Skip to content
13 items · Free checklist

EU GDPR Article 22 — Automated Decision-Making & AI Profiling Compliance Checklist 2026

GDPR Article 22 (in force since May 25, 2018) gives EU and EEA residents the right not to be subject to decisions based solely on automated processing — including AI profiling — that produces legal or

Maximum penalty: €20,000,000 or 4% of global annual turnover — whichever is higher (GDPR Art. 83(5))

Complete each item below to achieve compliance. Use Aegis Firma to generate all required documentation automatically.

Regulatory Requirements

1. Automated Decision-Making Disclosure

Inform EU/EEA individuals (in your privacy policy and at point of decision) when automated processing is used to make significant decisions about them. Explain the logic involved, the significance, and the envisaged consequences of such processing. The information duty sits in the Art. 13-15 transparency rights: Art. 13(2)(f) and 14(2)(g) at collection, Art. 15(1)(h) on access request — each covering "the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4)".

Due: May 25, 2018

2. Right to Human Review

Implement a mechanism for EU/EEA individuals to request human review of automated decisions affecting them, to express their point of view, and to contest the decision. Document your process for handling such requests. Art. 22(3): the controller "shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision."

Due: May 25, 2018

3. Records of Processing Activities (RoPA) — Profiling

Include all AI profiling and automated decision-making activities in your Records of Processing Activities (RoPA) under GDPR Article 30. Document the purpose, legal basis, data categories, retention periods, and safeguards for each AI processing activity.

Due: May 25, 2018

4. Data Protection Impact Assessment for AI

Conduct a DPIA for AI systems that systematically profile individuals, process sensitive data, or make automated decisions at scale. DPIA must assess risk to individual rights, proportionality, and necessity of processing. Art. 35(3) makes a DPIA mandatory for: (a) systematic and extensive evaluation based on automated processing, including profiling, on which decisions with legal or similarly significant effect are based; (b) large-scale processing of Art. 9 special categories or Art. 10 criminal-conviction data; (c) large-scale systematic monitoring of publicly accessible areas.

Due: May 25, 2018

5. Prohibition on Automated Decisions Based on Special Category Data

GDPR Art. 22(4) prohibits solely automated decisions based on special categories of personal data (health, racial/ethnic origin, political opinions, religious beliefs, biometric data) unless Art. 9(2)(a) explicit consent or Art. 9(2)(g) substantial public interest on the basis of Union/Member State law applies — these are the ONLY two Art. 9(2) gateways Art. 22(4) accepts — and suitable safeguard measures are in place. Any AI system using health data, facial recognition, or behavioral profiling for special category inferences must have one of these two legal bases.

Due: May 25, 2018

Implementation Steps

6. Audit all AI systems that make automated decisions affecting individuals

7. Update privacy notices to disclose automated decision-making

8. Implement a process for individuals to request human review

9. Document automated decisions in your Records of Processing Activities (RoPA)

10. Conduct a DPIA for any AI profiling that is high-risk

11. Ensure your AI vendor agreements include data processor agreements

12. Train staff on how to handle Art. 22 opt-out requests

13. Test your human review process to ensure it is genuinely meaningful