Article 22 GDPR : Regulation of Automated Decision-Making and Profiling
Article 22(1) GDPR establishes a general prohibition on solely automated decisions producing legal or similarly significant effects. Article 22(2) provides 3 exclusive exceptions (contract, statutory authorization, explicit consent), and Article 22(3) mandates statutory human intervention safeguards.
Prohibition Principle for Solely Automated Decisions (Art. 22(1) GDPR)
Article 22(1) provides that the data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
This statutory prohibition protects individuals against full automation of high-impact choices (e.g. credit scoring, automated recruitment screening, insurance denial, individualized dynamic pricing).
Profiling (Art. 4(4)) is defined as any form of automated processing of personal data consisting of using personal data to evaluate certain personal aspects relating to a natural person (performance at work, economic situation, health, personal preferences, reliability or behaviour).
The 3 Statutory Exceptions (Art. 22(2)) and Mandatory Human Safeguards (Art. 22(3))
Article 22(2) admits only three strict exceptions to the prohibition principle:
- a) Contractual necessity: The decision is necessary for entering into, or performance of, a contract between the data subject and a data controller;
- b) Statutory authorization: The decision is authorised by Union or Member State law which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests;
- c) Explicit consent: The decision is based on the data subject's explicit consent (under Arts. 9(2)(a) and 4(11)).
Mandatory minimum safeguards (Art. 22(3)): In cases referred to in points (a) (contract) and (c) (explicit consent), the controller is statutorily required to implement suitable measures, including at least:
1° The right to obtain human intervention on the part of the controller;
2° The right for the data subject to express his or her point of view;
3° The right to contest the decision taken.
Verified Official Sources
General Data Protection Regulation — EU Reference Legal Framework
Consult official source →Traitement de données personnelles dans le cadre du développement de modèles d'IA, évaluation du risque de mémorisation/extraction, anonymisation des pondérations, intérêt légitime et mesures d'atténuation (Avis Art. 64 du CEPD)
Consult official source →Ciblage sur réseaux sociaux, profilage, audiences personnalisées
Consult official source →Associated Operational Micro-Tools
Check whether your project triggers mandatory DPIA requirements or meets the EDPB 9 high-risk criteria.
See Also in the Legal Framework
Article 35 GDPR : Criteria and Methodology of the DPIA
Legal framework of the Data Protection Impact Assessment (Art. 35 GDPR): mandatory cases, WP248 high-risk criteria, asse...
EDPB Guidelines 03/2026: Web Scraping for Generative AI
Legal analysis of EDPB Guidelines 03/2026 (Draft Version 1.0 open for consultation until 30 Oct 2026): lawful grounds fo...