GDPR Article 22 and Automated Appointment Eligibility: When Scheduling Becomes a Decision
An automated scheduling feature does not fall under GDPR Article 22 merely because software is involved. The threshold asks three questions together: does the system make a decision, is that decision based solely on automated processing, and does it produce legal effects or similarly significantly affect the person? Automated appointment eligibility can cross that threshold when it denies, delays, or diverts access to care without meaningful human involvement, but the result depends on the actual workflow and effect.
Slot sorting, reminders, and administrative suggestions are not automatically Article 22 decisions. A product team needs to trace who or what determines the outcome, whether a person can genuinely change it before it takes effect, what data drives it, and how serious the consequence is for the person seeking care.
The three-part Article 22 threshold
Article 22(1) gives a person the right not to be subject to a decision based solely on automated processing, including profiling, when it produces legal effects concerning that person or similarly significantly affects that person. The Court of Justice described these as cumulative conditions in its SCHUFA judgment.
Start with a decision. Displaying open times may supply information without deciding whether a person can receive care. A rule that labels someone ineligible, blocks suitable times, creates a slower route, or assigns a pathway that determines access is closer to a decision. Labels such as “recommendation” or “triage support” do not settle what the system does.
Next ask whether processing is solely automated. A staff member who merely receives the score and confirms the same outcome may not supply meaningful involvement. Finally, assess the effect. Article 22 does not cover every inconvenience. The legal or similarly significant standard needs a fact-specific account of the person’s circumstances, the service, the delay, available alternatives, and the consequence of the outcome.
Scheduling support versus appointment eligibility
A calendar can automate steps without making an eligibility decision. It can sort slots by location, display clinician availability, send reminders, or detect a duplicate booking. Those functions may involve personal data and other GDPR duties, but Article 22 requires the three-part threshold.
Eligibility logic asks a different question. It may use age, location, symptoms, referral status, payment route, prior interactions, or a generated risk score to decide whether a person can book, which service is available, or how soon a request is considered. Some of those inputs can reveal health information. Some outcomes may have little effect; others may materially limit access.
Map the real outcome rather than the interface. A user who can click “request review” only after an automatic refusal has already experienced an automated decision. A clinician who receives a suggestion and freely assesses the underlying information before any effect may be part of a different workflow. The review must examine authority, timing, information, and actual ability to change the result.
What SCHUFA changes about upstream scores
In Case C-634/21, the Court considered a credit information agency that automatically created a probability value. A third party used that score to establish, implement, or terminate a contractual relationship. The Court held that producing the score could itself constitute automated individual decision-making where the third party drew strongly on it.
The case concerned credit scoring, not healthcare appointments. It should not be presented as a judgment that every health risk score is an Article 22 decision. Its relevant principle is functional: separating score generation from the final system does not necessarily avoid Article 22 when the score strongly determines the downstream result.
For an appointment workflow, test how often staff depart from the score, what information they see, whether they have authority and time to reassess it, and whether the person receives a different outcome before the decision takes effect. A nominal reviewer or an unexplained override button is not evidence by itself.
Exceptions do not remove the safeguards
Article 22(2) lists three circumstances in which paragraph 1 does not apply. The decision may be necessary for entering into or performing a contract, authorized by Union or Member State law that also provides suitable safeguards, or based on the person’s explicit consent. These are defined routes, not a general list of convenient legal bases.
For the contract and explicit-consent routes, Article 22(3) requires suitable measures to protect rights, freedoms, and legitimate interests. At minimum, the controller must provide the right to obtain human intervention, express a point of view, and contest the decision. A team should not assume that scheduling automation is necessary for a contract merely because it is cheaper or already deployed.
The law-authorized route depends on the applicable Union or Member State measure and the safeguards it establishes. National healthcare rules may also affect the service and professional duties. The sources mapped to this article do not answer those jurisdiction-specific questions, so a local legal assessment remains necessary.
Health data creates an additional restriction
Article 22(4) limits decisions covered by the Article 22(2) exceptions when they are based on special categories of personal data under Article 9(1). Health data is one of those categories. Such decisions may be based on special-category data only when Article 9(2)(a) or 9(2)(g) applies and suitable measures protect the person’s rights, freedoms, and legitimate interests.
Article 9(2)(a) concerns explicit consent under its stated conditions. Article 9(2)(g) concerns processing necessary for reasons of substantial public interest based on Union or Member State law that meets the regulation’s requirements. This restriction means a general Article 6 analysis or ordinary consent label does not complete the review.
Consent also needs to remain separate from unrelated permissions. The article on authorization, privacy consent, and platform permission addresses a US advertising context, but its operational lesson still helps: record each permission against its own source, purpose, and scope rather than treating one checkbox as universal approval.
Explanation, intervention, and contest must work in practice
In Case C-203/22, Dun & Bradstreet Austria, the Court interpreted the right to meaningful information about the logic involved under Article 15(1)(h). For automated decision-making within Article 22, the person may require an explanation of the procedure and principles actually applied to use personal data and reach the specific result. The explanation must be concise, transparent, intelligible, and easily accessible.
The judgment says the controller does not satisfy that duty by providing a complex formula alone. It also addresses claimed trade secrets and third-party data: the controller cannot simply refuse all information, although a competent supervisory authority or court may need to balance the interests and determine the scope of access.
For appointment eligibility, connect the explanation to the person’s result. State which categories of information mattered, how the procedure applied, what consequence followed, and how to seek intervention or contest the result. Do not disclose another person’s data or pretend that a generic model description explains a specific outcome.
A product review that preserves the legal boundary
- Write the outcome in ordinary language: ranking, suggestion, delay, diversion, refusal, or another result.
- Identify the controller, processors, data sources, model or rules, and downstream decision maker.
- Test whether a person exercises meaningful control before the outcome takes effect.
- Describe the legal or practical consequence for the affected person and available alternatives.
- If Article 22 applies, document the exact exception relied on and every required safeguard.
- Identify special-category inputs and test Article 22(4) with Article 9 separately.
- Prepare a result-specific explanation, intervention route, point-of-view channel, and contest process.
- Test the workflow with realistic scenarios, including disagreement, missing data, and an incorrect score.
This is an editorial review sequence, not a substitute for a GDPR assessment. It should sit beside the controller’s broader work on lawful processing, transparency, data quality, security, retention, rights, and any required impact assessment. A narrow Article 22 conclusion does not approve the rest of the processing.
Keep health data inside the approved processing boundary during product testing. Where teams also measure marketing outcomes, the review of health conversion tracking outside HIPAA shows why a non-HIPAA environment can still carry privacy risk. For cloud and advertising boundaries, see why a provider agreement does not follow data into another product.
Frequently asked questions
Does automatically sorting appointment slots trigger Article 22?
Not automatically. The workflow must meet all three conditions: a decision, solely automated processing, and a legal or similarly significant effect. Slot ordering may fall short, while an automatic denial or material delay may require closer review.
Does a staff approval step always prevent the decision from being solely automated?
No. Review the staff member’s authority, information, time, and actual ability to change the outcome before it affects the person. A token confirmation step may not amount to meaningful involvement.
Can explicit consent always authorize automated health eligibility?
No universal conclusion follows. Article 22(2)(c), Article 22(3), Article 22(4), and Article 9 must be applied to the facts. Other GDPR duties and applicable healthcare law also remain.
Must the controller reveal its source code?
The cited Dun & Bradstreet Austria judgment focuses on a concise and understandable explanation of the procedure and principles actually applied. It rejects reliance on a complex formula alone and provides a balancing route for protected information; it does not create a universal source-code disclosure rule.
References
- European Union, “Regulation (EU) 2016/679, General Data Protection Regulation,” retrieved August 16, 2026, https://eur-lex.europa.eu/eli/reg/2016/679/oj
- Court of Justice of the European Union, “Judgment in Case C-634/21, SCHUFA Holding and Others (Scoring),” retrieved August 16, 2026, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0634
- Court of Justice of the European Union, “Judgment in Case C-203/22, Dun & Bradstreet Austria,” retrieved August 16, 2026, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=ecli:ECLI:EU:C:2025:117
- European Data Protection Board, “Guidelines on Automated Individual Decision-Making and Profiling,” retrieved August 16, 2026, https://www.edpb.europa.eu/documents/guideline/automated-decision-making-and-profiling_en
Related articles
Do AWS CloudTrail Multi-Region Trails Move Healthcare Audit Data Into One Region?
Yes. An AWS CloudTrail multi-Region trail can centralize events from enabled AWS Regions into one selected Amazon S3 bucket. The bucket may…
Why a Zocdoc Timeslot Update Must Send the Complete Provider Day
A Zocdoc timeslot update is a full replacement for one provider and date. The documented PUT /v1/providers/{provider_id}/calendar/timeslots…
How DrChrono Chooses the Time Zone for Appointment Reminders
DrChrono appointment reminders use a defined time-zone precedence. The practice group supplies the default reminder source, but an…