Skip to content
Menu
Patent pending

Written for privacy counsel and DPOs, 16 August 2026

How do you show that human intervention was meaningful?

Article 22 turns on whether a person genuinely intervened or merely approved. That is a question about what someone did, and it is answered by evidence you either created at the time or did not. Here is what that evidence looks like.

Article 22 of the GDPR gives a person the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and where an exception applies, the right to obtain human intervention, to express a view, and to contest the decision. Regulators and courts have consistently read the human element as requiring authority and competence: a reviewer who can actually change the outcome, considering the case rather than confirming the score. Proving that happened requires a record made by that person, at that time, saying what they considered.

The provision and its safeguards are summarised at GDPR Article 22, safeguards on automated decisions.

Nominal review and the rubber stamp problem

The failure mode regulators describe is familiar: a system produces a score, a person clicks approve, and the organisation reports that a human was in the loop. On the record, that is indistinguishable from a considered decision. Both leave a user ID and a timestamp.

What distinguishes them is what the person actually weighed. If nobody recorded it at the time, the distinction cannot be recovered later, and the organisation is left arguing about a click.

What a record of real intervention carries

ElementWhat it shows
who intervenedA named person, attributable by their own signature, so authority can be traced to a role that holds it.
what they consideredThe factors and checks that person applied, in their words. This is the part that separates review from approval.
which decisionFingerprints binding the declaration to the exact record produced, so it cannot be attached to a different case.
whenThe time, marked self-asserted or countersigned by an independent time authority, so a reader knows what the timestamp is worth.
unchanged sinceA seal over the entry, so an edit after the fact shows rather than passing silently.

A Regulayer Receipt records exactly this and nothing about the data subject: fingerprints of the file, never the file. That matters here more than anywhere, because evidence of a decision should not require disclosing the personal data behind it. The format is at the Regulayer Receipt.

Current human authority, not retrospective sign-off

The value of the record comes from when it is made. A declaration written while the decision is being taken states what the reviewer weighed. One written afterwards, in response to a complaint, states what they recall or infer. Both may be honest; only one is contemporaneous.

This is what current human authority means in practice. The control sits before the consequence, at the point where a person exercises judgement, and the record of that judgement travels with the decision instead of being reconstructed when someone challenges it.

Data subject requests and what you can hand over

When someone contests a decision, they are entitled to meaningful information about the logic involved and to challenge the outcome. Producing evidence of the human step should not mean exposing other people's data, model internals or commercially sensitive material.

A content-free record is designed for that: it can be verified by anyone, including the data subject or a supervisory authority, without carrying the underlying case. The verifier runs in any browser, contacts no server, and needs only the record.

The limits

Tamper-evident, not tamper-proof. Nothing is unalterable. The guarantee is narrower and stronger: any change after sealing breaks the signature, and the break shows on verification.

It records evidence. It does not certify compliance. Whether processing falls inside Article 22, and whether an intervention was meaningful, are legal questions decided by regulators and courts on the facts. A record is evidence to put before them. It does not make an intervention meaningful and it does not certify compliance.

Attested, not proved. A signature makes a declaration permanent and attributable. It does not make it true. The record says a named person declared this, at this time, and nothing has changed since. That is what it shows, and it is all it shows.

Questions people ask

Does a signed record make the intervention meaningful?

No. Meaningfulness comes from the reviewer having the authority and competence to change the outcome, and actually considering the case. The record evidences what they did; it cannot supply what they did not do.

Does the record contain personal data?

It carries fingerprints of the file rather than the file, and nothing of the prompts, so it can be produced without disclosing the data subject's information. Whether the fields you choose to write include personal data is under your control.

Can the data subject check it themselves?

Yes. Verification is free, needs no account, and contacts no server. That independence is the point: the person contesting the decision does not have to take the controller's word for the record's integrity.

How does this relate to an audit trail more generally?

It is the same record applied to a specific obligation. What a defensible AI audit trail shows covers the general case, and the catalogue maps obligations to the evidence each one wants.

Record the intervention while the decision is being made.

The live demos sign a real record in your browser and let you alter it: change one character and verification flips to tampered. Seven days free, then $349 a month. Cancel at any time; records already signed stay independently verifiable.

Written 16 August 2026. A summary for orientation, not legal advice. A receipt attests what the signer declared; it does not certify compliance with Article 22, and the legal characterisation of any decision is for a regulator or court.