Skip to main content
Category: Data Subject Rights

Safeguards for Automated Decisions

Also known as: Article 22 safeguards, Safeguards for solely automated decision-making, Automated decision-making safeguards
Simply put

Safeguards for automated decisions are the protections that must be put in place when an organisation makes a decision about someone using only automated processing, without meaningful human involvement, where that decision has a significant effect on them. Under the GDPR framework, individuals generally have a right not to be subject to such decisions unless a specific exception applies, and where those decisions are permitted the individual is typically entitled to protections such as human review. The precise scope depends on how the decision and its effect are assessed in each case.

Formal definition

The term refers to the protective measures attaching to decisions based solely on automated processing, including profiling, that produce legal effects concerning the data subject or similarly significantly affect them, as addressed in Article 22 of the GDPR and the UK GDPR. Article 22 generally establishes a right for the data subject not to be subject to such solely automated decisions, subject to defined exceptions, and where an exception applies the controller must implement suitable safeguards for the data subject's rights, freedoms and legitimate interests. The application of these safeguards is contingent on the decision meeting the definitional threshold of being made solely by automated processing and having the requisite significant effect, and the reader should note that the UK regime has been subject to legislative change (for example provisions described as Article 22C under the DUAA), so the position may differ between the EU GDPR and UK law and should be verified against the current official text and applicable regulatory guidance. Special category data and the interaction with Article 9 conditions, as well as member state or national derogations, may vary the position and are not fully resolved by Article 22 alone.

Why it matters

Automated decision-making increasingly shapes outcomes that carry real consequences for individuals, from access to credit and employment to eligibility for services. Where a decision is made solely by automated processing and has a legal or similarly significant effect, the GDPR framework generally establishes a right for the individual not to be subject to that decision unless a defined exception applies. Safeguards for automated decisions exist to prevent people from being subjected to opaque, unchallengeable outcomes and to preserve their rights, freedoms and legitimate interests when such processing is permitted.

For organisations, these safeguards matter because they mark the difference between lawful and unlawful automated processing. Article 22 of the GDPR and the UK GDPR does not treat all automation the same way: the protections attach only where a decision meets the threshold of being made solely by automated processing and having the requisite significant effect. Misjudging that threshold, or deploying an automated system without the human review and other protections expected where an exception is relied upon, can expose an organisation to regulatory scrutiny and complaints from affected individuals.

The position is also in flux and should be handled with care. The UK regime has been subject to legislative change, including provisions described as Article 22C under the DUAA, meaning the EU GDPR and UK law may diverge. Organisations should verify the applicable rules against the current official text and relevant regulatory guidance, and should not assume that a treatment lawful in one regime is automatically lawful in the other.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams need to identify which of their organisation's processing activities involve decisions made solely by automated means with a significant effect, and to confirm whether an exception is being relied upon. They are typically responsible for ensuring that suitable safeguards, such as arrangements for human review, are documented and operational, and for monitoring whether the EU GDPR or UK regime (including changes such as those described under the DUAA) applies to a given activity.
Engineers and Product Teams Building Automated Systems
Those designing and deploying automated decision-making or profiling systems should understand when a decision is treated as made solely by automated processing, since that threshold determines whether Article 22-type safeguards attach. Building in meaningful human involvement or a mechanism for human review can affect whether a decision falls within scope, and engineers should coordinate with legal and compliance colleagues on where that boundary sits.
Privacy and Technology Lawyers
Lawyers advising on automated processing must assess whether a decision meets the definitional threshold, which exception (if any) supports it, and what safeguards are required where the processing is permitted. They should also advise on divergence between the EU GDPR and UK law, the interaction with special category data and Article 9 conditions, and the need to verify the position against the current official text and applicable regulatory guidance rather than a fixed snapshot.
Individuals Subject to Automated Decisions
People affected by decisions made solely through automated processing generally have a right not to be subject to such decisions unless an exception applies, and where those decisions are permitted they are typically entitled to protections such as human review. The precise scope of these rights depends on how the decision and its effect are assessed and on whether the EU or UK regime governs the processing.

Inside Safeguards for Automated Decisions

Right not to be subject to solely automated decisions
Article 22 GDPR generally gives data subjects the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them. The scope of 'solely automated' and 'similarly significantly affects' is subject to interpretation and regulatory guidance, and its application should be assessed case by case.
Permitted exceptions
Solely automated decision-making of the kind described is generally permitted where it is necessary for entering into or performing a contract, is authorised by Union or member state law to which the controller is subject, or is based on the data subject's explicit consent. National implementing law and member state derogations can vary the available grounds, so the position should be verified against the applicable law.
Suitable safeguards
Where solely automated decision-making is permitted under the contract or explicit consent grounds, the controller is generally required to implement suitable measures to safeguard the data subject's rights, freedoms, and legitimate interests. These typically include, at minimum, the right to obtain human intervention, to express a point of view, and to contest the decision.
Human intervention
A core safeguard is the ability of the data subject to obtain intervention by a human on the controller's side. To be meaningful, this generally involves review by someone with the authority and competence to alter the decision, rather than a token or purely nominal check; the precise threshold is informed by regulatory guidance.
Transparency and information duties
Controllers generally must inform data subjects about the existence of automated decision-making, including profiling, and provide meaningful information about the logic involved and the significance and envisaged consequences of the processing. The exact extent of 'meaningful information about the logic' is subject to ongoing interpretation and guidance.
Special category data limits
Where solely automated decisions rely on special category data under Article 9, additional constraints generally apply. Such processing is typically only permissible on narrower grounds, and an Article 9 condition must be satisfied in addition to an Article 6 legal basis. This should be assessed carefully before deployment.

Common questions

Answers to the questions practitioners most commonly ask about Safeguards for Automated Decisions.

Does Article 22 mean that all automated decision-making is prohibited?
No. Article 22 does not ban automated processing generally. It addresses a specific category: decisions based solely on automated processing, including profiling, that produce legal effects concerning the individual or similarly significantly affect them. Automated processing that involves meaningful human involvement, or that does not reach that threshold of effect, falls outside the specific Article 22 rule (though other GDPR obligations still apply). The scope of what counts as 'solely' automated and 'similarly significantly affects' is subject to regulatory guidance and case law interpretation, so each situation should be assessed on its facts.
Is individual consent always required before making an automated decision covered by Article 22?
No. Consent is only one of the recognised grounds on which a decision within Article 22 may be permitted. Generally, such a decision may be allowed where it is necessary for entering into or performing a contract, where it is authorised by Union or member state law to which the controller is subject, or where it is based on the individual's explicit consent. Which ground applies depends on the circumstances, and where special category data is involved additional conditions typically apply. Treating consent as the universal requirement is a common misconception.
What safeguards should we put in place when relying on contract or explicit consent as the basis for a qualifying automated decision?
In cases where a qualifying automated decision is permitted on the basis of contractual necessity or explicit consent, the controller should generally implement suitable measures to safeguard the individual's rights, freedoms and legitimate interests. These typically include, at a minimum, the ability to obtain human intervention, to express one's point of view, and to contest the decision. The precise measures depend on the risk and context, so a documented assessment of the appropriate safeguards is advisable rather than a fixed checklist.
How can we design meaningful human involvement so that a decision is not treated as 'solely' automated?
Guidance generally indicates that human involvement must be genuine and substantive rather than a token or rubber-stamp step. Typically this means a person with appropriate authority and competence reviews the relevant information and can actually influence or override the outcome, rather than routinely confirming a system's output. Whether involvement is sufficient to take a decision outside 'solely' automated processing is a fact-specific assessment, and organisations should document how and where human judgment is exercised. The exact boundary remains an area shaped by regulatory guidance.
What information should individuals receive about automated decision-making that falls within this area?
Where the relevant conditions apply, transparency obligations generally require informing the individual about the existence of automated decision-making, and providing meaningful information about the logic involved, as well as the significance and envisaged consequences of the processing for them. 'Meaningful information about the logic' does not typically require disclosure of proprietary algorithms in full technical detail, but should enable the individual to understand the basis of the decision. The appropriate level of explanation is subject to interpretation and evolving guidance, so this should be verified against current official sources.
How should we handle a request from an individual who wants to contest an automated decision?
As a general matter, the safeguards contemplated for qualifying automated decisions include enabling the individual to express their point of view, to contest the decision, and to obtain human intervention. In practice this usually means having a defined process for receiving such requests, routing them to a person able to review the outcome, considering the individual's submissions, and being able to reach a reviewed decision. The specific handling, timeframes and record-keeping should be aligned with the controller's broader obligations and assessed in context rather than assumed to be uniform across all cases.

Common misconceptions

All automated processing is prohibited or requires opt-in consent.
The Article 22 protection generally applies to decisions based solely on automated processing that produce legal or similarly significant effects, not to all automated processing or profiling. Where it applies, consent is only one of several possible grounds; contract necessity and authorisation by Union or member state law can also apply, subject to assessment.
Any human touching the process removes it from Article 22.
A decision can still be treated as 'solely' automated if human involvement is nominal or lacks real authority to change the outcome. Meaningful human intervention generally requires competence and authority to alter the decision. The precise boundary is informed by regulatory guidance and should be assessed on the facts.
Safeguards are satisfied simply by disclosing that automation is used.
Transparency is one element, but where the Article 22 grounds of contract or explicit consent are relied on, controllers generally must also provide at least the right to human intervention, to express a point of view, and to contest the decision. Disclosure alone typically does not meet the full safeguard obligation.

Best practices

Assess and document whether a given decision is 'solely' automated and whether it produces legal or similarly significant effects before treating Article 22 as applicable or inapplicable.
Identify and record the specific permitted ground (contract necessity, authorisation by Union or member state law, or explicit consent), and verify the position against applicable national implementing law and any derogations.
Implement meaningful human review conducted by someone with the competence and authority to alter the decision, and establish operational routes for data subjects to express their view and contest outcomes.
Provide clear information about the existence of automated decision-making and the significance and envisaged consequences, and provide meaningful information about the logic involved, keeping disclosures current with evolving guidance.
Where special category data is involved, confirm that a valid Article 9 condition and the applicable narrower grounds are satisfied in addition to an Article 6 basis, and reassess before deployment.
Review the arrangement periodically against updated regulatory guidance and verify article references and requirements against the current official text rather than relying on a fixed snapshot.