This article is for anyone who uses a system that makes, or helps make, decisions about people — candidates, customers, employees — and wants to know when the GDPR asks for more than a legal basis and a privacy notice. That requirement sits in Article 22, and it waits for no AI Act date: it is part of the GDPR, which applies to any processing of personal data.
The article is short and every word counts. It has a right with two conditions, three exceptions and a set of minimum safeguards. It is worth reading in that order, because most mistakes come from skipping one of the two conditions.
The right, and its two conditions
"The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her."
First condition: "based solely" on automated processing. A system being involved is not enough. The right concerns the decision the system takes on its own. If a person reviews the outcome with a real ability to change it, the decision no longer rests solely on automated processing. If that person merely confirms what the system proposes, with no information and no room to depart from it, the decision is still the system's, even with someone pressing a button.
Second condition: the effects. The decision has to produce legal effects for the person or similarly significantly affect them. Refusing credit, screening out an application, resolving a complaint or setting a condition that affects a specific person meet it. Reordering an inbox or prioritising tickets do not, however automated they are. It is the same threshold we explained when discussing what an agent should log.
And the clause in the middle: "including profiling". It makes clear that profiling is part of automated processing, not that every profile is a decision. A profile nobody uses to decide about the person does not trigger the right; one that decides on its own whether that person is offered something, refused it or screened out does, provided it also produces those effects.
The two conditions go together. An automated decision without significant effects falls outside Article 22. A decision with significant effects taken by a person does too. And automating a processing operation does not turn every step into a decision under this article: the AEPD says so expressly in its guidance on agentic AI.
The three exceptions
Paragraph 2 lists the cases in which paragraph 1 does not apply — that is, in which a decision based solely on automated processing with those effects is allowed. There are three, and the list is closed:
- (a) The contract. The decision "is necessary for entering into, or performance of, a contract between the data subject and a data controller". The word that carries weight is "necessary": an automated decision being convenient or efficient does not make it necessary for the contract.
- (b) The law. The decision "is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests". The authorisation comes with its own safeguards, set by that same law.
- (c) Explicit consent. The decision "is based on the data subject's explicit consent". Explicit, not the generic consent given when accepting terms and conditions.
Outside these three cases, the person has the right not to be subject to that decision.
The safeguards in paragraph 3
Where the decision relies on the contract or on explicit consent, the controller shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, "at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision".
Three things, and none of them is decorative. Human intervention has to be able to change the outcome, or it is not intervention. Expressing a point of view needs a channel through which the person can do so. And contesting needs someone who can review the decision, with that review having consequences. A review button that leads to nobody with the authority to reverse the decision meets none of the three.
What has to be said before deciding
Article 22 does not work on its own. Articles 13 and 14 require the data subject to be informed, when their data are obtained, of "the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject".
In other words: the person has to know that the automated decision exists, with what logic and with what consequences. Without that, the paragraph 3 safeguards are hard to exercise, because nobody contests what they do not know happened.
The bridge to the AI Act, without mixing up dates
The AI Act has an obligation that looks similar and is not the same. Its Article 26(2) says: "Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support." It is a duty of whoever deploys a high-risk system, and Article 26 applies from 2 December 2027 for high-risk systems under Annex III and from 2 August 2028 for those under Annex I; it does not reach products under Annex I, Section B.
The difference matters. Article 22 is a right of the person affected; it applies already and reaches any decision based solely on automated processing with significant effects, whether or not the system is high-risk. Article 26(2) is an organisational obligation for high-risk systems, with its own date. A CV filter or a creditworthiness model for individuals may be subject to both, and meeting one does not demonstrate the other. Who has the authority to intervene in what an agent does is covered in Article 26(2).
What is worth having written down
For each system that makes or helps make decisions about people, four answers:
- What it decides, and about whom. Whether any of its decisions produce legal or significant effects, and whether the system takes any of them on its own.
- Which exception it relies on, if it decides on its own: the contract, the law or explicit consent. Without an exception, it cannot take that decision.
- What the human intervention looks like: who reviews, with what information and with what authority to change the outcome.
- How people are informed: where the existence of the decision, its logic and its consequences are explained.
Article 22 is one of the five GDPR articles that bind your AI without waiting for the AI Act. If the system is also high-risk, like the recruitment systems we describe in the recruitment sector, the two layers add up.
Content in accordance with Articles 13, 14 and 22 of Regulation (EU) 2016/679, cited from the text published in OJ L 119 of 4.5.2016 and verified against the consolidated version, and Article 26 of Regulation (EU) 2024/1689.
This article is for informational purposes only and does not constitute legal advice.