EUAIACTUS.COM

Automated decision-making

GDPR Article 22 and the EU AI Act: automated decisions, HR AI and credit scoring

An AI system used to make or support significant decisions about people can trigger GDPR automated-decision rules and EU AI Act duties at the same time. Compliance requires separate analysis under each regime.

Updated: 26 September 2026 · Reviewed by Constantin Razvan Gospodin.

Direct answer

What is GDPR Article 22?

Article 22 protects individuals in relation to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them, subject to the GDPR's exceptions and safeguards. The EU AI Act does not replace this test; it asks separate questions about the AI system, actor role, intended purpose and risk category.

GDPR Article 22

The GDPR question is about solely automated decisions with legal or similarly significant effects.

Article 22 protects individuals in relation to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them, subject to statutory exceptions and safeguards. The analysis turns on the decision process, degree of human involvement, effect on the person and applicable exception.

Meaningful human involvement

A rubber stamp is not the same as genuine human review.

EDPB guidance stresses that human involvement must be meaningful rather than token. The reviewer should have authority and competence to assess the automated recommendation and change the outcome. The CJEU's SCHUFA judgment also confirmed that automated scoring can fall within Article 22 where the score plays a determining role in a decision with significant effects.

EU AI Act

The AI Act asks different questions.

Role

Are you provider, deployer, importer, distributor or another regulated actor?

Risk category

Is the use prohibited, subject to Article 50, GPAI-related or high-risk under Article 6/Annex III?

System obligations

What documentation, risk management, oversight, transparency, monitoring or value-chain requirements apply?

Timeline

Which rules apply now and which high-risk obligations begin in 2027/2028?

Where overlap is common

HR, credit and access-to-service use cases deserve combined review.

Recruitment / employment

Candidate screening or employment decisions can raise Annex III employment issues while also requiring GDPR analysis of profiling, automated decision-making, transparency and lawful processing.

HR AI compliance guide →

Creditworthiness

Natural-person creditworthiness and credit scoring are listed in Annex III, while GDPR Article 22 may separately matter where automated scoring determines or strongly shapes a decision with significant effects.

Financial-services AI guide →

Essential services

Eligibility or access decisions can create AI Act high-risk questions and GDPR data-subject/safeguard questions depending on the system and decision workflow.

Human review

A nominal human click does not automatically resolve GDPR Article 22 concerns. Separately, the AI Act can impose human-oversight duties for high-risk systems.

One evidence package, two analyses

Reuse facts — not conclusions.

System purpose, decision logic, data, users, human intervention, affected persons, performance and vendor documentation can support both reviews. The legal conclusions should still be recorded separately under GDPR and the AI Act.

Build a combined review for automated-decision systems.