Understanding your situation
What you need to prepare
- ✓The decision you want explained (letter, email, notification, or screenshot)
- ✓The organization's name, address, and DPO contact details
- ✓Your reference number, account number, or application ID with the organization
- ✓A description of what you believe was automated about the decision
- ✓Any previous correspondence with the organization about the decision
- ✓A list of specific questions you want answered
⏰ Deadline
GDPR access requests must be answered within one month (Article 12(3)), extendable to three months for complex requests. AI Act Article 86 right-to-explanation obligations apply once the relevant provisions take effect (2 August 2026 for high-risk systems).
🏛️ Authority
Step 1: The organization itself (address the request to the DPO or compliance officer). Step 2: National Data Protection Authority - UODO (PL), BfDI (DE), CNIL (FR), ICO (UK), AEPD (ES), Garante (IT), AP (NL). Step 3: National AI competent authorities (once designated) for AI Act-specific rights.
⚖️ Legal basis
GDPR Article 15(1)(h): right to meaningful information about the logic involved in automated decision-making, its significance, and envisaged consequences. GDPR Articles 13(2)(f) and 14(2)(g): proactive transparency obligations. GDPR Article 22(3): right to obtain human intervention and contest automated decisions. From 2 August 2026 under current law: EU AI Act Article 86 establishes a right to explanation for individuals affected by high-risk AI decisions (Annex III, excluding category 2). Article 26(11) will require deployers to explain AI-assisted decisions to affected persons. Already enforceable: Article 85 allows complaints to market surveillance authorities about AI systems.
Expert tips
- 1Be specific about what you want to know. Request: (a) which personal data was used as input, (b) how the data was weighted, (c) which factors were most influential, (d) what outcome different input values would have produced, and (e) whether human review occurred.
- 2Cite the exact GDPR articles: 'Pursuant to Article 15(1)(h) GDPR, I request meaningful information about the logic involved in the automated processing, its significance, and the envisaged consequences for me.'
- 3If the organization responds with 'proprietary model' as a refusal, push back. The GDPR right to meaningful information does not permit blanket refusals based on trade secrets.
- 4From 2 August 2026 under current law, AI Act Article 86 will grant an explicit right to explanation for decisions made by high-risk AI systems listed in Annex III (excluding category 2). Reference this provision when writing to organizations that deploy such systems.
- 5Set a clear response deadline (e.g., 30 days per Article 12(3) GDPR). If the organization fails to respond, this becomes grounds for a DPA complaint.
- 6If the explanation reveals errors or bias, use this as the basis for contesting the decision under GDPR Article 22(3) or filing a formal complaint.
