Automated Decision-Making
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing involving automated decisions without human involvement
Overview
24 sources · Jul 23, 2026Legal Framework
Automated decision-making under the GDPR is governed primarily by Article 22 (not fully reproduced here but referenced throughout), which restricts decisions based solely on automated processing that produce legal or similarly significant effects. The framework is supported by several interlocking provisions. Article 4(4) defines the core concept:
"‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements"
— GDPR Art. 4(4)
Transparency obligations reinforce this. Where data is collected directly from the subject, Article 13(2)(f) requires controllers to inform data subjects about the existence of automated decision-making. The same duty applies under Article 14(2)(g) when data is obtained indirectly. The right of access under Article 15(1)(h) entitles data subjects to receive:
"the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject."
— GDPR Art. 15(1)(h)
Where automated decision-making relies on explicit consent under Article 22(2)(c), the EDPB confirms that controllers must inform data subjects accordingly:
Key Developments
The CJEU's decision in Mousse (C‑394/23, 9 January 2025) reaffirmed that the right to object under Article 21 extends to profiling based on legitimate interests:
"The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions."
— CJEU, Mousse ¶10
This ruling clarifies that even profiling activities not rising to the level of Article 22 automated decisions remain subject to the objection right, creating a layered protection regime. Enforcement actions reinforce the practical stakes: the Italian Garante fined Character.AI €158,000 for failures involving generative AI interactions with users, and the Polish DPA fined a bank €135,600 for GDPR violations including deficiencies in automated processing. The EDPB has further signalled that explicit consent is the expected standard where automated decisions create serious data protection risks, noting that:
"Explicit consent is required in certain situations where serious data protection risk emerge, hence, where a high level of individual control over personal data is deemed appropriate."
— EDPB Guidelines 05/2020 §91
Status of the Debate
This topic is actively contested in court. The boundaries of Article 22 remain litigated — particularly what constitutes a decision producing "legal or similarly significant effects" and whether human involvement is sufficiently "meaningful" to remove processing from Article 22's scope. Courts have diverged on whether nominal human review satisfies the prohibition, and the interaction between Article 22 and the Article 21 objection right (as clarified in Mousse) creates overlapping but distinct remedies that practitioners must navigate. What would resolve the open questions: a CJEU reference on the threshold for "similarly significant effects" and the minimum substantive requirements for meaningful human intervention in automated decision pipelines.
Practical Guidance
- Map your automated decisions against Article 22 thresholds. Document whether each automated process produces legal or similarly significant effects for individuals, and classify accordingly. The distinction determines whether Article 22's prohibitions apply at all.
- Ensure transparency across all collection channels. Provide Article 13 or Article 14 information about automated decision-making at the point of data collection, and ensure Article 15 access responses include meaningful information about the logic involved.
- Secure explicit consent where relying on Article 22(2)(c). The EDPB requires explicit, granular consent for automated decisions involving serious risks — bundled or presumed consent will not suffice.
- Implement a robust objection mechanism. Following Mousse, profiling based on legitimate interests is objectionable under Article 21; controllers must have workflows to halt processing upon objection unless compelling legitimate grounds are demonstrated.
- Design human oversight that is substantive, not symbolic. A reviewer who rubber-stamps algorithmic output does not remove processing from Article 22's scope. Human intervention must involve meaningful evaluation with authority to override the automated result.