GDPR Article 22: the automated-decision backstop
Lesson 1 of 5 in Legal Intersections, Liability, and the Failure Files.
Before there was an AI Act, there was one sentence of EU data-protection law doing most of the work — and for systems processing personal data, it still applies in parallel with everything else you have learned. GDPR Article 22 is the oldest operative constraint on algorithmic decision-making in wide effect, and its anatomy repays close reading because every element has been litigated.
Three load-bearing phrases, three bodies of interpretation:
"Solely automated." The classic evasion was to route the algorithm’s output past a human before it took effect — a "human in the loop" whose loop was a rubber stamp. Regulators closed that door early: involvement must be meaningful, by someone with the authority and competence to change the decision, considering all relevant data — not a token gesture. You will recognize this as the same competence-authority-time-information test from the oversight module, now with legal teeth.
"Legal or similarly significant effects." Legal effects are the easy cases — contract cancellation, benefit denial, visa refusal. "Similarly significant" reaches decisions with serious impact on circumstances, behavior, or choices: credit refusal, e-recruiting without human review, and in some circumstances differential pricing. Showing someone an ad is generally out; deciding their livelihood is in.
The three exceptions. Solely automated significant decisions are permitted only where (a) necessary for a contract (necessity is read narrowly — "cheaper for us" does not qualify), (b) authorized by EU or member-state law with safeguards, or (c) based on explicit consent. And even inside an exception, Article 22(3) mandates safeguards: at minimum the right to obtain human intervention, to express one’s point of view, and to contest the decision. Special-category data raises the bar further.
Then, in December 2023, the CJEU detonated the market’s favorite workaround.
Does Article 22 bite? Walk the logic
Interactive decision tree — outcomes:
- Outside Article 22
No personal-data-based individual decisions, no Article 22. Other regimes (the AI Act, sector rules) may still apply — Article 22 is one layer, never the whole analysis.
- Not "solely automated" — but prove it
Article 22 does not apply where human involvement is meaningful. The burden of showing that is yours: document reviewer authority, information access, and real disagreement rates. A 99.8% approval rate at four seconds per case is evidence against you — and post-SCHUFA, a determining score cannot hide behind the human at all.
- Below the significance threshold
No legal or similarly significant effect, no Article 22(1) prohibition — though GDPR transparency and fairness duties still govern the processing itself.
- Permitted — with mandatory safeguards
The decision may proceed, but Article 22(3) safeguards are owed: a route to human intervention, the ability to express a point of view, and a genuine contest channel. Under Articles 13–15 the person is also owed meaningful information about the logic involved, and a DPIA is almost certainly triggered. Exception ≠ exemption.
- Prohibited as designed
A solely automated, significantly affecting decision with no applicable exception cannot lawfully run. Redesign options: introduce genuinely meaningful human review, establish a valid exception basis, or reduce the decision’s effect. This is the analysis the toeslagenaffaire’s architects never performed.
Article 22 and the AI Act now operate as a lattice, and mature programs run them as one workflow rather than two. The mappings that matter: the AI Act’s fundamental rights impact assessment and the GDPR DPIA cover overlapping ground (Art 27(4) expressly lets deployers fold one into the other); AI Act transparency duties parallel GDPR notice duties; Art 12 logs feed the accountability evidence GDPR already demanded; and GDPR Articles 13–15 add something the AI Act mostly does not — an individual right to meaningful information about the logic involved in automated decisions, which trade-secret claims can shape but not extinguish. When a rejected applicant asks "why?", the answer comes from this lattice: reason codes and logic explanations under GDPR, instructions-for-use and oversight records under the AI Act.
Key terms: automated decision-making, profiling, solely automated, meaningful information, data protection impact assessment, contestability
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.