
The Right to Talk to a Human (GDPR Article 22): What Your AI Bot Can Decide Alone
TL;DR
Yes, your customer has a right to talk to a human: GDPR Article 22 limits decisions a machine makes alone when they seriously affect someone. At a small business it almost never triggers — the bot informs, qualifies, and books; anything sensitive, or anyone who asks for a person, goes to your team via a warm handoff with full context. On voice it stays on the same call; on chat, the same thread.
If you're thinking about putting an AI in front of your customers, there's a piece of the world's strictest privacy law worth understanding before a customer brings it up: Article 22 of the GDPR. It's the one behind the idea of a right to talk to a human. And the short answer is reassuring. Article 22 doesn't ban an AI from handling customer service; it limits a machine from making serious decisions about someone on its own, and it guarantees a right to human intervention in the narrow cases where it applies. For a small business that informs, qualifies, and books, that almost never gets triggered. And when it does, the fix is common sense: get a person in, fast and with context. Let's translate it without the jargon.
What GDPR Article 22 says about automated decisions, in plain English
GDPR Article 22 says, in essence, one thing: no one should be subject to a decision based solely on automated processing when that decision produces legal effects or similarly significantly affects them (GDPR art. 22.1). And only in those cases does the person have the right to obtain human intervention, to express their point of view, and to contest the outcome (GDPR art. 22.3). That, in a sentence, is the right to talk to a human — a narrow right, not human service on demand for every question.
A quick note if you run a US business: the GDPR is EU law. It applies to you when you take calls from, or handle the data of, people in the EU — which more US companies do than realize it. Even where it doesn't bind you, it's the world's strictest data standard and a useful benchmark, and offering a person is fast becoming a baseline customer expectation everywhere — the kind of transparency US regulators like the FTC increasingly care about.
Read it twice and you'll spot the catch: the key word is solely. For Article 22 to kick in, three things have to be true at once: there's a specific decision about the person, it's made in a purely automated way (with no meaningful human involvement), and it produces legal effects or affects them in a similarly significant way (GDPR art. 22.1). Miss any one of the three and the article doesn't apply. The rule isn't concerned with an AI that helps you sort, inform, or set up an appointment. It's aimed at the machine that decides something big on its own — denying an online loan, screening out a job applicant, or refusing a benefit are the textbook examples from the EU's data protection board (the EDPB) — with no human able to step in. For ordinary customer service, that scenario simply doesn't come up.
This also overlaps with what the EU AI Act asks on transparency: a system that interacts with people has to tell them they're dealing with an AI (Regulation (EU) 2024/1689 — the AI Act — art. 50.1). That's a legal obligation on the system's provider under EU law, and it reaches you when you serve EU customers; outside the EU, disclosing that a customer is talking to an AI is simply best practice — and the kind of thing US regulators like the FTC frown on hiding. If you want the full picture of what's legal and what isn't when you use an AI agent for customer service, we break it down in is it legal to use an AI chatbot or voice agent for customer service.

What the bot decides on its own, and what needs a human
The easy way to think about it: the bot handles the objective and the repetitive; a person steps in when there's judgment, sensitivity, or consequence. Almost all of your day-to-day volume falls in the first column, and none of it is the kind of automated decision Article 22 regulates.
| Situation | The bot decides | A person decides |
|---|---|---|
| Sharing info and hours | – | |
| Qualifying a lead and capturing details | – | |
| Booking or moving an appointment based on availability | – | |
| Denying a service or a borderline case | – | |
| Serious complaints and disputes | – | |
| Sensitive data or a delicate situation | – |
Notice that booking an appointment or quoting a rate is not an Article 22 decision: it's objective information based on your availability and your prices. That's why the bot can do it without any problem, and it's actually where it adds the most value, because it picks up the phone in ~1 second, answers messages right away, and never clocks off, 24/7. What a machine shouldn't settle on its own is anything that carries real weight for the person: closing out a complaint, weighing a sensitive case, saying a "no" that has consequences.
The bot doesn't replace your team's judgment. It takes the 200 repeat questions off their plate so they arrive fresh at the 3 that matter.
There's a myth worth defusing here, because it's exactly what holds a lot of people back.
Myth
If I put in an AI, decisions about my customers get made by an algorithm, blindly.
Reality
The AI answers and prepares, but the decisions that carry weight are still made by your team. The handoff to a person is part of the design, not a patch.
Myth
The right to talk to a human means having someone on the phone at all times.
Reality
It means the customer can ask for one and get one. The AI covers 24/7 and routes to your team when human intervention is needed.
How to offer the right to talk to a human without friction
Article 22 grants the right to obtain human intervention, but only where an automated decision with legal or significant effects already exists, based on a contract or explicit consent (GDPR art. 22.3); it is not a universal right to have a human available for every question. That said, offering a path to escalate to a person is a trust best practice worth having at all times. The usual trap isn't denying that right on paper — it's making it so hard that in practice it doesn't exist: the fourteen-level phone menu, the endless "your call is important to us," the form nobody reads. That's the appearance of compliance without the substance.
Doing it well is the opposite, and it comes down to two things. One, the customer knows the option is there, because the agent says it's an AI from the very first second (how to say it without scaring anyone off is in how to disclose AI use without losing customers). And two, when they ask, it happens for real and fast. No maze. Saying "I'd rather talk to a person" should be enough.
1 click to pick up the conversation
That "fast and for real" is exactly where you see the difference between a well-built tool and an experiment stitched together from loose parts. And the piece that makes it possible has a name: the warm handoff.
Warm handoff: a person steps in with one click, with all the context
A "cold" handoff is the one we've all suffered: you get passed to someone else and have to tell the whole story again from scratch. A warm handoff is the opposite. The AI answered first, captured who you are, what you want, and what's been said so far, and when the human steps in, they step in with all of that in front of them. The customer repeats nothing: to them it's the same conversation; behind the scenes, who's on the other end has changed.
This is what turns the Article 22 right into something real instead of a checked box. There's no human "somewhere" you have to stumble your way toward: there's a clean handoff. Here's how it looks, step by step:
The AI answers first
The customer asks for a person, or the case calls for one
Warm handoff, on the same call or thread
The person continues with the context
And this works the same on a call as on WhatsApp, Instagram, Messenger, email, or web chat, because it all lands in one place. The difference is that on voice the handoff happens inside the call that's already live, and in messaging inside the thread that already exists. The human touch isn't lost: it's saved for when it adds something. We cover it in full in you don't lose the human touch: how AI hands the conversation to a person with full context.

How Totem handles it (and why it saves you the headache)
Here's the reassuring part. If you assemble your AI from loose parts, Article 22 becomes your job: who receives the request for a person? Where's the context? On which channel does the conversation continue? With an integrated platform, that's already solved by design.
With Totem, the AI answers first and your team takes over with all the context in the unified inbox. The "I want to talk to someone" request doesn't get lost or drop into a voicemail box; it triggers the handoff. If the channel is voice, your team steps into the same call. If it's chat, they step into the same thread. The decisions that carry weight are still made by your people, not an algorithm. And whatever the AI resolves is logged on your lead board, with sentiment analytics so you can see where a person should step in before the customer even asks.
~1 s
to pick up the phone, 24/7, disclosing that it's an AI
1 click
for a human to pick up the conversation with context
60%
less response time, according to our clients
Those are results our clients report, not a hard promise: the AI supplies the speed, but the judgment is still your team's. And the pieces that help you stay compliant — the AI Act disclosure, consent management, EU data hosting, and this handoff — come standard, not something you have to wire up by hand. One important nuance: the GDPR does not require data to physically stay in the EU — its Chapter V allows international transfers with adequate safeguards — so EU hosting is a product choice, not a legal requirement. We host to the EU standard anyway because that guarantee travels with you: even where no law makes us, you get a first-rate data baseline wherever you operate. How each piece fits together is in GDPR- and AI-Act-compliant AI customer service, built in. And if you've got concerns beyond the legal ones (whether it'll sound like a robot, where the human touch goes), we've answered them all in the guide to the most common concerns about AI customer service.
The takeaway is the same one we opened with: Article 22 doesn't hold you back; it describes how a good tool should work. Choose well, and the right to talk to a human is one click away — and you don't even have to think about it.
Official sources
- GDPR (Regulation (EU) 2016/679), art. 22 (automated decisions and human intervention) — EUR-Lex
- WP29/EDPB Guidelines on automated decision-making and profiling (WP251rev.01) — European Commission
- AI Act (Regulation (EU) 2024/1689), art. 50 (transparency) — EUR-Lex
Frequently asked questions
What does GDPR Article 22 say in a nutshell?
That no one may be subject to a decision based solely on automated processing when that decision produces legal effects or significantly affects them. And that, in those cases, the person has the right to obtain human intervention, to express their point of view, and to contest the decision. For ordinary customer service (informing, qualifying, booking), it almost never comes into play.
Can an AI agent decide on its own whether I get an appointment or a quote?
Booking an appointment based on availability or quoting a standard price is objective information, not a decision with significant effect, so the bot can do it. What a machine shouldn't settle on its own is something like denying a service, weighing a sensitive case, or closing out a complaint: that's where a person steps in.
How do you offer the right to talk to a human without friction?
It's enough that the customer can ask for it at any time and actually get it, with no endless menus. With Totem, saying 'I want to talk to someone' triggers the handoff: if it's a call, a human steps into that same call; if it's chat, into the same thread. Always with the context in front of them.
What is a warm handoff?
It's the relay where the AI answers first, gathers the context (who they are, what they want, what's been said) and, when a person is needed, that person takes over the conversation without the customer having to repeat everything. With Totem it happens in one click, in the same unified inbox.
Does GDPR Article 22 ban using AI in customer service?
No. Article 22 doesn't ban an AI from answering, informing, or qualifying. It only limits a machine from making, entirely on its own, a decision with legal or significant effects on a person, with no human able to review it. An AI that answers questions, captures details, and books appointments falls outside that scenario.
Does my customer have a right to know they're talking to an AI and not a person?
Under the EU AI Act, yes — a system that interacts with people must be designed to disclose it's an AI from the first moment (AI Act art. 50.1). That rule binds you if you serve EU customers; elsewhere, disclosing it up front is simply best practice (and the kind of transparency US regulators like the FTC expect). Either way, as a matter of good practice the customer should be able to ask for a person and actually get one. The duty to disclose falls on the system's provider, but the business using it must keep that notice switched on.



