When is it permissible to use AI for automated decisions regarding customers?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

You may use AI for automated decisions regarding customers if at least one of the three legal exceptions is met: the decision is necessary for a contract, the customer has given explicit consent, or a legal provision permits it. Outside of these exceptions, the GDPR prohibits fully automated decisions that have significant consequences for an individual. This applies to any organization that uses AI in customer interactions, from call routing to credit assessments. In this article, we answer the most frequently asked questions about automated decision-making and AI, so you know exactly where you stand.

What does the GDPR say about automated decision-making?

Article 22 of the GDPR (General Data Protection Regulation) grants data subjects the right not to be subject to a decision based solely on automated processing, including profiling, if that decision has significant consequences for them. This is not a ban on the use of AI, but a ban on fully automated decisions without human intervention, unless an exception applies.

In practice, this means that you are perfectly allowed to use AI as a support tool: an employee reviews the system’s recommendation and makes the final decision themselves. Only when the system makes a decision—without any human review—that has direct consequences for a customer do you fall within the scope of Article 22.

Important to know: The GDPR applies to all organizations that process personal data of individuals in the EU, regardless of where the organization itself is based. Furthermore, by 2026, the combination of the GDPR and the EU AI Act will become increasingly relevant. The AI Act adds an extra layer of regulation, particularly for so-called high-risk AI systems that profile natural persons. These systems always fall into the strictest category.

What are the three exceptions that allow for automated AI decisions?

The GDPR recognizes three situations in which fully automated decision-making is nevertheless permitted. First, if the decision is necessary for the performance or conclusion of a contract with the data subject. Second, if a legal provision permits or requires the decision. Third, if the data subject has given explicit consent to the automated processing.

In all three cases, additional obligations apply:

  • The individual concerned must have the right to request human intervention.
  • The person concerned must be given the opportunity to state his or her position.
  • The person concerned must be able to challenge the decision.

In practice, the exception based on a contract is most relevant to customer service. Examples include an automated credit check when signing up for a subscription, or identity verification when opening an account. The consent basis sounds appealing, but is difficult to apply in practice: consent must be freely given, specific, informed, and unambiguous. In situations involving an unequal balance of power—such as an employer-employee relationship—free consent can quickly become questionable.

What is the difference between profiling and an automated decision?

Profiling is the automated processing of personal data to evaluate certain personal aspects of an individual, such as behavior, interests, location, or reliability. An automated decision is a decision made solely on the basis of such automated processing, without a human reviewing the outcome. Profiling does not necessarily constitute a decision in and of itself, but it often serves as a precursor to one.

A concrete example: An AI system that analyzes customer behavior and assigns a risk score is performing profiling. If an employee then uses that score to decide whether a customer is eligible for a service, there is human intervention, and it falls outside the scope of Article 22. However, if the system automatically rejects an application or places a customer in a different rate category based on that score, it constitutes a fully automated decision.

Under the EU AI Act, profiling of natural persons is always classified as high-risk AI, regardless of the context. This means stricter requirements for documentation, transparency, and oversight, even if the outcome of the profiling is ultimately assessed by a human.

When does an AI decision have “significant consequences” for a customer?

A decision has significant consequences if it affects a person’s legal status, has a significant impact on their circumstances, or otherwise substantially affects them. Examples include denying a loan, terminating a contract, setting an insurance premium, or blocking access to a service. Not every AI recommendation falls under this category.

Dec isions that are generally considered significant:

  • Credit or insurance decisions based on an algorithmic score.
  • Automatic rejection of a service request or complaint.
  • Prioritizing customers in a way that systematically results in certain groups receiving poorer service.
  • Automatic termination or contract modification based on behavioral data.

Decisions that are generally not considered significant:

  • Personalized product recommendations that are not binding.
  • Automatic routing to the appropriate department based on the subject of a question.
  • Spam or fraud filters that flag messages for human review.

The line isn’t always clear-cut. When in doubt, it’s wise to always include a human review step and document it.

What obligations apply if AI makes decisions automatically anyway?

If you make use of one of the three exceptions and therefore make an automated decision, several specific obligations under the GDPR apply. The data subject must be informed in advance, the right to human intervention must be actively offered, and the decision must be subject to appeal. Furthermore, as an organization, you must be able to explain how the decision was reached.

Specifically, this means:

  • Transparency: Inform customers in your privacy policy that automated decision-making takes place, explain the logic behind it, and describe the potential consequences.
  • Right to Human Review: Always provide a clear and accessible channel through which a customer can request a human review.
  • Right to Object: Customers must be able to express their views before or after a decision is made.
  • Data minimization: Use only the personal data that is strictly necessary for the decision.
  • Data Protection Impact Assessment (DPIA): A DPIA is required for large-scale automated processing with significant consequences.

Under the EU AI Act, high-risk systems will be subject to additional requirements, such as maintaining log files, conducting fundamental rights impact assessments, and registering with the EU database.

How do you implement AI-driven decision-making without violating the GDPR?

The key to GDPR-compliant AI decision-making is incorporating meaningful human intervention at the right moments, combined with transparency toward the customer. This is not a bureaucratic formality, but a design requirement that you incorporate into your processes from the very beginning.

Practical steps to prevent violations:

  1. Identify which decisions have significant consequences. Create a list of all the areas where AI generates results that directly impact customers.
  2. For each decision, determine whether there is a valid exception. Agreement, law, or consent? Document this explicitly.
  3. In cases of doubt, include a human review step. Let AI provide advice, but have an employee make the decision in complex or sensitive situations.
  4. Ensure explainability. Use systems that can explain why a particular result was generated, even if it is a simplified explanation.
  5. Conduct a DPIA before deploying a new AI system with significant decision-making authority into production.
  6. Train your employees. Starting February 2, 2025, AI literacy will be a legal requirement under the EU AI Act. Employees who work with AI systems must understand what those systems do and when they need to intervene.

A well-designed AI system does not need to avoid automated decision-making, but rather makes it clear when human judgment is necessary and actively facilitates it.

How Pegamento Helps with Responsible AI Decision-Making

We understand that the combination of the GDPR and the EU AI Act can feel complex for many organizations, especially if you’re trying to improve customer interactions and automate processes at the same time. At Pegamento, we help you use AI responsibly—without falling into legal pitfalls or requiring costly custom development—by leveraging smart combinations of proven modules.

What we specifically do for you:

  • We design AI workflows that incorporate human intervention at the right moments, ensuring that you comply with Article 22 of the GDPR.
  • We use Agentic AI for customer service: an evolution from task-oriented bots to self-thinking assistants that take the initiative on their own, but always within the parameters you set.
  • We offer everything under one roof: from consulting and implementation to management and support, with a single point of contact for the complete package.
  • We operate in accordance with ISO 27001 (information security), ISO 9001, and ISO 26000, so you can be sure that data security and quality assurance are systematically embedded in our processes.
  • We’ll help you document your AI applications so that, should a regulatory inquiry arise, you can demonstrate that you are in control.

Would you like to know how your organization can use AI responsibly without violating the GDPR? Contact us, and we’d be happy to help you figure it out.

Frequently Asked Questions

Does Article 22 of the GDPR also apply if a person can still view the AI recommendation afterward but never actively intervenes?

Yes, that’s a common pitfall. Human intervention must be meaningful: an employee must actually be able to assess and adjust the AI’s output, not just formally click ‘approve’ without substantive review. If a human rubber-stamps the decision without a genuine assessment, the regulator will still consider it a fully automated decision. So make sure employees have sufficient time, information, and authority to be able to intervene effectively.

What should I do if a customer objects to an automated AI decision?

You are required to establish a clear and accessible objection process. Specifically, this means: a designated contact person or channel (such as an email address or form), a reasonable response time, and a substantive review by a human who does not simply repeat the AI’s outcome. Carefully document the objection and the outcome, because if a complaint is filed with the Dutch Data Protection Authority, you must be able to demonstrate that you actively facilitated the right to human intervention.

How do I explain to customers in an understandable way how an AI decision was reached?

The GDPR does not require a technical explanation of the algorithm, but it does require a meaningful explanation: what data was used, what the main factors were, and what the consequences of the decision are. Use clear language in your privacy policy and actively communicate at the time the decision is made, for example through an automated message stating the main reason. Avoid vague phrasing such as ‘based on an advanced model’; specify concrete factors such as payment history or contract duration.

When does a DPIA become mandatory for an AI system that makes customer decisions?

A Data Protection Impact Assessment (DPIA) is required as soon as the processing ‘is likely to result in a high risk to the rights and freedoms of natural persons.’ For automated decision-making with significant consequences, this is almost always the case, especially with large-scale deployment or profiling. Conduct the DPIA before the system goes live, not afterward. The Dutch Data Protection Authority has published a list of processing activities for which a DPIA is mandatory in any case, including automated decision-making regarding credit, insurance, and access to services.

What specific changes will the EU AI Act bring for my organization compared to what the GDPR already requires?

The GDPR governs the protection of personal data and the right to human intervention, while the EU AI Act imposes additional requirements on the AI systems themselves. For high-risk AI systems—including all profiling systems—requirements apply such as technical documentation, automatic logging, fundamental rights impact assessments, and mandatory registration in an EU database. In addition, the AI literacy requirement has been in effect since February 2, 2025: employees who work with AI must be able to demonstrate that they understand what the system does and when intervention is necessary.

Can I use consent as the legal basis for automated decision-making regarding my customers?

Technically, yes, but in practice this is the riskiest basis. Consent must be entirely voluntary, which means that customers must not suffer any disadvantage if they refuse. For a service that you can only use if you consent to automated decision-making, that consent is, by definition, not freely given. The basis of “necessary for the performance of a contract” is a more robust choice in most customer service contexts, provided that the automated decision is truly necessary for that contract and you can properly substantiate this.

How do I keep track of which AI decisions are being made in my organization so that I can demonstrate I’m in control?

Start with a central registry of all AI applications that influence customer decisions, including the type of decision, the legal basis used, the data involved, and the built-in safeguards. Link this to a logging structure that tracks, for each decision, what input was used and what the outcome was—this is also a requirement under the EU AI Act for high-risk systems. Combine this with periodic audits in which you conduct random checks to verify that the human review step is actually functioning as designed.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.

Ernst Vegter-Business consultant Pegamento

Ernst Vegter

Business Consultant

Hospitality is one of my deepest motivations.
Not surprisingly, of course, customer service is a common thread in my career. Aspects of hospitality is being able to connect, to facilitate but mainly to make someone feel genuinely welcome. My intuition is my greatest asset to be able to put myself in the shoes of a guest. A customer is my guest.

Fed by various senses, an image forms around the client. I listen to what is being said, watch facial expressions, taste the underlying tone and get a feel for the challenge to be addressed. An image literally forms on my retina. I have to be able to see it. If I can see it, I can create it.

In this, the trick is to pursue simplicity, give the client a warm feeling that the problem is understood, receive good advice, facilitated and carefully guided to the solution. Trust, connect and unburden.

The feeling when a guest arrives at your hotel after a long tiring journey, can sit in front of the fireplace, be handed a good glass of wine and stare carefree at the fire. My guest knows it will be okay.

This piece was written by Ernst Vegter, working as a Business Consultant at Pegamento.

Ger Koedam-Communication & Marketing Pegamento

Ger Koedam

Marketing & Communications

How can I help you? That’s pretty much the first question I ask when talking to people who are curious about our services. In such a conversation, the use of senses is very important. Because not everyone is the same. One person thinks in images, while for another words are important or how something feels. For me, sight and hearing are the most beautiful senses, because both eyes and ears absorb information and can convey or process emotions.

Why hearing? Because listening is essential in contact. And it’s the key to unlocking valuable insights.

I developed this skill early on. As a child, I enjoyed radio plays on the radio, bringing the stories to life in my head.

Rob Roode-Research Development

Rob Roode

Research & Development

Recognizing and automating patterns. Tasks we are constantly working on when implementing our robots at Pegamento. My 2 Drentsche Patrijshonden are hunting dogs and certainly not robots. The hunting instinct and intuition is basically in their genes. Continuing to offer new forms of training has taught them to recognize and act independently in hunting situations. Even “unsupervised,” even if I’m not around.

But when you try to teach a brain something, it also starts to see things you don’t expect. Dogs pick up on the slightest deviation in your voice or directions. To start recognizing that and correcting it again is perhaps the most complex challenge. But in our work, for the wonderful clients for whom we get to work, it often yields the most beautiful new insights!

This piece was written by Rob, founder of Pegamento and in charge of Marketing and R&D.

Serge Poppes-CEO Pegamento

Serge Poppes

CEO

Feeling. That’s the best thing Pegamento stands for. Feeling for technology in the broadest sense of the word. Not only feeling for the exciting stuff like AI, but also for the basics of communication.

The very best part of my job is selling, listening, translating and thinking about what really matters. We bring the digital transformation with a great team!
The diversity of our team, how sharp we are, but especially the wonderful things we get to make makes me feel extremely good. Hence, I intuitively chose the sense of “feeling.

Feeling gives life and differentiation!