LinkedInInstagramXTikTok

Automated decisions about people: where GDPR Article 22 meets the EU AI Act

Why this is the live risk, not a future one

When the Digital Omnibus on AI deferred the EU AI Act’s high-risk obligations to December 2027 and August 2028, a great many AI governance projects slowed down. That was a reasonable response to the AI Act. It was a poor response to the law that already governs the same systems.

Article 22 of the GDPR has applied since 25 May 2018. It regulates automated decisions about individuals, it was untouched by the Digital Omnibus, and it is being enforced now – by supervisory authorities and, increasingly, by the Court of Justice. If your business uses AI to score, rank, price or screen people, your immediate exposure is under the GDPR, not the AI Act. The AI Act adds a further layer later. It does not replace what is already there.

What Article 22 requires

Article 22(1) gives individuals the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. The Court of Justice has confirmed that this operates as a general prohibition rather than merely a right to object – a distinction that changes where the burden sits.

Three exceptions in Article 22(2) permit such decisions: where the decision is necessary for entering into or performing a contract between the data subject and the controller; where it is authorised by Union or Member State law that also lays down suitable safeguards; or where it is based on the individual’s explicit consent.

Where you rely on contract necessity or explicit consent, Article 22(3) requires suitable measures to safeguard rights and freedoms, including at least the right to obtain human intervention on the part of the controller, to express a point of view, and to contest the decision. Where you rely on Union or Member State law, the safeguards must come from that law itself.

Article 22(4) adds a hard constraint that catches insurance and health applications in particular: decisions falling under the exceptions must not be based on special categories of personal data under Article 9(1) unless explicit consent under Article 9(2)(a) or substantial public interest under Article 9(2)(g) applies, with suitable safeguards in place. The other Article 9 grounds are not available.

What the Court of Justice has decided

Scoring is itself a decision

In SCHUFA Holding (Case C-634/21, judgment of 7 December 2023), the Court held that the automated establishment of a probability value concerning a person’s ability to meet future payment commitments – a credit score – is itself a “decision” within Article 22(1), where a third party such as a bank draws strongly on that value in deciding whether to establish, perform or terminate a contractual relationship.

The argument that scoring is merely a preparatory step was rejected. The Court reasoned that treating it otherwise would create a gap in protection, because the transparency and access rights would be exercisable only against the lender, which does not hold the scoring logic.

The consequence for businesses is significant. If you produce scores, risk ratings or rankings that others act on, you may be making Article 22 decisions even though you never communicate with the individual and never make the final call.

Explanation must be intelligible, and trade secrets are not a shield

In CK v Dun & Bradstreet Austria (Case C-203/22, judgment of 27 February 2025), the Court addressed what “meaningful information about the logic involved” actually requires under Article 15(1)(h).

The controller must explain the procedure and principles actually applied to use the individual’s personal data by automated means to reach the specific result, in a concise, transparent, intelligible and easily accessible form. Communicating a complex mathematical formula or the algorithm itself is not sufficient. Nor is a detailed description of every step of the process. What is required is information enabling the person to understand which of their personal data were used and how – and, in the Court’s most practical direction, the extent to which a variation in the personal data taken into account would have led to a different result.

That is a counterfactual explanation. These factors drove the outcome, and here is how much your circumstances would have needed to differ to change it.

On trade secrets, the Court held that where a controller considers the information contains third-party personal data or trade secrets, it must supply the allegedly protected information to the competent supervisory authority or court, which then balances the competing rights. A national rule that excludes the right of access as a matter of course where a trade secret would be compromised is precluded by EU law.

Where the AI Act adds to this

Article 86 and the solely automated gap

Article 86 of the AI Act gives an affected person subject to a decision taken by a deployer on the basis of output from an Annex III high-risk AI system – with the exception of critical infrastructure systems – which produces legal effects or similarly significantly affects them in a way they consider adverse to their health, safety or fundamental rights, the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken.

The important structural point is that Article 86 is not limited to decisions based solely on automated processing. GDPR Article 22 requires “solely”; Article 86 does not. That closes the most exploited gap in the current regime, where inserting a nominal human reviewer takes a decision outside Article 22 entirely.

Article 86(3) provides that the article applies only to the extent the right is not otherwise provided for under Union law – so where GDPR Articles 15(1)(h) and 22(3) already deliver it, Article 86 does not duplicate. Its practical significance lies where Article 22 does not reach.

Telling people they are subject to AI

Article 26(11) requires deployers of Annex III high-risk systems that make decisions, or assist in making decisions, about natural persons to inform those persons that they are subject to the use of the high-risk AI system. Again, note the broader wording – “assist in making” reaches human-in-the-loop processes that Article 22 does not.

Where the two regimes collide

The overlap is concentrated in a few Annex III categories. Point 4 covers employment and worker management, including recruitment, filtering applications, evaluating candidates, and decisions on promotion, termination and task allocation. Point 5(b) covers creditworthiness assessment and credit scoring of natural persons, excluding systems used to detect financial fraud. Point 5(c) covers risk assessment and pricing for life and health insurance. Point 5(a) covers public authorities evaluating eligibility for essential public assistance benefits and services.

Points 5(b) and 5(c) are also the only private sector deployers required to carry out a fundamental rights impact assessment under Article 27.

Impact assessments: one document, not two

Article 27 requires a fundamental rights impact assessment from deployers that are bodies governed by public law or private entities providing public services, and from deployers of credit scoring and life and health insurance pricing systems. It covers the processes in which the system will be used, the period and frequency of use, the categories of people likely to be affected, the specific risks of harm, the human oversight measures, and the steps to take if risks materialise.

The Digital Omnibus strengthened the relationship with the GDPR: a fundamental rights impact assessment may now include or cross-refer to the relevant sections of a data protection impact assessment carried out under Article 35 GDPR, and the Commission template is to support that route. The practical effect is one integrated assessment rather than two overlapping documents.

The converse does not hold. A fundamental rights impact assessment does not discharge the DPIA obligation, which is independent and mandatory for systematic automated evaluation producing legal or similarly significant effects.

What meaningful human involvement actually means

Because Article 22 bites only on decisions taken solely by automated means, the single most common compliance strategy is to insert a human. Regulators anticipated this. The Article 29 Working Party guidance endorsed by the EDPB states that a controller cannot avoid Article 22 by fabricating human involvement, and that the reviewer must have the authority and competence to change the decision and must actually consider all the relevant data rather than routinely applying an automatically generated profile.

The Spanish data protection authority set out the most concrete working test in 2024, built on four criteria: competence, meaning authority to alter the outcome rather than merely execute it; training sufficient to understand the system’s strengths, limitations and operating context; independence and diligence, including freedom from automation bias and organisational pressure; and practical means, including access to the underlying information, analytical resources, and enough time per decision to make review real.

The evidential problem is straightforward. The burden of showing a decision is not solely automated sits with the controller, and a review process with a near-zero override rate is difficult to defend. Log the reviewer, what they saw, how long they took and how often they departed from the recommendation.

Practical example

A Nordic insurer uses an AI model to price life insurance. A human underwriter signs off each quote, and the business considers Article 22 inapplicable.

Three problems follow. If the underwriter routinely accepts the model output without the competence, information or time to depart from it, the decision is in substance solely automated and Article 22 applies – with health data engaging the Article 22(4) restriction, meaning explicit consent or substantial public interest is required. Under Dun & Bradstreet, an applicant asking why they were priced as they were is entitled to an intelligible explanation of the factors and how different data would have changed the outcome; the model’s complexity is not an answer, and a trade secret claim goes to a supervisory authority or court to balance, not to the customer as a refusal.

Then from December 2027, life and health insurance pricing sits in Annex III point 5(c), bringing a fundamental rights impact assessment under Article 27, the Article 26(11) duty to tell applicants they are subject to an AI system, and the Article 86 explanation right, which applies whether or not the underwriter’s involvement is meaningful.

Common mistakes companies make

The first is treating the AI Act deferral as a general pause. GDPR Article 22 applies today and is being enforced today.

The second is relying on nominal human review. A reviewer without authority, information or time does not take a decision outside Article 22.

The third is assuming that producing a score rather than a decision keeps you out of scope. SCHUFA decided otherwise where a third party draws strongly on the score.

The fourth is answering explanation requests with technical documentation. A formula or an algorithm description is expressly insufficient; an intelligible account of factors and counterfactuals is what is required.

The fifth is treating trade secrets as an absolute answer. They are an input to a balancing exercise conducted by an authority or court, not a blanket exemption.

Recommended actions

Inventory every automated decision affecting individuals and test each against Article 22: is there a decision, is it based solely on automated processing, does it produce legal or similarly significant effects? Include scores and rankings that others act on.

Audit your human review layer against the competence, training, independence and practical means criteria, and instrument it so you can evidence override rates and review time. Build counterfactual explanation capability into systems now rather than retrofitting it after a subject access request; Dun & Bradstreet sets the standard and the design implications are real.

Confirm your Article 22(2) legal basis and, where special category data is involved, check that Article 22(4) is satisfied. Update Article 13 and 14 privacy notices, which carry the same “meaningful information about the logic involved” wording as the access right. And where you deploy systems that will fall within Annex III, plan a single integrated impact assessment that satisfies both the DPIA and the fundamental rights impact assessment.

Frequently asked questions

Does the AI Act deferral delay our Article 22 obligations?

No. Article 22 GDPR has applied since 2018 and was not amended by the Digital Omnibus on AI. The deferral relates only to AI Act obligations for high-risk systems. Supervisory authorities have imposed multi-million euro fines on platform operators for automated decision-making failures, and those enforcement powers are unaffected.

How much detail must we give when someone asks why an AI decided about them?

Enough for them to understand which of their personal data were used and how, and how far their data would have had to differ for the outcome to change. The Court has confirmed that handing over a formula or algorithm is not sufficient, and that a step-by-step description of the whole process is not required either. Intelligibility to the individual is the standard.

Is a human reviewer enough to take us outside Article 22?

Only if the involvement is meaningful. The reviewer must have authority to change the outcome, the competence and information to evaluate it, freedom from pressure and automation bias, and realistic time to do so. Rubber-stamping does not work, and the burden of proof sits with you. Note also that AI Act Articles 26(11) and 86 apply to systems that merely assist in making decisions, so the “solely” threshold does not help there.

Conclusion

Automated decisions about people are governed by two regimes on different timetables. GDPR Article 22 applies now, has been sharpened by the Court of Justice in SCHUFA and Dun & Bradstreet, and demands a real legal basis, genuine human involvement and an explanation an ordinary person can understand. The AI Act’s provisions add transparency and explanation rights that reach beyond solely automated decisions, arriving with the Annex III regime. Businesses that build for the GDPR standard now will find the AI Act layer an extension rather than a rebuild. Lawgent helps businesses assess their automated decision-making against Article 22, design human oversight that stands up to scrutiny, and prepare integrated impact assessments that satisfy both the GDPR and the EU AI Act.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop