Automated decision-making

More and more decisions are taken without a human being involved: a credit application refused, an insurance premium raised, a job application filtered out at the screening stage. The GDPR sets limits to that.

Legal basis

Article 22 GDPR gives data subjects the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. There are three exceptions: the decision is necessary for entering into or performing a contract, it is authorised by Union or Member State law, or the data subject has given explicit consent. In the first and third situations suitable safeguards must be in place, including at least the right to obtain human intervention, to express a point of view and to contest the decision. Articles 13, 14 and 15 add a duty to provide meaningful information about the logic involved. Where a public authority decides, the duties of care and reasoning in the General Administrative Law Act apply as well.

How it works in practice

The question is almost always whether the decision is truly taken solely by automated means. An employee who merely clicks through a proposed decision does not amount to human intervention; that requires a competent reviewer who can actually change the outcome. For high-risk systems the AI Act adds requirements on documentation, oversight and transparency.

Where it goes wrong

Three points recur. First, human intervention that exists on paper but is a formality in practice. Second, the explanation of the logic, which often stops at a reference to trade secrets. Third, the absence of a data protection impact assessment, which is mandatory where systematic automated evaluation takes place.

Related terms

Automated decision-making connects to the AI Act, to the data protection impact assessment and to data subject rights.

Assessed by an algorithm? Our IT lawyers request the reasoning and challenge the decision.