Article 22(1) is usually described as a prohibition and sometimes as a right to object. The distinction has consequences, but the practical work is in Article 22(2), which contains three ways through — and they are not interchangeable.
The shape of the provision
Article 22(1) of the GDPR says the data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. The Article 29 Working Party read that as a general prohibition rather than as a right the person must exercise, in its Guidelines on Automated individual decision-making and Profiling (WP251rev.01, adopted 3 October 2017 and revised 6 February 2018, subsequently endorsed by the EDPB). The Court of Justice proceeded on the same basis in SCHUFA. Treat it as a prohibition: it is the reading regulators apply, and building on the other reading leaves you with no defence if a supervisory authority disagrees.
Article 22(2) then sets out three exemptions. Article 22(3) attaches safeguards to two of them. Article 22(4) puts a separate and stricter bar in front of decisions based on special categories of data. Four paragraphs, and the third and fourth are the ones organisations most often miss because they read 22(2), find a gateway that fits, and stop.
This page describes provisions; it is not legal advice, and whether an exemption is available to you turns on the specifics of your processing, your sector and your member state. Take advice before relying on any of the three.
Necessary for a contract
Article 22(2)(a) permits the decision where it is necessary for entering into, or performance of, a contract between the data subject and the controller. The load-bearing word is “necessary”, and it carries the meaning it has everywhere else in the Regulation: not useful, not commercially preferable, not how you happen to have built it. If the same contractual purpose can be achieved by a less intrusive route, the automated decision is not necessary for it.
The argument that usually succeeds is volume. Where a controller receives applications at a rate that no human process could handle within any reasonable time, automating the decision is arguably necessary to perform the contract at all, and WP251 gives high-volume consumer lending as the paradigm. The argument that usually fails is efficiency. Automating a decision that fifty people currently make because it costs less is a business decision, not a necessity, and saying so on the record in a DPIA is more defensible than a strained necessity claim.
Note also who the contract must be with: the data subject and the controller. A decision made about a person under a contract between you and their employer, their insurer or their landlord does not fit this gateway, and that excludes a large share of B2B screening products from it.
Authorised by Union or member state law
Article 22(2)(b) permits the decision where it is authorised by Union or member state law to which the controller is subject and which lays down suitable measures to safeguard the data subject’s rights, freedoms and legitimate interests. This is the gateway for fraud and tax-evasion monitoring, for regulated anti-money-laundering screening, and for whatever a national legislature has specifically enabled.
It has a structural feature the other two do not, and it is the single most-missed point in the article: the Article 22(3) safeguards do not apply to it. Article 22(3) is drafted to cover the cases referred to in points (a) and (c) of Article 22(2). Under point (b) the safeguards come from the authorising law itself, which must lay them down. The consequence is asymmetric. It does not mean fewer protections apply in practice — it means you must read the national instrument to find out what they are, rather than reaching for the familiar list. Relying on (b) without identifying the specific provision and its safeguards is relying on nothing.
Explicit consent
Article 22(2)(c) permits the decision on the data subject’s explicit consent. Explicit is a higher bar than the ordinary unambiguous indication of Article 4(11): it means an express statement rather than an inference from conduct, and in practice a separate affirmative act naming the automated decision-making specifically. A tick in a general terms-and-conditions box is not it.
Consent also carries the rest of the consent machinery with it. It must be freely given, which is difficult where the controller holds the position of power described in Recital 43 — an employer, a monopoly service — and it must be as easy to withdraw as to give, under Article 7(3). Withdrawal is prospective only, so it does not unwind decisions already made, but from the moment of withdrawal the gateway closes and the processing must stop unless another applies. Designing a product whose core function depends on a consent that a material share of users will withdraw is a product risk as much as a legal one.
Where you rely on (a) or (c), Article 22(3) requires the controller to implement suitable measures to safeguard rights and freedoms, at least the right to obtain human intervention on the part of the controller, to express his or her point of view, and to contest the decision. “At least” is doing work: those three are a floor, not a list. And human intervention means intervention by someone with the authority and the information to reach a different answer — the point developed in meaningful human involvement. A reviewer who can only confirm is not a safeguard.
The separate bar in Article 22(4)
Article 22(4) provides that decisions under Article 22(2) shall not be based on the special categories of personal data in Article 9(1) unless Article 9(2)(a) — explicit consent — or Article 9(2)(g) — substantial public interest on the basis of Union or member state law — applies, and suitable measures to safeguard rights, freedoms and legitimate interests are in place.
This narrows the field sharply, and it does so in a way that catches machine-learning systems specifically. Article 9(1) covers data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and genetic, biometric, health, sex-life or sexual-orientation data. A model that was never given any of those fields can still produce inferences that fall inside them, and an inference about health or ethnicity is special-category data when it is used as such. So a controller relying on Article 22(2)(a) contract necessity, having satisfied itself that no special-category field is in the input, can still land inside 22(4) by way of what the model infers.
Two practical consequences. First, the contract-necessity gateway effectively closes for special-category decisions, since 22(4) admits only 9(2)(a) and 9(2)(g): you are back to explicit consent or a specific law. Second, testing for whether the system produces special-category inferences is not a fairness nicety but the thing that determines which paragraph of Article 22 you are in. The documentation trail for that testing is also what an evidence pack needs to contain, and it overlaps with the data-governance duties in Article 10 of the AI Act for high-risk systems, which is a separate instrument with separate obligations rather than an alternative to this one.
Top comments (0)