Back to Home
APIR Intelligence · Legal

GDPR Article 22 | Automated Decision-Making Disclosure

Last updated: May 24, 2026

Plain-English Summary

GDPR Article 22 gives you the right not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you. This page is APIR's honest answer to the question: do we do that?

Short answer: no, we don't make any decisions about people that meet the Article 22 threshold. But we do operate algorithms that score and rank things, and the law (and good practice) says we should explain them anyway. That's what this page does.

1.Article 22 | What It Covers

Article 22(1) reads, in essence: a data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

For Article 22 to bite, three conditions must all be true:

(a) The decision is solely automated. A human reviewer who can override the output breaks “solely”.

(b) It produces legal effects or similarly significant effects. Account closure, credit denial, insurance refusal, employment decision, access to essential services.

(c) The data subject is a natural person whose data is processed. APIR's outputs are about AI agents (software), not about natural persons. This is an important distinction explored in section 3.

2.Automated Decisions APIR Makes | And Whether They Trigger Article 22

Here is every algorithmic or AI-driven decision in the platform, and our assessment.

DecisionAbout WhomSolely Automated?Significant Effect?Art. 22 Applies?
Trust Genome scoreAn AI agent (software entity)Yes (deterministic algorithm)No: scores software, not peopleNo
Insurance ScoreAn AI agent (software entity)Yes (deterministic algorithm)No on the user; brokers underwrite humans separatelyNo
Ghost Audit findingsAn AI agent (software entity)No, human reviewer required to publishNoNo
Compliance AssessmentCustomer's agent + customer orgNo, drafts require human approvalNo: informational, not bindingNo
Kill-switch activationCustomer's agentNo, admin confirmation requiredNo effect on natural personsNo
Free-scan scoreA submitted AI modelYes (deterministic)No: about software, informationalNo
Spam / abuse blockingAccount holderSoft block: yes. Hard ban: no, requires human review.A soft block is reversible on contact; a hard ban could trigger Art. 22Borderline, handled with human review
Subscription billingAccount holderYes (Stripe)Contractual, Art. 22(2)(a) exception appliesExempt

3.Agents Are Not People

APIR scores AI agents. AI agents are software, not natural persons, so the agent-level scores (Trust Genome, Insurance Score, Ghost Audit findings) do not trigger Article 22, there is no data subject whose personal data is the basis of the decision.

What could trigger Article 22 is downstream use of these scores by a third party (e.g. a hiring platform using an agent's Trust score as a proxy for the developer's competence). We do not encourage that use, and our public scores carry a disclaimer to that effect.

4.The Logic Involved | Plainly

The algorithms we run are documented and reproducible. Here is how each works, in plain language:

Trust Genome score (0–100): an equal-weighted composite of 12 published dimensions, each capped by what the evidence model can attest. The canonical dimension list, caps and formula are published in the Trust Genome Methodology: that document is authoritative, not this summary. Inputs are objective signals from your audit history.

Insurance Score (0–100, grades AAA–D): a weighted blend of 8 sub-scores aligned to insurance underwriting factors. Sub-scores derive from the same audit signals as Trust Genome plus claim-history features. Weights are published.

Ghost Audit findings: deterministic rule pipeline (four layers: pulse check, drift detection, deep scan, adversarial probe) generates severity-tagged events. Claude drafts the narrative description from those events.

Compliance Assessment: Claude evaluates your registered agent metadata against the relevant framework's controls, drafts findings, suggests remediation. Humans review and publish.

You can request the exact prompt template, model version, and decision tree for any output by emailing privacy@apir.ai with subject “Art. 15 / Art. 22 request”.

5.Significance And Consequences

For each decision the platform makes about your data, here is the realistic consequence:

A low Trust Genome score on your agent: the agent shows as needing attention in your dashboard and may be flagged in a Trust Passport. It does not affect your account standing, billing, or access to the platform.

A low Insurance Score on your agent: brokers viewing it may quote higher premiums or decline to bind specific coverage. The decision to bind is the broker's, not APIR's. You can request a manual re-score at any time.

A Ghost Audit finding flagged on your agent: appears in your dashboard as a finding. No action is automatic. You can dismiss it as a false positive, request a human review, or remediate it.

A soft abuse block: reduced rate limits or temporary feature restrictions. Reversible on email contact within 24 hours.

6.Right To Human Review

Even though none of our decisions strictly trigger Article 22, we offer human review on every algorithmic output as a matter of policy. The procedure:

Email privacy@apir.ai with subject “Human review request” and reference the specific score, finding, or decision. A compliance team member responds within 48 business hours with the model used (if any), the inputs considered, and a manual second-pass assessment. If we got it wrong, we'll say so and fix it. If we stand by the original output, we'll explain why with citations.

For decisions you believe should never have been automated, you can also raise the issue with your supervisory authority. The European Data Protection Board maintains a list at edpb.europa.eu.

7.Right To Contest A Decision

If you disagree with an automated output that affects you, you can:

Request a re-run. Most scores are recomputed daily anyway; you can force a recompute at any time from the relevant page in the platform.

Submit additional evidence. If our score is missing context (e.g. you have an external audit we don't know about), upload it. The new evidence is incorporated within 7 business days.

Demand a human decision. For any score, finding, or restriction you believe materially affects you, email privacy@apir.ai requesting human review. We will not invoke the “contractual necessity” exception under Art. 22(2)(a) to avoid this.

8.Children And Vulnerable Users

The platform is not directed at people under 18 and we do not process data about children. We do not operate any automated decision-making that affects minors.

9.Updates

If we ever build a feature that would meet the Article 22 threshold, this page will be updated before the feature ships, and existing users will be notified by email at least 30 days in advance. We will run a Data Protection Impact Assessment (DPIA) under Art. 35 and publish a redacted summary.

10.Contact

For Article 22, Article 15, or any automated-decision question: privacy@apir.ai

Data Protection Officer: dpo@apir.ai

Report an AI incident: incidents@apir.ai