You may use AI for automated decisions regarding customers if at least one of the three legal exceptions is met: the decision is necessary for a contract, the customer has given explicit consent, or a legal provision permits it. Outside of these exceptions, the GDPR prohibits fully automated decisions that have significant consequences for an individual. This applies to any organization that uses AI in customer interactions, from call routing to credit assessments. In this article, we answer the most frequently asked questions about automated decision-making and AI, so you know exactly where you stand.
What does the GDPR say about automated decision-making?
Article 22 of the GDPR (General Data Protection Regulation) grants data subjects the right not to be subject to a decision based solely on automated processing, including profiling, if that decision has significant consequences for them. This is not a ban on the use of AI, but a ban on fully automated decisions without human intervention, unless an exception applies.
In practice, this means that you are perfectly allowed to use AI as a support tool: an employee reviews the system’s recommendation and makes the final decision themselves. Only when the system makes a decision—without any human review—that has direct consequences for a customer do you fall within the scope of Article 22.
Important to know: The GDPR applies to all organizations that process personal data of individuals in the EU, regardless of where the organization itself is based. Furthermore, by 2026, the combination of the GDPR and the EU AI Act will become increasingly relevant. The AI Act adds an extra layer of regulation, particularly for so-called high-risk AI systems that profile natural persons. These systems always fall into the strictest category.
What are the three exceptions that allow for automated AI decisions?
The GDPR recognizes three situations in which fully automated decision-making is nevertheless permitted. First, if the decision is necessary for the performance or conclusion of a contract with the data subject. Second, if a legal provision permits or requires the decision. Third, if the data subject has given explicit consent to the automated processing.
In all three cases, additional obligations apply:
- The individual concerned must have the right to request human intervention.
- The person concerned must be given the opportunity to state his or her position.
- The person concerned must be able to challenge the decision.
In practice, the exception based on a contract is most relevant to customer service. Examples include an automated credit check when signing up for a subscription, or identity verification when opening an account. The consent basis sounds appealing, but is difficult to apply in practice: consent must be freely given, specific, informed, and unambiguous. In situations involving an unequal balance of power—such as an employer-employee relationship—free consent can quickly become questionable.
What is the difference between profiling and an automated decision?
Profiling is the automated processing of personal data to evaluate certain personal aspects of an individual, such as behavior, interests, location, or reliability. An automated decision is a decision made solely on the basis of such automated processing, without a human reviewing the outcome. Profiling does not necessarily constitute a decision in and of itself, but it often serves as a precursor to one.
A concrete example: An AI system that analyzes customer behavior and assigns a risk score is performing profiling. If an employee then uses that score to decide whether a customer is eligible for a service, there is human intervention, and it falls outside the scope of Article 22. However, if the system automatically rejects an application or places a customer in a different rate category based on that score, it constitutes a fully automated decision.
Under the EU AI Act, profiling of natural persons is always classified as high-risk AI, regardless of the context. This means stricter requirements for documentation, transparency, and oversight, even if the outcome of the profiling is ultimately assessed by a human.
When does an AI decision have “significant consequences” for a customer?
A decision has significant consequences if it affects a person’s legal status, has a significant impact on their circumstances, or otherwise substantially affects them. Examples include denying a loan, terminating a contract, setting an insurance premium, or blocking access to a service. Not every AI recommendation falls under this category.
Dec isions that are generally considered significant:
- Credit or insurance decisions based on an algorithmic score.
- Automatic rejection of a service request or complaint.
- Prioritizing customers in a way that systematically results in certain groups receiving poorer service.
- Automatic termination or contract modification based on behavioral data.
Decisions that are generally not considered significant:
- Personalized product recommendations that are not binding.
- Automatic routing to the appropriate department based on the subject of a question.
- Spam or fraud filters that flag messages for human review.
The line isn’t always clear-cut. When in doubt, it’s wise to always include a human review step and document it.
What obligations apply if AI makes decisions automatically anyway?
If you make use of one of the three exceptions and therefore make an automated decision, several specific obligations under the GDPR apply. The data subject must be informed in advance, the right to human intervention must be actively offered, and the decision must be subject to appeal. Furthermore, as an organization, you must be able to explain how the decision was reached.
Specifically, this means:
- Transparency: Inform customers in your privacy policy that automated decision-making takes place, explain the logic behind it, and describe the potential consequences.
- Right to Human Review: Always provide a clear and accessible channel through which a customer can request a human review.
- Right to Object: Customers must be able to express their views before or after a decision is made.
- Data minimization: Use only the personal data that is strictly necessary for the decision.
- Data Protection Impact Assessment (DPIA): A DPIA is required for large-scale automated processing with significant consequences.
Under the EU AI Act, high-risk systems will be subject to additional requirements, such as maintaining log files, conducting fundamental rights impact assessments, and registering with the EU database.
How do you implement AI-driven decision-making without violating the GDPR?
The key to GDPR-compliant AI decision-making is incorporating meaningful human intervention at the right moments, combined with transparency toward the customer. This is not a bureaucratic formality, but a design requirement that you incorporate into your processes from the very beginning.
Practical steps to prevent violations:
- Identify which decisions have significant consequences. Create a list of all the areas where AI generates results that directly impact customers.
- For each decision, determine whether there is a valid exception. Agreement, law, or consent? Document this explicitly.
- In cases of doubt, include a human review step. Let AI provide advice, but have an employee make the decision in complex or sensitive situations.
- Ensure explainability. Use systems that can explain why a particular result was generated, even if it is a simplified explanation.
- Conduct a DPIA before deploying a new AI system with significant decision-making authority into production.
- Train your employees. Starting February 2, 2025, AI literacy will be a legal requirement under the EU AI Act. Employees who work with AI systems must understand what those systems do and when they need to intervene.
A well-designed AI system does not need to avoid automated decision-making, but rather makes it clear when human judgment is necessary and actively facilitates it.
How Pegamento Helps with Responsible AI Decision-Making
We understand that the combination of the GDPR and the EU AI Act can feel complex for many organizations, especially if you’re trying to improve customer interactions and automate processes at the same time. At Pegamento, we help you use AI responsibly—without falling into legal pitfalls or requiring costly custom development—by leveraging smart combinations of proven modules.
What we specifically do for you:
- We design AI workflows that incorporate human intervention at the right moments, ensuring that you comply with Article 22 of the GDPR.
- We use Agentic AI for customer service: an evolution from task-oriented bots to self-thinking assistants that take the initiative on their own, but always within the parameters you set.
- We offer everything under one roof: from consulting and implementation to management and support, with a single point of contact for the complete package.
- We operate in accordance with ISO 27001 (information security), ISO 9001, and ISO 26000, so you can be sure that data security and quality assurance are systematically embedded in our processes.
- We’ll help you document your AI applications so that, should a regulatory inquiry arise, you can demonstrate that you are in control.
Would you like to know how your organization can use AI responsibly without violating the GDPR? Contact us, and we’d be happy to help you figure it out.
Frequently Asked Questions
Does Article 22 of the GDPR also apply if a person can still view the AI recommendation afterward but never actively intervenes?
Yes, that’s a common pitfall. Human intervention must be meaningful: an employee must actually be able to assess and adjust the AI’s output, not just formally click ‘approve’ without substantive review. If a human rubber-stamps the decision without a genuine assessment, the regulator will still consider it a fully automated decision. So make sure employees have sufficient time, information, and authority to be able to intervene effectively.
What should I do if a customer objects to an automated AI decision?
You are required to establish a clear and accessible objection process. Specifically, this means: a designated contact person or channel (such as an email address or form), a reasonable response time, and a substantive review by a human who does not simply repeat the AI’s outcome. Carefully document the objection and the outcome, because if a complaint is filed with the Dutch Data Protection Authority, you must be able to demonstrate that you actively facilitated the right to human intervention.
How do I explain to customers in an understandable way how an AI decision was reached?
The GDPR does not require a technical explanation of the algorithm, but it does require a meaningful explanation: what data was used, what the main factors were, and what the consequences of the decision are. Use clear language in your privacy policy and actively communicate at the time the decision is made, for example through an automated message stating the main reason. Avoid vague phrasing such as ‘based on an advanced model’; specify concrete factors such as payment history or contract duration.
When does a DPIA become mandatory for an AI system that makes customer decisions?
A Data Protection Impact Assessment (DPIA) is required as soon as the processing ‘is likely to result in a high risk to the rights and freedoms of natural persons.’ For automated decision-making with significant consequences, this is almost always the case, especially with large-scale deployment or profiling. Conduct the DPIA before the system goes live, not afterward. The Dutch Data Protection Authority has published a list of processing activities for which a DPIA is mandatory in any case, including automated decision-making regarding credit, insurance, and access to services.
What specific changes will the EU AI Act bring for my organization compared to what the GDPR already requires?
The GDPR governs the protection of personal data and the right to human intervention, while the EU AI Act imposes additional requirements on the AI systems themselves. For high-risk AI systems—including all profiling systems—requirements apply such as technical documentation, automatic logging, fundamental rights impact assessments, and mandatory registration in an EU database. In addition, the AI literacy requirement has been in effect since February 2, 2025: employees who work with AI must be able to demonstrate that they understand what the system does and when intervention is necessary.
Can I use consent as the legal basis for automated decision-making regarding my customers?
Technically, yes, but in practice this is the riskiest basis. Consent must be entirely voluntary, which means that customers must not suffer any disadvantage if they refuse. For a service that you can only use if you consent to automated decision-making, that consent is, by definition, not freely given. The basis of “necessary for the performance of a contract” is a more robust choice in most customer service contexts, provided that the automated decision is truly necessary for that contract and you can properly substantiate this.
How do I keep track of which AI decisions are being made in my organization so that I can demonstrate I’m in control?
Start with a central registry of all AI applications that influence customer decisions, including the type of decision, the legal basis used, the data involved, and the built-in safeguards. Link this to a logging structure that tracks, for each decision, what input was used and what the outcome was—this is also a requirement under the EU AI Act for high-risk systems. Combine this with periodic audits in which you conduct random checks to verify that the human review step is actually functioning as designed.

