ETH-06 · Risk, Ethics & Accountability

GDPR Article 22: Your Right to Human Review

GDPR Article 22 gives you the right not to be subject to a decision based solely on automated processing — what it covers, and how it relates to the AI Act.

Accountability chain: data, model and automated decision are links that lead back to a named person who answers for the outcome (GDPR Article 22)dataINPUTSmodelSYSTEMdecisionOUTPUTanswers for itART. 22 · A NAMED PERSON ANSWERS FOR THE DECISION

What does GDPR Article 22 actually give you?

GDPR Article 22 gives you the right not to be subject to a decision based solely on automated processing — including profiling — where that decision produces legal effects concerning you or similarly significantly affects you. In plain terms: if a computer alone decides something important about your life, with no meaningful human in the chain, you have a right to object to that arrangement and to have a person involved. Where the decision is allowed to go ahead automatically, you are still owed three concrete safeguards: the right to obtain human intervention, the right to express your point of view, and the right to contest the decision.

The important word is solely. Article 22 is not a general right to a human review of every algorithmic output. It targets a specific, narrow situation: a fully automated decision, with real consequences, made without a person who could have changed the outcome. A loan refused by a scoring engine, a job application filtered out before any recruiter sees it, an insurance premium set by a model, a benefit denied by a rules system — these are the kinds of decisions the article was written for. A product recommendation or a spam filter, by contrast, rarely clears the “significantly affects you” bar.

So the right is real but conditional. To know whether you can invoke it — or, if you run an organisation, whether you have to honour it — you need to test three things: is the decision solely automated, does it have a significant effect, and does an exception apply that changes which safeguards are owed. The rest of this article walks through each test, and then sets Article 22 against the EU AI Act, which approaches the same problem from a different angle.

When does Article 22 apply?

Three conditions have to be met together. Miss one and Article 22 in its strict form does not bite — though, as we will see, other parts of the GDPR may still apply.

The decision must be based solely on automated processing. “Solely” means no meaningful human involvement in reaching the decision. A human who merely clicks “approve” on whatever the system outputs, without the authority, knowledge or time to reach a different conclusion, does not break the chain. European regulators have been clear that token human involvement does not convert a solely automated decision into a human one. The person has to be able to actually change the outcome for the processing to count as something other than “solely” automated. This is the same standard that animates meaningful human oversight more broadly: the test is influence, not presence.

The decision must produce legal effects or similarly significantly affect you. A legal effect changes your legal rights or status — a contract cancelled, a benefit withdrawn, entry to a country refused. “Similarly significantly affects” is the broader, harder-to-pin category: effects that are not strictly legal but weigh as heavily, such as being denied credit, being automatically rejected for a job, or being charged a materially different price. Trivial or fleeting effects do not qualify.

Profiling is included, but profiling alone is not the trigger. Article 22 explicitly covers decisions that involve profiling — analysing or predicting aspects of a person such as performance, economic situation, health, preferences, reliability or behaviour. Profiling is the engine behind most automated decisions of consequence. But Article 22 is about the decision, not the analysis: profiling that informs a human’s judgement is a different situation from profiling that drives an automatic outcome.

What counts as a “solely automated” decision?

This is where the law has been tested in court, and the answer is broader than many organisations assumed.

In its December 2023 ruling in the SCHUFA case (C-634/21), the Court of Justice of the European Union looked at credit scoring. A credit reference agency calculates a score; a bank then uses that score to decide whether to lend. The agency argued it was not making the decision — the bank was. The Court disagreed. It held that the automated generation of a score can itself be an automated decision under Article 22 where that score plays a determining role in the subsequent decision by a third party. If the bank essentially follows the score, then the score is the decision in all but name.

The practical lesson is that you cannot dodge Article 22 by splitting a decision across two organisations, where one builds the model and the other rubber-stamps the result. Regulators and courts look at substance: who, or what, actually determined the outcome. This matters for the long chains of vendors, scoring services and risk engines that sit behind modern lending, insurance and hiring.

What are the exceptions, and do they remove the safeguards?

Article 22 is not an absolute ban. Even a solely automated decision with a significant effect is permitted in three cases — but each comes with conditions, and none of them removes your protection entirely.

Exception (Art. 22(2)) What it permits What you are still owed
Contract — necessary for entering into or performing a contract between you and the controller Automated decisions that are genuinely necessary to a contract (e.g. high-volume online lending) Human intervention, express your view, contest the decision
Authorised by law — permitted by Union or Member State law that lays down safeguards Automated decisions a public body is empowered to make (e.g. tax, fraud detection) The safeguards set by that specific law
Explicit consent — you have explicitly agreed Automated decisions you knowingly opted into Human intervention, express your view, contest the decision

For the contract and consent routes, Article 22(3) requires the controller to implement suitable measures to safeguard your rights — and names a floor of at least three: the right to obtain human intervention on the part of the controller, the right to express your point of view, and the right to contest the decision. So even where the automated decision is lawful, the human-review rights survive. The exceptions change whether the decision can be made automatically, not whether you can challenge it afterwards.

There is a further limit. Article 22(4) restricts automated decisions that rely on special category data — health, ethnicity, religion, sexual orientation, biometrics and the like. Such decisions are only allowed where you have given explicit consent or there is a substantial public interest basis in law, and suitable safeguards are in place. The bar for letting a machine decide on the basis of sensitive data is deliberately high.

What must organisations put in place?

If you operate a solely automated decision with significant effects, the GDPR turns three abstract rights into operational obligations. Honouring Article 22 is not a policy paragraph; it is a set of working capabilities.

A real human-review route. Someone with the competence and authority to look at an individual case, reconsider it, and reach a different outcome — not a support agent who can only re-read the same automated verdict. This is the practical heart of human-in-the-loop AI: a person who can actually intervene, not just observe.

A way for the person to express their view and contest the decision. That means an accessible channel, a defined timeline, and a process that genuinely reconsiders rather than re-confirms. A contest mechanism that always returns the original answer is the legal equivalent of rubber-stamping.

Transparency before the fact. Articles 13 to 15 require you to tell people, up front and on request, that automated decision-making is taking place, and to provide meaningful information about the logic involved together with the significance and the envisaged consequences for them. People cannot exercise a right they do not know exists. You do not have to hand over your source code, but you do have to explain the logic in terms a person can understand and act on.

A documented lawful basis and a DPIA. You need to identify which Article 22(2) exception you rely on, and solely automated decisions with significant effects will typically require a Data Protection Impact Assessment because of the high risk to individuals.

Recital 71, which interprets Article 22, also describes a right to obtain an explanation of the decision reached. Its exact legal force is debated, but the direction is clear: people should be able to understand, question and challenge decisions made about them by machines.

How does Article 22 relate to the EU AI Act?

This is where people most often get confused, so it is worth being precise: GDPR Article 22 and the EU AI Act are different instruments solving overlapping problems.

Article 22 is a data-protection right. It is triggered by a fully automated decision with a significant effect on an individual, and it gives that individual specific rights after the fact — intervention, voice, contest. It applies regardless of how sophisticated the underlying technology is; a deterministic rules engine can trigger it just as a machine-learning model can.

The AI Act is product-safety-style regulation of AI systems. Its human-oversight duty, in Article 14, is a design and deployment requirement for systems classified as high-risk: the system must be built so that competent people can effectively oversee it while it is in use — whether or not any single decision is fully automated. The two complement each other. Article 22 gives the affected person a right; AI Act Article 14 obliges the provider and deployer to build oversight in so that right can be meaningful in practice. You can explore that design angle further in our AI Act human oversight hub.

On timing, keep two dates separate and resist the scare stories. The AI Act’s transparency obligations under Article 50 apply from 2 August 2026. The high-risk obligations, including the Article 14 oversight requirements, have been pushed toward December 2027 under the Commission’s Digital Omnibus simplification package, and the precise dates are still being finalised — so confirm them before relying on any single figure. GDPR Article 22, by contrast, is already in force and has been since 2018. If a fully automated decision significantly affects people today, the obligation is current, not future.

The honest summary: do not wait for the AI Act to think about human review. If your system makes consequential decisions about people on its own, Article 22 already requires you to let a person intervene, listen, and reconsider. For a wider map of where these duties sit, see our Risk, Ethics & Accountability hub.

Frequently asked

What does 'solely automated' mean under GDPR Article 22?

It means a decision reached with no meaningful human involvement — no person who has the authority, competence and time to reach a different outcome. A human who only clicks 'approve' on whatever the system outputs does not break the chain; regulators treat that as still solely automated. The test is whether a person could actually have changed the result, not whether a person was nominally present.

What is the difference between human intervention, expressing a view, and contesting the decision?

They are three distinct safeguards in Article 22(3). Human intervention means a competent person reconsiders your case and can change the outcome. Expressing your point of view means you can put your side before or after the decision. Contesting means you can formally challenge the decision and have it reviewed. Together they ensure a fully automated decision is never the final word.

Does GDPR Article 22 apply to profiling?

Profiling is expressly included, but profiling on its own is not the trigger. Article 22 applies to a decision that is both solely automated and significantly affecting, where profiling is involved. Profiling that merely informs a human's judgement, rather than driving an automatic outcome, falls outside the strict Article 22 right — though transparency duties under Articles 13 to 15 may still apply.

What did the SCHUFA ruling change about Article 22?

In case C-634/21 (December 2023), the Court of Justice of the EU held that automatically generating a credit score can itself be an automated decision under Article 22 where that score plays a determining role in a third party's decision, such as a bank's refusal to lend. It means organisations cannot avoid Article 22 by splitting model-building and decision-making across separate companies when the score effectively dictates the outcome.

Can a company make a fully automated decision about me legally?

Yes, in three cases under Article 22(2): when it is necessary for a contract with you, when it is authorised by Union or Member State law with safeguards, or when you have given explicit consent. But for the contract and consent routes the company must still give you the right to human intervention, to express your view, and to contest the decision. The exceptions permit the decision; they do not remove your right to challenge it.

Is GDPR Article 22 the same as the AI Act's human oversight requirement?

No. Article 22 is a data-protection right held by the affected individual, triggered by a fully automated decision with a significant effect. AI Act Article 14 is a design-and-deployment duty on providers and deployers of high-risk AI systems to build them so people can effectively oversee them in use, whether or not any single decision is fully automated. They overlap but address different things and sit on different timelines.

Is GDPR Article 22 in force now?

Yes. Article 22 has applied since the GDPR took effect in May 2018. If a fully automated decision significantly affects people, the obligation is current — unlike the AI Act's high-risk human-oversight duties under Article 14, which have been pushed toward December 2027 under the Digital Omnibus package, with dates still being finalised.

Do organisations have to explain how the automated decision was made?

Articles 13 to 15 require controllers to tell people that automated decision-making is taking place and to provide meaningful information about the logic involved, plus the significance and likely consequences. You do not have to disclose source code, but you must explain the logic in terms a person can understand and act on. Recital 71 also points toward a right to an explanation of the specific decision reached, though its precise legal force is debated.