Skip to content

GDPR Article 22

Article 22 gives a person the right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal effects or similarly significantly affects them. It is the provision that separates a system which informs a human decision from one which makes the decision itself.

The word that carries the article is solely: a decision with a real human in it falls outside the prohibition.

Why it matters when the plan changes

Any system that scores people and feeds a consequential decision about them has to be designed with this article in view. The line it draws is not about whether a model was involved but about whether a person with authority and understanding actually made the decision. A signature on an output the signatory could not inspect does not count as one, and the difference between a recommendation and a decision only holds if the person retains the power to depart from what the system suggests.

The tension is that the exceptions are narrow and frequently misread. Explicit consent is one of them, and consent in an employment relationship is treated as unlikely to be freely given. Contractual necessity is another, and it is hard to argue for a promotion decision. In practice the defensible route is meaningful human involvement rather than an exception, with the reasoning visible enough for that person to engage with it, not merely sign it.

In practice

A hiring process adds an automated screen that rejects applicants below a threshold before any person sees the file. A candidate asks how the decision was made and whether a person was involved. Nobody was, and no exception applies. The process is redesigned so that a recruiter reviews every rejection with the reasoning visible, which is what the article had required from the start.

Evidence

What it cannot tell you

Article 22 addresses the automation of a decision, not the quality or fairness of the model behind it. A process can involve a human at every step and still produce a biased or poorly reasoned outcome; the article is silent on that. It also does not define how substantive human involvement must be, which leaves 'solely' open to interpretation in practice.

Questions

That no person with authority and understanding actually made the decision. Recital 71 of the General Data Protection Regulation (2016) frames this as a right not to be subject to a decision based solely on automated processing. A signature on an unreviewed output does not satisfy that standard.

No. It restricts decisions with legal or similarly significant effects that rest solely on automated processing. A score that informs a human decision, where the human can see the reasoning and depart from it, sits outside the prohibition. The design of that human step is what matters.

Explicit consent, necessity for a contract, and authorisation by law, each with safeguards attached. Article 14 of the European Union Artificial Intelligence Act (2024) reinforces this by requiring human oversight of high-risk systems, which narrows how far any exception can substitute for a genuine human decision.

At minimum the right to obtain human intervention, to express a point of view and to contest the decision. In practice that means the reasoning has to be recorded and available, because a person cannot contest a decision whose basis nobody can show them.

Both are decisions with significant effects on a person, so any automated element in them has to be examined against the article. The usual answer is not to remove models from the process but to make sure a person genuinely decides, with the model's reasoning visible and the ability to disagree.