Automated decision making explained: what Article 22 restricts and why
Automated decision making is a decision taken about a person by automated processing alone, including profiling, with no meaningful human involvement in the outcome that person receives. Article 22 GDPR restricts it wherever the decision produces legal effects or similarly significant effects for that person.
Article 22(1) is worded as a right, not a permission: the data subject "shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her." Regulators read that as a general prohibition, so the working assumption should be that the pattern is off limits unless you can point to an exception.
When does the restriction apply?
Three conditions have to be met together:
- There is a decision. An output that changes what happens to someone, not a report a human reads and ignores.
- It is based solely on automated processing. No meaningful human involvement in reaching it.
- The effect is legal or similarly significant. Refusing credit, terminating a contract, declining a claim, denying access to a service.
Article 22(2) sets out the exceptions: the decision is necessary for entering into or performing a contract, it is authorised by Union or Member State law with suitable safeguards, or it is based on the person's explicit consent. Article 22(4) adds that decisions of this kind cannot rest on special category data unless Article 9(2)(a) or 9(2)(g) applies with safeguards in place.
What counts as meaningful human involvement?
Not a rubber stamp. The Article 29 Working Party guidance on automated decision making, endorsed by the EDPB, sets the bar at review carried out by someone with the authority and competence to change the decision, who considers all the relevant data rather than just the machine output. A reviewer clicking approve on a queue of scores at forty seconds each is not providing that, and a workflow that gives no realistic route to a different answer is solely automated whatever the org chart says.
Three practical tests: can the reviewer see the underlying material, do they have authority to overturn, and does the record show cases where they did.
A fraud signal that triggers an automatic rejection
This is the pattern Article 22 exists to restrict, and it is worth saying plainly. If a fraud indicator or a risk score causes a claim to be declined, a payment to be blocked or an account to be closed without a person who can and does change the outcome, you are making a solely automated decision with a significant effect on that individual. Repudiating a claim has an obvious financial effect on the claimant. Wiring the signal straight to the rejection is the design error.
The fix is architectural, not cosmetic. Signals belong at the routing layer: control points logged around a submission should decide which files a human looks at more closely, and the decision itself should stay with that human. Grade signals as attention, keep the record of what the reviewer saw and concluded, and make the escalation path to a specialist unit explicit.
What the UK changed after Brexit
The UK no longer mirrors Article 22. Section 80 of the Data (Use and Access) Act 2025 replaced it in the UK GDPR with new Articles 22A to 22D, in force on 5 February 2026, turning a general prohibition into a safeguards regime. For most personal data, a significant decision may now be taken by solely automated processing on any lawful basis, including legitimate interests, provided the safeguards are in place. Special category data stays tightly restricted, and a significant decision cannot rest solely on automated processing carried out in reliance on Article 6(1)(ea), the new recognised legitimate interests ground.
Article 22A carries the definitions across in statutory form: a decision is significant if it produces a legal effect or a similarly significant effect, and it is based solely on automated processing if there is no meaningful human involvement in the taking of the decision. Other jurisdictions run their own versions, with several US state privacy laws giving a right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects. The EU rules are not the global default.
The safeguards you have to put in place
- Human intervention on request, the right to express a point of view and the right to contest the decision, required by Article 22(3) GDPR and by Article 22C of the UK GDPR, which adds providing information about the decision.
- Transparency up front, under Articles 13 and 14: tell people the automated decision making exists and give meaningful information about the logic and consequences.
- Access on request, under Article 15(1)(h), so the same explanation has to survive a data subject request months later.
- A data protection impact assessment, which Article 35(3)(a) requires for systematic and extensive automated evaluation producing legal or similarly significant effects.
Venta Capture, a product of VentaVid, is built around that separation. The signals logged around a submission are presented as a reason for a reviewer to look more closely, never as a verdict, and the decision stays with the qualified person who can change it.