AI Regulation Tracker · EU AI Act · Statute

What does GDPR Article 22 say about AI in banking?

Published May 4, 2016 · Last reviewed Aug 26, 2026

Article 22 of the General Data Protection Regulation (Regulation (EU) 2016/679, applicable since May 25, 2018) gives individuals the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects — with automated credit refusal the textbook example. Such decisions are allowed only where necessary for a contract, authorised by EU or member-state law, or based on explicit consent, and then only with safeguards including the right to obtain human intervention, express a view and contest the decision. Articles 13–15 add a duty to provide meaningful information about the logic involved.

DocumentGDPR Article 22Regulation (EU) 2016/679 (GDPR), Article 22 — Automated individual decision-making, including profiling
Issued byRegulation (EU) 2024/1689 — the EU Artificial Intelligence Act
TypeStatute
StatusIn force
PublishedMay 4, 2016
EffectiveMay 25, 2018
Applies toAny controller processing personal data of individuals in the EU, including banks making automated credit decisions
Official sourceeur-lex.europa.eu
Use casesCredit scoring & underwriting · Data & privacy · Fair lending & discrimination · Customer-facing chatbots

What are the key points of GDPR Article 22?

  • Art. 22(1): right not to be subject to a solely automated decision with legal or similarly significant effects; Recital 71 names automatic refusal of an online credit application.
  • Art. 22(2) exceptions: necessary for entering or performing a contract, authorised by law with suitable safeguards, or explicit consent.
  • Art. 22(3) safeguards: at least the right to human intervention, to express one's point of view and to contest the decision.
  • Art. 22(4): decisions may not be based on special-category data (e.g., health, ethnicity) unless Art. 9(2)(a) or (g) applies with safeguards.
  • Arts. 13(2)(f), 14(2)(g), 15(1)(h): duty to disclose the existence of automated decision-making and meaningful information about the logic, significance and envisaged consequences.
  • CJEU, SCHUFA (C-634/21, December 7, 2023): a credit-bureau score is itself an Art. 22 'decision' where a lender draws strongly on it — extending the regime to scoring vendors.
  • Fines up to €20M or 4% of worldwide annual turnover (Art. 83(5)).

What did GDPR Article 22 change for banks?

Article 22 was the EU's operative rule on algorithmic credit decisions for six years before the AI Act and remains fully in force alongside it: the AI Act governs how a high-risk system is built and monitored, while Article 22 governs whether and how a bank may rely on it for an individual decision. The SCHUFA judgment pulled scoring providers into scope, and the Digital Omnibus on AI also clarified the AI Act–GDPR interface.

Does GDPR Article 22 ban automated credit decisions?

No. It restricts solely automated decisions with significant effects to three lawful gateways — contractual necessity, legal authorisation or explicit consent — and requires safeguards such as human intervention and the right to contest. Most bank credit decisions rely on contractual necessity.

How does GDPR Article 22 interact with the EU AI Act for credit scoring?

They stack. The AI Act's Annex III 5(b) regime covers the system's design, data, documentation and oversight; Article 22 covers the individual's rights when a decision is automated. Compliance with one does not satisfy the other.

DateDocumentStatus
Jul 24, 2026Regulation (EU) 2026/1744 (Digital Omnibus on AI)Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)In force
May 19, 2026Draft Commission guidelines on high-risk classificationDraft Commission Guidelines on the classification of high-risk AI systems under Article 6 of the AI ActProposed
Nov 21, 2025EBA factsheet on the AI ActAI Act: implications for the EU banking and payments sector (EBA factsheet)Final
Jul 10, 2025General-Purpose AI Code of PracticeGeneral-Purpose AI Code of Practice under the AI Act (Transparency, Copyright, and Safety and Security chapters)In force
Feb 4, 2025Commission guidelines on prohibited AI practicesCommission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act)In force
Jul 12, 2024Regulation (EU) 2024/1689Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)In force

Follow every document these regulators publish

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →