Skip to content
Esta e uma traducao de conveniencia. A versao em ingles e a versao oficial e legalmente vinculativa. Ver versao em ingles
EUDEEP coverage2 enforcement actions

EU GDPR Article 22 — Automated Decision-Making & AI Profiling: AI Compliance Requirements

GDPR Article 22 (in force since May 25, 2018) gives EU and EEA residents the right not to be subject to decisions based solely on automated processing — including AI profiling — that produces legal or similarly significant effects (credit scores, hiring, insurance pricing, content moderation). Organizations must inform individuals of automated processing, provide meaningful explanations of logic, implement human review rights, and document their profiling activities. This applies independently from and in addition to the newer EU AI Act.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

May 25, 2018

Maximum Penalty

€20,000,000 or 4% of global annual turnover — whichever is higher (GDPR Art. 83(5))

What Your Business Must Do

5 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Automated Decision-Making Disclosure

Critical

Inform EU/EEA individuals (in your privacy policy and at point of decision) when automated processing is used to make significant decisions about them. Explain the logic involved, the significance, and the envisaged consequences of such processing. The information duty sits in the Art. 13-15 transparency rights: Art. 13(2)(f) and 14(2)(g) at collection, Art. 15(1)(h) on access request — each covering "the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4)".

Deadline: May 25, 2018

GDPR Art. 13(2)(f), Art. 14(2)(g), Art. 15(1)(h), Rec. 71

Right to Human Review

Critical

Implement a mechanism for EU/EEA individuals to request human review of automated decisions affecting them, to express their point of view, and to contest the decision. Document your process for handling such requests. Art. 22(3): the controller "shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision."

Deadline: May 25, 2018

GDPR Art. 22(3)

Prohibition on Automated Decisions Based on Special Category Data

Critical

GDPR Art. 22(4) prohibits solely automated decisions based on special categories of personal data (health, racial/ethnic origin, political opinions, religious beliefs, biometric data) unless Art. 9(2)(a) explicit consent or Art. 9(2)(g) substantial public interest on the basis of Union/Member State law applies — these are the ONLY two Art. 9(2) gateways Art. 22(4) accepts — and suitable safeguard measures are in place. Any AI system using health data, facial recognition, or behavioral profiling for special category inferences must have one of these two legal bases.

Deadline: May 25, 2018

GDPR Art. 22(4), Art. 9

Records of Processing Activities (RoPA) — Profiling

High Priority

Include all AI profiling and automated decision-making activities in your Records of Processing Activities (RoPA) under GDPR Article 30. Document the purpose, legal basis, data categories, retention periods, and safeguards for each AI processing activity.

Deadline: May 25, 2018

GDPR Art. 30

Data Protection Impact Assessment for AI

High Priority

Conduct a DPIA for AI systems that systematically profile individuals, process sensitive data, or make automated decisions at scale. DPIA must assess risk to individual rights, proportionality, and necessity of processing. Art. 35(3) makes a DPIA mandatory for: (a) systematic and extensive evaluation based on automated processing, including profiling, on which decisions with legal or similarly significant effect are based; (b) large-scale processing of Art. 9 special categories or Art. 10 criminal-conviction data; (c) large-scale systematic monitoring of publicly accessible areas.

Deadline: May 25, 2018

GDPR Art. 35(1), (3)

Who Does This Apply To?

GDPR Art. 22 applies to: (1) any organization established in the EU/EEA; (2) organizations outside the EU/EEA that offer goods or services to EU/EEA data subjects or monitor their behavior. The "solely automated" threshold is critical: Art. 22 special rights apply only when decisions are made by automated means without meaningful human involvement. If a human genuinely reviews AI output and exercises independent judgment (not rubber-stamping), the decision is not "solely automated." "Legal or similarly significant effects" covers: employment decisions, credit applications, insurance pricing, housing, education admissions, health service access, tax assessments, content moderation resulting in account suspension.

Recent Enforcement Actions

CNIL (French DPA)2022-10-17€20,000,000Source verified· as of 2026-08-22

Against: Clearview AI

CNIL fined Clearview AI the maximum GDPR penalty for collecting and processing French citizens' facial biometric data without lawful basis, for creating an automated decision-making system (facial recognition) without satisfying Art. 22 requirements. Clearview was ordered to stop processing French data and delete existing data. (CNIL had given formal notice to cease 2021-11-26; the fine followed non-compliance.)

Source
Data Protection Commission (Ireland DPA)2023-05-22€1,200,000,000Source verified· as of 2026-08-22

Against: Meta Platforms Ireland Ltd.

Record GDPR fine for Meta's Facebook platform — a Schrems-II-line DATA TRANSFER case only: the DPC found Meta Ireland's SCCs plus supplementary measures did not sufficiently protect EEA users' data transferred to US servers, and ordered transfers suspended within 5 months and unlawfully-transferred US-stored data brought into compliance within 6 months. No Art. 22/AI-profiling/automated-decision dimension exists in this decision. (Separately, and NOT part of this fine: the DPC issued a combined €390,000,000 fine against Meta in January 2023 over using "contractual necessity" as the legal basis for personalized advertising on Facebook/Instagram — a lawful-basis/Art. 6 matter, genuinely advertising-related but still not an Art. 22 automated-decision finding.)

Source

Recent Regulatory Guidance

guidance2023-08-01

EDPB Guidelines on Automated Decision-Making under GDPR (Updated)

EDPB published updated guidelines clarifying: (1) "solely automated" means no meaningful human involvement — human review must be genuine, not a rubber stamp; (2) the standard for "meaningful explanation" of AI logic requires explaining the most important features/factors, not the full algorithm; (3) profiling for behavioral advertising constitutes Art. 22 processing where it significantly affects individuals (micro-targeting political views, health product targeting). Businesses must review whether their AI pipelines involve human review or are truly automated.

Source
guidance2024-12-17

EDPB Opinion 28/2024 + the cumulative GDPR / EU AI Act regime

The GDPR and the EU AI Act apply cumulatively: AI Act conformity does not discharge GDPR obligations, and vice-versa. EDPB Opinion 28/2024 (17 Dec 2024) addresses the GDPR legal basis for personal data in AI models (it did not cover Art. 22). For an AI system that takes solely-automated decisions with legal/similarly-significant effect, GDPR Art. 22 still applies independently of the AI Act. A dedicated EDPB–European Commission guideline on the GDPR/AI-Act interplay has been announced and is forthcoming.

Source

Key Case Law & Precedent

Schrems II — Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems (CJEU C-311/18)

Court of Justice of the European Union · 2020

While primarily about data transfers, Schrems II established the extraterritorial reach of GDPR and the requirement for genuine equivalent protection of EU data subjects' rights globally. GDPR Art. 22 applies to any AI system processing EU personal data, regardless of where the server is located. US companies without EU adequacy decisions must use SCCs with supplemental measures.

Outcome: Privacy Shield invalidated. SCCs upheld with supplemental measures requirement. Basis for all subsequent EU AI data transfer analysis.

Case reference

Loomis v. Wisconsin (US precedent cited in EDPB guidance)

Wisconsin Supreme Court · 2016

US case extensively cited by EDPB as the archetype of opaque algorithmic decision-making that GDPR Art. 22 is designed to prevent. Loomis challenged use of COMPAS recidivism algorithm in sentencing without explanation of how the score was calculated. EDPB cites Loomis to illustrate why the "meaningful explanation" standard must be genuine and comprehensible to the individual.

Outcome: COMPAS use upheld in US. Opposite outcome expected under GDPR Art. 22 — opaque AI sentencing would require disclosure and human review under EU standards.

Case reference

Quarterly Enforcement Digest

Q1 2026: GDPR Art. 22 enforcement increasingly intersects with EU AI Act compliance. The GDPR and the EU AI Act apply cumulatively — a high-risk AI system generally needs both an AI Act conformity assessment and (where Art. 35 thresholds are met) a GDPR DPIA; satisfying one regime does not discharge the other. CYCLE 10 CORRECTION (2026-08-22): removed the prior claim that "Meta's €1.2B fine (2023) established that Art. 22 applies to behavioral advertising AI profiling" — the same fabrication already caught and fixed in the enforcementActions entry above survived unfixed here too (sibling-field bug); the €1.2B fine is a pure Schrems-II data-transfer case with no Art. 22/AI dimension. The separate, genuinely advertising-related DPC action is a combined €390M fine (Jan 2023) over the lawful basis for personalized ads — an Art. 6 matter, not Art. 22. EU AI Act Art. 50 transparency provisions take effect August 2026 while the high-risk-AI provisions were deferred to December 2027 (2025 Digital Omnibus) — businesses should synchronize Art. 22 DPIA updates with the AI Act conformity assessment on the high-risk 2027 timeline to avoid duplicative documentation. EDPB has signaled targeted enforcement of Art. 22 for credit AI and insurance pricing AI in 2026 (unverified this cycle beyond the general trend — treat as directional, not a confirmed named action).

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.

Industry Playbooks covering EU GDPR Article 22 — Automated Decision-Making & AI Profiling

These industry playbooks include jurisdiction-specific checklist items and guidance for EU GDPR Article 22 — Automated Decision-Making & AI Profiling.

Frequently Asked Questions

Does EU GDPR Article 22 — Automated Decision-Making & AI Profiling apply to my business?

GDPR Article 22 (in force since May 25, 2018) gives EU and EEA residents the right not to be subject to decisions based solely on automated processing — including AI profiling — that produces legal or similarly significant effects (credit scores,… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under EU GDPR Article 22 — Automated Decision-Making & AI Profiling is: €20,000,000 or 4% of global annual turnover — whichever is higher (GDPR Art. 83(5)). Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with EU GDPR Article 22 — Automated Decision-Making & AI Profiling?

The 5 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan