GDPR Article 22: automated individual decision-making, including profiling
GDPR Article 22(1) gives a data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her. Article 22(2) allows it only for contract necessity, Union or Member State law, or explicit consent.
Applies to: Controllers that make decisions about people in the EU based solely on automated processing, including profiling, where the decision has legal or similarly significant effects.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanAutomated decision-making is where profiling stops being analysis and starts changing outcomes for a person. Article 22 of the EU GDPR is the rule that governs it. It gives people a default protection against being judged by an algorithm alone when the stakes are high, then sets out the narrow cases where you may do it and what you must build around it. If you run credit scoring, automated hiring filters, or fraud models that act without a human, this is your article.
What does Article 22 actually say?
Under Article 22(1), the data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. Two conditions have to be true for the core rule to apply. The decision must be solely automated, meaning there is no meaningful human involvement, and it must have a legal or similarly significant effect, such as refusing a loan, ending a service, or rejecting a job application. If a person genuinely reviews the outcome and can change it, or the effect is trivial, you are outside Article 22's specific regime, though every other GDPR duty still applies.
When are automated decisions allowed?
Article 22(2) sets three grounds, and you need one of them to make a qualifying automated decision. The decision can be necessary for entering into or performing a contract between the person and the controller. It can be authorised by Union or Member State law that also lays down suitable safeguards. Or it can be based on the person's explicit consent. These are narrow. Explicit consent is a higher bar than ordinary consent, and contract necessity means the automated decision is genuinely required, not merely convenient. Choosing a ground is the first thing a regulator will ask you to show.
What safeguards must you put in place?
Where you rely on contract necessity or explicit consent, Article 22(3) requires suitable measures to safeguard the person's rights and freedoms, and it names a floor: at least the right to obtain human intervention on the part of the controller, to express their point of view, and to contest the decision. Build those as real routes, not a form nobody answers. Article 22(4) adds a hard limit: a solely automated decision cannot be based on special category data under Article 9(1) unless Article 9(2)(a) or (g) applies and suitable safeguards are in place. Profiling that leans on health, biometrics, or similar data faces this extra gate.
Profiling and automated decision transparency
Article 22 sets the substantive rule, but the transparency duty sits in the information articles. Article 13(2)(f) requires a controller collecting personal data from the person to tell them about "the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject".
Three things follow for a privacy notice. First, disclosure is owed at the point of collection, not on request. Second, "meaningful information about the logic involved" is not the source code and not the marketing description; regulators read it as an explanation a person could actually use to understand why they got the outcome they got. Third, the duty is anchored to Article 22(1) and (4), so it bites on the same qualifying decisions the substantive rule covers. If you run automated scoring that clears Article 22, write the logic explanation into the notice at the same time as you build the human-review route.
What is the official text of Article 22?
The consolidated text on EUR-Lex reads:
Article 22(1): "The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her."
Article 22(2): "Paragraph 1 shall not apply if the decision: (a) is necessary for entering into, or performance of, a contract between the data subject and a data controller; (b) is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or (c) is based on the data subject's explicit consent."
Article 22(3): "In the cases referred to in points (a) and (c) of paragraph 2, the data controller shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision."
Article 22(4): a decision referred to in paragraph 2 "shall not be based on special categories of personal data referred to in Article 9(1), unless point (a) or (g) of Article 9(2) applies and suitable measures to safeguard the data subject's rights and freedoms and legitimate interests are in place."
Two points repay close reading. The Article 22(3) safeguards are owed only in the contract and explicit-consent cases, points (a) and (c), and not where the decision is authorised by Union or Member State law under point (b), because that law is itself required to lay down suitable measures. And the three items named in 22(3) are a floor, introduced by "at least", so a controller relying on contract or consent may owe more than human intervention, a point of view and a route to contest.
How it fits your other GDPR duties
Article 22 sits next to the other individual rights. A person can object to processing under Article 21, including profiling, and where you profile on the basis of legitimate interests the two rights interact. You also owe transparency about the logic involved when you carry out this kind of processing, which links back to your privacy information duties. Treat automated decisions as a mapped, documented category rather than something buried inside a model.
Next step
If you use profiling or automated scoring and are not sure whether Article 22 applies or which safeguards you owe, the free 2-minute Obligation Scan flags where the GDPR reaches you and which data-subject rights you need a process for. The GDPR compliance hub sets the duties in order.
Compliance checklist
- Map any decision you make about EU individuals that runs solely on automated processing or profiling.
- Check whether the decision has a legal or similarly significant effect, which is what brings Article 22 into play.
- Confirm your legal ground: contract necessity, authorisation by Union or Member State law, or the person's explicit consent, under Article 22(2).
- For contract or consent grounds, give people a way to obtain human intervention, express their view, and contest the decision, under Article 22(3).
- Do not base a solely automated decision on special category data unless Article 9(2)(a) or (g) applies with safeguards, under Article 22(4).
Sources
- Regulation (EU) 2016/679 (GDPR), Article 22 (automated individual decision-making, including profiling), official consolidated text on EUR-Lex
- Regulation (EU) 2016/679 (GDPR), Article 9 (special categories of personal data), official text on EUR-Lex
Last verified: 2026-09-15
Informational, not legal advice.