Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

UK GDPR automated decision making — UK GDPR Automated Decision Making: Articles 22A to 22C Explained

UK GDPR Automated Decision Making: Articles 22A to 22C Explained

UK GDPR automated decision making rules were rewritten on 5 February 2026. Article 22, the EU-derived provision that framed solely automated decisions as something an individual had a right not to be subject to, was replaced by Articles 22A to 22D, inserted by section 80 of the Data (Use and Access) Act 2025.

The new framework is permissive: a solely automated decision with significant effects may be made, provided the controller builds in four safeguards, and provided decisions based on special category data meet a stricter condition. This guide explains the two definitions that decide whether the rules apply, the special category restriction, the four safeguards, and how to assess an AI or scoring tool against them before it goes live.

What this guide covers

UK GDPR automated decision making explained
UK GDPR Automated Decision Making: Articles 22A to 22C Explained

The two definitions in UK GDPR automated decision making

Article 22A supplies the definitions. A decision is “based solely on automated processing” where there is no meaningful human involvement in taking it. A “significant decision” is one that produces a legal effect for the individual, or has a similarly significant effect on them. The rules in Articles 22B and 22C apply only to decisions that are both: solely automated and significant. Most of the practical work in applying the regime is deciding, honestly, whether a given process meets both definitions.

The UK GDPR automated decision making statute adds a pointer on human involvement: in deciding whether there is meaningful human involvement, the controller must consider, among other things, the extent to which the decision is reached by means of profiling. A process that scores a person by profiling and puts the score in front of a reviewer who approves almost every recommendation has a human in the loop, but not meaningful involvement. The test is whether a person with the authority and the competence to change the outcome actually considers it.

Question Inside the regime if Outside if
Is there meaningful human involvement? A reviewer rubber-stamps, lacks authority to change the outcome, or sees only the score A competent person with authority considers the case and could and does decide differently
Is there a legal effect? The decision affects legal rights or status: a contract refused, a benefit stopped, a licence denied No change to rights or status
Is there a similarly significant effect? Access to credit, employment, housing, insurance, education, essential services; a material financial consequence Which advert is shown; the order of search results; routine personalisation with no material consequence

Article 22B: the special category restriction

The second UK GDPR automated decision making rule concerns special category data. Where a solely automated significant decision is based entirely or partly on special category data, Article 22B permits it only in two situations: the individual has given explicit consent to the decision, or the decision is necessary for a contract with the individual or is required or authorised by law, and in either case a substantial public interest condition under Article 9(2)(g) is met. There is a third rule that is easy to miss.

Article 22B(4) provides that a significant decision may not be based solely on automated processing where the processing relies on the recognised legitimate interests basis in Article 6(1)(ea). A fraud system or a safeguarding tool that makes decisions without human review cannot use that basis; it needs another. Our guide to recognised legitimate interests explains the basis and its limits.

Article 22C: the four UK GDPR automated decision making safeguards

For every solely automated significant decision, whatever its lawful basis, Article 22C requires the controller to ensure that safeguards for the individual’s rights, freedoms and legitimate interests are in place. The article names four, and each has to be designed into the process rather than promised in a policy.

  • Information. The individual is told that a solely automated decision has been made about them, and given information about it: in the privacy notice in advance, and at the point of decision. The information should cover the logic in outline and the consequences, in terms the person can act on.
  • Representations. A route to make representations about the decision, stated in the communication that delivers it.
  • Human intervention. The ability to obtain human intervention from a named role with the authority to reconsider, within a stated period.
  • Contest. A route to contest the decision, with the outcome of the contest told to the person in writing, and the complaint routes stated.

The safeguards must be operating, not merely available. A “request a review” link that lands in an unmonitored inbox, or a human reviewer who has no power to change the automated outcome, is a safeguard on paper only. The Commissioner’s guidance on automated decision-making and profiling is the reference for what it expects to see operating.

How UK GDPR automated decision making differs from the EU rule

The EU’s Article 22 starts from a prohibition: the individual has the right not to be subject to a solely automated decision with legal or similarly significant effects, unless the decision is necessary for a contract, authorised by law, or based on explicit consent. The UK’s Articles 22A to 22D start from permission with conditions.

In practice the two produce the same outcome for special category data, where the UK rule is as strict as the EU’s, but they diverge for ordinary personal data: a UK controller may run a solely automated significant decision on legitimate interests, with the four safeguards, where an EU controller would need one of the three exceptions. The UK statute also defines meaningful human involvement in the text, which the EU leaves to guidance and case law. An organisation running the same tool for UK and EU individuals therefore applies two rules to it; see UK GDPR vs EU GDPR.

Assessing a tool before it goes live

The UK GDPR automated decision making assessment is a page, and it should be completed for every automated decision process, including AI tools bought from vendors, before deployment. It answers, in order: what decision is taken and about whom; whether there is meaningful human involvement, naming the reviewer, their authority and what they actually consider; whether the decision has a legal or similarly significant effect; whether it therefore falls within the regime; whether any special category data is used and which Article 22B condition applies; whether any of the processing relies on Article 6(1)(ea); and how each of the four safeguards is delivered.

Every such decision also requires a DPIA under Article 35(3)(a), which covers systematic and extensive evaluation based on automated processing on which decisions with legal or similar effects are based. Our guide to the DPIA covers the assessment; the automated decision page sits inside it.

Vendor assurances deserve particular scepticism. A supplier that says its tool “keeps a human in the loop” is describing its product, not the customer’s process. Whether involvement is meaningful depends on what the customer’s reviewer does with the output, and that is tested by looking at the override rate and the reviewer’s authority, not at the brochure.

Three UK GDPR automated decision making cases

An applicant tracking system rejects candidates below a score with no review. Solely automated; access to employment is a similarly significant effect; inside the regime. If the score uses health or disability data, Article 22B applies and explicit consent or a legal route with a substantial public interest condition is needed. Otherwise: lawful basis, DPIA, and the four safeguards, including a named recruiter who can and does reconsider.

A lender’s affordability model declines applications automatically. Solely automated; a legal effect; inside the regime. The notice, the decline letter with a representations route, a human underwriter with authority, and a contest process are the safeguards. If the model uses recognised legitimate interests for fraud screening, it cannot make the decision solely automatically on that basis.

A streaming service recommends content by profiling. Solely automated, but no legal or similarly significant effect; outside the regime, though profiling still needs a lawful basis, transparency and the right to object.

Transitional position

The new UK GDPR automated decision making articles applied from 5 February 2026 under the sixth commencement regulations, with transitional provisions for decisions in train. A process assessed under the old Article 22 before that date should be reassessed against the two definitions and the four safeguards, because the old exceptions and the new safeguards do not map one to one. Our summary of the Data (Use and Access) Act 2025 lists the commencement dates for each change.

Building UK GDPR automated decision making into the programme

A procedure that applies the two definitions and the special category rule; an assessment template per decision process; the four safeguards written into the notice, the decision communication and the review process; a register of automated decision processes; and a DPIA for each. The UK GDPR Toolkit ships the procedure with the assessment table and the safeguards table, the DPIA screening questionnaire that sends every such decision into a full assessment, and privacy notices that carry the automated decision-making statement. For the wider framework these rules sit in, see our guide to the UK GDPR.

Frequently asked questions on UK GDPR automated decision making

Is automated decision-making now allowed in the UK?

Under the UK GDPR automated decision making rules, solely automated significant decisions are permitted with the Article 22C safeguards, subject to the special category restriction in Article 22B. They were restricted under the old Article 22; they are conditioned under the new articles.

What counts as meaningful human involvement?

A person with the authority and competence to change the outcome who actually considers the individual case. The statute directs the controller to weigh how far the decision is reached by profiling; a reviewer who approves a profile-generated score without examining it is not meaningfully involved.

Does this apply to AI tools bought from a vendor?

Yes. The controller deploying the tool is responsible for the decisions it takes. The assessment is of the customer’s process, including what its reviewers do with the tool’s output.

Do I need a DPIA?

Yes, where a decision with legal or similarly significant effects is based on systematic and extensive automated evaluation. Article 35(3)(a) makes it mandatory in that case.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.