Law / European Union

GDPR Article 22, Automated Individual Decision-Making

Regulation (EU) 2016/679, Arts. 13(2)(f), 14(2)(g), 15(1)(h) and 22

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

A data subject rights rule binding public and private bodies.

As of 23 September 2026.

What it requires

  • Do not subject a person in the EU to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them, unless it is necessary to enter into or perform a contract with them, is authorised by a law that itself safeguards their rights, or rests on their explicit consent.
  • Where relying on the contract-necessity or explicit-consent exception, implement suitable safeguards, at minimum the right to obtain human intervention, to express a point of view, and to contest the decision.
  • Do not base such a decision on special category data under Article 9(1) unless the data subject gave explicit consent or the processing serves a substantial public interest, with suitable safeguards in place.
  • Tell the data subject, when collecting their data and on any access request, that this kind of automated decision-making occurs, and give meaningful information about the logic involved, the significance, and the envisaged consequences.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

Article 83(5)(b) subjects an infringement of the data subjects' rights in Articles 12 to 22, Article 22 included, to the higher administrative-fine tier, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher.

Rule
Higher of
As of
23 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

The data protection supervisory authority designated by each EU Member State under Article 51, coordinated on cross-border cases through the one stop shop mechanism and the European Data Protection Board (Articles 68-76).

Enforcement record

CMS GDPR Enforcement Tracker Report, 7th edition (cut-off 1 March 2026, published 21 May 2026): 2,685 fines with complete amount, date and controller information recorded across the EU/EEA since the GDPR became applicable on 25 May 2018 (3,062 including cases with incomplete information), totalling approximately EUR 6.11 billion, the first time the tracker's cumulative total crossed EUR 6 billion. actions_per_year (440) and fines_per_year (approximately EUR 487.6 million) are the report's own comparison against its prior, 2025 edition (roughly a one-year interval between editions), not a fixed calendar year; trend is recorded as rising on that reported increase. Counts DPA-imposed administrative fines only; the report does not separately track private civil claims under Article 82. This is the Regulation's enforcement record as a whole, not specific to Article 22.

As of
2 September 2026
Trend
Rising
Currency
EUR
Source link
https://cms.law/en/int/publication/GDPR-Enforcement-Tracker-Report/numbers-and-figures
Total fines
6,110,000,000
Fines per year
487,600,000
Actions per year
440

What it reaches

Obligation class

Data subject rights, Disclosure

Also on the record

EEA status

Annex
XI
Status
Incorporated
Force date
20 July 2018
Joint committee decision number
154/2018
Source link
https://www.efta.int/eea-lex/32016r0679
Decision date
6 July 2018

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 22(1) gives a data subject the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them.

Article 22(2) narrows that right where the decision is necessary to enter into or perform a contract with the data subject, is authorised by Union or Member State law that itself safeguards the data subject's rights, or rests on the data subject's explicit consent, and Article 22(3) conditions the contract and consent exceptions on suitable safeguards, at minimum the right to obtain human intervention, to express a point of view, and to contest the decision.

Article 22(4) forbids basing such a decision on special category data under Article 9(1) unless the data subject gave explicit consent or the processing serves a substantial public interest, again with suitable safeguards.

Articles 13(2)(f), 14(2)(g) and 15(1)(h) require the controller to tell the data subject, at collection and on a subsequent access request, that this kind of automated decision-making occurs and to give meaningful information about the logic involved, the significance, and the envisaged consequences, a duty that arises only alongside Article 22(1) and (4) processing.

The Court of Justice held in SCHUFA (Case C-634/21, 7 December 2023) that an automated credit score a third party relies on to make its own decision falls within Article 22 even though the scoring entity is not the final decision maker.

When LexLint raises it

  • high_risk_decisions

Read the law

Official Journal text, EUR-Lex, Regulation (EU) 2016/679
CJEU Case C-634/21 (SCHUFA)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app