Answer guide

"Does your product make automated decisions about individuals?" — the ADM question

This question is less about your product than about your buyer's own obligations. Article 22 GDPR gives individuals the right not to be subject to a decision based solely on automated processing that produces legal effects concerning them or similarly significantly affects them. Your buyer needs to know whether deploying your product puts them on that hook — and whether the use case wanders into the EU AI Act's high-risk list. Treat it as a classification exercise.

Why buyers ask this

Two regimes cross at this question:

Your answer determines which of the buyer's compliance workstreams switches on — a vague answer generates follow-up rounds; a precise one closes the question.

A recommender is not a scoring engine with effects

Article 22 has three elements: a decision, based solely on automated processing, with legal or similarly significant effects. Apply them to your actual workflow:

The test is what happens to the individual and who actually determines it — not what the feature is called in your marketing.

The honest answer structure

Classify, state the effects, then describe the real human role — factually, without decoration:

Template — orientation only. Adapt every bracket to your actual workflow; delete anything that isn't true. Draft language for your review, not legal advice.

"[Your product] generates [scores/rankings/drafts/recommendations] that support decisions made by our customers' staff; it does not itself take decisions that produce legal or similarly significant effects for individuals. In [workflow], the output is presented to [role] together with [the underlying records], no action affecting an individual is taken without that person's review, and reviewers can edit, override or reject the output; overrides are logged. [Your product] is not designed or marketed for [credit scoring / employment screening / eligibility decisions for essential services]; customers planning such a use case are asked to contact us first."

Two cautions on the human role. On the GDPR side, a rubber stamp does not turn an automated decision into a human one — under the Article 29 Working Party guidelines on automated decision-making (WP251rev.01, endorsed by the EDPB), human involvement counts as meaningful when the reviewer has the authority and competence to change the decision; describe only review steps where that is true. On the AI Act side, don't dress the description up as "human oversight" compliance: Article 14 binds only high-risk systems. For a limited-risk product, your obligations under Regulation (EU) 2024/1689 are the Article 50 transparency duties (check yours with the free Article 50 checker); the review measures you describe are voluntary good practice supporting the buyer's risk management, not compliance the Act demands of you.

The mistake that costs deals

The inflated human-in-the-loop. "Every output is reviewed by a human before any action" is a strong claim — and a checkable one. If your own documentation advertises auto-send, auto-reject or fully automated workflows, the contradiction surfaces in due diligence, takes the answer down, and drags the buyer's Article 22 position with it. A thin-but-real human role, described accurately, outperforms an inflated one. The mirror-image mistake — a reflexive "no" from a product that ranks, filters or scores people — fails the same way. And if the use case genuinely touches Annex III territory (employment, creditworthiness, essential services), don't guess: mark the item "under legal review", as in step 5 of our method guide.

Mini-FAQ

What counts as a "legal or similarly significant effect"?
Recital 71's examples: automatic refusal of an online credit application, e-recruiting without any human intervention. Ranking a document is not that; deciding whether a person gets credit, an interview or a service can be.

Our product only makes recommendations — is that automated decision-making?
Usually not, if a human genuinely decides before anything happens to the individual — but describe the workflow rather than answering a bare "no". If the output in practice determines the outcome, the label "recommendation" will not save the answer.

Is automated decision-making the same as "high-risk" under the EU AI Act?
No — Article 22 turns on solely-automated processing with significant effects; Annex III on defined use cases, from 2 December 2027 after the Digital Omnibus. A product can trigger one, both, or neither. Annex III territory → "under legal review", not a guess.

Related: "Do you have an AI governance policy?" · Just received the questionnaire? Start with the first-24-hours playbook.

Sources
  • Regulation (EU) 2016/679 (GDPR) — Art. 22, Recital 71
  • Article 29 Working Party, Guidelines on Automated individual decision-making and Profiling (WP251rev.01), endorsed by the EDPB
  • Regulation (EU) 2024/1689 — Art. 14, Art. 50, Annex III
  • Digital Omnibus, adopted 16/29 June 2026 (Annex III high-risk moved to 2 December 2027; Art. 50 unchanged)

This question is one of sixty in front of you?

Send the questionnaire — first 3 answers free within 24h, full delivery in 48h for $490 flat (up to 60 questions), paid after delivery. Judge the work on the public sample first.

Send your questionnaire →