Automated decision-making is the part of the Data (Use and Access) Act 2025 that changed the most and has been explained the least. Most commentary on the Act led with cookies, complaints procedures and subject access searches. Meanwhile, section 80 quietly deleted Article 22 of the UK GDPR and replaced it with four new articles that invert the default position UK businesses have worked to since 2018.
The old rule was a prohibition. You could not make a solely automated decision with legal or similarly significant effects unless you fitted one of three narrow exceptions. The new rule is a permission with conditions attached. For ordinary personal data you may now make those decisions, provided you build and evidence a specific set of safeguards. That sounds like deregulation. In practice it moves work from your lawyers to your engineers, and it moves the risk from “did we have an exception?” to “can we show the safeguards actually worked?” Automated decision-making is now an operational discipline rather than a legal opinion.
This article covers what the new regime requires, where regulatory exposure sits in ordinary business software, and how to get compliant in sixty days. It is the fourth in our series on the Act. If you want the full statutory walkthrough, read the Data Use and Access Act 2025 risk checklist. For the before-and-after comparison, read what the DUAA changed against UK GDPR. For the small-business version, read the DUAA compliance checklist for UK SMEs.
One warning before the detail. The relaxation is narrower than the headlines suggested, and the enforcement surface is wider. Automated decision-making now carries a documented duty to notify, to accept representations, to provide human intervention and to allow a contest. Every one of those is a process an individual can test, and a complainant who tests one and finds nothing has handed the regulator a complete case.
Table of contents
- What Automated Decision-Making Means Under the Data Use and Access Act
- The Four Safeguards Every Automated Decision-Making Process Must Carry
- Special Category Data Keeps the Stricter Automated Decision-Making Rules
- Where Automated Decision-Making Hides in Ordinary Business Software
- Automated Decision-Making for UK Firms That Still Serve EU Customers
- Building the Automated Decision-Making Evidence Pack
- Seven Automated Decision-Making Failure Patterns the ICO Will Look For
- A 60-Day Plan to Bring Automated Decision-Making Into Compliance
- Automated Decision-Making Questions UK Businesses Keep Asking
- References
What Automated Decision-Making Means Under the Data Use and Access Act
Before anything else, establish whether the rules reach you at all. Two conditions must both be true, and a great many systems that feel automated fail the second one entirely.
The two-part test that decides everything
A decision falls inside the regime only if it is significant and solely automated. Significant means it produces legal effects for the individual, or similarly significant effects — a job rejection, a credit refusal, a price that materially changes what someone pays, the closure of an account. Solely automated means there was no meaningful human involvement in reaching it. Fail either limb and the automated decision-making safeguards in Article 22C do not apply, although transparency, fairness and lawful basis obligations still do.
What “meaningful human involvement” actually requires
This is where most compliance programmes break. The ICO’s draft guidance takes a deliberately strict line. A human who designed or trained the system is not involved in the decision, because design happens before any individual case exists. A reviewer who has authority on paper but has never overturned an output is not involved either. Meaningful involvement means a named person, competent and authorised to change the outcome, who sees the inputs, understands the reasoning, and can and sometimes does decide differently.
Where the Act moved the line
Article 22A supplies the definitions. Article 22B keeps a prohibition for decisions based on special category data. Article 22C sets out the safeguards for everything else. Article 22D gives the Secretary of State power to define, by regulations, what counts as meaningful human involvement and what counts as a significant decision — so the boundary of automated decision-making can move again without new primary legislation.
The dates that matter
The Act received Royal Assent on 19 June 2025. The automated decision-making provisions in section 80 were commenced on 5 February 2026 by the Commencement No. 6 Regulations, and the remaining data protection provisions completed their staged commencement on 19 June 2026. There is no transitional period left to rely on.
| Aspect | Old Article 22 (to 4 Feb 2026) | New Articles 22A-22D (from 5 Feb 2026) |
|---|---|---|
| Default position | Prohibited unless an exception applied | Permitted for ordinary data with safeguards |
| Legal basis needed | Consent, contract necessity or law | Any valid lawful basis, including legitimate interests |
| Special category data | Explicit consent or substantial public interest | Effectively unchanged — still restrictive |
| Safeguards | Required only inside the exceptions | Required for every significant decision |
| Definition of “solely” | Case law and guidance only | Defined in statute at Article 22A |
| Where the risk sits | Choosing a valid exception | Evidencing that safeguards operated |
The Four Safeguards Every Automated Decision-Making Process Must Carry
Article 22C is short, and each of its four limbs turns into a concrete build item. Treat them as product requirements rather than policy statements, because that is how a complaint will test them.
Tell the individual a decision was automated
The person must be informed that a significant decision about them was taken by automated means. A line buried in a privacy notice is weak evidence. Strong evidence is the decision message itself carrying the disclosure, logged and retrievable months later. This is the cheapest of the four automated decision-making safeguards to build and the one most often missing.
Let them make representations
Representations mean the individual can put their side before or after the outcome — new evidence, context the model never had, a correction to an input. You need a route that accepts free text, an owner who reads it, and a record that it was considered. An address that nobody monitors is worse than no address at all.
Provide genuine human intervention
Human intervention is the safeguard with teeth. Someone with authority must be able to re-take the decision. Automated decision-making programmes fail here most often, because the review queue is staffed by people who can explain the model but cannot overrule it. If your reviewer’s only available action is to re-run the system, you do not have a safeguard.
Allow a contest, and answer it
Contesting is distinct from complaining, though the two collide in practice. Since 19 June 2026 every UK controller must also run a data protection complaints procedure with a 30-day acknowledgement clock, so a contested automated decision usually arrives through that door. Align the two processes or you will answer the same person twice, inconsistently.
| Safeguard | What “done” looks like | Evidence to retain |
|---|---|---|
| Notification | Disclosure inside the decision message | Message template plus send log |
| Representations | Monitored channel with a named owner | Case record showing what was considered |
| Human intervention | Reviewer authorised to overturn | Override rate and reasons, by quarter |
| Contest | Published route with a response deadline | Outcome log aligned to the complaints file |
| All four | Tested end to end at least annually | Dated test record with the tester named |
A first pass across a mid-sized controller with three or four in-scope systems runs to roughly 54 hours of work: 12 hours of discovery, 8 hours classifying what you find, 20 hours building safeguards, 10 hours testing and documenting, and about 4 hours per quarter to keep it alive.
Special Category Data Keeps the Stricter Automated Decision-Making Rules
The automated decision-making liberalisation stops abruptly at special category data. If a significant decision draws on health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation data, Article 22B keeps you close to the old regime.
What still needs an exception
For special category data, automated decision-making is prohibited unless the individual has given explicit consent, or the processing is necessary for a contract with them, or it is authorised by law — and in the latter two cases you also need a condition that meets the substantial public interest test. Legitimate interests will not carry you here, which is exactly the shortcut the ordinary-data reform invites people to take.
The inference trap
Special category data does not have to be collected deliberately to be present. A model that infers a health condition from shopping patterns, or ethnicity from a name and postcode, is processing special category data whether or not you asked for it. The ICO has been consistent on this point for years, and the DUAA did not change it.
Criminal offence data sits alongside it
Criminal offence data is not technically special category data but attracts a comparable restriction under Article 10. Any automated screening against a criminal records source, common in vetting and financial services, needs its own lawful footing before you consider safeguards.
| Question | Ordinary personal data | Special category data |
|---|---|---|
| Is a solely automated significant decision allowed? | Yes, with Article 22C safeguards | Only via a permitted route |
| Can legitimate interests be the basis? | Yes, if the balancing test holds | No |
| Is explicit consent needed? | No | Usually, unless contract or law applies |
| Do the four safeguards still apply? | Yes | Yes, on top of the permitted route |
| Does inferred data count? | Treated as ordinary | Yes — inference is enough |
| Is a DPIA likely mandatory? | Often | Almost always |
Where Automated Decision-Making Hides in Ordinary Business Software
Very few UK businesses believe they run automated decisions. Most of them do. The exposure rarely sits in a model somebody built; it sits in a feature somebody switched on inside a product they already pay for.
Recruitment and HR platforms
Applicant tracking systems that rank, score or auto-reject candidates are the clearest case, and the ICO has singled recruitment out for attention. Where a rejection is issued without a recruiter reading the application, that is automated decision-making with a significant effect, and CV parsing built on natural language processing can pull health or disability disclosures into scope alongside it.
Credit, payments and fraud
Credit scoring, affordability checks and payment fraud blocks are all significant decisions. A blocked transaction that strands a customer at a checkout has a similarly significant effect even if it lasts an hour, and volume makes the complaint arithmetic unforgiving.
Pricing, eligibility and insurance
Dynamic pricing that changes what an individual pays, eligibility engines that decide who sees an offer, and any renewal quote generated without human sight all belong on the automated decision-making register. Insurance pricing is the most exposed of these because it usually touches health data as well.
Access, moderation and account closure
Automated account suspension, content removal and access revocation are decisions about a person with real consequences. Businesses classify these as security controls rather than personal-data decisions, which is how they escape the register — and how they later surface in a complaint.
| System | In scope? | First action |
|---|---|---|
| ATS auto-rejection by score | Yes, almost always | Insert a real reviewer or build 22C safeguards |
| CRM lead scoring | Usually not significant | Document why it falls outside |
| Credit or affordability check | Yes | Full safeguards plus DPIA |
| Fraud block at checkout | Yes | Fast human review route |
| Individual dynamic pricing | Often | Assess effect, then notify |
| Automated account closure | Yes | Notification and contest route |
| Rota or shift allocation | Sometimes | Check the effect on pay and hours |
Deciding where a genuine person sits in each of these flows is a design problem before it is a legal one. Our guide to human-in-the-loop AI workflows covers how to place reviewers so they can actually change outcomes rather than approve them.
Automated Decision-Making for UK Firms That Still Serve EU Customers
Divergence is the trap that catches exporters and anyone with an EU-facing website. The UK moved; the European Union did not.
EU Article 22 is unchanged
For personal data processed under the EU GDPR, the original Article 22 prohibition still applies in full. A UK business handling EU residents’ data runs two regimes at once, and the stricter one governs that population. Building to the UK standard alone quietly breaks your EU position.
The SCHUFA judgment still bites
In SCHUFA (C-634/21) the Court of Justice held that producing a credit score can itself be the automated decision where a third party draws strongly on it. That reasoning applies to any scoring service whose output effectively determines the customer’s answer, and it has no UK equivalent softening it.
The EU AI Act overlaps but does not replace
The EU AI Act classifies employment, creditworthiness and essential-services systems as high risk, with its own documentation and human oversight duties. Data protection compliance does not discharge them. Our EU AI Act compliance checklist for UK companies sets out where the two regimes overlap and where they do not.
Adequacy is the commercial stake
The UK’s adequacy decision is the reason data flows from the EU without extra paperwork. Aggressive automated decision-making practices that stretch the new UK flexibility are the kind of thing that features in adequacy reviews, which is a reason for boards to stay conservative even where the statute allows more.
Building the Automated Decision-Making Evidence Pack
Under the old law the question was whether you had a valid exception, and that was a document. Under the new law the question is whether the safeguards worked, and that is a record. Assume you will have to prove it eighteen months after the decision.
The register
One row per system: what it decides, whether the effect is significant, whether a human is meaningfully involved, the lawful basis, whether special category data is touched, who owns it, and the date of the last test. Six columns beat a forty-page policy nobody opens.
The DPIA
A data protection impact assessment remains mandatory for systematic evaluation with significant effects. The reform did not remove that trigger, and a live DPIA is the single artefact most likely to be requested first when a complaint lands.
The override log
Keep the rate at which human reviewers change automated outcomes, with reasons. It is the only direct evidence that intervention is real, and a rate of zero across thousands of decisions is an admission rather than a reassurance.
The model change record
Note when a threshold moves, a vendor ships a new version, or a training set is refreshed. Automated decision-making complaints usually concern a decision taken under a configuration that no longer exists, and without this record you cannot reconstruct it.
The annual test
Have someone unconnected to the system submit a representation and a contest through the public route, then record what happened and how long it took. This is the cheapest control here and the most persuasive to a regulator.
Seven Automated Decision-Making Failure Patterns the ICO Will Look For
These are the recurring shapes of failure. None of them requires a sophisticated model to go wrong.
The rubber stamp
A reviewer approves outputs at a rate indistinguishable from automatic. The organisation believes it has human involvement; the ICO reads the override rate and concludes the decision was solely automated after all, which means the safeguards were never in place.
The privacy notice that predates February 2026
Notices still describing the Article 22 prohibition are now wrong on the law and wrong about your practice. It is a two-hour drafting job and the most visible artefact you have.
The unowned inbox
A contest route pointing at an address that reaches a shared mailbox nobody reads. Automated decision-making duties fail on operations far more often than on drafting.
The vendor black box
Buying a scoring product whose logic the supplier will not explain does not transfer accountability. You remain the controller, and “the vendor would not tell us” is not a defence at any point in the chain.
The silent threshold change
Somebody moves a cut-off to reduce workload and nobody records it. Decisions before and after are materially different and you cannot demonstrate which rule applied to whom.
The security exception
Fraud and abuse controls classified as cybersecurity rather than as decisions about people. The effect on the individual is what counts, not the internal department that owns the switch.
The special category blind spot
A model fed free-text fields where applicants mention health, caring responsibilities or religion. Nobody chose to process special category data, but the system does, and Article 22B applies regardless of intent.
A 60-Day Plan to Bring Automated Decision-Making Into Compliance
Sixty days is enough for a mid-sized controller with a handful of systems, provided you start with discovery and resist the urge to write policy first.
Days 1 to 15 — discover
List every system that produces an outcome about a person. Ask each owner one question: can this system reject, price, rank, block or close without a person reading the case? Include vendor features you did not commission. Discovery is the phase people rush and then repeat.
Days 16 to 35 — classify and assess
Apply the two-part test to each candidate and record the answer with reasons. Mark special category exposure, including inferred data. Start or refresh DPIAs for everything still in scope. Most organisations find the in-scope list is shorter than feared and the special category list is longer.
Days 36 to 50 — build
Add the notification text, stand up the representations and contest routes with named owners, and give reviewers written authority to overturn outcomes. Automated decision-making safeguards are mostly small changes to systems you already run, not new platforms.
Days 51 to 60 — test and document
Run the end-to-end test, fix what breaks, and file the register, the DPIAs, the test record and the override baseline together. Diarise the quarterly review before you close the project, because an untested safeguard decays quietly.
Automated Decision-Making Questions UK Businesses Keep Asking
Does the DUAA mean we no longer need consent for automated decisions?
For ordinary personal data, largely yes — any valid lawful basis can now support automated decision-making, including legitimate interests. For special category data, explicit consent or another permitted route is still required under Article 22B.
Is profiling on its own caught by the automated decision-making rules?
No. Profiling is regulated processing but the Article 22C safeguards attach to significant decisions. Profiling that only informs a human decision-maker falls outside them, provided the human involvement is genuine.
Do these rules apply to internal decisions about staff?
Yes. Employees and candidates are data subjects, and hiring, performance and shift decisions with financial consequences are significant. Workplace systems attract close scrutiny precisely because the power imbalance limits reliance on consent.
What happens if we get a contest and disagree with it?
You must genuinely reconsider, then explain the outcome. You are not obliged to reverse the decision, only to show a competent person re-took it on the merits. Record the reasoning; it becomes your defence.
Does using a third-party AI service change our obligations?
No. If you decide the purpose, you are the controller and the safeguards are yours. Put explainability, override capability and change notification in the contract, because you cannot build the safeguards without them.
References
Data (Use and Access) Act 2025
Data (Use and Access) Act 2025, Section 80: Automated Decision-Making
The Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026
ICO: Data (Use and Access) Act 2025
ICO: Summary of the Changes to Data Protection Law
ICO Consultation on Draft Guidance About Automated Decision-Making, Including Profiling
ICO: Rights Related to Automated Decision Making Including Profiling
ICO: Data Protection Impact Assessments
Court of Justice of the European Union, Case C-634/21 (SCHUFA Holding)
Regulation (EU) 2024/1689 Laying Down Harmonised Rules on Artificial Intelligence