01/05/2025 - Since the General Data Protection Regulation (GDPR) took effect in 2018, data subjects have been afforded the right to avoid decisions based solely on automated processing when those decisions carry legal or similarly significant effects. In recent months, several key legal developments have shaped the interpretation, transparency obligations and enforcement of this right. These changes reflect the rapid growth of algorithmic decision-making since the GDPR’s introduction. This blog will explore these developments and explain their practical impact on data subjects and businesses subject to the GDPR.
What does the GDPR say?
Under Article 22 GDPR, Organizations are generally prohibited from solely automated decision-making which would produce legal or similar significant effects on the data subject. Keep in mind, this general prohibition only relates to decision taken solely by automated means. Organizations are authorized to make decisions by automated means where those decisions are accompanied by human intervention.
Organizations are only allowed to take a solely automated decision about someone in one of the following cases:
Furthermore, Article 15 GDPR requires organizations to transparently disclose the use of automated decision making, and, if requested, to provide “meaningful information about the logic involved, as well as the significance and the envisaged consequences” of such decision for the individual concerned.
Transparency of Automated Decision Making:
In February of this year, the Court of Justice of the European Union (CJEU) handed down a significant judgement in Case C-203/22 concerning individuals right to request access to their personal data, specifically as it related to automated decision-making. In that case, an individual was denied a mobile phone contract because the network operator determined they lacked sufficient creditworthiness on the basis of an automated credit assessment provided by a third party.
In cases of automated decision making, the CJEU ruled that data controllers must provide concise, transparent, intelligible, and easily accessible explanations of “the procedure and principles actually applied”, by automated means, to the individuals personal data to arrive at a specific result. Failing this, organizations could not meet their Article 15 GDPR obligations (described above). According to the CJEU a “mere communication of a complex mathematical formula, such as an algorithm, or by the detailed description of all the steps in automated decision-making” is not enough to satisfy this obligation, as this would not “constitute a sufficiently concise and intelligible explanation”.
But what does this mean practically? For many organizations utilizing solely automated decision-making, this judgement would at a minimum require a rewording of their privacy statements. It’s not enough to simply disclose that you use automated decision-making. Organizations will be required to intelligently formulate a concise description that clearly explains how a decision was reached on the basis of an individual’s personal data by automated means. This will have to be in a language that the individual understands, and to be produced on request by the individual concerned. Considering the complexity of these procedures, this is no easy task.
“Meaningful” human intervention:
As mentioned above, the general prohibition provided under Article 22 GDPR only applies to solely automated decision-making. In its Guidelines on Automated individual decision-making and Profiling, the European Data Protection Board (EDPB) clarified this distinction by explaining: “Solely automated decision-making is the ability to make decisions by technological means without human involvement”. They further clarify that an organization cannot avoid the obligations laid out in Article 22 GDPR (listed above) by fabricating human involvement. In the EDPBs words: “To qualify as human involvement, the controller must ensure that any oversight of the decision is meaningful, rather than just a token gesture.”
Unfortunately, there has been a lack of clarity regarding what meaningful human involvement means. Recognizing this uncertainty, on 6 March 2025, the Dutch Data Protection Authority (AP) initiated a public consultation on tools for meaningful human intervention in algorithmic decision-making. The intention is to create a tool for those within an organization who design and implement human intervention, and for those who carry out the human intervention. In its preliminary Outline, the AP explains, to be meaningful, the person who “intervenes” must be able to adequately assess whether the decision is justified in a particular case. That requires possession of all relevant factors concerning the decision, and possession of sufficient knowledge and skill on the part of the assessor.
The AP has concluded the consultation process and have published their results on the AP Website.
As developments in this area continue to unfold, we at Considerati remain committed to providing timely and practical support. We are ready to assist your organization in updating transparency statements and evaluating whether your automated decision-making processes align with the standards for meaningful human oversight. If your organization is seeking clarity on compliance support, we invite you to contact our team for a consultation. Let us help you navigate these evolving requirements with confidence.
Would you like to learn how your organisation can meet the AI literacy requirements? Contact us for training or tailored advice.
Our services ContactRecente blogs
The right of access is one of the fundamental rights in the General Data Protection Regulation (GDPR). In this blog, we outline the main pitfalls from…