AI Compliance Vendors
RegulationIn forceEU

GDPR Article 22 — Automated Individual Decision-Making

Article 22 of the EU General Data Protection Regulation gives data subjects the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal effects concerning them or similarly significantly affects them. The right applies across the EU and EEA and has been in force since May 25, 2018. The European Data Protection Board's Guidelines 1/2024 (adopted December 2024) clarify the scope, including how it applies to large language models and recommender systems. The CJEU's SCHUFA ruling (Case C‑634/21, December 2023) confirmed that automated credit scoring constitutes a "decision" under Article 22 where the score effectively determines whether a loan or contract is granted. Enforcement is by national Data Protection Authorities; penalties for Article 22 violations fall under the GDPR's higher tier — up to €20 million or 4% of worldwide annual turnover.

Jurisdiction

EU

Enforcement

May 25, 2018

Maximum penalty

Up to €20M or 4% of global annual turnover

Key obligations

  • 01Identify any processing operation that produces a decision based solely on automated means and that has legal or similarly significant effects on a natural person.
  • 02Establish a lawful basis under Article 22(2): explicit consent, necessity for performance of a contract, or specific Member-State or Union law authorisation.
  • 03Provide meaningful information about the logic, significance, and envisaged consequences of the automated decision (Articles 13(2)(f), 14(2)(g), 15(1)(h)).
  • 04Implement suitable safeguards: at minimum the right to obtain human intervention, to express a point of view, and to contest the decision.
  • 05Carry out a Data Protection Impact Assessment (DPIA) where the processing is likely to result in high risk to the rights and freedoms of natural persons.
  • 06Apply heightened protections for special-category data (Article 9) and for children — processing of these populations triggers tighter restrictions.
  • 07Maintain Records of Processing Activities (Article 30) that document automated decision-making logic, safeguards, and review cadence.

Vendors that support GDPR Art. 22

Sorted by coverage level. Full coverage shown first.

15 vendors

VendorHQFoundedSizePricingCoverageLast verified
Scrut AutomationPalo Alto, US202151-200Contact for pricingComprehensiveApr 24, 2026
BraintrustSan Francisco, US202351-200Contact for pricingComprehensiveApr 24, 2026
GiskardParis, France202111-50Contact for pricingComprehensiveApr 24, 2026
AporiaSan Jose, US201951-200Enterprise pricing only. Not publicly listed.ComprehensiveApr 27, 2026
Luminos.Law (ZwillGen AI Division)Washington, DC, US201951-200Contact for pricingPartialApr 24, 2026
DrataSan Francisco, US2020501-1000Contact for pricingPartialApr 24, 2026
VantaSan Francisco, USA2018500-1000Contact for pricingPartialApr 26, 2026
ServiceNow AI Control TowerSanta Clara, USA20041000+Contact for pricingPartialApr 26, 2026
Securiti Data Command CenterSan Jose, USA2018500-1000Contact for pricingPartialApr 26, 2026
BigIDNew York, USA2016500-1000Contact for pricingPartialApr 26, 2026
CalypsoAIDublin, IE201851-200Enterprise licensing; contact sales for quote, depending on deployment (SaaS/on-prem/hybrid) and plan.PartialApr 26, 2026
TrustArcWalnut Creek, US1997501-1000Enterprise subscription; contact sales for quote; modular pricing based on scope and modulesPartialApr 26, 2026
NaaiaLouveciennes, FR202111-50No public pricing tiers; demo and quote requested via website.PartialApr 27, 2026
BABL AIIowa City, US201811-50Contact for pricingAdjacentApr 24, 2026
2021.AICopenhagen, DK201651-200Contact for pricingAdjacentApr 27, 2026

Frequently asked

In-depth answers about GDPR Art. 22.

Compare across industries

See which vendors support GDPR Art. 22 in your sector.

Last verified April 28, 2026. Informational summary only — not legal advice. Consult qualified counsel for specific obligations.