Automated decision-making is the part of the Data (Use and Access) Act 2025 that changed the most and has been explained the least. Most commentary on the Act led with cookies, complaints procedures and subject access searches. Meanwhile, section 80 quietly deleted Article 22 of the UK GDPR and replaced it with four new articles that invert the default position UK businesses have worked to since 2018.

The old rule was a prohibition. You could not make a solely automated decision with legal or similarly significant effects unless you fitted one of three narrow exceptions. The new rule is a permission with conditions attached. For ordinary personal data you may now make those decisions, provided you build and evidence a specific set of safeguards. That sounds like deregulation. In practice it moves work from your lawyers to your engineers, and it moves the risk from “did we have an exception?” to “can we show the safeguards actually worked?” Automated decision-making is now an operational discipline rather than a legal opinion.

This article covers what the new regime requires, where regulatory exposure sits in ordinary business software, and how to get compliant in sixty days. It is the fourth in our series on the Act. If you want the full statutory walkthrough, read the Data Use and Access Act 2025 risk checklist. For the before-and-after comparison, read what the DUAA changed against UK GDPR. For the small-business version, read the DUAA compliance checklist for UK SMEs.

One warning before the detail. The relaxation is narrower than the headlines suggested, and the enforcement surface is wider. Automated decision-making now carries a documented duty to notify, to accept representations, to provide human intervention and to allow a contest. Every one of those is a process an individual can test, and a complainant who tests one and finds nothing has handed the regulator a complete case.

What Automated Decision-Making Means Under the Data Use and Access Act

automated decision-making - automated decision making under the duaa b balanced scales beam

Before anything else, establish whether the rules reach you at all. Two conditions must both be true, and a great many systems that feel automated fail the second one entirely.

The two-part test that decides everything

A decision falls inside the regime only if it is significant and solely automated. Significant means it produces legal effects for the individual, or similarly significant effects — a job rejection, a credit refusal, a price that materially changes what someone pays, the closure of an account. Solely automated means there was no meaningful human involvement in reaching it. Fail either limb and the automated decision-making safeguards in Article 22C do not apply, although transparency, fairness and lawful basis obligations still do.

What “meaningful human involvement” actually requires

This is where most compliance programmes break. The ICO’s draft guidance takes a deliberately strict line. A human who designed or trained the system is not involved in the decision, because design happens before any individual case exists. A reviewer who has authority on paper but has never overturned an output is not involved either. Meaningful involvement means a named person, competent and authorised to change the outcome, who sees the inputs, understands the reasoning, and can and sometimes does decide differently.

Where the Act moved the line

Article 22A supplies the definitions. Article 22B keeps a prohibition for decisions based on special category data. Article 22C sets out the safeguards for everything else. Article 22D gives the Secretary of State power to define, by regulations, what counts as meaningful human involvement and what counts as a significant decision — so the boundary of automated decision-making can move again without new primary legislation.

The dates that matter

The Act received Royal Assent on 19 June 2025. The automated decision-making provisions in section 80 were commenced on 5 February 2026 by the Commencement No. 6 Regulations, and the remaining data protection provisions completed their staged commencement on 19 June 2026. There is no transitional period left to rely on.

AspectOld Article 22 (to 4 Feb 2026)New Articles 22A-22D (from 5 Feb 2026)
Default positionProhibited unless an exception appliedPermitted for ordinary data with safeguards
Legal basis neededConsent, contract necessity or lawAny valid lawful basis, including legitimate interests
Special category dataExplicit consent or substantial public interestEffectively unchanged — still restrictive
SafeguardsRequired only inside the exceptionsRequired for every significant decision
Definition of “solely”Case law and guidance onlyDefined in statute at Article 22A
Where the risk sitsChoosing a valid exceptionEvidencing that safeguards operated

The Four Safeguards Every Automated Decision-Making Process Must Carry

automated decision making under the duaa c shielded data cube

Article 22C is short, and each of its four limbs turns into a concrete build item. Treat them as product requirements rather than policy statements, because that is how a complaint will test them.

Tell the individual a decision was automated

The person must be informed that a significant decision about them was taken by automated means. A line buried in a privacy notice is weak evidence. Strong evidence is the decision message itself carrying the disclosure, logged and retrievable months later. This is the cheapest of the four automated decision-making safeguards to build and the one most often missing.

Let them make representations

Representations mean the individual can put their side before or after the outcome — new evidence, context the model never had, a correction to an input. You need a route that accepts free text, an owner who reads it, and a record that it was considered. An address that nobody monitors is worse than no address at all.

Provide genuine human intervention

Human intervention is the safeguard with teeth. Someone with authority must be able to re-take the decision. Automated decision-making programmes fail here most often, because the review queue is staffed by people who can explain the model but cannot overrule it. If your reviewer’s only available action is to re-run the system, you do not have a safeguard.

Allow a contest, and answer it

Contesting is distinct from complaining, though the two collide in practice. Since 19 June 2026 every UK controller must also run a data protection complaints procedure with a 30-day acknowledgement clock, so a contested automated decision usually arrives through that door. Align the two processes or you will answer the same person twice, inconsistently.

SafeguardWhat “done” looks likeEvidence to retain
NotificationDisclosure inside the decision messageMessage template plus send log
RepresentationsMonitored channel with a named ownerCase record showing what was considered
Human interventionReviewer authorised to overturnOverride rate and reasons, by quarter
ContestPublished route with a response deadlineOutcome log aligned to the complaints file
All fourTested end to end at least annuallyDated test record with the tester named

A first pass across a mid-sized controller with three or four in-scope systems runs to roughly 54 hours of work: 12 hours of discovery, 8 hours classifying what you find, 20 hours building safeguards, 10 hours testing and documenting, and about 4 hours per quarter to keep it alive.

Where the 54 hours go in a first automated decision-making review
Building the safeguards 20 hrs
Discovery across systems 12 hrs
Testing and documenting 10 hrs
Classifying what you find 8 hrs
Quarterly upkeep 4 hrs

Special Category Data Keeps the Stricter Automated Decision-Making Rules

automated decision making under the duaa d layered approval stack

The automated decision-making liberalisation stops abruptly at special category data. If a significant decision draws on health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation data, Article 22B keeps you close to the old regime.

What still needs an exception

For special category data, automated decision-making is prohibited unless the individual has given explicit consent, or the processing is necessary for a contract with them, or it is authorised by law — and in the latter two cases you also need a condition that meets the substantial public interest test. Legitimate interests will not carry you here, which is exactly the shortcut the ordinary-data reform invites people to take.

The inference trap

Special category data does not have to be collected deliberately to be present. A model that infers a health condition from shopping patterns, or ethnicity from a name and postcode, is processing special category data whether or not you asked for it. The ICO has been consistent on this point for years, and the DUAA did not change it.

Criminal offence data sits alongside it

Criminal offence data is not technically special category data but attracts a comparable restriction under Article 10. Any automated screening against a criminal records source, common in vetting and financial services, needs its own lawful footing before you consider safeguards.

QuestionOrdinary personal dataSpecial category data
Is a solely automated significant decision allowed?Yes, with Article 22C safeguardsOnly via a permitted route
Can legitimate interests be the basis?Yes, if the balancing test holdsNo
Is explicit consent needed?NoUsually, unless contract or law applies
Do the four safeguards still apply?YesYes, on top of the permitted route
Does inferred data count?Treated as ordinaryYes — inference is enough
Is a DPIA likely mandatory?OftenAlmost always

Where Automated Decision-Making Hides in Ordinary Business Software

automated decision making under the duaa e clock ring marker

Very few UK businesses believe they run automated decisions. Most of them do. The exposure rarely sits in a model somebody built; it sits in a feature somebody switched on inside a product they already pay for.

Recruitment and HR platforms

Applicant tracking systems that rank, score or auto-reject candidates are the clearest case, and the ICO has singled recruitment out for attention. Where a rejection is issued without a recruiter reading the application, that is automated decision-making with a significant effect, and CV parsing built on natural language processing can pull health or disability disclosures into scope alongside it.

Credit, payments and fraud

Credit scoring, affordability checks and payment fraud blocks are all significant decisions. A blocked transaction that strands a customer at a checkout has a similarly significant effect even if it lasts an hour, and volume makes the complaint arithmetic unforgiving.

Pricing, eligibility and insurance

Dynamic pricing that changes what an individual pays, eligibility engines that decide who sees an offer, and any renewal quote generated without human sight all belong on the automated decision-making register. Insurance pricing is the most exposed of these because it usually touches health data as well.

Access, moderation and account closure

Automated account suspension, content removal and access revocation are decisions about a person with real consequences. Businesses classify these as security controls rather than personal-data decisions, which is how they escape the register — and how they later surface in a complaint.

SystemIn scope?First action
ATS auto-rejection by scoreYes, almost alwaysInsert a real reviewer or build 22C safeguards
CRM lead scoringUsually not significantDocument why it falls outside
Credit or affordability checkYesFull safeguards plus DPIA
Fraud block at checkoutYesFast human review route
Individual dynamic pricingOftenAssess effect, then notify
Automated account closureYesNotification and contest route
Rota or shift allocationSometimesCheck the effect on pay and hours

Deciding where a genuine person sits in each of these flows is a design problem before it is a legal one. Our guide to human-in-the-loop AI workflows covers how to place reviewers so they can actually change outcomes rather than approve them.

Automated Decision-Making for UK Firms That Still Serve EU Customers

automated decision making under the duaa f two column ledger

Divergence is the trap that catches exporters and anyone with an EU-facing website. The UK moved; the European Union did not.

EU Article 22 is unchanged

For personal data processed under the EU GDPR, the original Article 22 prohibition still applies in full. A UK business handling EU residents’ data runs two regimes at once, and the stricter one governs that population. Building to the UK standard alone quietly breaks your EU position.

The SCHUFA judgment still bites

In SCHUFA (C-634/21) the Court of Justice held that producing a credit score can itself be the automated decision where a third party draws strongly on it. That reasoning applies to any scoring service whose output effectively determines the customer’s answer, and it has no UK equivalent softening it.

The EU AI Act overlaps but does not replace

The EU AI Act classifies employment, creditworthiness and essential-services systems as high risk, with its own documentation and human oversight duties. Data protection compliance does not discharge them. Our EU AI Act compliance checklist for UK companies sets out where the two regimes overlap and where they do not.

Adequacy is the commercial stake

The UK’s adequacy decision is the reason data flows from the EU without extra paperwork. Aggressive automated decision-making practices that stretch the new UK flexibility are the kind of thing that features in adequacy reviews, which is a reason for boards to stay conservative even where the statute allows more.

The 60-day plan, by phase length (days)
Classify and assess 20 days
Discover every candidate system 15 days
Build the safeguards 15 days
Test and document 10 days

Building the Automated Decision-Making Evidence Pack

Under the old law the question was whether you had a valid exception, and that was a document. Under the new law the question is whether the safeguards worked, and that is a record. Assume you will have to prove it eighteen months after the decision.

The register

One row per system: what it decides, whether the effect is significant, whether a human is meaningfully involved, the lawful basis, whether special category data is touched, who owns it, and the date of the last test. Six columns beat a forty-page policy nobody opens.

The DPIA

A data protection impact assessment remains mandatory for systematic evaluation with significant effects. The reform did not remove that trigger, and a live DPIA is the single artefact most likely to be requested first when a complaint lands.

The override log

Keep the rate at which human reviewers change automated outcomes, with reasons. It is the only direct evidence that intervention is real, and a rate of zero across thousands of decisions is an admission rather than a reassurance.

The model change record

Note when a threshold moves, a vendor ships a new version, or a training set is refreshed. Automated decision-making complaints usually concern a decision taken under a configuration that no longer exists, and without this record you cannot reconstruct it.

The annual test

Have someone unconnected to the system submit a representation and a contest through the public route, then record what happened and how long it took. This is the cheapest control here and the most persuasive to a regulator.

Seven Automated Decision-Making Failure Patterns the ICO Will Look For

These are the recurring shapes of failure. None of them requires a sophisticated model to go wrong.

The rubber stamp

A reviewer approves outputs at a rate indistinguishable from automatic. The organisation believes it has human involvement; the ICO reads the override rate and concludes the decision was solely automated after all, which means the safeguards were never in place.

The privacy notice that predates February 2026

Notices still describing the Article 22 prohibition are now wrong on the law and wrong about your practice. It is a two-hour drafting job and the most visible artefact you have.

The unowned inbox

A contest route pointing at an address that reaches a shared mailbox nobody reads. Automated decision-making duties fail on operations far more often than on drafting.

The vendor black box

Buying a scoring product whose logic the supplier will not explain does not transfer accountability. You remain the controller, and “the vendor would not tell us” is not a defence at any point in the chain.

The silent threshold change

Somebody moves a cut-off to reduce workload and nobody records it. Decisions before and after are materially different and you cannot demonstrate which rule applied to whom.

The security exception

Fraud and abuse controls classified as cybersecurity rather than as decisions about people. The effect on the individual is what counts, not the internal department that owns the switch.

The special category blind spot

A model fed free-text fields where applicants mention health, caring responsibilities or religion. Nobody chose to process special category data, but the system does, and Article 22B applies regardless of intent.

A 60-Day Plan to Bring Automated Decision-Making Into Compliance

Sixty days is enough for a mid-sized controller with a handful of systems, provided you start with discovery and resist the urge to write policy first.

Days 1 to 15 — discover

List every system that produces an outcome about a person. Ask each owner one question: can this system reject, price, rank, block or close without a person reading the case? Include vendor features you did not commission. Discovery is the phase people rush and then repeat.

Days 16 to 35 — classify and assess

Apply the two-part test to each candidate and record the answer with reasons. Mark special category exposure, including inferred data. Start or refresh DPIAs for everything still in scope. Most organisations find the in-scope list is shorter than feared and the special category list is longer.

Days 36 to 50 — build

Add the notification text, stand up the representations and contest routes with named owners, and give reviewers written authority to overturn outcomes. Automated decision-making safeguards are mostly small changes to systems you already run, not new platforms.

Days 51 to 60 — test and document

Run the end-to-end test, fix what breaks, and file the register, the DPIAs, the test record and the override baseline together. Diarise the quarterly review before you close the project, because an untested safeguard decays quietly.

Automated Decision-Making Questions UK Businesses Keep Asking

Does the DUAA mean we no longer need consent for automated decisions?

For ordinary personal data, largely yes — any valid lawful basis can now support automated decision-making, including legitimate interests. For special category data, explicit consent or another permitted route is still required under Article 22B.

Is profiling on its own caught by the automated decision-making rules?

No. Profiling is regulated processing but the Article 22C safeguards attach to significant decisions. Profiling that only informs a human decision-maker falls outside them, provided the human involvement is genuine.

Do these rules apply to internal decisions about staff?

Yes. Employees and candidates are data subjects, and hiring, performance and shift decisions with financial consequences are significant. Workplace systems attract close scrutiny precisely because the power imbalance limits reliance on consent.

What happens if we get a contest and disagree with it?

You must genuinely reconsider, then explain the outcome. You are not obliged to reverse the decision, only to show a competent person re-took it on the merits. Record the reasoning; it becomes your defence.

Does using a third-party AI service change our obligations?

No. If you decide the purpose, you are the controller and the safeguards are yours. Put explainability, override capability and change notification in the contract, because you cannot build the safeguards without them.

References