---
title: "GDPR Article 22 and automated decisions inside the enterprise"
url: https://zerofive.ai/en/blog/compliance/gdpr-article-22-automated-decisions-enterprise
canonical: https://zerofive.ai/en/blog/compliance/gdpr-article-22-automated-decisions-enterprise
language: en
published: 2026-08-24
updated: 2026-09-18
author: "ZeroFive.AI"
tags: GDPR Article 22, automated decisions, AI Act, Annex III, human in the loop, compliance, AI governance
abstract: "Uber's EUR 825m fine shows what Article 22 requires. How to inventory automated flows and where the upstream stop point belongs."
---

# GDPR Article 22 and automated decisions inside the enterprise

On 21 August 2026 the Autoriteit Persoonsgegevens, the Dutch data protection authority, fined Uber EUR 824,990,000. It is the second largest fine ever issued under the GDPR. The case concerns a system that deactivated driver accounts through a fully automated process, with no person reviewing the case before the block took effect. The conduct under scrutiny spans 2018 to 2022. Uber has appealed, arguing that most suspensions are short, that no permanent deactivation happens without human review, and that drivers can appeal.

Uber's defence is the most useful part of the case for anyone assessing their own exposure. A human review and an appeal channel existed, and they were not enough.

## What the regulator found

The legal basis is Article 22 of the GDPR, which prohibits subjecting a person to a decision based solely on automated processing where that decision produces legal effects or similarly significantly affects them. On top of this sit the information and transparency duties of Articles 12 to 15, for failing to adequately explain how the decision-making process worked.

Monique Verdier, deputy chair of the authority, summarised the principle by saying that a computer should not make decisions on its own that carry major consequences for a person, and that those decisions should have been reviewed by a human being first.

The two words that matter are "on its own" and "first". Whether the algorithm performs well is not the question. Whether a remedy exists after the fact is not the question either. What the regulator measures is whether, at the moment the decision takes effect, a person with the power to stop it was involved.

## The actual scope of the problem

The case comes from ride hailing, which leads many companies to file it away as a platform and gig-work matter. That reading is expensive, because the sanctioned pattern is among the most common in the operational systems of entirely conventional businesses.

Examples we encounter regularly in our assessments:

- **Automatic supplier suspension** from a procurement portal once a scoring, delay or documentation-compliance threshold is crossed
- **Automatic credit blocking** for a customer when a system-calculated risk parameter is reached
- **Automatic rejection of applications** at the screening stage, with filters or scores applied before any human reading
- **Automatic downgrading** of a reseller or agent from one commercial tier to another, affecting commissions and terms
- **Automatic revocation of access or permissions** for a worker based on usage metrics or system flags
- **Automatic denial of claims or requests** in insurance, healthcare and warranty workflows

In nearly every case we have seen, these flows were never designed as automated decisions. They started as efficiency rules inside an ERP, a CRM or a portal, they were configured years ago by a vendor who is no longer around, and no one ever recorded them as processing relevant under Article 22.

## How this interlocks with the AI Act

Since 2 August 2026 the European Commission, through the AI Office and together with national authorities, has begun enforcing the AI Act ([what is actually binding from that date](/en/blog/compliance/ai-act-august-2-2026-what-is-binding)), and the transparency obligations of Article 50 became applicable, carrying fines of up to EUR 15 million or 3% of total worldwide annual turnover.

Nineteen days later, the first substantial European penalty over an algorithmic decision affecting work did not come from the AI Act. It came from the GDPR.

That tells two things to anyone allocating a compliance budget over the next six months.

First, the apparatus with immediate operational capacity is the data protection one, with staffed authorities, eight years of practice and settled case law behind it. Second, there is the question of sequence. Annex III of the AI Act classifies as high risk the systems used for recruitment, selection, promotion, termination and task allocation, but those obligations are not applicable yet: the Digital Omnibus moved them to 2 December 2027. Reading that as a reprieve is a mistake. Article 22 already covers much of the same ground today, with an authority that enforces and a ceiling the Uber case has just demonstrated. A company that inventories its automated flows now for the GDPR is building the register it will need in 2027 for the AI Act, with seventeen months of headroom rather than against a deadline.

Doing the same work twice, with two separate working groups and two separate vendors, is the most expensive sequencing error we are seeing right now.

## The automated decision inventory

In the 05 Framework this activity belongs to the ASSESS phase, before any use case is selected. The reason is practical: a company that does not know which automated decisions it already runs in production cannot assess the risk of the ones it is about to add.

The inventory starts from five questions, applied to every flow where a system produces an outcome affecting a natural person.

1. **What outcome does the system produce, and for whom.** An employee, a contractor, a candidate, an individual customer, a sole trader. Legal entities fall outside Article 22, but the same flow often hits both and no one has separated the two cases.
2. **Does the outcome have significant effects.** Loss of income, exclusion from an opportunity, termination of a relationship, restriction of access, worsening of commercial terms.
3. **Is there a stop point upstream.** Not a complaints channel, not a later review: a person with the authority and the actual time to block the outcome before it takes effect.
4. **Does that person have what they need to decide.** An operator who sees only a score and a confirm button is not human oversight, it is a signature. The Dutch authority assessed the substance of the involvement, not its formal existence.
5. **Does the affected person know the decision is automated**, and have they been given an understandable explanation of the logic applied.

Anyone answering no to the third or fourth question on a flow that cleared the first two has found an exposure, whether or not an AI model sits anywhere in that flow.

## Human in the loop as an architecture requirement

The most common outcome of this inventory is a decision to write a policy. It is the wrong answer, and the Uber case shows why: a procedure that calls for human review offers no protection if the system can still produce the outcome without waiting for it.

The control belongs in the flow, not in the document. Concretely, this means the system must not be able to close the operation until an authorisation has been recorded, that the authorisation must be logged with identity and timestamp, and that whoever authorises must see the case and not only the score.

This is an architecture decision, and it belongs in the ARCHITECT phase alongside the rest of the design, not bolted on during ACTIVATE once the system is already live. In our experience, adding an authorisation point to a flow already in production costs three to six times what it costs to design it in from the start.

## Where to start

A structured Italian company typically has between fifteen and forty flows worth checking, spread across ERP, CRM, supplier portals, HR systems and customer service platforms. The inventory takes two to four weeks of work and produces three outputs: the map of the flows, a risk classification for each, and a prioritised list of the authorisation points to introduce.

The same inventory then serves as the basis for classification under Annex III of the AI Act once those obligations apply in December 2027, with no need to rebuild it from scratch.

---

**Sources**

- [Autoriteit Persoonsgegevens, press release of 21 August 2026](https://autoriteitpersoonsgegevens.nl/en/current/uber-fined-nearly-825-million-euros-for-automated-driver-blocking)
- [European Commission, start of AI Act enforcement, 2 August 2026](https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1714)
- [Cooley, Article 50 transparency obligations in force from 2 August 2026](https://www.cooley.com/news/insight/2026/2026-08-03-eu-ai-act-transparency-obligations-take-effect-2-august-2026)
- [TechCrunch, Uber's position and appeal, 23 August 2026](https://techcrunch.com/2026/08/23/uber-faces-fine-of-nearly-1b-over-automated-driver-suspensions/)
