an individual right to meaningful information about the logic involved in automated decisions, which trade-secret claims can shape but not extinguish. When a rejected applicant asks "why?", the answer comes from this lattice: reason codes and logic explanations under GDPR, instructions-for-use and oversight records under the AI Act.

Key terms: automated decision-making, profiling, solely automated, meaningful information, data protection impact assessment, contestability

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.