Skip to content
EU GDPR · EU-GDPR-ART22-AUTOMATED-DECISIONS

EU GDPR Article 22 — Automated individual decision-making, including profiling

Solely automated decisions with legal or similarly significant effects are prohibited unless one of three grounds applies, and then only with safeguards including human intervention

CRITICALRequirementAutomated decisionsBinding regulationIn forceEnforceable from 25 May 2018

Where this comes from

Provision: Article 22 — Automated individual decision-making, including profiling

Instrument: EU General Data Protection Regulation (Regulation (EU) 2016/679)

Citation: Article 22, Regulation (EU) 2016/679

Text version: Regulation (EU) 2016/679 (GDPR), OJ L 119, 4.5.2016, p. 1 (CELEX 32016R0679)

Checked against the source: 2 September 2026

Read the official text ↗

Who it applies to

Personal data is processed and decided on by automated means alone (Art. 22(1)) — all of these:

  • Service processes personal data
  • Service makes solely automated decisions with legal or similarly significant effects

…unless:

  • Art. 2(2)(c): the Regulation does not apply to processing of personal data 'by a natural person in the course of a purely personal or household activity'. Recital 18 keeps controllers or processors providing the means for such processing in scope. (GDPR Art. 2(2)(c))
  • Art. 22(2)(a): paragraph 1 does not apply where the decision 'is necessary for entering into, or performance of, a contract between the data subject and a data controller'. Art. (GDPR Art. 22(2)(a))
  • Art. 22(2)(b): paragraph 1 does not apply where the decision 'is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate... (GDPR Art. 22(2)(b))
  • Art. 22(2)(c): paragraph 1 does not apply where the decision 'is based on the data subject's explicit consent'. Art. 22(3) safeguards are mandatory. (GDPR Art. 22(2)(c))

Scope in the source's own terms

  • Art. 3(1)/(2): the processing is carried out in the context of the activities of an establishment in the Union, or relates to offering goods or services to, or monitoring the behaviour of, data subjects in the Union
  • Art. 2(1) read with Art. 4(1): the activity is the processing of personal data — any information relating to an identified or identifiable natural person
  • Art. 4(7): the duty binds the 'controller' — the person which, alone or jointly with others, determines the purposes and means of the processing (a processor's parallel duties sit in Art. 28/30(2))
  • Art. 22(1): there is a decision 'based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her'. Both limbs are required: meaningful human involvement in the decision takes it outside Art. 22 altogether

What engineering work it implies

  • Human Oversight Gate (Review Queue with Stop and Override)Covers part of it

    A decision state machine that holds an automated decision as a proposal until a designated, competent reviewer releases, overrides or stops it — with an audit of who...

  • Right to Explanation Endpoint (Art. 86 / GDPR Art. 22)Covers part of it

    Request intake plus a templated explanation of the AI system's role and the main elements of the decision, assembled from the decision record rather than written by hand.

Sample acceptance criteria Landfall generates for this obligation:

  • Each decision flow is classified as solely automated or not, and the classification is recorded with its reasoning
  • Where it is solely automated, the Art. 22(2) ground relied on is named per flow — not asserted organisation-wide
  • Human intervention is available and MEANINGFUL: the person reviewing can actually change the outcome, and does so from the inputs
  • The data subject can express a point of view and contest the decision through a route that terminates in a human
  • Special-category data is excluded from the decision basis unless an Art. 9(2)(a) or (g) condition is recorded with its safeguards (Art. 22(4))

Evidence an auditor expects

  • Process recordDocument review

    Register of solely automated decisions with legal or similarly significant effect, and the Art. 22(2) ground relied on for each

    Per-decision-type record stating whether the decision is based SOLELY on automated processing, the effect it produces, and the Art. 22(2)(a) contract necessity, (b) authorising Union/Member State law, or (c) explicit consent relied on. Where meaningful human involvement is claimed to take the decision outside Art. 22, evidence of the authority and competence of the human reviewer to change the outcome

  • Technical controlTechnical audit

    Art. 22(3) safeguards implemented: human intervention, expression of a point of view, contest

    Evidence that the data subject can in fact obtain human intervention on the part of the controller, express a point of view, and contest the decision — the route, the service level, and the record that contested decisions are actually re-decided by a human with authority to change them

  • Consent recordDocument reviewRecommended

    Explicit consent records where Art. 22(2)(c) is relied on, and the Art. 22(4) special-category check

    Consent records meeting Art. 4(11) and Art. 7 (freely given, specific, informed, unambiguous, withdrawable, with proof of what was consented to and when); plus a record confirming the decision is not based on Art. 9(1) special-category data unless Art. 9(2)(a) or (g) applies with suitable safeguards (Art. 22(4))

Questions people ask

Does EU GDPR Article 22 — Automated individual decision-making, including profiling apply to my service?
It applies when Service processes personal data; Service makes solely automated decisions with legal or similarly significant effects. It does not apply where Art. 2(2)(c): the Regulation does not apply to processing of personal data 'by a natural person in the course of a purely personal or household activity'. Recital 18 keeps controllers or processors providing the means for such processing in scope. (GDPR Art. 2(2)(c)).
When does this become enforceable?
EU GDPR Article 22 — Automated individual decision-making, including profiling is enforceable from 25 May 2018. Its current status is: in force.
What evidence does an auditor expect?
Register of solely automated decisions with legal or similarly significant effect, and the Art. 22(2) ground relied on for each; Art. 22(3) safeguards implemented: human intervention, expression of a point of view, contest; Explicit consent records where Art. 22(2)(c) is relied on, and the Art. 22(4) special-category check.

Find out whether this one lands on you

Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.

Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.

What Landfall Is NOT

Critical Boundaries

Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.

NOT Legal Advice

This product does not provide legal advice and does not create an attorney-client relationship.

Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.

NOT a Risk Score

We do not quantify, calculate, or certify your compliance risk level.

No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.

NOT Runtime Enforcement

This is a planning and mapping tool, not a runtime enforcement system.

Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.

NOT Regulatory Approval

Using this tool does not mean you are compliant with any regulation.

No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.

NOT Authoritative Interpretation

Our interpretations are not binding and may differ from regulatory guidance.

Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.

NOT a Safe Harbor

This tool does not shield you from enforcement actions or liability.

Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.

NOT an AI Compliance Agent

AI features assist analysis but do not make compliance decisions for you.

AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.

NOT Complete Coverage

We do not cover all regulations, all obligations, or all jurisdictions.

Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.

What This Tool IS:

  • A structured workflow for mapping regulatory requirements to implementation tasks
  • A documentation system for compliance decisions (audit trail)
  • A collaboration platform for compliance, legal, and engineering teams
  • An informational resource for understanding regulatory obligations