Everyone's watching the EU AI Act. But if your charity already uses AI to score applicants, rank a waiting list, or flag which cases get attention, a much older law is already talking to you — and it gives the people affected the right to ask a simple question: "why was this decided about me?" That law is the GDPR, and Article 22 is the part most small organisations have never read.
This article explains, in plain terms, when an AI-assisted decision triggers duties under data-protection law, what the people affected are entitled to, and how to set things up so you can answer them calmly. It's written for people who run organisations, not for lawyers.
This article is general information, not legal advice. It does not constitute legal advice, Vedomia does not certify compliance, and nothing here guarantees legal conformity. For your specific situation, speak to a qualified solicitor or your data protection adviser.
The rule most charities missed
Article 22 of the GDPR gives a person the right not to be subject to a decision based solely on automated processing — including profiling — where that decision produces legal effects or similarly significantly affects them.
Two phrases carry the weight, and both are good news for a careful charity:
- "Solely" automated. The rule bites when there is no meaningful human involvement — the system decides and the outcome stands. If a person genuinely reviews and can override the output, you're generally outside the strictest part of the rule. But the human review has to be real: a staff member who rubber-stamps whatever the AI says is not meaningful involvement.
- "Legal or similarly significant effects." This is about decisions that matter to someone's life — access to a service, a grant, support, a place on a programme, or being turned away. A decision about which newsletter to send is not this; a decision about who gets emergency assistance is.
The question isn't "do we use AI?" It's "does an AI decision, with no real human check, change something important for a person?" If yes, this rule is speaking to you.
Why this reaches charities before the AI Act does
Here's the part that surprises people. The AI Act's demanding "high-risk" obligations were pushed back to 2027 and 2028. But the GDPR has been in force since 2018. So if your charity uses AI to help make significant decisions about people, the data-protection duties may already apply today — regardless of where we are in the AI Act timeline.
Charities are more exposed here than they think, because the decisions they make are exactly the kind that "significantly affect" people:
- scoring or ranking applicants for support, grants or places on a programme;
- prioritising a waiting list or triaging who gets help first;
- flagging cases as high-need or high-risk;
- filtering job or volunteer applicants;
- using a third-party AI platform that quietly does any of the above on your behalf.
What the person affected is entitled to
Where Article 22 applies, the GDPR expects you to put safeguards in place. In practice, a person affected by a solely-automated significant decision has the right to:
- Human intervention — to have a real person look at the decision;
- To express their point of view;
- To contest the decision.
Alongside this, other parts of the GDPR (Articles 13–15) give people the right to "meaningful information about the logic involved" — often loosely called the "right to explanation." Legally it's narrower than a full technical breakdown, but the practical bar is clear enough: you should be able to tell someone, in plain language, what factors fed the decision and how it was reached. If no one in your organisation can explain that, that's the gap to close.
The plain-language test: if a service user emailed tomorrow and asked, "why was I turned down, and did a person decide?" — could you give a truthful, understandable answer within a few days? If not, the problem isn't the email. It's that the decision was never made explainable.
Two more duties that often travel with it
When AI helps make significant decisions about people, two other GDPR expectations usually come along:
- A Data Protection Impact Assessment (DPIA). The GDPR expects a DPIA before high-risk processing — and automated decision-making of this kind is a classic trigger. A DPIA is simply a structured think-through: what data, what could go wrong for people, and what safeguards reduce that risk. In Ireland, the Data Protection Commission publishes guidance and a list of processing that requires one.
- Transparency up front. People should be told, at the point you collect their data, if you use automated decision-making of this kind — not only when they complain. A clear line in your privacy notice, in words a person can understand, is the baseline.
A five-step check for your charity
You don't need a legal team to get your footing. You need one honest pass over how decisions actually get made.
Step 1 — Find the decisions that matter
List the decisions your organisation makes about people that genuinely affect them: who gets support, who gets a place, who gets prioritised, who gets hired. Ignore the trivial ones for now.
Step 2 — Mark where AI or scoring is involved
For each one, note whether any software, algorithm or AI tool produces a score, ranking or recommendation that feeds the decision — including tools hidden inside a third-party platform you use.
Step 3 — Ask the "solely" question honestly
For each AI-touched decision: does a person genuinely review and have the authority to overrule the system — and do they actually use it? Or does the output effectively stand on its own? Be honest; a review that never changes anything is not a review.
Step 4 — Make each one explainable
Write, in a few plain sentences, what factors drive the decision and how a person can question it. If you can't write it, you can't yet explain it to a service user — and that's the work.
Step 5 — Give people a way in
Decide, before anyone asks, how a person requests human review or contests a decision, and who handles it. Put that route somewhere they can find it. Keep a simple record when it's used.
A lightweight record you can keep
You don't need a database. A short internal table turns "we think we're fine" into evidence you can show a funder, a board, or the Data Protection Commission.
Significant decisions & automation — internal record
| Decision | AI / scoring involved? | Real human review? | How we explain & how a person can contest it |
|---|---|---|---|
| [e.g. Priority on support waiting list] | [e.g. Yes — platform assigns a need score] | [e.g. Caseworker reviews & can override; logged] | [Plain-language note of the factors; email route to request review within 10 days] |
| [e.g. Volunteer application screening] | [e.g. No — reviewed manually] | [n/a] | [Standard feedback on request] |
Review whenever you adopt or change a tool that scores or ranks people, and at least once a year.
How Vedomia can help
Vedomia is an Irish company focused on one thing: helping organisations make their processes and their use of AI visible, explainable and auditable. We work mainly with charities, nonprofits and publicly funded organisations.
Article 22 is, at heart, one of Vedomia's four pillars — Justification: being able to explain why a decision was made, on what basis, and who is responsible. That starts with seeing where AI touches the decisions you make about people.
- Transparency Self-Audit (free). Around 20 questions across four pillars — Visibility, Sequence, Justification, Auditability. It helps you surface where automated decisions happen and whether you can explain them.
- Mapped with you (€1,450, one-off). A single 90-minute session: you describe how one key process really runs, Sandra maps it live, and you leave with a finished, official document — the process end to end, where AI enters it, the evidence to keep and a prioritised 30–90 day plan. No homework, and it begins with a free Clarity Call.
To be clear about what we do and don't do: Vedomia supports readiness, helps you document your AI use, and identifies transparency gaps. We do not provide legal advice, we do not certify compliance, and nothing we provide guarantees legal conformity. For legal questions about a specific decision, speak to a qualified solicitor or your data protection adviser.
The right to ask "why was this decided about me?" isn't a threat to a good charity — it's a description of one. If you can answer it plainly, you're already most of the way there.
This article is general information about data-protection law and does not constitute legal advice.
Prepared with the help of an AI assistant, reviewed by Sandra Fedakova.
Not sure whether you could explain your AI-assisted decisions? Start here.
Take the Free Transparency Self-Audit