Skip to main content
v2026.11,772 entries · CC-BY 4.0
Dictionary termTrack DProposedv2026.1

GDPR Article 22 (Automated Decision-Making in Research)

GDPR Article 22(1) gives a data subject 'the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.' A research activity triggers Article 22 only if all three elements hold at once: (1) the decision is made solely by an automated system, with no meaningful human involvement in reaching the specific outcome -- a human merely rubber-stamping an algorithmic output does not count as meaningful involvement, but a human who genuinely reviews the case and can depart from the system's recommendation does; (2) the processing includes profiling or another automated evaluation of the person, not just automated data collection or storage; and (3) the decision produces a legal effect or similarly significant effect on that individual -- something that meaningfully affects their circumstances, behaviour, or choices, not a trivial or cosmetic outcome. In a research context this most commonly arises where an AI/ML system automatically screens, ranks, or excludes real individuals as part of a study -- for example, a clinical-trial-eligibility screening tool that auto-rejects applicants, or an automated participant-selection or risk-stratification algorithm that determines who is invited, enrolled, or offered an intervention -- as opposed to a model that only analyses aggregate or already-anonymised data with no decision made about a specific identifiable person. Article 22(2) narrows this to a qualified right rather than an absolute prohibition: solely automated decisions with legal/significant effect are permitted where (a) necessary for entering into or performing a contract, (b) authorised by Union or Member State law that also lays down suitable safeguards, or (c) based on the data subject's explicit consent. Where (a) or (c) applies, Article 22(3) requires the controller to implement suitable safeguards -- at minimum the right to obtain human intervention, to express a point of view, and to contest the decision. Article 22(4) adds a further restriction: these decisions must not be based on special category data (Article 9(1) -- including data concerning health, which covers most clinical and biomedical research) unless a specific Article 9(2)(a) or (g) exemption applies and suitable safeguards are in place. For research controllers, this means an automated eligibility or selection tool operating on health or genetic data faces a materially higher bar than one operating on non-sensitive data, even where a general Article 6 lawful basis for the underlying processing is otherwise sound.

ByCASRAI Editorial Board
· Last updated 4 Sept 2026
Share this

Ask CASRAI · included with Regulatory Radar

Ask about GDPR Article 22 (Automated Decision-Making in Research)

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Examples

Worked examples

  • Is an instance

    An AI-based clinical-trial-eligibility screening tool ingests a prospective participant's health records and automatically rejects them as ineligible with no case-by-case human review of individual rejections -- this is a solely automated decision producing a significant effect (exclusion from a trial and its potential benefits) on an identifiable, real individual, and because it operates on health data, it also engages the Article 22(4) special-category restriction.

  • Is an instance

    A university research team uses a machine-learning model to automatically rank and select which members of a recruited cohort receive a scarce follow-up intervention, with the model's output directly determining enrollment and no researcher reviewing individual allocations before they take effect -- this falls within Article 22(1) because the automated ranking alone determines a real-world outcome (who receives the intervention) for identifiable people.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A machine-learning model analyses a fully anonymised, aggregate dataset to identify population-level risk patterns and produces summary statistics with no decision made about, or effect on, any specific identifiable individual -- Article 22 does not apply because there is no 'decision' concerning a data subject, only aggregate analysis.

  • Not an instance

    An automated tool flags candidates as potentially eligible for a study, but a researcher independently reviews each flagged case, has genuine discretion to overrule the flag, and makes the actual enrollment decision -- this is not 'solely' automated processing under EDPB guidance, because there is meaningful human involvement in the specific outcome, even though software assisted the process.

Editorial commentary

GDPR Article 22(1) gives a data subject ‘the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.’ A research activity triggers Article 22 only if all three elements hold at once: (1) the decision is made solely by an automated system, with no meaningful human involvement in reaching the specific outcome — a human merely rubber-stamping an algorithmic output does not count as meaningful involvement, but a human who genuinely reviews the case and can depart from the system’s recommendation does; (2) the processing includes profiling or another automated evaluation of the person, not just automated data collection or storage; and (3) the decision produces a legal effect or similarly significant effect on that individual — something that meaningfully affects their circumstances, behaviour, or choices, not a trivial or cosmetic outcome. In a research context this most commonly arises where an AI/ML system automatically screens, ranks, or excludes real individuals as part of a study — for example, a clinical-trial-eligibility screening tool that auto-rejects applicants, or an automated participant-selection or risk-stratification algorithm that determines who is invited, enrolled, or offered an intervention — as opposed to a model that only analyses aggregate or already-anonymised data with no decision made about a specific identifiable person.

Article 22(2) narrows this to a qualified right rather than an absolute prohibition: solely automated decisions with legal/significant effect are permitted where (a) necessary for entering into or performing a contract, (b) authorised by Union or Member State law that also lays down suitable safeguards, or (c) based on the data subject’s explicit consent. Where (a) or (c) applies, Article 22(3) requires the controller to implement suitable safeguards — at minimum the right to obtain human intervention, to express a point of view, and to contest the decision. Article 22(4) adds a further restriction: these decisions must not be based on special category data (Article 9(1) — including data concerning health, which covers most clinical and biomedical research) unless a specific Article 9(2)(a) or (g) exemption applies and suitable safeguards are in place. For research controllers, this means an automated eligibility or selection tool operating on health or genetic data faces a materially higher bar than one operating on non-sensitive data, even where a general Article 6 lawful basis for the underlying processing is otherwise sound.

The three-element test, applied to research

A research activity triggers Article 22 only when all three elements are present at once: a decision made solely by automated processing (no meaningful human involvement in the specific outcome — a human who merely rubber-stamps an algorithmic output does not count, but genuine case-by-case review with real discretion to depart from the recommendation does); processing that includes profiling or another automated evaluation of the person, not just automated storage or retrieval; and a decision producing a legal effect or similarly significant effect on that individual. The European Data Protection Board (successor to the Article 29 Working Party) frames “meaningful” human involvement as requiring a reviewer with real authority and competence to change the outcome who actually exercises it, not a nominal sign-off step.

Where this shows up in a research pipeline

In practice, Article 22 most commonly arises where an AI/ML system automatically screens, ranks, or excludes real, identifiable individuals as part of a study — an automated clinical-trial-eligibility screening tool that auto-rejects applicants, or a risk-stratification algorithm that alone determines who is invited, enrolled, or offered a scarce intervention. It generally does not apply to a model that analyses only aggregate or already-anonymised data, because there is no decision made about, or effect on, any specific identifiable data subject in that case.

The qualified right, and its safeguards

Article 22(2) narrows the Article 22(1) right to a qualified one rather than an absolute prohibition: solely automated decisions with legal or similarly significant effect are permitted where (a) necessary for entering into or performing a contract, (b) authorised by Union or Member State law that also lays down suitable safeguards, or (c) based on the data subject’s explicit consent. Where (a) or (c) is the basis, Article 22(3) requires the controller to implement at least the right to obtain human intervention, to express a point of view, and to contest the decision.

The extra bar for health and other special category data

Article 22(4) adds a further restriction specific to research: these automated decisions must not be based on Article 9(1) special category data — which includes data concerning health, and therefore covers most clinical and biomedical research — unless a specific Article 9(2)(a) (explicit consent) or 9(2)(g) (substantial public interest, with a Member State/Union law basis) exemption applies, alongside suitable safeguards. In practice, this means an automated eligibility or selection tool operating on health or genetic data faces a materially higher compliance bar than one operating on non-sensitive data, even where the underlying processing already has a sound general Article 6 lawful basis.

Worked examples

  • An AI-based clinical-trial-eligibility screening tool ingests a prospective participant’s health records and automatically rejects them as ineligible with no case-by-case human review of individual rejections — this is a solely automated decision producing a significant effect (exclusion from a trial and its potential benefits) on an identifiable, real individual, and because it operates on health data, it also engages the Article 22(4) special-category restriction.
  • A university research team uses a machine-learning model to automatically rank and select which members of a recruited cohort receive a scarce follow-up intervention, with the model’s output directly determining enrollment and no researcher reviewing individual allocations before they take effect — this falls within Article 22(1) because the automated ranking alone determines a real-world outcome (who receives the intervention) for identifiable people.

Counter-examples

  • A machine-learning model analyses a fully anonymised, aggregate dataset to identify population-level risk patterns and produces summary statistics with no decision made about, or effect on, any specific identifiable individual — Article 22 does not apply because there is no ‘decision’ concerning a data subject, only aggregate analysis.
  • An automated tool flags candidates as potentially eligible for a study, but a researcher independently reviews each flagged case, has genuine discretion to overrule the flag, and makes the actual enrollment decision — this is not ‘solely’ automated processing under EDPB guidance, because there is meaningful human involvement in the specific outcome, even though software assisted the process.

Related terms

Frequently Asked Questions

Does Article 22 ban using AI to screen research participants?

No — it does not ban automated screening outright. It gives data subjects a right not to be subject to a decision based solely on automated processing with a legal or similarly significant effect, subject to the exceptions in Article 22(2) (contract necessity, authorising law with safeguards, or explicit consent) and the mandatory safeguards in Article 22(3).

Does a human “final check” always take a decision outside Article 22?

Only if the human involvement is genuine and meaningful — real authority and competence to change the outcome, actually exercised on the specific case. A nominal or rubber-stamp sign-off does not remove the decision from Article 22’s scope, per EDPB guidance.

Why does health data make Article 22 harder to satisfy?

Article 22(4) adds a specific restriction: a solely automated decision with legal/significant effect cannot be based on Article 9(1) special category data (which includes health data) unless a 9(2)(a) explicit-consent or 9(2)(g) substantial-public-interest exemption applies, plus suitable safeguards — a materially higher bar than for non-sensitive data.

Does Article 22 apply to a model that only analyses anonymised, aggregate data?

Generally no — Article 22 requires a decision concerning an identifiable data subject. A model producing only population-level, non-identifying summary statistics is not making a “decision” about any specific individual in the sense Article 22 addresses.

Last verified 2026-07-23 via direct review of the GDPR Article 22 text (gdpr-info.eu/art-22-gdpr/) and EDPB/Article 29 Working Party guidance on meaningful human involvement. Stable, low-churn primary regulation text; re-verify if reused after roughly 12 months, or if new EDPB guidance revises the “meaningful human involvement” interpretation.

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="GDPR Article 22 (Automated Decision-Making in Research)"
      vocab-term-identifier="https://casrai.org/dictionary/term/gdpr-article-22-automated-decision-making-in-research" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/gdpr-article-22-automated-decision-making-in-research",
  "name": "GDPR Article 22 (Automated Decision-Making in Research)",
  "identifier": "https://casrai.org/dictionary/term/gdpr-article-22-automated-decision-making-in-research",
  "description": "GDPR Article 22(1) gives a data subject 'the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.' A research activity triggers Article 22 only if all three elements hold at once: (1) the decision is made solely by an automated system, with no meaningful human involvement in reaching the specific outcome -- a human merely rubber-stamping an algorithmic output does not count as meaningful involvement, but a human who genuinely reviews the case and can depart from the system's recommendation does; (2) the processing includes profiling or another automated evaluation of the person, not just automated data collection or storage; and (3) the decision produces a legal effect or similarly significant effect on that individual -- something that meaningfully affects their circumstances, behaviour, or choices, not a trivial or cosmetic outcome. In a research context this most commonly arises where an AI/ML system automatically screens, ranks, or excludes real individuals as part of a study -- for example, a clinical-trial-eligibility screening tool that auto-rejects applicants, or an automated participant-selection or risk-stratification algorithm that determines who is invited, enrolled, or offered an intervention -- as opposed to a model that only analyses aggregate or already-anonymised data with no decision made about a specific identifiable person. Article 22(2) narrows this to a qualified right rather than an absolute prohibition: solely automated decisions with legal/significant effect are permitted where (a) necessary for entering into or performing a contract, (b) authorised by Union or Member State law that also lays down suitable safeguards, or (c) based on the data subject's explicit consent. Where (a) or (c) applies, Article 22(3) requires the controller to implement suitable safeguards -- at minimum the right to obtain human intervention, to express a point of view, and to contest the decision. Article 22(4) adds a further restriction: these decisions must not be based on special category data (Article 9(1) -- including data concerning health, which covers most clinical and biomedical research) unless a specific Article 9(2)(a) or (g) exemption applies and suitable safeguards are in place. For research controllers, this means an automated eligibility or selection tool operating on health or genetic data faces a materially higher bar than one operating on non-sensitive data, even where a general Article 6 lawful basis for the underlying processing is otherwise sound.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/gdpr-article-22-automated-decision-making-in-research",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "author": {
    "@id": "https://casrai.org/#editorial-team"
  },
  "datePublished": "2026-07-23T09:04:11",
  "dateModified": "2026-09-04T07:20:14",
  "inLanguage": "en-GB",
  "isAccessibleForFree": true
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.