Examples
Worked examples
- Is an instance
An AI-based clinical-trial-eligibility screening tool ingests a prospective participant's health records and automatically rejects them as ineligible with no case-by-case human review of individual rejections -- this is a solely automated decision producing a significant effect (exclusion from a trial and its potential benefits) on an identifiable, real individual, and because it operates on health data, it also engages the Article 22(4) special-category restriction.
- Is an instance
A university research team uses a machine-learning model to automatically rank and select which members of a recruited cohort receive a scarce follow-up intervention, with the model's output directly determining enrollment and no researcher reviewing individual allocations before they take effect -- this falls within Article 22(1) because the automated ranking alone determines a real-world outcome (who receives the intervention) for identifiable people.
Counter-examples
Looks similar, but isn't
- Not an instance
A machine-learning model analyses a fully anonymised, aggregate dataset to identify population-level risk patterns and produces summary statistics with no decision made about, or effect on, any specific identifiable individual -- Article 22 does not apply because there is no 'decision' concerning a data subject, only aggregate analysis.
- Not an instance
An automated tool flags candidates as potentially eligible for a study, but a researcher independently reviews each flagged case, has genuine discretion to overrule the flag, and makes the actual enrollment decision -- this is not 'solely' automated processing under EDPB guidance, because there is meaningful human involvement in the specific outcome, even though software assisted the process.
Editorial commentary
GDPR Article 22(1) gives a data subject ‘the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.’ A research activity triggers Article 22 only if all three elements hold at once: (1) the decision is made solely by an automated system, with no meaningful human involvement in reaching the specific outcome — a human merely rubber-stamping an algorithmic output does not count as meaningful involvement, but a human who genuinely reviews the case and can depart from the system’s recommendation does; (2) the processing includes profiling or another automated evaluation of the person, not just automated data collection or storage; and (3) the decision produces a legal effect or similarly significant effect on that individual — something that meaningfully affects their circumstances, behaviour, or choices, not a trivial or cosmetic outcome. In a research context this most commonly arises where an AI/ML system automatically screens, ranks, or excludes real individuals as part of a study — for example, a clinical-trial-eligibility screening tool that auto-rejects applicants, or an automated participant-selection or risk-stratification algorithm that determines who is invited, enrolled, or offered an intervention — as opposed to a model that only analyses aggregate or already-anonymised data with no decision made about a specific identifiable person.
Article 22(2) narrows this to a qualified right rather than an absolute prohibition: solely automated decisions with legal/significant effect are permitted where (a) necessary for entering into or performing a contract, (b) authorised by Union or Member State law that also lays down suitable safeguards, or (c) based on the data subject’s explicit consent. Where (a) or (c) applies, Article 22(3) requires the controller to implement suitable safeguards — at minimum the right to obtain human intervention, to express a point of view, and to contest the decision. Article 22(4) adds a further restriction: these decisions must not be based on special category data (Article 9(1) — including data concerning health, which covers most clinical and biomedical research) unless a specific Article 9(2)(a) or (g) exemption applies and suitable safeguards are in place. For research controllers, this means an automated eligibility or selection tool operating on health or genetic data faces a materially higher bar than one operating on non-sensitive data, even where a general Article 6 lawful basis for the underlying processing is otherwise sound.
The three-element test, applied to research
A research activity triggers Article 22 only when all three elements are present at once: a decision made solely by automated processing (no meaningful human involvement in the specific outcome — a human who merely rubber-stamps an algorithmic output does not count, but genuine case-by-case review with real discretion to depart from the recommendation does); processing that includes profiling or another automated evaluation of the person, not just automated storage or retrieval; and a decision producing a legal effect or similarly significant effect on that individual. The European Data Protection Board (successor to the Article 29 Working Party) frames “meaningful” human involvement as requiring a reviewer with real authority and competence to change the outcome who actually exercises it, not a nominal sign-off step.
Where this shows up in a research pipeline
In practice, Article 22 most commonly arises where an AI/ML system automatically screens, ranks, or excludes real, identifiable individuals as part of a study — an automated clinical-trial-eligibility screening tool that auto-rejects applicants, or a risk-stratification algorithm that alone determines who is invited, enrolled, or offered a scarce intervention. It generally does not apply to a model that analyses only aggregate or already-anonymised data, because there is no decision made about, or effect on, any specific identifiable data subject in that case.
The qualified right, and its safeguards
Article 22(2) narrows the Article 22(1) right to a qualified one rather than an absolute prohibition: solely automated decisions with legal or similarly significant effect are permitted where (a) necessary for entering into or performing a contract, (b) authorised by Union or Member State law that also lays down suitable safeguards, or (c) based on the data subject’s explicit consent. Where (a) or (c) is the basis, Article 22(3) requires the controller to implement at least the right to obtain human intervention, to express a point of view, and to contest the decision.
The extra bar for health and other special category data
Article 22(4) adds a further restriction specific to research: these automated decisions must not be based on Article 9(1) special category data — which includes data concerning health, and therefore covers most clinical and biomedical research — unless a specific Article 9(2)(a) (explicit consent) or 9(2)(g) (substantial public interest, with a Member State/Union law basis) exemption applies, alongside suitable safeguards. In practice, this means an automated eligibility or selection tool operating on health or genetic data faces a materially higher compliance bar than one operating on non-sensitive data, even where the underlying processing already has a sound general Article 6 lawful basis.
Worked examples
- An AI-based clinical-trial-eligibility screening tool ingests a prospective participant’s health records and automatically rejects them as ineligible with no case-by-case human review of individual rejections — this is a solely automated decision producing a significant effect (exclusion from a trial and its potential benefits) on an identifiable, real individual, and because it operates on health data, it also engages the Article 22(4) special-category restriction.
- A university research team uses a machine-learning model to automatically rank and select which members of a recruited cohort receive a scarce follow-up intervention, with the model’s output directly determining enrollment and no researcher reviewing individual allocations before they take effect — this falls within Article 22(1) because the automated ranking alone determines a real-world outcome (who receives the intervention) for identifiable people.
Counter-examples
- A machine-learning model analyses a fully anonymised, aggregate dataset to identify population-level risk patterns and produces summary statistics with no decision made about, or effect on, any specific identifiable individual — Article 22 does not apply because there is no ‘decision’ concerning a data subject, only aggregate analysis.
- An automated tool flags candidates as potentially eligible for a study, but a researcher independently reviews each flagged case, has genuine discretion to overrule the flag, and makes the actual enrollment decision — this is not ‘solely’ automated processing under EDPB guidance, because there is meaningful human involvement in the specific outcome, even though software assisted the process.
Related terms
- GDPR Article 5(1)(b) — purpose limitation and the research compatible-use carve-out.
- GDPR Article 6(1)(e) — the public-task lawful basis many public-sector research controllers rely on.
- GDPR Recital 33 — broad consent for scientific research.
- Data Protection Impact Assessment (DPIA) — an automated-decision-making research tool of this kind is a strong trigger for requiring a DPIA.
Frequently Asked Questions
Does Article 22 ban using AI to screen research participants?
No — it does not ban automated screening outright. It gives data subjects a right not to be subject to a decision based solely on automated processing with a legal or similarly significant effect, subject to the exceptions in Article 22(2) (contract necessity, authorising law with safeguards, or explicit consent) and the mandatory safeguards in Article 22(3).
Does a human “final check” always take a decision outside Article 22?
Only if the human involvement is genuine and meaningful — real authority and competence to change the outcome, actually exercised on the specific case. A nominal or rubber-stamp sign-off does not remove the decision from Article 22’s scope, per EDPB guidance.
Why does health data make Article 22 harder to satisfy?
Article 22(4) adds a specific restriction: a solely automated decision with legal/significant effect cannot be based on Article 9(1) special category data (which includes health data) unless a 9(2)(a) explicit-consent or 9(2)(g) substantial-public-interest exemption applies, plus suitable safeguards — a materially higher bar than for non-sensitive data.
Does Article 22 apply to a model that only analyses anonymised, aggregate data?
Generally no — Article 22 requires a decision concerning an identifiable data subject. A model producing only population-level, non-identifying summary statistics is not making a “decision” about any specific individual in the sense Article 22 addresses.
Last verified 2026-07-23 via direct review of the GDPR Article 22 text (gdpr-info.eu/art-22-gdpr/) and EDPB/Article 29 Working Party guidance on meaningful human involvement. Stable, low-churn primary regulation text; re-verify if reused after roughly 12 months, or if new EDPB guidance revises the “meaningful human involvement” interpretation.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="GDPR Article 22 (Automated Decision-Making in Research)"
vocab-term-identifier="https://casrai.org/dictionary/term/gdpr-article-22-automated-decision-making-in-research" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/gdpr-article-22-automated-decision-making-in-research",
"name": "GDPR Article 22 (Automated Decision-Making in Research)",
"identifier": "https://casrai.org/dictionary/term/gdpr-article-22-automated-decision-making-in-research",
"description": "GDPR Article 22(1) gives a data subject 'the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.' A research activity triggers Article 22 only if all three elements hold at once: (1) the decision is made solely by an automated system, with no meaningful human involvement in reaching the specific outcome -- a human merely rubber-stamping an algorithmic output does not count as meaningful involvement, but a human who genuinely reviews the case and can depart from the system's recommendation does; (2) the processing includes profiling or another automated evaluation of the person, not just automated data collection or storage; and (3) the decision produces a legal effect or similarly significant effect on that individual -- something that meaningfully affects their circumstances, behaviour, or choices, not a trivial or cosmetic outcome. In a research context this most commonly arises where an AI/ML system automatically screens, ranks, or excludes real individuals as part of a study -- for example, a clinical-trial-eligibility screening tool that auto-rejects applicants, or an automated participant-selection or risk-stratification algorithm that determines who is invited, enrolled, or offered an intervention -- as opposed to a model that only analyses aggregate or already-anonymised data with no decision made about a specific identifiable person. Article 22(2) narrows this to a qualified right rather than an absolute prohibition: solely automated decisions with legal/significant effect are permitted where (a) necessary for entering into or performing a contract, (b) authorised by Union or Member State law that also lays down suitable safeguards, or (c) based on the data subject's explicit consent. Where (a) or (c) applies, Article 22(3) requires the controller to implement suitable safeguards -- at minimum the right to obtain human intervention, to express a point of view, and to contest the decision. Article 22(4) adds a further restriction: these decisions must not be based on special category data (Article 9(1) -- including data concerning health, which covers most clinical and biomedical research) unless a specific Article 9(2)(a) or (g) exemption applies and suitable safeguards are in place. For research controllers, this means an automated eligibility or selection tool operating on health or genetic data faces a materially higher bar than one operating on non-sensitive data, even where a general Article 6 lawful basis for the underlying processing is otherwise sound.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/gdpr-article-22-automated-decision-making-in-research",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"author": {
"@id": "https://casrai.org/#editorial-team"
},
"datePublished": "2026-07-23T09:04:11",
"dateModified": "2026-09-04T07:20:14",
"inLanguage": "en-GB",
"isAccessibleForFree": true
}







