EU-wide · Article 22 GDPR

GDPR Article 22: Automated Decision-Making and Profiling

Primary-source study guide grounded in EUR-Lex, CJEU C-634/21 (SCHUFA) and C-203/22 (Dun & Bradstreet) · Stand: 09/2026

People keep asking whether “the computer said no” is even legal, whether a credit score is already the decision, and how much of the algorithm a lender must explain. GDPR Article 22 automated decision-making is a prohibition in principle on decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect a person — unless one of three exceptions applies.

Key facts at a glance

Article 22(1) applies only when three conditions are met together: a decision, solely automated processing including profiling, and a legal or similarly significant effect.

Binding rule
Article 22 of Regulation (EU) 2016/679
Legal character
Prohibition in principle (CJEU C-634/21, paragraph 52)
Scoring
A credit-agency probability value can itself be the decision (C-634/21)
Explanation
Article 15(1)(h) as read in C-203/22, 27 February 2025

On this page

  1. When does Article 22 apply?
  2. Which everyday cases are in or out?
  3. What are the three exceptions?
  4. Does a credit score count?
  5. What must be explained?
  6. How was this guide checked?
  7. Frequently asked questions

When does GDPR Article 22 automated decision-making apply?

Article 22(1) gives the data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her. In SCHUFA Holding (C-634/21, 7 December 2023, paragraph 43) the Court treated those as three cumulative conditions: a “decision”, solely automated processing including profiling, and a legal or similarly significant effect. Article 4(4) defines profiling as automated processing that evaluates personal aspects — that definition is not, by itself, a ban. Recital 71’s examples are automatic refusal of an online credit application and e-recruiting without any human intervention. This sits next to the subject access request rules; The EU GDPR Explained only lists Article 22 in one line.

Which everyday cases are in or out of Article 22?

Article 22 bites where a solely automated output is the decision that grants, refuses or otherwise significantly shapes a legal or equivalent outcome; it does not bite merely because an algorithm ranks, recommends or prepares a file for a human who actually decides. This trainer’s data-subject-rights chapter (Articles 12–22) includes exam items on credit-scoring decisions and the information that must accompany them.

SituationArticle 22?Why, on the primary sources
Online loan auto-refused by a scoring engineYes, if solely automatedRecital 71 names automatic refusal of an online credit application. All three Article 22(1) conditions can be met.
Credit bureau produces a probability value that a lender draws on stronglyYes, for the bureauC-634/21 operative part: establishing that value is itself automated individual decision-making in those circumstances.
Product recommendations with no legal or equivalent effectUsually noProfiling under Article 4(4) can still occur, but the third Article 22(1) condition (legal or similarly significant effect) is missing.
A human reviews the file and can change the outcomeOutside Article 22(1) if not “solely” automatedArticle 22(1) requires a decision based solely on automated processing. Recital 71’s examples have no human intervention. C-634/21 and C-203/22 do not add a separate rubber-stamp test.

What are the three exceptions in Article 22(2)?

Article 22(1) does not apply if the decision is necessary for entering into or performing a contract between the data subject and a controller, is authorised by Union or Member State law that also lays down suitable safeguards, or is based on the data subject’s explicit consent. Those are Article 22(2)(a), (b) and (c). For (a) and (c), Article 22(3) requires at least human intervention, a chance to express a point of view, and a right to contest the decision. For (b), the authorising law itself must lay down suitable measures (Article 22(2)(b); C-634/21, paragraphs 53 and 65). Article 22(4) forbids basing those decisions on Article 9(1) special categories unless Article 9(2)(a) or (g) applies and suitable measures are in place. Systematic, extensive automated evaluation that produces such effects is a listed DPIA case under Article 35(3)(a).

Does a credit score count as GDPR Article 22 automated decision-making?

Yes, where a credit information agency automatically establishes a probability value about someone’s ability to meet payment commitments and a third party draws strongly on that value to establish, implement or terminate a contract with that person. That is the operative ruling in C-634/21. The Court treated “decision” as broad enough to include that probability value (paragraphs 44–46), treated the scoring as profiling under Article 4(4) (paragraph 47), and treated a near-decisive effect on a loan as a similarly significant effect (paragraphs 48–50). Paragraph 52 is the exam trap: Article 22(1) is a prohibition in principle; the person does not have to invoke it individually. Splitting bureau and lender does not empty Article 22 if the third party draws strongly on the score (paragraphs 61–63).

What must be explained as “meaningful information about the logic involved”?

In automated decision-making within Article 22(1), the data subject may require the controller, as “meaningful information about the logic involved” under Article 15(1)(h), to explain in a concise, transparent, intelligible and easily accessible form the procedure and principles actually applied to use that person’s data to obtain a specific result, such as a credit profile. That is operative part 1 of Dun & Bradstreet Austria (C-203/22, 27 February 2025). A complex formula or a blow-by-blow of every step is not enough (paragraph 59). Articles 13(2)(f) and 14(2)(g) impose the same duty up front — see Article 13 versus Article 14. If the controller claims third-party data or a trade secret, operative part 2 requires that material to go to the competent supervisory authority or court for a case-by-case balance; Recital 63 says that balance must not mean refusing all information.

How was this guide checked?

GDPR Exam Trainer mapped each legal sentence to the English EUR-Lex text of Articles 4(4), 13(2)(f), 14(2)(g), 15(1)(h), 22 and 35(3)(a) and to the operative parts of C-634/21 and C-203/22. The responsible organisation is GDPR Exam Trainer. The method is source mapping plus an independent citation gate, for DPO candidates — not legal advice. WP29 Guidelines on automated individual decision-making (wp251rev.01, 6 February 2018) appear only where the Court itself quotes them in C-203/22, paragraphs 45 and 60.

Frequently asked questions

These answers apply Article 22, Article 15(1)(h) and the two Court of Justice rulings to the questions candidates actually ask about profiling and “the computer said no”.

Is profiling banned under the GDPR?

No. Article 4(4) defines profiling as automated processing that evaluates personal aspects relating to a natural person. Article 22(1) restricts only a decision based solely on automated processing, including profiling, which produces legal effects concerning the person or similarly significantly affects that person.

Does a credit score count as an automated decision under Article 22?

It can. In SCHUFA Holding (C-634/21, 7 December 2023) the Court held that a credit information agency’s automated probability value is automated individual decision-making where a third party draws strongly on that value to establish, implement or terminate a contract with the person.

What are the three exceptions in Article 22(2)?

Article 22(1) does not apply if the decision is necessary for entering into or performing a contract with the controller, is authorised by Union or Member State law that also lays down suitable safeguards, or is based on the data subject’s explicit consent.

What must a controller explain about the logic of an automated decision?

Under Article 15(1)(h), as interpreted in Dun & Bradstreet Austria (C-203/22, 27 February 2025), the person may require an explanation, in a concise, transparent, intelligible and easily accessible form, of the procedure and principles actually applied to obtain a specific result, such as a credit profile. A complex mathematical formula alone is not enough.

Can trade secrets block that explanation?

Not as a blanket refusal. Recital 63 says the result of balancing trade secrets should not be a refusal to provide all information. In C-203/22 the Court held that allegedly protected information must be given to the competent supervisory authority or court, which then balances the rights and interests to determine the extent of access.

Practise Article 22 questions

Turn the three-part test, the SCHUFA scoring trap and the explanation duty into exam-ready recall with chapter training and realistic GDPR questions.

Start freeTry 30 questions free — no time limit, no credit card.

Which sources support this guide?

The binding legal statements come from the official EUR-Lex text of Regulation (EU) 2016/679 and the two Court of Justice judgments; practitioner pages below are qualitative signals of recurring questions, not legal sources.

This guide summarises the GDPR for study and general information. It is not legal advice. For a binding interpretation, consult the official text, your competent supervisory authority or a qualified data protection lawyer.