The load-bearing sentence.
Read it as one obligation hanging on three load-bearing phrases. Solely automated. Legal effects. Similarly significantly affects. Each phrase has an interpretive history. Each one has been narrowed by regulators and widened by courts. Together, they decide whether a given AI agent's decision falls inside the article or outside it.
Solely automated. The European Data Protection Board reads the word strictly. A human in the loop who routinely accepts the system's output without changing it does not displace the article. The EDPB Guidelines say the human review must be meaningful — performed by someone with the authority and competence to alter the decision, not someone whose role is to approve in batches. A pipeline that puts a credit officer's name on every algorithmic refusal but never sees that officer overrule the algorithm is, for Article 22 purposes, solely automated.
Legal effects. The narrow reading. The decision must produce a change in the data subject's legal position. A refused loan agreement, a terminated contract, a denied insurance policy, an immigration outcome — all clear cases. The EDPB list is not closed.
Similarly significantly affects. The wider reading, where most contemporary AI argument lives. The EDPB Guidelines name as examples decisions that affect the data subject's financial circumstances, access to health services, employment opportunities, or access to education. Behavioural advertising is not normally significant; targeted differential pricing or scoring that gates access to a credit product is.
The structure matters. Paragraph 1 is the right. Paragraph 2 is the three carve-outs. Paragraph 3 is the safeguards that travel with two of those carve-outs. Paragraph 4 is the special-categories overlay. Four sub-clauses. Most of the regulatory weight sits in the first.
The three carve-outs verbatim.
Three doors out of paragraph 1. Each door has a doorman. The EDPB Guidelines and supervisory authority practice have built up a regulator-recognised set of safeguards for each exception.
Three doors. The third door — explicit consent — is rarely the right one for systems that operate at scale. Mass consent is brittle, withdrawable at any moment, and supervisory authorities are sceptical of the genuineness of consent in employment and credit contexts. Most production AI agents that depend on Article 22(2) sit on (a) or (b).
The three safeguards verbatim.
Three operative safeguards, each load-bearing.
The right to obtain human intervention on the part of the controller. Not anywhere; on the part of the controller. The reviewer must be employed or instructed by the controller, must be able to access the inputs and outputs of the automated decision, and must have the authority to alter the outcome. The EDPB Guidelines underline that intervention must be more than a token gesture. A help-desk that returns the same automated answer is not intervention.
The right to express his or her point of view. The data subject must be able to put information in. New facts, contextual explanations, contested premises. The controller must consider the input.
The right to contest the decision. A contest is more than a complaint. The data subject can demand the decision be reviewed and altered or unwound. The supervisory authority track record after 2018 reads contest as a substantive right with a procedural shape — channel, timeline, response.
Note what the operative paragraph does not include. There is no right to an explanation of the decision in Article 22(3) itself. The right to an explanation lives in Recital 71 and, since the Dun and Bradstreet Austria judgment, operatively in Article 15(1)(h). The architecture of the safeguard is asymmetric: the data subject can intervene, contest, and reshape, but the textual right to ask why is housed in the access regime.
The special-categories overlay.
Article 9(1) lists racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a natural person's sex life or sexual orientation. Article 22(4) raises the bar when any of those feed into the automated decision.
Two doors only. Article 9(2)(a) — explicit consent. Article 9(2)(g) — substantial public interest under Union or Member State law. The everyday Article 22(2)(a) contract-necessity door is closed when special categories are involved. A health-insurance pricing model that ingests medical history must run through 9(2)(a) explicit consent or 9(2)(g) statutory authorisation. There is no contract-necessity path.
The supervisory authority practice on derived special categories — proxies, inferences, embedding-level signals — is unsettled. EDPB Guidelines treat inferred special-category data as in scope of Article 9 once the inference is sufficiently reliable. AI systems that produce probabilistic class membership over protected attributes sit close to this boundary.
Recital 71 · the rich-text version.
Recitals are not operative law. They are interpretive aid. Recital 71 nonetheless does two things that matter operatively.
First, it surfaces the named example use cases — automatic refusal of an online credit application, e-recruiting without any human intervention. Both have shaped the EDPB's reading of similarly significantly affects. Both have shaped national supervisory-authority enforcement priority. Recital 71 is not exhaustive but it tells controllers where the article is felt most.
Second, and more importantly, Recital 71 names a fourth safeguard not present in the operative Article 22(3): the right to obtain an explanation of the decision reached after such assessment. The asymmetry between Recital 71 and Article 22(3) was an open interpretive question for years. The Dun and Bradstreet Austria judgment in February 2025 closed it — not by reading explanation into Article 22(3), but by reading the existing transparency obligations in Articles 13, 14, and 15 to require an operative explanation of the procedure and principles actually applied.
Recital 71 also lists the kind of profiling the article targets: analysis or prediction of performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements. The list is the EDPB's working catalogue of significant-effect profiling. AI systems that score along any of these axes are in scope.
The EDPB Guidelines · WP251rev.01.
The Article 29 Working Party — the EDPB's predecessor — adopted Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679 on 3 October 2017 and last revised them on 6 February 2018, indexed as WP251rev.01. The EDPB endorsed them at its first plenary in May 2018. They remain the supervisory authority's canonical reading of Article 22.
Three positions in the Guidelines are doing operative work in 2026.
One. The meaning of "solely". The Guidelines treat human review as meaningful only where the reviewer has the authority and competence to change the decision, considers all the relevant data, and is not constrained to a token check. To qualify as human involvement, the controller must ensure that any oversight of the decision is meaningful, rather than just a token gesture. Cosmetic review does not move a system out of Article 22(1).
Two. The meaning of "meaningful information about the logic involved". The Guidelines explicitly disclaim a requirement for source code or for a complete mathematical specification of the algorithm. They require, instead, information that allows the data subject to understand the reasons for the decision — the kinds of inputs, the relative weight of those inputs in general terms, and the categories of personal data used. The position has now been confirmed and operationalised by the Dun and Bradstreet Austria ruling.
Three. Profiling without a § 1 decision. Profiling that does not produce legal effects or similarly significantly affect the data subject still triggers transparency duties under Articles 13(2)(f) and 14(2)(g). The Article 22 prohibition does not attach, but the disclosure obligation does. The EDPB has consistently treated marketing-personalisation profiling this way.
The Guidelines also emphasise that paragraph 2(a) contract-necessity must be read narrowly. Necessary means strictly necessary, not merely useful. Where a less intrusive non-automated alternative is available and reasonably efficient, the controller cannot rely on (a).
SCHUFA · credit scoring as automated decision.
On 7 December 2023, the First Chamber of the Court of Justice handed down its judgment in OQ v Land Hessen, intervener SCHUFA Holding AG, Case C-634/21. The reference came from the Verwaltungsgericht Wiesbaden. The question was whether the establishment by a credit reference agency of an automated probability value about a person's payment behaviour amounted to a decision based solely on automated processing within Article 22(1) — when the score itself was produced by SCHUFA but the actual contractual decision (lend or do not lend) was taken by the third party using it.
The Court rejected the narrower reading that the score is merely preparatory and that only the lending bank's downstream decision is the decision under Article 22(1). The qualifying condition the Court applied: where the third party draws strongly on the score to establish, implement, or terminate a contractual relationship, the score itself is the decision. The supervisory authorities had argued for this reading since the EDPB Guidelines. The Court adopted it.
The reasoning is not confined to credit reference agencies, but be careful what the judgment actually decided. It answered a question about scoring by a credit information agency on the facts referred to it. It did not hold that every AI system producing a probability value, risk score or class assignment about a person — fraud risk, employment fit, insurance-pricing tier, recidivism estimate — sits inside Article 22(1), and it did not allocate controller status between the party that scores and the party that acts on the score. Whether a given scoring system is inside Article 22(1) turns on the strong-reliance condition applied to its own facts, and who is controller for that processing is a separate question this judgment left open. Any wider reading is argument, not holding.
Two practical readings follow, and they are readings rather than holdings. First, where the scoring itself is the Article 22(1) decision, the safeguards in Article 22(3) — human intervention, point of view, contest — have to be reachable in respect of that decision; the Court did not decide which party must operate them. Second, the transparency obligations in Articles 13(2)(f), 14(2)(g), and 15(1)(h) attach to whoever is controller of the scoring processing, and identifying that party on given facts is not something this judgment settles. The Dun and Bradstreet Austria ruling fifteen months later is what gives the disclosure operative content.
Dun and Bradstreet Austria · the right to an explanation.
On 27 February 2025, the Court of Justice handed down its judgment in CK v Magistrat der Stadt Wien, with Dun & Bradstreet Austria GmbH as the other party, Case C-203/22. The reference came from the Verwaltungsgericht Wien. The data subject had been denied a mobile phone contract on the basis of an automated credit assessment performed by Dun and Bradstreet Austria. She invoked Article 15(1)(h) and asked for meaningful information about the logic involved. She was given general explanations she considered inadequate. The referring court asked the CJEU what the right actually requires.
The Court's operative ruling — point 1 — required the controller to explain, by means of relevant information and in a concise, transparent, intelligible and easily accessible form, the procedure and principles actually applied in order to use, by automated means, the personal data concerning that person with a view to obtaining a specific result, such as a credit profile.
What the Court did not do is also load-bearing. It did not require disclosure of the source code. It did not require disclosure of the trained model parameters. It did not mandate full algorithmic transparency. The right is not a right to inspect the system. It is a right to an explanation pitched at a level the data subject can use.
Three operative implications for AI controllers from the February 2025 reading.
One. Per-decision provenance. The controller must be able to say, for the specific decision in question, which of this person's personal data was used and in what way. Not a generic model card. A per-decision trace. Aggregate documentation of the model is necessary but not sufficient.
Two. Procedure and principles in plain text. The disclosure must be intelligible. A Bayesian-network diagram is not, by itself, intelligible. A generic boilerplate sentence is not, by itself, intelligible. The controller must produce an explanation that allows the data subject to understand why.
Three. Trade-secret defence is not absolute. The Court addressed the controller's interest in protecting algorithmic trade secrets. It held that the protection of trade secrets cannot extinguish the data subject's right entirely. National courts and supervisory authorities are to balance the two — the practical answer is layered disclosure: a usable explanation to the data subject, more detailed disclosure to the supervisory authority on request.
Together, SCHUFA and Dun and Bradstreet Austria define the post-2025 perimeter. SCHUFA brings credit-reference scoring inside Article 22(1) where the strong-reliance condition is met. Dun and Bradstreet Austria says the resulting transparency obligation has operative content — the data subject is entitled to a real explanation of the procedure and principles actually applied. The two rulings are the regulator's answer to the question of what an algorithm must explain to the person it judges. The United States reaches the same demand for a credit denial by a different instrument — the adverse-action notice under ECOA Regulation B, 12 CFR 1002.9(b)(2), which survived the CFPB's 12 May 2025 withdrawal of its AI circulars; the reading is at CFPB AI guidance for lending and credit agents.
Article 22 GDPR under the AI Act.
Regulation (EU) 2024/1689 — the EU AI Act — does not displace Article 22. Recital 9 says its harmonised rules should be without prejudice to existing Union law, in particular on data protection, and Recital 10 names the instrument: This Regulation does not seek to affect the application of existing Union law governing the processing of personal data, having recalled that the right is safeguarded in particular by Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680. Where an AI system processes personal data, both regimes attach. The AI Act adds obligations on the system side. Article 22 GDPR remains the operative right on the data-subject side.
The two regimes carry parallel disclosure and oversight obligations that overlap without merging.
A credit-scoring agent is high-risk through Article 6(2) and Annex III point 5(b), and the Chapter III rules for that class apply from 2 December 2027 — 2 August 2028, subject to Article 2(13), for systems classified high-risk through Article 6(1) and Annex I. Both dates come from Article 113, third paragraph, point (c), as replaced by Article 1(40)(b) of Regulation (EU) 2026/1744, in force 27 July 2026 (OJ 24 July 2026). The dates they displaced were two separate fixed dates, not one: 2 August 2026 for the Annex III limb and 2 August 2027 for the Annex I limb. Article 2(13), inserted by Article 1(3) of the same Regulation, permits the Annex I limb to be limited where sectoral Union law provides equivalent or higher protection. From then such an agent must satisfy AI Act Art. 12 logging, AI Act Art. 13 transparency to the deployer, AI Act Art. 14 human oversight, AI Act Art. 86 explanation rights, and Article 22 GDPR's data-subject perimeter, all at once. The evidence package that satisfies the regulator must address all five. Sibling reading: EU AI Act Article 13, line by line.
What the record carries, and what it does not.
State the limit first. Article 22 GDPR is not an evaluated regime in Warrant's corpus. The corpus at digest 6871ee8b holds 20 regimes and none of them is Regulation (EU) 2016/679. A lending trace does surface Article 22 in classification, and the package then says so in terms — the published sample reads GDPR Article 22. Not evaluated: regime present in classification but no obligations table in corpus. That disclosure is the honest output, not a per-clause Article 22 finding, and this section describes the fields that exist rather than fields that would be needed.
The evidence model treats each agent action as the unit and records, per action, whether it sat within purpose, whether its preconditions held, whether human oversight was appropriate, and whether it was reversible. Those are the facts a supervisory authority's Article 22 questions run on; the Article 22 conclusions are not drawn for you. The package is independently verifiable without contacting Warrant, so neither the findings nor the coverage limits can be amended after the fact. The four-layer evidence stack describes the architecture. For the sibling privacy regimes governing the same processing, see China's PIPL and HIPAA read against AI agents.
Questions a privacy officer asks first.
Read the source directly.
- Regulation (EU) 2016/679 · EUR-Lex CELEX:32016R0679
- Article 22 · automated individual decision-making, including profiling
- Recital 71 · profiling
- Article 13(2)(f) · transparency at collection
- Article 14(2)(g) · transparency for indirect collection
- Article 15(1)(h) · right of access, meaningful information about the logic involved
- Article 83(5) · higher-tier administrative fines
- EDPB · Guidelines on Automated individual decision-making and Profiling · WP251rev.01
- CJEU · OQ v Land Hessen · Case C-634/21 · 7 December 2023
- CJEU · CK v Magistrat der Stadt Wien · Case C-203/22 · 27 February 2025
- Per-obligation Warrant evidence field mapping
Authored by Warrant Compliance, the regulatory-analysis function at Warrant. [email protected]. Editorial commentary on regulatory text. Not legal advice. Verbatim quotation of Article 22 reflects the official English-language text of Regulation (EU) 2016/679 as published in the Official Journal of the European Union on 4 May 2016. Quotations from the CJEU rulings are taken from the official English-language text of the judgments as published on EUR-Lex.