EU Privacy Law EU/EEA

Automated Decision-Making: GDPR Article 22 Rules and the SCHUFA Judgment

When solely automated decisions are prohibited under GDPR Article 22, what the CJEU's SCHUFA ruling changed, and how the EU AI Act layers on top.

Regulation

GDPR Article 22; AI Act (2024/1689)

Max Penalty

EUR 20 million or 4% of global annual turnover (GDPR)

Enforcing Authority

National data protection authorities; EU AI Office for AI Act duties

Official Source

eur-lex.europa.eu

Executive Summary

  • Article 22 gives individuals the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects.
  • Three exceptions permit such decisions: necessity for a contract, authorization by EU or member state law, or explicit consent, each requiring safeguards including human intervention.
  • The CJEU's SCHUFA judgment (C-634/21, December 2023) held that credit scoring itself can be an Article 22 decision when third parties rely on it decisively, closing the 'we only advise' loophole.
  • Meaningful human involvement must be real: a reviewer who rubber-stamps the machine output does not take the decision outside Article 22.
  • The same systems frequently qualify as high-risk under the EU AI Act, adding documentation, oversight, and data governance duties from August 2026.

Article 22 is the GDPR’s answer to government-by-algorithm: individuals have the right not to be subject to decisions with legal or similarly significant effects that are based solely on automated processing. For years the practical questions were what “solely” means and who exactly takes the “decision.” The CJEU’s SCHUFA judgment answered the second question expansively, and the EU AI Act now regulates many of the same systems from the product side.

RegulationGDPR Article 22
Max penaltyEUR 20M or 4% of global annual turnover
Key caseSCHUFA, CJEU C-634/21 (December 2023)
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

The rule and its three exits

A decision is caught when three elements meet: it is based solely on automated processing (including profiling), and it produces legal effects or similarly significantly affects the person. Loan denials, algorithmic hiring rejections, automated insurance pricing that excludes someone, and benefit cutoffs are the canonical examples; ad targeting normally is not, unless it gates access to something significant.

The exceptions in Article 22(2) are contract necessity, legal authorization, and explicit consent. All demand safeguards, and for contract and consent routes Article 22(3) names the floor: the right to obtain human intervention, to express one’s point of view, and to contest the decision. If the decision involves special category data, the gate narrows further to explicit consent or substantial public interest (Article 22(4)).

SCHUFA: the score is the decision

Germany’s SCHUFA credit bureau argued it merely calculates scores; banks make the decisions. The CJEU disagreed in C-634/21: where a third party draws strongly on an automated score to establish, implement, or end a contract, the scoring itself constitutes the Article 22 decision. The consequence reaches every vendor whose output effectively determines outcomes downstream: fraud scores, tenant screening, hiring assessments. Contractual disclaimers that “the customer decides” no longer relocate the obligation if the customer in practice follows the score.

A companion line of cases addresses explanation. In C-203/22 (2025), the CJEU held that the “meaningful information about the logic involved” owed under GDPR must let the person understand how their data produced the decision, in intelligible form, and that trade secrets cannot reduce the explanation to nothing; the balance is struck through supervisory authorities and courts, not by blanket refusal.

Compliance design, plus the AI Act layer

For each consequential automated process, decide honestly which side of the line it sits on. If humans are involved, make the involvement real: authority to overrule, access to the underlying evidence, and measured override behavior. If the process is solely automated, pick the lawful exception, build the intervention-and-contest workflow, and write the explanation capability into the system rather than improvising per request.

Many of the same systems (credit, employment, essential services) are Annex III high-risk under the EU AI Act, which adds provider and deployer duties from August 2026; see the AI Act and GDPR overview and the combined impact assessment guide. The DPIA duty applies almost automatically to this processing; the DPIA methodology guide covers it.

Frequently Asked Questions

What decisions does Article 22 cover?

Decisions based solely on automated processing that produce legal effects or similarly significantly affect a person: credit refusals, automated hiring rejections, benefit determinations, and comparable outcomes. Profiling that feeds such decisions is included.

When are solely automated decisions allowed?

Under three exceptions in Article 22(2): necessary for entering or performing a contract with the person, authorized by EU or member state law with safeguards, or based on explicit consent. The contract and consent routes require at minimum the right to obtain human intervention, express a view, and contest the decision.

What did the SCHUFA judgment decide?

In C-634/21 (December 2023), the CJEU held that a credit bureau's automated score is itself an Article 22 decision where lenders draw strongly on it to grant or refuse credit. Scoring providers cannot escape the article by pointing at the human downstream.

What counts as meaningful human involvement?

Someone with authority and competence to change the outcome, who actually weighs the case rather than confirming the machine. Regulators look at override rates and process design; a 99.9% agreement rate suggests the human is decorative.

Do individuals get an explanation of automated decisions?

Articles 13(2)(f), 14(2)(g), and 15(1)(h) require meaningful information about the logic involved and the significance and consequences for the person. The CJEU's C-203/22 judgment (2025) confirmed this means a genuinely intelligible explanation of how the decision was reached, not the algorithm's source code and not an empty formula.

Regulatory Crosswalk

EU AI ActCCPA/CPRA ADMT rulesColorado AI Act

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.