Article 22 of the General Data Protection Regulation (Regulation (EU) 2016/679, applicable since May 25, 2018) gives individuals the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects — with automated credit refusal the textbook example. Such decisions are allowed only where necessary for a contract, authorised by EU or member-state law, or based on explicit consent, and then only with safeguards including the right to obtain human intervention, express a view and contest the decision. Articles 13–15 add a duty to provide meaningful information about the logic involved.
| Document | GDPR Article 22 — Regulation (EU) 2016/679 (GDPR), Article 22 — Automated individual decision-making, including profiling |
| Issued by | Regulation (EU) 2024/1689 — the EU Artificial Intelligence Act |
| Type | Statute |
| Status | In force |
| Published | May 4, 2016 |
| Effective | May 25, 2018 |
| Applies to | Any controller processing personal data of individuals in the EU, including banks making automated credit decisions |
| Official source | eur-lex.europa.eu ↗ |
| Use cases | Credit scoring & underwriting · Data & privacy · Fair lending & discrimination · Customer-facing chatbots |
What are the key points of GDPR Article 22?
- Art. 22(1): right not to be subject to a solely automated decision with legal or similarly significant effects; Recital 71 names automatic refusal of an online credit application.
- Art. 22(2) exceptions: necessary for entering or performing a contract, authorised by law with suitable safeguards, or explicit consent.
- Art. 22(3) safeguards: at least the right to human intervention, to express one's point of view and to contest the decision.
- Art. 22(4): decisions may not be based on special-category data (e.g., health, ethnicity) unless Art. 9(2)(a) or (g) applies with safeguards.
- Arts. 13(2)(f), 14(2)(g), 15(1)(h): duty to disclose the existence of automated decision-making and meaningful information about the logic, significance and envisaged consequences.
- CJEU, SCHUFA (C-634/21, December 7, 2023): a credit-bureau score is itself an Art. 22 'decision' where a lender draws strongly on it — extending the regime to scoring vendors.
- Fines up to €20M or 4% of worldwide annual turnover (Art. 83(5)).
What did GDPR Article 22 change for banks?
Article 22 was the EU's operative rule on algorithmic credit decisions for six years before the AI Act and remains fully in force alongside it: the AI Act governs how a high-risk system is built and monitored, while Article 22 governs whether and how a bank may rely on it for an individual decision. The SCHUFA judgment pulled scoring providers into scope, and the Digital Omnibus on AI also clarified the AI Act–GDPR interface.
Does GDPR Article 22 ban automated credit decisions?
No. It restricts solely automated decisions with significant effects to three lawful gateways — contractual necessity, legal authorisation or explicit consent — and requires safeguards such as human intervention and the right to contest. Most bank credit decisions rely on contractual necessity.
How does GDPR Article 22 interact with the EU AI Act for credit scoring?
They stack. The AI Act's Annex III 5(b) regime covers the system's design, data, documentation and oversight; Article 22 covers the individual's rights when a decision is automated. Compliance with one does not satisfy the other.
| Date | Document | Status |
|---|---|---|
| Jul 24, 2026 | Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) | In force |
| May 19, 2026 | Draft Commission guidelines on high-risk classification — Draft Commission Guidelines on the classification of high-risk AI systems under Article 6 of the AI Act | Proposed |
| Nov 21, 2025 | EBA factsheet on the AI Act — AI Act: implications for the EU banking and payments sector (EBA factsheet) | Final |
| Jul 10, 2025 | General-Purpose AI Code of Practice — General-Purpose AI Code of Practice under the AI Act (Transparency, Copyright, and Safety and Security chapters) | In force |
| Feb 4, 2025 | Commission guidelines on prohibited AI practices — Commission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act) | In force |
| Jul 12, 2024 | Regulation (EU) 2024/1689 — Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) | In force |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →