Data Protection HubIndividual Topics

Automated individual decision-making (Article 22 GDPR)

General prohibition, statutory criteria and exceptions of automated individual decision-making under Article 22 GDPR: solely automated processing, profiling and scoring, safeguards under Article 22(3), sensitive data and the relationship to the AI Act.

Article 22(1) GDPR prohibits, in principle, subjecting a person to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her. The individual is protected against becoming the mere object of a machine decision. The provision is closely connected with human dignity and with the right to the protection of personal data (Article 8 of the EU Charter of Fundamental Rights).

Key takeaways

  • Article 22(1) GDPR is an objective prohibition, not merely a right that has to be invoked. The data subject does not first have to assert it; he or she can waive it only by explicit consent.
  • Four statutory criteria: a decision that is taken solely by automated means, that produces legal effects or a significant adverse effect, and to which the person is subject.
  • What matters is not whether a human being may intervene, but whether he or she actually intervenes with genuine decision-making authority. A purely formal confirmation is not sufficient.
  • Three exceptions (Article 22(2) GDPR): contract (point (a)), legal provision (point (b)), explicit consent (point (c)). They are exhaustive.
  • Even where decisions are permitted, safeguards are mandatory (paragraph 3); for sensitive data, a narrow counter-exception applies (paragraph 4).
  • In addition, the AI Act applies independently to AI-supported systems (high-risk scoring, human oversight, right to explanation).

1. Overview and classification

Article 22(1) GDPR is intended to capture situations in which no relevant human decision-making step intervenes any longer. According to its wording and its systematic position in the chapter on the rights of the data subject, the provision is indeed formulated as an individual right. It is, however, to be understood as a comprehensive prohibition that operates irrespective of any individual assertion. Otherwise the protection would be ineffective, because providers could rely on data subjects not knowing the right or not enforcing it. This is also supported by Article 22(4) GDPR, which imposes a prohibition independent of any assertion even where automated decisions are exceptionally permitted.

Article 22 GDPR must be distinguished from the right to object under Article 21 GDPR: Article 21 GDPR permits an objection to profiling that merely prepares a decision; Article 22 GDPR prohibits the fully automated decision itself.

The underlying rationale draws on the object formula derived from human dignity (Article 1 of the Charter): the individual should not become the mere object of a machine evaluation. This does not, however, give rise to any automatic conclusion: not every automated decision infringes human dignity, since otherwise the exceptions in Article 22(2) GDPR would be inadmissible, because human dignity is not subject to any limitation. In practice, the protective thrust of the provision is therefore aimed above all at preventing incorrect or discriminatory outcomes of purely machine-based processing. The prohibition cannot be justified by transparency alone, because transparency is already ensured by the information and access rights in Articles 13 to 15 GDPR.

1.2 Relationship to Article 6 GDPR

Article 22(1) GDPR is not itself a ground for lawful processing. It applies as an additional requirement of lawfulness alongside the legal bases in Article 6 GDPR and does not dispense with their requirements. This results in a tiered assessment: the processing must first be permitted under Article 6 (or Article 9) GDPR; despite that permission, the prohibition in paragraph 1 applies to a fully automated individual decision; and only an exception under paragraph 2 renders it lawful again. An automated individual decision therefore requires both: a legal basis under Article 6 GDPR and an exception under Article 22(2) GDPR. The prohibition is addressed to whoever takes the decision.

1.3 Structure of the assessment

The following overview shows the structure of the assessment. The prohibition applies only once all four statutory criteria are met; the next question is whether an exception applies and whether the safeguards and the special rule for sensitive data have been observed.

2. The general prohibition (paragraph 1)

2.1 Decision

Not every automated operation is covered, but only a decision. Decisions are formative acts that make a choice between at least two alternatives and produce an effect in the outside world. Besides declarations of intent, other measures may also be covered that are directed solely at a factual outcome. The measure must relate to an individual case; abstract and general rules and mere recommendations are not sufficient.

The fact that a system takes only simple if-then decisions (such as a cash machine or a billing program) does not exclude a decision within the meaning of Article 22(1) GDPR. The prohibition is not linked to the degree of complexity, but solely to the fact that the decision is taken without any further human involvement.

According to its protective purpose, however, the decision presupposes a minimum degree of evaluation of personal aspects relating to the data subject. This limitation follows from Recital 71 GDPR and from the proximity to the concept of profiling in Article 4(4) GDPR. Pure identification processes without any evaluation, such as an access system that merely compares a fingerprint, do not meet this requirement.

2.2 Solely automated

The word "solely" requires that no relevant human decision-making step intervenes. The prohibition covers, first of all, all cases in which a system decides without any human influence whatsoever, for example on the granting of credit, university places or jobs, on social security or insurance benefits, or on automatically issued administrative fine notices.

2.2.1 No purely formal human decision

Difficulties arise with multi-stage procedures in which a system prepares a decision and a human being merely implements it. If the human activity is exhausted in a purely formal act of confirmation, the decision remains an automated one. What matters is not whether a human being may intervene, but whether he or she actually intervenes with genuine decision-making authority. The automated chain is broken only under two cumulative conditions: the case handler must have a margin of decision of his or her own, and must also exercise it.

The following do not constitute human involvement in this sense:

  • the mere decision not to intervene in the process,
  • purely random sample checks or the sorting out of obviously implausible cases,
  • manual preparation (such as the scanning of documents) without any decision-making competence of one's own,
  • involvement in the training phase of a learning system or the mere programming of the software.

If, by contrast, a natural person has the power to review the machine result on the merits and to modify it, and actually exercises that power, the decision is partially automated. It does not fall under the prohibition; the right to human intervention under paragraph 3 is then without object, because the review has already taken place. The procedural stage at which this review takes place is irrelevant.

2.2.2 Decision support and automation bias

Mere decision support does not fall under Article 22 GDPR. If a system only pre-sorts data (ranking of applicants, preparation of case law) or calculates a probability of recidivism as an indication for a human decision-maker, there is no automated decision, provided that the selection does not itself take the final decision. Pure assistance systems that only analyze, prepare or supply background information without submitting a specific proposal for a decision (for example a language model that supplies general information to a case handler) remain outside the scope of application.

Decision-support systems may in fact turn into automated decisions. If the responsible case handler regularly adopts the system's proposal without reviewing it, for example because of time pressure or a lack of expertise (so-called automation bias), the software effectively decides. A high adoption rate is an indication of this, but not conclusive proof. What is decisive is whether a substantive review actually takes place with sufficient time and competence. One suitable mechanism is to impose a burden of justification on the case handler where he or she follows the proposal.

2.3 Profiling and scoring as an area of application

Article 22(1) GDPR declares a decision based solely on profiling to be unlawful in principle, but not profiling as such. Profiling is only one conceivable, not a necessary, form of automated processing. Scoring is the most important sub-case in practice: a probability value concerning future behavior is calculated from existing data.

For a long time the position was as follows: the mere calculation of a score by a credit information agency merely prepares a decision; only the decision of the user (such as the bank) based on that score was covered. The CJEU has softened this distinction: the automated establishment of the score is itself an automated individual decision where a third party draws on that value to a determining degree in deciding on a contractual relationship (CJEU, judgment of 7 December 2023, C-634/21, SCHUFA Holding (Scoring)). The Court did not define "determining" more precisely; the judgment has therefore been criticized. For practice, one question above all counts: does a competent person actually review the machine result on the merits and can that person change it, or is it merely formally "waved through" (rubber-stamping)? In the first case the prohibition does not apply.

Specific consequences follow from this:

  • Credit institutions may not adopt an external score unquestioningly, but must incorporate it into a creditworthiness decision of their own taken on the merits (see also § 18a(3) of the German Banking Act (KWG) and § 505a of the German Civil Code (BGB)).
  • Credit information agencies protect themselves by contractually obliging their customers not to rely on the transmitted value either solely or to a "determining" degree.
  • A distinction must be drawn between internal scoring (the user calculates the value itself, often incorporating external values) and external scoring (supplied by a credit information agency).

For scoring, national law contains a rule in § 31 of the German Federal Data Protection Act (BDSG), whose compatibility with Union law the CJEU has left open and which is regarded as doubtful in substance. A reform (a new § 37a BDSG, including the exclusion of social media data and of pure account analyses, and extended information obligations) failed because of the discontinuity of the legislative procedure; the legal position therefore remains uncertain for the time being. Banks' internal risk measurement and rating systems do not fall under Article 22 GDPR, but under § 10(2) KWG.

2.4 Subject to the decision

The prohibition applies only where the person is subject to the decision, that is, exposed to a system whose rules are unilaterally laid down by a third party and on which he or she cannot exert any substantial influence. The fact that the person agrees to the use, or that the decision is based on a contractual arrangement, does not change this; this follows a contrario from the exceptions in Article 22(2)(a) and (c) GDPR. By contrast, a person is not subject to a decision where he or she can configure an application entirely on his or her own (such as a smart home thermostat) or where he or she controls a result through his or her own input (such as search engine results).

2.5 Effect of the decision

Only decisions with legal effects or with a similarly significant adverse effect are covered.

  • Legal effect exists where the measure alters the legal status, that is, triggers a legal consequence (termination of a contract, acceptance or rejection of a contractual offer, a fully automated administrative act under § 35a of the German Administrative Procedure Act (VwVfG), § 155(4) of the German Fiscal Code (AO), § 31a of Book X of the German Social Code (SGB X)). Purely indirect effects are not sufficient.
  • Significant adverse effect means effects that are equivalent to a legal effect, such as discrimination, the refusal of a contract that is essential to a person's way of life (health services, insurance) or the automatic rejection of an online credit application.

According to the prevailing view, the refusal to conclude a contract (such as a loan) does not change the data subject's legal position and therefore has no legal effect in itself. It may, however, amount to a significant adverse effect where the contract serves basic supply needs, where there is no reasonable alternative source of supply, or where there is an obligation to contract (for example the right to a basic payment account under § 31 of the German Payment Accounts Act (Zahlungskontengesetz)).

The following overview classifies typical cases from practice:

ConstellationEffect within the meaning of Article 22(1)
Fully automated administrative act, termination of contract, acceptance/rejection of a contractual offerlegal effect (+)
Refusal of a cash machine withdrawal for fraud preventionlegal effect possible (+), often covered by contract (point (a))
Refusal of a contract of basic supply / where there is an obligation to contractsignificant adverse effect (+)
Automated pre-selection of applications, scouting, debt collection measuresas a rule no significant adverse effect (-)
Personalized advertising, minor price differentiationas a rule no significant adverse effect (-)

Background: price differentiation is as a rule merely an invitatio ad offerendum, and minor price differences do not exceed the threshold of significance; the position may be different in the case of prohibitive prices or de facto exclusion from participation. Personalized advertising typically does not produce a significant adverse effect, which is confirmed a contrario by the right to object to direct marketing (Article 21(2) GDPR). An automated pre-selection (application, scouting) merely prepares a later human decision and as a rule does not reach the threshold of significance.

Only adverse decisions are covered. If the system grants the data subject's request in full (for example an approval in accordance with the application), the prohibition does not apply. This is also confirmed by the explanatory memorandum to the planned BDSG reform, which sought to delete § 37(1) no. 1 BDSG (exception for decisions granting a request) as superfluous, because a decision that grants a request in full does not fall under Article 22(1) GDPR in the first place.

3. Exceptions to the prohibition (paragraph 2)

The prohibition is not absolute. Article 22(2) GDPR permits three exhaustive exceptions.

ExceptionProvisionCore requirement
Contractual relationshipArticle 22(2)(a) GDPRnecessary for entering into or performance of the contract
Legal provision (opening clause)Article 22(2)(b) GDPRUnion or Member State law with suitable safeguards
Explicit consentArticle 22(2)(c) GDPRinformed, freely given and explicitly related to full automation

3.1 Contractual relationship (point (a))

The decision is permitted in so far as it is necessary for entering into or performing the contract. "Necessary" does not mean "useful" or "desirable", but indispensable. The point of reference is not the full automation, but the decision: what matters is whether the decision associated with the processing is necessary for the contract, not whether it could also be carried out manually. Public law contracts and the preparation of contracts are also covered, but not unilateral legal transactions or statutory obligations. Unlike the earlier rule in § 6a BDSG in its former version, the exception also applies where the conclusion of the contract is refused. The Union law standard applies to necessity, as under Article 6(1)(b) GDPR.

3.2 Opening clause (point (b))

Point (b) allows the Union and the Member States to authorize automated decisions by legal provision, provided that the provision lays down suitable safeguards. "Legal provisions" need not necessarily be formal statutes; substantive statutory law is also sufficient, but not mere administrative regulations or self-regulatory rules, because these are not sufficiently foreseeable for the addressee of the norm. The German legislature has made use of this margin, for example in § 37 BDSG (automated decisions on insurance benefits) as well as in § 35a VwVfG, § 31a SGB X and § 155(4) AO. Whether § 31 BDSG (scoring) is capable of serving as such a legal provision is disputed and has been left open by the CJEU (see above under 2.3). The AI Act, for its part, is not a suitable legal provision within the meaning of point (b): it does not authorize any specific automated decision, but merely lays down product and procedural requirements (see in more detail under 7.).

In the public sector, constitutional law draws an additional limit: a fully automated administrative act is permissible only where there is no discretion and no margin of appraisal (§ 35a VwVfG; similarly § 31a SGB X and § 155(4) AO). Discretionary decisions, indeterminate legal concepts and hardship assessments (such as "undue hardship" under the German Federal Training Assistance Act (BAföG)) require the involvement of a natural person; here only decision-preparing systems are conceivable. Information provided by the party concerned that is relevant to the individual case must also be taken into account in the automated procedure.

As a rule, the safeguards do not require disclosure of the program code; that would infringe trade secrets and go beyond what is necessary. It is sufficient to grant the data subject insight into the evaluation criteria and meaningful information about the logic involved (see in more detail under 6.).

Consent excludes the prohibition where it is informed, freely given and given by a person capable of understanding. It must relate explicitly to fully automated processing; general consent that also covers partial automation is not sufficient. The standards for whether consent is freely given and specific are Article 4(11) and Article 7 GDPR. Consent is not freely given in particular where there is a structural imbalance of power or where the data subject has to accept the automated procedure in order to obtain a service. Consent must be documented (burden of proof, Articles 5(2) and 7(1) GDPR).

A withdrawal takes effect only for the future. A decision that has already been taken is not thereby automatically reversed; the withdrawal is, however, to be treated as a contestation and gives the data subject the rights under paragraph 3 (in particular human review).

4. Safeguards for permitted decisions (paragraph 3)

For decisions based on a contract (point (a)) or on consent (point (c)), Article 22(3) GDPR makes lawfulness conditional on minimum guarantees that the data subject cannot waive. They are at the same time a mandatory component of the data protection impact assessment (Article 35(3)(a) in conjunction with Article 35(7)(d) GDPR).

4.1 Intervention, point of view and re-assessment

  • Right to obtain human intervention. The data subject may request that a person intervene in the process. This is not a right to be spared automated decisions in general, and it does not compel any change to the decision. The case handler may also confirm the result after a review on the merits, but may not confine himself or herself to a purely formal act.
  • Right to express one's own point of view. It is not sufficient to be allowed to express oneself; the submission must actually be heard. This presupposes that a human being considers it. A choice from pre-formulated statements is not sufficient.
  • Right to contest the decision and to a substantive re-assessment. "Contestation" does not mean avoidance under §§ 119 et seq. BGB and is not a legal remedy by which the data subject could unilaterally "make the decision disappear". He or she can only demand a serious, and not merely formal, re-assessment by a person. If that person confirms the result after a review on the merits, it stands; in the private sector, private autonomy does not compel any departure from a contractual decision.

4.2 Fair and transparent processing

It follows from the principle of fairness and transparency (Article 5(1)(a) GDPR, Recital 71 GDPR) that the system must be based on appropriate mathematical or statistical procedures. Only criteria that are demonstrably relevant to the decision may be incorporated into the decision model; the greater the possible harm, the higher the probability of a correct conclusion must be. In addition, the data basis must be accurate and up to date; the controller must minimize the risk of error by technical and organizational measures (principle of accuracy, Article 5(1)(d) GDPR) and prevent discriminatory effects as far as possible.

4.3 No general obligation to state reasons

A general obligation to state reasons for the decision does not follow from the GDPR. An explanation is owed only in so far as it is necessary to show the data subject how the point of view he or she expressed was incorporated into the decision. A more far-reaching right to an explanation of the decision-making in the individual case exists for high-risk AI systems under Article 86(1) of the AI Act (see 7.).

5. Sensitive data (paragraph 4)

Even where an exception under paragraph 2 applies, it is in principle unlawful to base the decision on special categories of personal data within the meaning of Article 9(1) GDPR (counter-exception). The inclusion of sensitive data is permitted only in two cases: where there is explicit consent (Article 9(2)(a) GDPR) or where the processing is necessary and proportionate for reasons of substantial public interest (Article 9(2)(g) GDPR). In both cases, suitable measures to protect data subjects must be in place. In the case of mixed data sets, paragraph 4 applies in principle only to the sensitive data; where sensitive and non-sensitive data are inseparably intertwined, it covers the entire data set.

6. Information and access rights

Anyone who takes a fully automated decision with legal or comparable effect must provide the data subject with meaningful information: about the existence of automated decision-making as well as about the logic involved and the significance of the processing (Article 13(2)(f), Article 14(2)(g) and Article 15(1)(h) GDPR). How this information is to be integrated into the privacy notice is dealt with under the transparency obligations.

The CJEU has clarified how far the information about the "logic involved" must go: the controller must explain the procedure and the principles in such a way that the data subject can understand which of his or her data were used and in what way. Neither the mere communication of complex formulas nor the disclosure of the algorithm is owed, but rather a comprehensible explanation oriented to the individual case. Where the information conflicts with trade secrets or the rights of third parties, an in camera procedure is possible: the controller submits the information to the supervisory authority or to the court, which determines the scope of the right of access (CJEU, judgment of 27 February 2025, C-203/22, Dun & Bradstreet Austria).

As a rule, there is no right to disclosure of the profiling or score value established; what is owed is information about the facts relied on and the logic applied, not about the value judgment as such. The data subject must be informed, upon request, of the safeguards taken under paragraph 3 (Article 12(3), first sentence, GDPR).

In practice, this obligation to provide access has a noticeable effect on scoring: credit information agencies and credit institutions can no longer rely in a blanket manner on trade secrecy, but must disclose in a comprehensible manner the data and criteria used, their weighting and the informative value of the score. In doing so, the information must not become something the data subject has to go and fetch. The Consumer Credit Directive (EU) 2023/2225 points in the same direction: where a credit agreement is refused on the basis of a database consultation, the consumer must be informed of this.

7. Relationship to the AI Act

For AI-supported decisions, the GDPR and the AI Act apply independently alongside one another (Article 2(7) of the AI Act). The protective logic differs: the GDPR is based on individual rights and asks about the specific adverse effect on the data subject; the AI Act is systemic and classifies AI systems according to their risk potential. An AI system that meets the requirements of the AI Act is therefore not thereby compliant with data protection law; it still has to be measured against the standard of Article 22 GDPR.

7.1 Risk-based approach of the AI Act

The AI Act does not regulate the automated decision as such, but the system. It distinguishes four risk levels:

  • Prohibited practices (Article 5 of the AI Act), which take up the protective rationale of Article 22 GDPR, such as social scoring (point (c)), AI for assessing the risk of criminal offenses (point (d)), emotion recognition in the workplace (point (f)) and biometric categorization (point (g)). The prohibition also applies to the mere use for decision support.
  • High-risk systems (Article 6 in conjunction with Annex III of the AI Act), including credit scoring as well as admission and applicant selection procedures. They are subject to the strict obligations of Articles 8 et seq. of the AI Act (transparency, human oversight, accuracy, risk and quality management). Where the system does not materially influence the outcome of the decision-making, it exceptionally falls outside that category (Article 6(3) of the AI Act); profiling of natural persons, however, always makes it high-risk.
  • Systems subject to transparency obligations (Article 50 of the AI Act), such as chatbots or deepfakes.
  • Minimal risk without specific obligations.

7.2 No separate ground for lawful processing, but de facto safeguards

The AI Act is not a legal provision that permits an automated decision within the meaning of Article 22(2)(b) GDPR. It does not authorize any specific decision concerning individuals, but expressly leaves data protection law unaffected (Recitals 10 and 41 of the AI Act); the rules on regulatory sandboxes (Articles 57 et seq. of the AI Act) expressly do not constitute a protective statute. Anyone who uses an AI system cannot therefore rely on that system's compliance with the AI Act, but must additionally have an exception under Article 22(2) GDPR and a legal basis under Article 6 GDPR. Where no exception applies, the decision may not be left to a system alone; where a specific statutory basis is lacking, its use is unlawful (as held by the Austrian administrative courts with regard to the Austrian labor market opportunities model).

In practice, the two regimes interlock: the deployer obligations for high-risk systems (Article 26 of the AI Act) and the remedies available to data subjects (complaint under Article 85, right to explanation under Article 86 of the AI Act) operate de facto like the safeguards required by Article 22(3) GDPR. Anyone who uses such a system (the "deployer") is at the same time, as a rule, the controller under data protection law.

7.3 Human oversight as the common denominator

The effective human oversight of high-risk systems required by Article 14 of the AI Act points in the same direction as Article 22 GDPR (human in the loop). Anyone who ensures organizationally and technically that a human being actually intervenes at the decisive point by carrying out a review does not even cross the threshold of Article 22(1) GDPR. A mere "waving through" (rubber-stamping) is not sufficient for that purpose; the human being must be able to review the result and to modify it. The two sets of rules thus complement each other: the AI Act secures the system, the GDPR the lawful use in the individual case.

8. Enforcement, sanctions and special cases

An infringement of Article 22 GDPR is subject to fines: administrative fines of up to EUR 20 million or of up to 4 % of the total worldwide annual turnover are possible (Article 83(5)(b) GDPR). The supervisory authority may also issue warnings and reprimands and order compliance with data subjects' rights (Article 58 GDPR).

Two special cases must be noted:

  • Police and judiciary. Automated decisions in the field of law enforcement are governed not by Article 22 GDPR but by § 54 BDSG (implementing Article 11 of the Law Enforcement Directive (Directive (EU) 2016/680)); discriminatory profiling on the basis of sensitive data is expressly prohibited there.
  • Children. Automated decisions should in principle not concern children (Recital 71 GDPR). They are permissible only exceptionally and with specific safeguards, such as age verification as a condition of access.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn