TwinEthosRequest access

Law

EU GDPR Art. 22 (ADM)

EU data protection authorities (EDPB / national DPAs) · European Union (EU) · 1 provision encoded · verified against the official source as of 2026-08-30.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: eur-lex.europa.eu.

Binding law — in force

No solely-automated significant decision without human-intervention safeguards (GDPR Art. 22)

GDPR Article 22(1) · official text · In force: applies since 25 May 2018 · European Union (EU)

Under GDPR Art. 22, a data subject has the right not to be subject to a decision based SOLELY on automated processing (including profiling) that produces legal effects or similarly significantly affects them (e.g. credit, lending, insurance, employment screening). Such decisions are permitted only on a lawful basis (contract necessity, Union/Member-State law, or explicit consent) AND with safeguards: at minimum the right to obtain human intervention, to express a view, and to contest the decision. Controllers must also disclose the existence of ADM and meaningful information about the logic. SCHUFA (C-634/21) confirms a token human rubber-stamp doesn't exit Art. 22. Detect a consequential decision path executed solely by an automated model with no human-intervention/contest affordance.

Who it applies to

  • Duty falls on: controller
  • Systems covered: automated decision, consequential decision
  • Sectors: lending, insurance, employment, housing, essential services
  • Controllers processing personal data of people in the EU who make decisions based solely on automated processing/profiling with legal or similarly significant effects. In force since 2018-05-25. Exceptions (Art.22(2)) require the human-intervention/contest safeguards of Art.22(3); special-category data needs Art.9(2)(a)/(g).

The guard to add

Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.

At the point where model output becomes a significant decision about a person (approve, deny, underwrite, set_status), either queue the case for a reviewer who weighs the evidence and can change the outcome before it takes effect (review_queue.enqueue, requires_human_review), or, where the decision stays solely automated, record the permitted basis for that decision type and wire the safeguards in. Those safeguards are a notice in the decision message that it was made by automated processing, reasons the person can read, and request_human_review or contest routes where the person can give their view and have a human reconsider. A reviewer who approves every case without examining it does not make the decision non-automated, so the review records reviewer identity, the evidence viewed, and the outcome.

Where it goes: 1 application source code, 9 AI output handling, 15 agent action surface, 14 user-facing text.

What this provision adds:

  • Record which lawful basis applies (contract necessity, Union or Member-State law, or explicit consent), and offer at minimum human intervention, a way to express a view, and a way to contest.
  • Disclose the existence of the automated decision-making and meaningful information about the logic involved.

Example (Python + OpenAI SDK), before:

verdict = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
if verdict.strip() == 'deny':
    deny(applicant)
    send_decision_email(applicant, 'Your application was not approved.')

After:

out = client.chat.completions.create(model=MODEL, messages=msgs,
                                     response_format={'type': 'json_object'})
result = json.loads(out.choices[0].message.content)
if result['decision'] == 'deny':
    if requires_human_review('credit'):                 # a person decides
        review_queue.enqueue(applicant.id, proposal=result)
    else:                                               # solely automated, recorded basis
        deny(applicant, basis=DECISION_BASIS['credit'], reasons=result['reasons'])
        send_decision_email(applicant, render('adm_denial.txt', notice=ADM_NOTICE,
            reasons=result['reasons'], contest_url=f'{BASE}/decisions/{applicant.id}/contest'))

Control: Solely-automated significant decision without human-intervention safeguards. The same guard addresses 3 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id eu-gdpr-art22.solely-automated-decision-safeguards · review status: primary source derived