Article 22 is the GDPR’s answer to government-by-algorithm: individuals have the right not to be subject to decisions with legal or similarly significant effects that are based solely on automated processing. For years the practical questions were what “solely” means and who exactly takes the “decision.” The CJEU’s SCHUFA judgment answered the second question expansively, and the EU AI Act now regulates many of the same systems from the product side.
| Regulation | GDPR Article 22 |
|---|---|
| Max penalty | EUR 20M or 4% of global annual turnover |
| Key case | SCHUFA, CJEU C-634/21 (December 2023) |
| Enforcing authority | National supervisory authorities, coordinated by the EDPB |
| Official text | EUR-Lex CELEX 32016R0679 |
The rule and its three exits
A decision is caught when three elements meet: it is based solely on automated processing (including profiling), and it produces legal effects or similarly significantly affects the person. Loan denials, algorithmic hiring rejections, automated insurance pricing that excludes someone, and benefit cutoffs are the canonical examples; ad targeting normally is not, unless it gates access to something significant.
The exceptions in Article 22(2) are contract necessity, legal authorization, and explicit consent. All demand safeguards, and for contract and consent routes Article 22(3) names the floor: the right to obtain human intervention, to express one’s point of view, and to contest the decision. If the decision involves special category data, the gate narrows further to explicit consent or substantial public interest (Article 22(4)).
SCHUFA: the score is the decision
Germany’s SCHUFA credit bureau argued it merely calculates scores; banks make the decisions. The CJEU disagreed in C-634/21: where a third party draws strongly on an automated score to establish, implement, or end a contract, the scoring itself constitutes the Article 22 decision. The consequence reaches every vendor whose output effectively determines outcomes downstream: fraud scores, tenant screening, hiring assessments. Contractual disclaimers that “the customer decides” no longer relocate the obligation if the customer in practice follows the score.
A companion line of cases addresses explanation. In C-203/22 (2025), the CJEU held that the “meaningful information about the logic involved” owed under GDPR must let the person understand how their data produced the decision, in intelligible form, and that trade secrets cannot reduce the explanation to nothing; the balance is struck through supervisory authorities and courts, not by blanket refusal.
Compliance design, plus the AI Act layer
For each consequential automated process, decide honestly which side of the line it sits on. If humans are involved, make the involvement real: authority to overrule, access to the underlying evidence, and measured override behavior. If the process is solely automated, pick the lawful exception, build the intervention-and-contest workflow, and write the explanation capability into the system rather than improvising per request.
Many of the same systems (credit, employment, essential services) are Annex III high-risk under the EU AI Act, which adds provider and deployer duties from August 2026; see the AI Act and GDPR overview and the combined impact assessment guide. The DPIA duty applies almost automatically to this processing; the DPIA methodology guide covers it.