Short answer. GDPR Article 22 gives every person in the EU the right not to be subject to a decision based solely on automated processing, including profiling, when that decision produces legal effects or similarly significant effects. It has applied since 25 May 2018. A bank that auto-rejects a loan below a credit-score threshold with no meaningful human review falls under this rule. Non-compliance carries fines up to EUR 20 million or 4% of global annual turnover.
Article 22 targets decisions made “solely” by a machine that carry weight for a person: a loan refusal, an insurance premium, a job screening. Two conditions trigger it. The decision is fully automated, and it produces a legal or similarly significant effect on the individual. When both hold, the processing is prohibited unless one of three grounds applies: the decision is necessary for a contract, authorized by EU or member-state law, or based on the person’s explicit consent.
Even under one of those grounds, the controller must add safeguards. The person keeps the right to obtain human intervention, to express their point of view, and to contest the outcome. In practice this is where most banking and insurance workflows fall short: the automated score exists, but the override path and the explanation do not.
Enforcement is concrete. In September 2025 the Hamburg data protection authority fined a financial services provider close to EUR 500,000 for using automated creditworthiness assessment in credit-card applications without explaining the logic or providing the Article 22 safeguards.
For banks and insurers in Slovakia, Czechia, and Austria, automated scoring is standard operating practice. Article 22 has bound every EU controller since 25 May 2018, so this is settled law, not a future obligation. What has changed is enforcement and case law, which now reach the exact models that price credit and insurance. GDPR fines run to EUR 20 million or 4% of worldwide annual turnover, whichever is higher, and a supervisory authority can order the processing to stop.
The EU AI Act adds a second layer on the same decision. From 2 August 2026, creditworthiness assessment for consumers and risk assessment and pricing for life and health insurance count as high-risk under Annex III. That classification triggers human oversight under Article 14, technical documentation, logging, and a right to explanation of individual decisions under Article 86. Meeting Article 22 does not discharge the AI Act, and meeting the AI Act does not discharge Article 22. Both apply to the same credit refusal at the same time.
GDPR Article 22 bars solely automated decisions with legal or significant effect unless a lawful ground and safeguards apply, in force since 25 May 2018.
The Court of Justice of the EU answered this in the SCHUFA ruling, Case C-634/21, decided on 7 December 2023. The court held that calculating a credit-score probability value is itself an automated decision under Article 22 when a third party, such as a bank, draws strongly on that value to grant or refuse a contract. Before this judgment, credit bureaus argued the score was only an input and that the lender made the real decision.
The court closed that gap. If the score in practice determines the outcome in almost all cases, the agency that produces it is making the Article 22 decision, and the obligations attach to it. For CEE lenders that rely on bureau scores, this means the scoring provider and the bank can both carry duties toward the applicant, not just the party who sends the rejection letter.
The reference point is Dun & Bradstreet Austria, Case C-203/22, decided on 27 February 2025. An Austrian applicant, CK, was refused a mobile contract after a negative automated credit assessment. The CJEU confirmed a genuine right to explanation under Article 15(1)(h). The controller must describe the procedure and the principles actually applied, so the person can understand how their specific data led to the result, in a concise, transparent, and intelligible form.
A raw dump of the algorithm or a bare list of variables does not satisfy this. The explanation has to be meaningful to the individual. Trade secrets do not override the right either: where a controller claims confidentiality, it must hand the protected information to the supervisory authority or the court, which then balances the competing interests. Banks and insurers can no longer hide a rejection behind “the model decided.”
Only when the review is real. The safeguard in Article 22(3) is meaningful human intervention: a person with the authority and the competence to review the file and change the outcome. A rubber-stamp sign-off, where an officer approves the model output without assessing it, does not move the decision out of “solely automated.” Regulators read the word “solely” by substance, not by whether a human name appears on the record.
For a lender, that sets a clear test. The reviewer has to understand the credit logic, see the applicant’s data, and hold the mandate to override the score. A workflow where the human clicks approve on 500 files an hour is a formal signature, not an intervention, and it leaves the bank exposed under both Article 22 and the EU AI Act.
They stack rather than replace each other. Article 22 is a data-protection right that the individual holds and can invoke directly. The EU AI Act is product regulation that the provider and the deployer of a high-risk system must satisfy before and during use. From 2 August 2026, an AI system that scores consumer creditworthiness or prices life and health insurance is high-risk under Annex III.
The deployer then has to ensure human oversight under Article 14, keep logs, run the system against its documentation, and honor the affected person’s right to a clear explanation of the AI’s role under Article 86. A single automated loan refusal can trigger Article 22 safeguards, Article 15 access rights, and the full high-risk regime at once. Programs that treat these as one governance effort, rather than three disconnected projects, avoid building the same control three times.
Map every decision point where a model output determines an outcome for a person: lending, pricing, fraud blocking, onboarding, claims triage. For each one, record the Article 22 legal basis, the safeguards in place, and whether a competent human can actually override the result. Then write the explanation you would hand a rejected applicant and test whether a non-specialist can follow it.
Most gaps surface at that last step. The score exists, the override path does not, and no one can state in plain language why the applicant was refused. Fixing that order, decision inventory first, override and explanation second, turns a compliance risk into a documented, defensible process before an audit or a complaint arrives.
Ableneo builds these controls into production systems for regulated clients rather than adding them before an audit. In 2025 the team shipped 34 production AI projects, and about 4 of 5 reach production instead of stalling as pilots. Work across banking and insurance in Slovakia, Czechia, and Austria means the governance layer, human-override paths, decision logs, and explanation templates, is designed alongside the model from the start. See how this connects to the wider compliance picture in the Ableneo AI transformation FAQ.
Key takeaways
Planning AI in a regulated business? Ableneo takes systems from classification to governed production.