Article 22: the right not to be subject to an automated decision

Article 22 of the GDPR is the central provision for AI systems that influence decisions about individuals. It prohibits decisions "based solely on automated processing, including profiling, which produces legal effects concerning a natural person or similarly significantly affects them."

Three exceptions allow derogation from this prohibition: the explicit consent of the data subject, necessity for the performance of a contract, or an authorisation laid down by Union or Member State law. In the cases referred to in Article 22(2)(a) and (c), that is, contract and explicit consent, the person retains at least the right to obtain human intervention on the part of the controller, to express their point of view and to contest the decision (Article 22(3)). Where the decision is authorised by Union or Member State law (point (b)), it is those laws that must lay down suitable measures to safeguard the data subject's rights, freedoms and legitimate interests.

In practice, AI systems for credit scoring, CV screening, personalised insurance pricing and professional performance evaluation are all potentially subject to Article 22. The "solely automated" qualification is interpreted strictly: a purely formal human validation, with no real ability to influence the decision, is not enough to take a decision outside the scope of the article.

The DPIA: obligation and methodology

A Data Protection Impact Assessment (DPIA, or AIPD in French) is mandatory before any deployment of an AI system that presents a high risk to the rights and freedoms of individuals. The CNIL has published a list of the types of processing that always require a DPIA; that list explicitly includes systems for evaluating or scoring individuals, automated decisions with significant effects, large-scale processing of special categories of data, and systematic monitoring of publicly accessible spaces.

The DPIA must document: a description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to the rights and freedoms of individuals, and the protective measures planned. It must be carried out before deployment, not after.

Training data and legal basis

Using personal data to train AI models requires a distinct legal basis for that specific purpose. Reusing data collected for other purposes to train AI is lawful only if it is compatible with the original purpose, a compatibility test that the CNIL applies rigorously. Models trained on personal data may themselves constitute personal data if that data can be extracted from them, a point the EDPB explicitly raised in its opinion on large language models.