# Right to Explanation — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/right-to-explanation-individual-decisions
> Sources are cited per item. Verify against the official texts before relying on them.

This topic is essential as it specifically addresses the fundamental right of individuals to receive meaningful explanations about how automated decisions affecting them are made, which is a critical transparency and accountability mechanism in both GDPR and AI Act frameworks.

## Overview

## Legal Framework

The right to explanation operates at the intersection of two regulatory regimes. Under Article 22 GDPR, data subjects have the right not to be subject to solely automated decisions producing legal or similarly significant effects, unless an exception applies. Where such processing is permitted, Article 22(3) GDPR requires safeguards including the data subject's right to obtain human intervention, to express their point of view, and to contest the decision. Article 15(1)(h) GDPR complements this by granting a right of access to meaningful information about the logic of automated processing.

The AI Act reinforces these protections through Article 86, which establishes a dedicated right to explanation of individual decision-making for outputs produced by high-risk AI systems. This provision extends the transparency obligation beyond the GDPR's scope, applying to deployers of high-risk AI systems whose outputs produce legal or similarly significant effects for affected persons. The rationale across both instruments is to ensure that individuals subject to algorithmic decisions can understand, challenge, and seek redress against outcomes that materially affect their rights and freedoms.

## Key Developments

Dutch case law illustrates the practical thresholds for triggering Article 22 protections. In the ICS Card credit card refusal case, the Hague Court of Appeal examined whether a score model constituted solely automated decision-making. The court found that where a human applied acceptance policy criteria and the decision hinged on a pre-existing spending limit rather than an automated score, Article 22 did not apply. The court declined to treat the application form's reference to an automated assessment as conclusive evidence of solely automated processing, focusing instead on whether a human decision-maker exercised genuine discretion.

This establishes a demanding threshold: Article 22 applies only where the decision is produced without meaningful human involvement. A nominal human review that merely rubber-stamps an algorithmic output would likely qualify, but a decision where human judgment materially influences the outcome may fall outside Article 22's scope. However, such decisions may still trigger Article 15(1)(h) access rights and, where high-risk AI is deployed, Article 86 AI Act explanation rights.

The EDPB's guidance on facial recognition technology further signals that automated processing in law enforcement contexts attracts heightened scrutiny, with human oversight requirements serving as a critical safeguard against unaccountable algorithmic decision-making.

## Practical Guidance

- **Distinguish between Article 22 and Article 15(1)(h) obligations.** Even where decisions are not solely automated and thus fall outside Article 22's prohibition, the Article 15(1)(h) access right to information about processing logic remains independently enforceable. Maintain separate response procedures for each.

- **Document the degree of human involvement in every automated-assisted decision.** The ICS Card ruling demonstrates that courts will scrutinize whether human intervention was substantive or merely formal. Retain records showing the specific criteria a human decision-maker applied and how they exercised discretion.

- **Implement explanation mechanisms proportionate to decision impact.** For high-risk AI systems subject to Article 86 AI Act, prepare clear, accessible explanations of how the system functions, the main parameters influencing the output, and the reasoning behind individual decisions affecting data subjects.

- **Audit application forms and privacy notices for accuracy.** References to automated assessment on customer-facing materials may create expectations or evidentiary burdens. Ensure that descriptions of automated processing accurately reflect the actual decision-making workflow.

- **Establish a contestation and human review pathway.** Where Article 22 applies, provide a structured process allowing data subjects to express their views, request human reconsideration, and contest the decision with a named individual empowered to override the automated outcome.

## Legislation (full text of key provisions)

### Right to explanation of individual decision-making

*Source: AI Act, aiact-art-86-en, 2024-06-12 — https://overview.legal/posts/93391*

### Recital 171 — right to explanation for affected persons

*Source: AI Act, aiact-rec-171-en, 2024-06-12 — https://overview.legal/posts/94024*

Affected persons should have the right to obtain an explanation where a deployer’s decision is based mainly upon the output from certain high-risk AI systems that fall within the scope of this Regulation and where that decision produces legal effects or similarly significantly affects those persons in a way that they consider to have an adverse impact on their health, safety or fundamental rights. That explanation should be clear and meaningful and should provide a basis on which the affected persons are able to exercise their rights. The right to obtain an explanation should not apply to the use of AI systems for which exceptions or restrictions follow from Union or national law and should apply only to the extent this right is not already provided for under Union law.

### Recital 10 — personal data protection safeguarding

*Source: AI Act, aiact-rec-10-en, 2024-06-12 — https://overview.legal/posts/93702*

The fundamental right to the protection of personal data is safeguarded in particular by Regulations (EU) 2016/679 (11) and (EU) 2018/1725 (12) of the European Parliament and of the Council and Directive (EU) 2016/680 of the European Parliament and of the Council (13). Directive 2002/58/EC of the European Parliament and of the Council (14) additionally protects private life and the confidentiality of communications, including by way of providing conditions for any storing of personal and non-personal data in, and access from, terminal equipment. Those Union legal acts provide the basis for sustainable and responsible data processing, including where data sets include a mix of personal and non-personal data. This Regulation does not seek to affect the application of existing Union law governing the processing of personal data, including the tasks and powers of the independent supervisory authorities competent to monitor compliance with those instruments. It also does not affect the obligations of providers and deployers of AI systems in their role as data controllers or processors stemming from Union or national law on the protection of personal data in so far as the design, the development or the use of AI systems involves the processing of personal data. It is also appropriate to clarify that data subjects continue to enjoy all the rights and guarantees awarded to them by such Union law, including the rights related to solely automated individual decision-making, including profiling. Harmonised rules for the placing on the market, the putting into service and the use of AI systems established under this Regulation should facilitate the effective implementation and enable the exercise of the data subjects’ rights and other remedies guaranteed under Union law on the protection of personal data and of other fundamental rights.

### Recital 59 — high-risk AI law enforcement systems

*Source: AI Act, aiact-rec-59-en, 2024-06-12 — https://overview.legal/posts/93800*

Given their role and responsibility, actions by law enforcement authorities involving certain uses of AI systems are characterised by a significant degree of power imbalance and may lead to surveillance, arrest or deprivation of a natural person’s liberty as well as other adverse impacts on fundamental rights guaranteed in the Charter. In particular, if the AI system is not trained with high-quality data, does not meet adequate requirements in terms of its performance, its accuracy or robustness, or is not properly designed and tested before being put on the market or otherwise put into service, it may single out people in a discriminatory or otherwise incorrect or unjust manner. Furthermore, the exercise of important procedural fundamental rights, such as the right to an effective remedy and to a fair trial as well as the right of defence and the presumption of innocence, could be hampered, in particular, where such AI systems are not sufficiently transparent, explainable and documented. It is therefore appropriate to classify as high-risk, insofar as their use is permitted under relevant Union and national law, a number of AI systems intended to be used in the law enforcement context where accuracy, reliability and transparency is particularly important to avoid adverse impacts, retain public trust and ensure accountability and effective redress. In view of the nature of the activities and the risks relating thereto, those high-risk AI systems should include in particular AI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices, or agencies in support of law enforcement authorities for assessing the risk of a natural person to become a victim of criminal offences, as polygraphs and similar tools, for the evaluation of the reliability of evidence in in the course of investigation or prosecution of criminal offences, and, insofar as not prohibited under this Regulation, for assessing the risk of a natural person offending or reoffending not solely on the basis of the profiling of natural persons or the assessment of personality traits and characteristics or the past criminal behaviour of natural persons or groups, for profiling in the course of detection, investigation or prosecution of criminal offences. AI systems specifically intended to be used for administrative proceedings by tax and customs authorities as well as by financial intelligence units carrying out administrative tasks analysing information pursuant to Union anti-money laundering law should not be classified as high-risk AI systems used by law enforcement authorities for the purpose of prevention, detection, investigation and prosecution of criminal offences. The use of AI tools by law enforcement and other relevant authorities should not become a factor of inequality, or exclusion. The impact of the use of AI tools on the defence rights of suspects should not be ignored, in particular the difficulty in obtaining meaningful information on the functioning of those systems and the resulting difficulty in challenging their results in court, in particular by natural persons under investigation.

## Guidance

### Report on stakeholder event on processing of personal data to target or deliver political advertisements

*Source: EDPB, report-on-stakeholder-event-on-processing-of-personal-data-en, 2026-03-27 — https://overview.legal/posts/125684 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-processing-of-personal-data_en*

Report on stakeholder event on processing of personal data to target or deliver political advertisements 27 March 2026 1. Background The EDPB organised an online stakeholder event on 27 March 2026 to collect stakeholders’ input on processing of personal data to target or deliver political advertisements. The objective was to engage with stakeholders at an early stage of drafting the EDPB Guidelines on the processing of personal data to target or deliver political advertisements (Chapter III of…

### Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

*Source: EDPB, opinion-282024-on-certain-data-protection-aspects-related-to-en, 2024-12-18 — https://overview.legal/posts/125697 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en*

Adopted 1 Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models Adopted on 17 December 2024 Adopted 2 Executive summary AI technologies create many opportunities and benefits across a wide range of sectors and social activities. By protecting the fundamental right to data protection, GDPR supports these opportunities and promotes other EU fundamental rights, including the right to freedom of thought, expression and information,…

### Report of the work undertaken by the ChatGPT Taskforce

*Source: EDPB, report-of-the-work-undertaken-by-the-chatgpt-taskforce-en, 2024-05-24 — https://overview.legal/posts/125752 — original: https://www.edpb.europa.eu/documents/task-force-report/report-of-the-work-undertaken-by-the-chatgpt-taskforce_en*

Report of the work undertaken by the ChatGPT Taskforce 23 May 2024 Final 2 Final 3 D ISCLAIMER The positions presented in this document result from the coordination of the members of the ChatGPT taskforce with a view to handling investigations regarding the service ChatGPT provided by the US based company OpenAI OpCo, LLC . They reflect the common denominator agreed by the S upervisory A uthorities in their interpretation of the applicable provisions of the GDPR in relation to the matters that…

### Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications

*Source: EDPB, guidelines-012020-on-processing-personal-data-in-the-context-of-connected-en, 2021-03-09 — https://overview.legal/posts/126056 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012020-on-processing-personal-data-in-the-context-of-connected_en*

Adopted 1 Guidelines 0 1 / 2020 on processing personal data in the context of connected vehicles and mobility related applications Version 2 .0 Adopted on 9 March 2021 Adopted 2 Version h istory Version 2.0 9 March 2021 Adoption of the Guidelines after public consultation Version 1.0 2 8 January 2020 Adoption of the Guidelines for public consultation Adopted 3 Adopted 4 The European Data Protection Board Having regard to Article 70 (1 ) ( e) of the Regulation 2016/679/EU of the European…

### Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement

*Source: EDPB, edpb-guidelines-on-the-use-of-facial-recognition technology-in-the-area-of-law-enforcement, 2023-05-17 — https://overview.legal/posts/38075 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052022-on-the-use-of-facial-recognition-technology-in-the-area-of_en*

More  and  more  law  enforcement  authorities  (LEAs)  apply  or  intend  to  apply  facial  recognition technology (FRT). It may be used to authenticate or to identify a person and can be applied on videos (e.g. CCTV) or  photographs. It may be used for various purposes, including to search for persons  in police watch lists or to monitor a person's movements in the public space. FRT is  built on the processing of biometric data , therefore, it encompasses the processing of special categories ...

### Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (LED) under Article 62

*Source: EDPB, contribution-of-the-edpb-to-the-european-commissions-en, 2021-12-14 — https://overview.legal/posts/125973 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/contribution-of-the-edpb-to-the-european-commissions_en*

Adopted Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive ( LED ) under Article 62 Adopted on 14 December 2021 2 3 The European Data Protection Board Having regard to Articles 51(1)(a)(b) and (h) of the Directive ( EU ) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal da ta by competent authorities for the purposes of the…

## Recent developments

### Swedbank refuses transparency in automatic interest calculation

*Source: noyb - European Center for Digital Rights, 2025-02-27 — https://overview.legal/posts/53160 — original: https://noyb.eu/en/swedbank-refuses-transparency-automatic-interest-calculation*

Data Subject Rights Nowadays, more and more banks set their interest rates automatically, and without any human intervention. But even the smallest inaccuracies can cost consumers thousands of additional euros. While EU law allows the use of such an automatic system in certain circumstances, companies must follow strict rules to protect people’s fundamental right to privacy. Banks, for example, would need to provide their customers with “meaningful information about the logic involved” in calcul

### Europe is undermining its own digital rights from within.

*Source: European Digital Rights, 2025-11-27 — https://overview.legal/posts/52062*

The new "Digital Omnibus" from the European Commission is presented as a simple "simplification," but in practice, it undermines important safeguards in the GDPR, the ePrivacy regulations, and the AI Act. It would make access to device data easier, weaken restrictions on automated decision-making, and reduce protection against discriminatory AI. The article "Europe Undermines Its Digital Rights From Within" originally appeared on European Digital Rights (EDRi).

### Europe is dismantling its digital rights from within

*Source: European Digital Rights, 2025-11-27 — https://overview.legal/posts/49191 — original: https://edri.org/our-work/europe-is-dismantling-its-digital-rights-from-within/*

The European Commission’s new Digital Omnibus is presented as simple “streamlining”, but in practice it dismantles key safeguards in the GDPR, ePrivacy rules and the AI Act. It would make access to device data easier, weaken limits on automated decision-making and lower protections against discriminatory AI.

### Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems?

*Source: Gaming Tech Law, 2023-03-29 — https://overview.legal/posts/6223 — original: https://www.gamingtechlaw.com/2023/03/draft-ai-act-general-purpose-artificial-intelligence/#entry-4244*

> The growth of generative artificial intelligence systems has led EU lawmakers to focus on General Purpose AI in drafting the AI Act, which will set the framework governing artificial intelligence in the European Union. As previously reported, the EU Parliament has already broadened the definition of artificial intelligence for the purposes of the AI Act…

### Quod erat demonstrandum? - Towards a typology of the concept of explanation for the design of explainable AI

*Source: ScienceDirect, 2022-09-27 — https://overview.legal/posts/6270 — original: https://www.sciencedirect.com/science/article/pii/S0957417422019066?via=ihub#entry-812*

> * We propose a framework for defining different types of explanations of AI systems.
> * We contextualize current XAI discourses within the proposed framework.
> * We highlight two broad perspectives for defining quality criteria for explainability.
> * We discuss the relevance of our framework in light of current and upcoming AI regulation.

## Literature

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### Perlindungan Hukum terhadap Inferred data dalam Automated Decision-Making: Studi Perbandingan GDPR dan UU PDP

*Source: Jurnal Ilmu Hukum, Humaniora dan Politik, 2026-05-25 — https://overview.legal/posts/132606 — original: https://doi.org/10.38035/jihhp.v6i4.8347*

Perkembangan kecerdasan buatan dan sistem automated decision-making (ADM) mendorong penggunaan inferred data yang memungkinkan pembentukan profil individu tanpa keterlibatan langsung subjek data. Praktik ini menimbulkan risiko terhadap hak individu, termasuk diskriminasi algoritmik dan kurangnya transparansi. Namun, belum ada kajian yang secara spesifik membandingkan perlindungan inferred data dalam kedua rezim ini. Penelitian ini bertujuan menganalisis klasifikasi inferred data dalam kerangka G

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### Privacy vs. business convenience: the Mousse judgment and the future of data protection in the EU

*Source: Unio - EU Law Journal, 2025-06-18 — https://overview.legal/posts/53865 — original: https://doi.org/10.21814/unio.11.1.6632*

The Mousse ruling represents a pivotal moment in EU data protection law, reinforcing strict limitations on personal data processing and clarifying the legal standards under the General Data Protection Regulation (GDPR). The Court of Justice of the European Union (CJEU) reaffirmed that data collection must be objectively indispensable for a specified legal basis, rejecting broad interpretations of contractual necessity and legitimate interest. Additionally, the ruling confirms that the right to o

### Eu regulatory ecosystem for ethical AI

*Source: AI and Ethics, 2025-06-02 — https://overview.legal/posts/53866 — original: https://doi.org/10.1007/s43681-025-00749-x*

Abstract AI applications raise complex ethical, legal, and security challenges that demand comprehensive and coordinated governance at multiple levels. In this paper, we examine how key European Union (EU) regulatory frameworks, such as the AI Act, GDPR, and NIS2, interact to set standards for AI security, functionality, and ethical performance. By comparing the objectives and requirements outlined in these regulatory instruments, we identify points of convergence that encourage a holistic appro

## Related topics

- **Automated Decision-Making** — https://overview.legal/topics/geautomatiseerde-besluitvorming
  Processing involving automated decisions without human involvement
- **Profiling** — https://overview.legal/topics/profiling
  Automated processing to evaluate personal aspects
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Marketing** — https://overview.legal/topics/marketing
  Use of personal data for marketing and advertising purposes
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/right-to-explanation-individual-decisions · 2026-08-22
