Automated decision-making
GDPR Article 22 and the EU AI Act: automated decisions, HR AI and credit scoring
An AI system used to make or support significant decisions about people can trigger GDPR automated-decision rules and EU AI Act duties at the same time. Compliance requires separate analysis under each regime.
Updated: 26 September 2026 · Reviewed by Constantin Razvan Gospodin.
Direct answer
What is GDPR Article 22?
Article 22 protects individuals in relation to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them, subject to the GDPR's exceptions and safeguards. The EU AI Act does not replace this test; it asks separate questions about the AI system, actor role, intended purpose and risk category.
GDPR Article 22
The GDPR question is about solely automated decisions with legal or similarly significant effects.
Article 22 protects individuals in relation to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them, subject to statutory exceptions and safeguards. The analysis turns on the decision process, degree of human involvement, effect on the person and applicable exception.
Meaningful human involvement
A rubber stamp is not the same as genuine human review.
EDPB guidance stresses that human involvement must be meaningful rather than token. The reviewer should have authority and competence to assess the automated recommendation and change the outcome. The CJEU's SCHUFA judgment also confirmed that automated scoring can fall within Article 22 where the score plays a determining role in a decision with significant effects.
EU AI Act
The AI Act asks different questions.
Role
Are you provider, deployer, importer, distributor or another regulated actor?
Risk category
Is the use prohibited, subject to Article 50, GPAI-related or high-risk under Article 6/Annex III?
System obligations
What documentation, risk management, oversight, transparency, monitoring or value-chain requirements apply?
Timeline
Which rules apply now and which high-risk obligations begin in 2027/2028?
Where overlap is common
HR, credit and access-to-service use cases deserve combined review.
Recruitment / employment
Candidate screening or employment decisions can raise Annex III employment issues while also requiring GDPR analysis of profiling, automated decision-making, transparency and lawful processing.
Creditworthiness
Natural-person creditworthiness and credit scoring are listed in Annex III, while GDPR Article 22 may separately matter where automated scoring determines or strongly shapes a decision with significant effects.
Essential services
Eligibility or access decisions can create AI Act high-risk questions and GDPR data-subject/safeguard questions depending on the system and decision workflow.
Human review
A nominal human click does not automatically resolve GDPR Article 22 concerns. Separately, the AI Act can impose human-oversight duties for high-risk systems.
One evidence package, two analyses
Reuse facts — not conclusions.
System purpose, decision logic, data, users, human intervention, affected persons, performance and vendor documentation can support both reviews. The legal conclusions should still be recorded separately under GDPR and the AI Act.
Primary sources
Official material on automated decisions and AI
EDPB — automated individual decision-making and profiling guidance