GDPR Article 22: CJEU vs United Kingdom — widening gap on automated decisions
On 7 December 2023, the CJEU tightened GDPR Article 22, while the UK broadened permitted cases via the 2025 DUAA. Luxembourg groups operating in the UK must now manage two diverging regimes.
Excerpt — Verifiable fact: On 7 December 2023, the CJEU (SCHUFA cases) tightened the reading of GDPR Article 22, while the UK has, since 19 June 2025, broadened permitted fully automated decisions via its Data (Use and Access) Act. Luxembourg groups active in the UK must now manage two diverging regimes.
The case
- European Union: On 7 December 2023, the Court of Justice (CJEU) held in SCHUFA Holding (C‑634/21; C‑26/22 and C‑64/22) that certain credit scores qualify as “decisions” under Article 22(1) GDPR when they produce legal or similarly significant effects, thereby reinforcing the baseline prohibition on decisions based solely on automated processing. See the press release and official judgments: CJEU, 7/12/2023. curia.europa.eu
- United Kingdom: The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025. It substantially reshapes the UK GDPR’s “Article 22” by creating Articles 22A–22D, broadening the circumstances where a fully automated decision, including profiling‑based, is permitted, under harmonised safeguards. See the official text and explanatory notes: legislation.gov.uk
The ICO has also indicated that its doctrine on automated decision‑making (ADM) is being updated following the DUAA. See “Rights related to automated decision‑making” and “AI and data protection.” ico.org.uk
Legal reasoning
EU/Luxembourg
- GDPR Article 22 sets a general prohibition on subjecting a person to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significant effects, unless the decision is necessary for a contract, authorised by Union/Member State law, or based on explicit consent — with Article 22(3) safeguards (human intervention, right to express views, right to contest). The text is available on the CNPD portal. cnpd.public.lu — see also the GDPR framework.
- In SCHUFA, the CJEU clarifies two key points: (i) a score provided to a third party and used determinatively can be a “decision” under Art. 22(1); (ii) legal bases (including legitimate interests, Art. 6(1)(f)) and the exceptions in Art. 22(2) are interpreted strictly and cannot circumvent the effective protection of Article 22. curia.europa.eu
- The EDPB endorsed the WP29 Guidelines on profiling and automated decision‑making (WP251 rev.01), detailing the “solely automated” test, “similarly significant effects,” and concrete safeguards (meaningful human intervention, information on underlying logic, etc.). The CNPD also refers to these principles in its AI resources. edpb.europa.eu
United Kingdom
- The 2025 DUAA overhauls the UK GDPR’s “Article 22” (creating Arts. 22A–22D). It “broadens the circumstances” in which a decision based solely on automated processing is permitted, systematising safeguards (information, possibility of human review, traceability) and granting regulatory powers to supplement these safeguards. legislation.gov.uk
- Pending its updated doctrine, the ICO maintains its practical ADM and AI guidance (e.g., “Guidance on AI and Data Protection”; “Rights related to automated decision‑making”), noting they are “under review” in light of the DUAA. ico.org.uk
In short, the EU (via CJEU + EDPB) tightens the qualification and exception conditions of Art. 22. The UK unifies and extends permitted cases under guardrails, shifting from a “prohibition‑with‑exceptions” model to a “permission‑with‑safeguards” framework.
What this changes in practice
- Credit/Scoring: In the EU, a score that conditions credit or service provision may fall under Art. 22(1) and require an Art. 22(2) ground (e.g., specific law) or robust explicit consent, with strong safeguards (meaningful human intervention, right to challenge). This is SCHUFA’s takeaway. In the UK, the DUAA may permit more fully automated decisions, provided 22C safeguards are evidenced (information, redress channels, effective human review). curia.europa.eu
- Anti‑fraud and transactional blocks: Fraud‑scoring systems deployed “without a human in the loop” must be carefully qualified. In the EU, if the block has significant effects (e.g., refusal of an essential service), you fall under Art. 22(1). In the UK, an automated block may be more readily justified if DUAA safeguards are met (notice, swift review, human channel). Refer to the ICO ADM guidance, currently under review. ico.org.uk — and organise your AI governance for ADM accordingly.
- Recruitment: Purely automated screening of CVs or tests may fall under Art. 22 (similarly significant effect). In the EU, require meaningful human intervention and WP251 documentation. In the UK, map applicable DUAA safeguards and implement “real and traceable” human review paths. EDPB WP251 vs ICO AI guidance. aepd.es
- Information/Transparency: In the EU, the CNPD recalls the obligation to disclose the existence of ADM, underlying logic and envisaged consequences (Articles 13–15 and 22(3)). In the UK, the ICO expects “meaningful” explanations and is updating its explainability models post‑DUAA. cnpd.public.lu
Common pitfalls
- Assuming “profiling” ≠ “decision,” hence no Art. 22: In the EU, if the score determines the outcome (credit, contract, service), the CJEU may treat it as an automated “decision.” Document human intervention and its real ability to change the result. curia.europa.eu
- Relying on “legitimate interests” for ADM in the EU: Art. 22(1) is a special prohibition; Art. 6(1)(f) alone is not enough. You must fall within a 22(2) exception and apply 22(3). See SCHUFA. eur-lex.europa.eu
- Token human‑in‑the‑loop: A mere “approve” click is not “meaningful” human intervention under WP251. Formalise real review with criteria, timelines and accountability. aepd.es
- Copy‑pasting UK notices for the EU (and vice versa): Requirements differ. In the EU, focus on underlying logic, significance and envisaged consequences; in the UK, DUAA safeguards structure information and the right to review. ICO flags its pages as “under review” — do not transpose them as‑is in the EU. cnpd.public.lu — for Luxembourg specifics, see AI compliance in Luxembourg.
- Forgetting extraterritorial reach: A Luxembourg entity targeting UK residents may fall under UK GDPR/DUAA; conversely, a UK subsidiary targeting the EU is subject to GDPR/CJEU. Scope ADM governance by perimeter (markets, data subjects, systems) and by distinct legal bases.
Official sources
- CJEU — Press release and SCHUFA judgments (7 Dec 2023): press release No 186/23; EUR‑Lex C‑634/21; InfoCuria C‑26/22. curia.europa.eu
- EDPB — Endorsed guidelines (WP251 rev.01 on Profiling and ADM). edpb.europa.eu
- CNPD Luxembourg — GDPR Chapter III (Art. 22) and AI thematic resources (ADM and transparency). cnpd.public.lu
- United Kingdom — Data (Use and Access) Act 2025: text and explanatory notes (reforms to UK GDPR Arts. 22A–22D); Government memorandum on ADM reform. legislation.gov.uk
- ICO — “Rights related to automated decision‑making”; “Guidance on AI and Data Protection”; pages flagged as under review post‑DUAA. ico.org.uk
In brief: Since SCHUFA, the EU consolidates a high‑protection reading of Article 22; the UK, via the DUAA, accepts more fully automated decisions but under codified safeguards. Luxembourg groups should segment uses (credit, anti‑fraud, HR) and notices by jurisdiction, evidence human intervention in the EU, and demonstrate end‑to‑end DUAA safeguards in the UK.
Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →