# Article 22 review checklist — solely automated decisions

> Run this whenever a system informs a decision about a person. It takes about twenty minutes
> and is the single cheapest way to avoid the most expensive GDPR mistake in AI deployment.
> Fines for Article 22 breaches sit in the 4% / €20M tier.

**System:** · **Assessor:** · **Date:**

---

## Step 1 — Is it in scope?

| | Yes | No |
|---|---|---|
| Is a decision made about an identified or identifiable person? | ☐ | ☐ |
| Is that decision based on automated processing, including profiling? | ☐ | ☐ |

If either is "No", Article 22 does not apply. Record the reasoning and stop.

## Step 2 — Is it *solely* automated?

Human involvement only defeats "solely" where it is **meaningful**. Test honestly:

| | Yes | No |
|---|---|---|
| Does a human review each decision before it takes effect? | ☐ | ☐ |
| Does that person have the **authority** to change the outcome? | ☐ | ☐ |
| Do they have the **competence** to evaluate the recommendation? | ☐ | ☐ |
| Do they see enough information to form an independent view? | ☐ | ☐ |
| Do they have realistic **time** to do so? (Volume ÷ headcount — be honest) | ☐ | ☐ |
| Is there evidence they actually overturn outputs sometimes? | ☐ | ☐ |

> If reviewers approve essentially everything, you have a rubber stamp, not human involvement.
> Track the override rate — it is the evidence a regulator will ask for.

**Conclusion:** ☐ Solely automated ☐ Meaningful human involvement (record evidence)

## Step 3 — Legal or similarly significant effect?

Likely **yes**: credit, employment or promotion, insurance pricing, access to education,
benefits or public services, account closure, housing, pricing that materially excludes.

Likely **no**: routine personalisation with a trivial effect, internal prioritisation not
affecting outcomes.

**Conclusion:** ☐ Significant effect ☐ No significant effect

> If Steps 2 and 3 are both "yes", the processing is **prohibited** unless Step 4 applies.

## Step 4 — Exception (Art. 22(2))

| Exception | Applies? | Justification |
|---|---|---|
| (a) Necessary for entering into or performing a contract | ☐ | |
| (b) Authorised by EU or member-state law | ☐ | |
| (c) Explicit consent | ☐ | |

No exception → **do not deploy** as a solely automated decision. Introduce genuine human review
or change the design.

## Step 5 — Safeguards (Art. 22(3)) — mandatory where (a) or (c) is relied on

| Safeguard | In place? | How it works |
|---|---|---|
| Right to obtain human intervention | ☐ | |
| Right to express a point of view | ☐ | |
| Right to contest the decision | ☐ | |
| Route is communicated to the person at decision time | ☐ | |
| Staff are trained and resourced to handle challenges | ☐ | |
| Challenge outcomes are logged and reviewed for patterns | ☐ | |

## Step 6 — Special category data (Art. 22(4))

Does the decision rely on Art. 9 data? ☐ No ☐ Yes

If yes, it is permitted **only** under Art. 9(2)(a) explicit consent or 9(2)(g) substantial
public interest, with suitable safeguards. Record which:

## Step 7 — Transparency (Arts. 13(2)(f) / 14(2)(g) / 15(1)(h))

| | Done | Where |
|---|---|---|
| Existence of automated decision-making disclosed | ☐ | |
| Meaningful information about the logic involved | ☐ | |
| Significance and envisaged consequences explained | ☐ | |
| Explanation is intelligible to a non-expert | ☐ | |

> "Meaningful information about the logic" does not mean publishing the model. It means the
> factors used, their broad weighting, and what a person could change. The "right to an
> explanation" of a *specific* decision appears in Recital 71, which is not binding.

---

## Outcome

☐ Out of scope ☐ Compliant ☐ Compliant with conditions ☐ Must not deploy as automated

**Conditions and owners:**

**Reviewed by:** **Date:** **Next review:**
