AI & Automated Decision-Making

Is your human oversight actually doing anything?

Article 22 GDPR gives people the right to meaningful human review of automated decisions — not a rubber stamp. This self-assessment is built directly from EDPS guidance on what real oversight requires, and what regulators treat as symbolic.

Based on EDPS TechDispatch #2/2025 — Human Oversight of Automated Decision-Making, and the EDPS Practical Checklist on Human Intervention (May 2026). For guidance purposes — not legal advice.

Share this

Start here: the 4-condition test

If any of these is false, EDPS would not consider your oversight "meaningful" — regardless of how the rest of the checklist scores.

01

Governance & Protocol

Whether the rules for human review exist on paper, and whether anything undermines them in practice.

02

System & Interface Design

Whether the tool itself helps a human review properly, or quietly pushes them to click "approve."

03

Operator Readiness

Whether the human doing the reviewing is actually equipped to do it.

04

Audit & Accountability

Whether anyone is checking that oversight stays real over time.

Check the boxes above to see your result

Your answers stay in this browser as you go. Enter your email when you're ready to unlock your personalized result and get a copy sent to you.

Unlock your result

See your personalized oversight assessment now, and we'll email you a copy.

Not sure where the gaps are?

A short audit can tell you exactly which of these controls are missing, and what fixing them actually involves for your business.

Get a GDPR audit
19 items not yet checked
out of 19
Start checking the boxes
Prefer to listen? Click play for AI narration
Why It Matters

Automated decisions need a human who can actually intervene

Article 22 GDPR restricts decisions based solely on automated processing — including AI — when they have a legal or similarly significant effect on someone: rejecting a job applicant, denying credit, adjusting a price, flagging an account for fraud. A human "in the loop" who just clicks approve without real ability to review or override the outcome doesn't satisfy this — regulators and the EDPS have been explicit that oversight has to be meaningful, not decorative.

This checklist walks through how your AI or automated system is actually used and scores it against the human-oversight standard, so you can see where a rubber-stamp review would fail scrutiny.

1

Describe the system

What the AI or automated process decides, and what effect that decision has on people.

2

Checked against Article 22

Assessed against GDPR's automated-decision rules and current EDPS oversight guidance.

3

Get a scored assessment

A clear picture of where your oversight meets the standard, and where it's a gap to fix.

Common Questions

Before you start

What counts as "automated decision-making" here?
Any decision made without meaningful human involvement that has a legal or similarly significant effect — think hiring screens, credit or pricing decisions, fraud flags, or eligibility checks driven by an algorithm or AI model.
If a person reviews the AI's output, does that count as oversight?
Only if the reviewer has real authority, time, and information to actually change the outcome. A reviewer who habitually approves whatever the system recommends, with no practical ability to challenge it, doesn't meet the "meaningful involvement" standard.
Does this also cover the EU AI Act?
This checklist is built around GDPR Article 22 and EDPS guidance. The AI Act adds its own, additional human-oversight obligations for high-risk AI systems — if your system falls into that category, treat this as a starting point, not full AI Act coverage.
Who should run this assessment?
Anyone using AI or automated systems to make decisions about customers, applicants or employees — HR tech, credit scoring, pricing engines, fraud detection, and AI-assisted customer service with real consequences attached.
Is my answers data stored?
No. Your responses are processed to generate the assessment, then discarded — nothing is retained on our servers. See the note below for the full legal basis.
Is this legal advice?
No. It's a self-assessment tool to help you spot gaps quickly — for a system with real regulatory exposure, have the results reviewed by a data protection or AI governance specialist.
Paid guides · €39

You’ve scored your oversight. Now close the gaps.

Three of the seven guides in the Compliance Field Kit go straight at the problems this checklist surfaces: The EU AI Act Without the Scare Tactics, the AI Vendor Vetting Checklist, and the Shadow AI Audit Kit. 97 pages of checklists, templates and decision trees — no consultant, instant download.

See the Compliance Field Kit →