The New Rules Are Now in Force
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. Section 80 replaced the former UK GDPR Article 22 framework with Articles 22A to 22D.
The ICO confirmed on 19 June 2026 that all DUAA data-protection provisions are now in force.
The central change is significant. For non-special-category personal data, the old narrow set of gateways has been replaced with greater scope to make solely automated significant decisions, provided the controller has an appropriate lawful basis and applies Article 22C safeguards.
That is permission with conditions, not a removal of accountability.
The ICO published detailed draft automated-decision guidance on 31 March 2026. The consultation closed on 29 May, and the ICO currently expects final guidance in winter 2026. This article reflects the legislation and that draft guidance as of 31 July 2026.
First Decide Whether Articles 22A–22D Apply
The ADM provisions apply only when all three elements are present.
| Question | Test |
|---|---|
| Is there a decision about a person? | The system reaches an evaluative conclusion or outcome using personal data |
| Is it significant? | It has a legal or similarly significant effect |
| Is it solely automated? | There is no meaningful human involvement in taking it |
An automated rule does not always amount to an automated decision. For example, a system that merely applies a payment-card rule previously fixed by a person may not itself evaluate the individual.
Likewise, an automated recommendation may be outside Articles 22A–22D if it does not significantly affect the person. The rest of UK GDPR still applies.
The ICO’s scope guidance gives examples of significant effects including:
- credit approval or refusal;
- recruitment decisions;
- access to housing, education or healthcare;
- public benefits and licences;
- bank-account freezes;
- insurance and financial terms;
- decisions affecting reputation or professional standing;
- some behavioural targeting involving children.
Context matters. A decision that is minor for most people may be significant for someone in a vulnerable position.
“Human Involvement” and “Human Intervention” Are Not the Same
This distinction should shape the product architecture.
| Concept | When it happens | Why it matters |
|---|---|---|
| Meaningful human involvement | Before the decision is applied | If genuine, the decision is not solely automated |
| Human intervention | After a solely automated significant decision | It is one of the Article 22C safeguards |
The ICO’s draft guidance says meaningful involvement must be active rather than tokenistic. The reviewer should:
- assess the particular decision at a point where it can still change;
- have discretion and authority to alter it;
- understand the system’s logic, outputs, limitations and risks;
- consider the relevant data and factors;
- record how they influenced the outcome.
Ad hoc sampling is not meaningful involvement for every decision because some outcomes receive no review. A person who simply accepts a score under time pressure may not be exercising real judgement.
Human intervention is the post-decision right to have a solely automated outcome reviewed case by case. The reviewer must again have the information and authority to change it.
Which Lawful Bases Can Be Used?
Controllers still need an Article 6 lawful basis and must meet the principles of fairness, lawfulness and transparency.
The DUAA opens a wider range of lawful bases for non-special-category ADM. One distinction is especially important:
- ordinary legitimate interests may be available, subject to the purpose, necessity and balancing tests;
- the new recognised legitimate interests basis cannot be used for significant solely automated decisions.
These are separate lawful bases. The ICO’s lawfulness guidance warns against confusing them.
| Potential basis | Practical question |
|---|---|
| Consent | Is it freely given, informed, specific and withdrawable? |
| Contract | Is the processing genuinely necessary for that person’s contract? |
| Public task | Is the task or authority laid down by law and is ADM necessary? |
| Legitimate interests | Does a documented three-part assessment support the impact? |
| Recognised legitimate interests | Prohibited as a basis for ADM |
A contractual term saying that automation may be used does not automatically make the processing necessary for contract. Recruitment shortlisting, for example, affects many applicants with whom no employment contract will be formed. The ICO draft uses that scenario to illustrate why another basis, potentially legitimate interests, may be more appropriate.
Whichever basis applies, Article 22C safeguards are still required.
Special-Category Data Remains Restricted
Article 22B preserves stricter rules where a significant solely automated decision is based wholly or partly on special-category data.
Under section 80 of the Act, this is permitted only where one of these routes applies:
- the decision is based entirely on personal data for which the person gave explicit consent; or
- the decision is necessary for a contract or required/authorised by law, and Article 9(2)(g) substantial public interest applies.
For the second route, the controller must identify an applicable substantial-public-interest condition in Schedule 1 Part 2 of the Data Protection Act 2018.
The analysis must cover three separate layers:
- an Article 6 lawful basis;
- an Article 9 condition;
- an Article 22B condition.
Do not collapse them into a single “lawful basis” field.
Sensitive Inferences Need a Precise Test
A proxy is not automatically special-category data simply because it correlates with a protected characteristic.
The ICO’s draft special-category guidance for ADM says inferred information may be special category where the controller intends to:
- infer information linked to a special category; or
- treat someone differently based on that inferred information.
If that intention exists, the inference may count even if it is uncertain or wrong.
A lineage review should therefore record:
- raw personal data;
- derived features and profiles;
- intended inferences;
- proxy variables;
- how each feature affects the outcome;
- whether special-category treatment is intended;
- downstream reuse and retention.
A vague statement that “the model might infer health” is not enough. Investigate what the organisation intends to learn or do with the output.
The Four Article 22C Safeguards
Article 22C requires controllers to put safeguards in place for every significant solely automated decision. They must enable the person to:
- receive information about the decision;
- make representations;
- obtain human intervention;
- contest the decision.
The ICO’s draft safeguard guidance says these safeguards must be applied consistently, not at the controller’s discretion.
Decision-specific information
A generic privacy notice is insufficient after an actual decision. The affected person needs information about their outcome, including:
- what the system decided;
- the practical effect;
- material data and timeframe;
- factors that contributed;
- whether profiling was involved;
- relevant third-party data;
- how to request correction or review.
The explanation should be concise and understandable. It does not need to expose source code, but the controller must understand enough about the process to explain the outcome.
Representations
Give the person a straightforward way to add facts, correct records or explain context the system missed. Tell them explicitly that they can do so.
Human intervention
The reviewer should have:
- the original data and material facts;
- the decision and its reason;
- the applicable policy;
- additional evidence supplied by the person;
- authority to change the outcome;
- training on the system and its limitations.
Contesting the decision
Create an identifiable case, ownership queue and status route. The ICO draft says controllers must act without undue delay and at the latest within one month, with a possible further two-month extension for complex or multiple requests. If extended, the person must be told within the first month and given a reason.
Information Is Required at Three Moments
The ICO’s draft guidance on individual rights distinguishes three disclosure moments:
- when personal data is collected;
- when the person exercises access rights;
- when a significant solely automated decision is made.
At collection, privacy information should explain that ADM exists, provide meaningful information about the logic and describe significance and envisaged consequences.
After the decision, provide case-specific information that lets the person understand and challenge what happened.
For children, explanations must be genuinely age-appropriate.
A DPIA Is Part of the Design Work
The ICO says a data protection impact assessment is mandatory where processing involves systematic and extensive evaluation based on automation, including profiling, on which legally or similarly significant decisions are based.
Its draft DPIA section recommends a DPIA for any ADM because it is highly likely to create high risk.
A useful DPIA should document:
- the decision and affected population;
- purpose and lawful basis;
- data sources and inferred features;
- necessity and proportionality;
- special-category analysis;
- foreseeable error, bias and exclusion;
- information and contest routes;
- human-review capacity;
- security, retention and supplier controls;
- monitoring and shutdown conditions.
Complete it before the commercial workflow becomes difficult to change.
For systems used in underwriting or claims, our UK insurance AI guide applies the same decision, fairness, and review tests to a concrete regulated workflow.
Build a Review Packet, Not a Rubber Stamp
| Review element | Why it matters |
|---|---|
| Outcome and practical effect | Shows what must be reconsidered |
| Material inputs and timeframe | Enables accuracy checks |
| Policy and decision criteria | Separates model output from business rule |
| Missing or conflicting data | Reveals uncertainty |
| Plain-language reason | Supports meaningful challenge |
| Person’s representations | Adds overlooked context |
| Reviewer actions | Confirms real authority |
| Audit record | Demonstrates what changed and why |
Confidence scores can be included where they are valid and meaningful, but should not substitute for facts or create false precision.
Example: Automated Recruitment Shortlisting
A company uses an automated system to reject applicants before interview.
The decision may be significant because it affects employment opportunity. It is solely automated if no person meaningfully assesses each rejection before it is applied.
Before launch, the company should:
- identify an Article 6 basis;
- complete a legitimate-interests assessment if relying on legitimate interests;
- complete a DPIA;
- examine training and feature data for bias and sensitive inferences;
- tell applicants that ADM is used and explain the consequences;
- provide decision-specific reasons;
- let applicants correct data and submit context;
- appoint trained reviewers with authority to reinstate candidates;
- monitor overturns and group differences.
Adding a manager who occasionally samples rejected applications does not transform every decision into a human decision. Sampling is monitoring; case-level review is different.
That distinction should also be carried into the product controls described in our AI agent governance guide.
Monitor the Safeguard, Not Only the Model
Track:
- review-request rate;
- time to acknowledge and resolve;
- percentage of outcomes changed;
- corrections to source data;
- recurring decision factors in overturned cases;
- differences in access to review across groups;
- repeat complaints;
- reviewer capacity and confidence.
A high overturn rate may reveal poor data, an inappropriate policy, model weakness or inadequate scope. A very low review rate may indicate that the route is difficult to find or understand.
Monitoring statistical accuracy is also not human intervention. It does not reconsider a particular person’s decision.
Launch Checklist
- Define the exact decision and effect.
- Determine whether it is significant.
- Determine whether human involvement is genuinely meaningful.
- Identify and document the Article 6 basis.
- Distinguish legitimate interests from recognised legitimate interests.
- Map Article 9 and Article 22B conditions where special-category data is involved.
- Test intended sensitive inferences.
- Complete the DPIA.
- Design all four Article 22C safeguards.
- Provide information at collection, access and decision stages.
- Staff a qualified review queue.
- Meet the one-month rights-response deadline.
- Record reviews, reversals and systemic fixes.
- Monitor final ICO guidance expected in winter 2026.
Frequently Asked Questions
Did the DUAA remove restrictions on significant automated decisions?
It widened the lawful routes for non-special-category data. It retained restrictions for special-category data and requires Article 22C safeguards for significant solely automated decisions.
Can a company use legitimate interests?
Ordinary legitimate interests may be available after the three-part assessment. The separate recognised-legitimate-interests basis cannot be used for ADM.
Does adding a person make the decision non-automated?
Only if their involvement is meaningful: timely, informed, active and capable of changing the outcome before it is applied.
Does every inferred sensitive characteristic count as special-category data?
Not automatically. The ICO focuses on whether the controller intends to infer a special-category characteristic or treat someone differently based on the inference.
Is a privacy notice enough?
No. The person also needs decision-specific information and effective routes to make representations, obtain human intervention and contest the outcome.
The durable design principle is simple: determine scope precisely, keep the decision explainable and make correction a working product feature rather than an emergency compliance add-on.



