Skip to content

Automated decision making GDPR: UK rules after DUAA

Automated decision making under the UK GDPR changed after the DUAA. Test significant decisions, lawful bases, special category data and human challenge routes.

A recruitment screening diorama places a small reviewer beside two sorting bays beneath CAN THE ALGORITHM DECIDE?, with signs for SIGNIFICANT DECISION, HUMAN INTERVENTION and RIGHT TO CHALLENGE.
By AI Priority Map Editorial

Quick Answer: Automated decision making under the UK GDPR permits significant decisions solely by algorithm after the DUAA since 5 February 2026, but needs a lawful basis other than recognised legitimate interests and special-category checks. Affected people need information, a chance to challenge and make representations, and access to human intervention 1,2,3.

Summary in a mind map

Automated decision making GDPR: UK rules after DUAA
│
├─ Classify the decision
│   ├─ No meaningful human involvement means solely automated
│   └─ Legal or similar effect means significant
│
├─ Check permission
│   ├─ Review special-category data separately
│   ├─ Choose an applicable lawful basis
│   └─ Recognised legitimate interests is excluded
│
├─ Build safeguards
│   ├─ Explain significant decisions
│   ├─ Receive representations and challenges
│   └─ Provide meaningful human intervention
│
└─ Keep evidence
    ├─ Record workflow and reviewer authority
    └─ Test the challenge route before launch

First decide whether the algorithm makes the significant decision

The practical starting point is one real workflow, not the technology's product label. A recruitment agency might use a model to rank applicants, while a human reads every application and decides whom to interview. Another agency might automatically reject everyone below a threshold. Those workflows call for different assessments because the statutory test asks about the decision and the human role 1.

Screening stepWhat to establishEvidence to keep
OutputIs it advice, a ranking or a final decision?Workflow and configuration
Human roleCan the reviewer genuinely change the outcome?Instructions and review record
EffectDoes the outcome have a legal or similarly significant effect?Impact assessment for the person

Section 80 inserts Article 22A into the UK GDPR. Under that provision, a decision is solely automated if there is no meaningful human involvement. It is significant if it has a legal or similarly significant effect. Those are two separate questions. A process may use an algorithm without making the final decision solely by automated means; a final automated choice may also have an effect that is not significant under this definition 1.

What the DUAA changes for non-special-category decisions

Since 5 February 2026, the DUAA route has permitted significant solely automated decisions using non-special-category data more broadly, with Article 22C safeguards 1. Before that date, such decisions were restricted to cases necessary for a contract, permitted by UK law with appropriate safeguards, or made with the person's consent 2. The new route still excludes recognised legitimate interests 1,2. It does not mean a business can remove its purpose, lawful-basis and fairness review 2.

For a recruitment team, the decision is whether to permit automated rejection at all. The policy should specify the stage at which the system can act, the evidence it uses, and the person who can reverse an outcome after a challenge. If those controls cannot be described plainly, the company has not yet translated the legal possibility into a defensible process.

The distinction also matters for automated order processing. A system recommending which order to inspect is different from one that automatically denies a service to an identifiable customer. The effect on the person, the amount of human involvement and the data categories must be assessed for that use case, not borrowed from another automation project.

When special-category data still restricts the route

The wider position summarised by the ICO is not a blanket permission to make significant solely automated decisions using special-category data. Under UK GDPR Article 22B, inserted by section 80, such a decision is allowed only with the person's explicit consent, or where it is necessary for a contract or required or authorised by law and the substantial-public-interest condition in Article 9(2)(g) applies 1. The data used and inferred need to be examined, including sensitive information a model derives from ordinary inputs. A recruitment example could involve health information supplied to request an adjustment. It would be unsafe to treat that information as an ordinary screening score simply because it entered through the same form 2.

An intake map should show which fields, uploaded documents and inferred attributes the system can access. It should also show whether a sensitive field can influence the final outcome. This practical map determines which legal route needs closer review. If the answer is uncertain, the organisation should hold the automated step until it can explain the relevant data and restrictions.

The point is not to classify the entire supplier as safe or unsafe. A single deployment can contain several decisions. One feature may sort routine records; another may make a consequential decision about a person. The safeguards and data restrictions follow the actual processing, not the brand of software.

Which lawful bases remain available under the UK GDPR

The ICO states that any lawful basis except recognised legitimate interests may potentially be used for significant solely automated decisions. “Potentially” matters. A business still needs to establish that its chosen basis applies to the specific purpose and processing, and that other conditions are met. It cannot call the project a legitimate interest in general and assume that resolves the statutory exception 2.

The decision record should state the purpose, the proposed basis and why that basis fits the activity. It should identify any separate data category issue and the team approving the choice. A procurement document saying that the supplier is compliant does not replace the controller's account of why its own decision is lawful. The distinction between a controller and processor remains relevant to who makes that assessment.

For a company operating across the UK and EU, the UK route should be recorded separately from the EU position. A shared product interface does not make the two legal regimes identical. The UK and EU AI governance overview can help identify where a separate review is needed, but the business must still write down the basis for its UK decision.

What information and challenge route a person needs

The government's guidance identifies three safeguards: information about significant decisions, an opportunity to make representations and challenge them, and the ability to obtain human intervention. These are operational requirements, not a sentence to add to a policy while leaving the workflow untouched 3.

For the recruitment example, the candidate should be able to understand that an automated process made a significant decision and where to take a challenge. An inbox must reach someone who can retrieve the relevant decision record and assess it. The reviewer needs authority to change the result where justified. A team that can only repeat the system output has no effective review route.

The organisation should test the route before launch. Send a sample challenge, measure whether it reaches the right team and check that the reviewer can see the material required for a genuine assessment. This is a practical way to expose a missing human step before a person depends on it.

In words, the tree branches like this: if the decision is not significant, document the ordinary processing assessment. If a person meaningfully decides, retain evidence of that role. If a significant decision is solely automated, test the data, lawful basis and safeguards before enabling it.

How a person obtains human intervention

After a significant solely automated decision, Article 22C gives the affected person a route to obtain human intervention. The reviewer should consider the person's representations and challenge, examine the relevant decision record and be able to change the result. The organisation should specify where that authority sits and how the person reaches it 1,3.

A review log need not expose proprietary model details to be useful. It can identify the decision, the person's representation, the material considered by the reviewer and the outcome. That record gives the organisation evidence that the challenge route exists beyond its notice. Access should be limited to staff who need the information for that review.

This article cannot decide whether a particular output is “similarly significant” or which lawful basis fits a specific recruitment practice without its facts. The consequence for the individual and the actual decision path must be examined. Neither a vendor's feature description nor a generic policy can settle that assessment.

What to do next

Choose one proposed automated decision and diagram its data, outcome and human role. Ask whether the effect is significant, whether a person genuinely determines it, and whether special-category information can influence it. Record the proposed lawful basis and test the information, representation, challenge and human-intervention routes with a sample case. The safeguards described by the government should be usable in the real workflow 3.

If the process also involves business communications, assess that channel on its own rules. A lawful automated decision does not automatically make the collection, communication or later use of the person's data lawful.

Frequently Asked Questions

What is a solely automated significant decision under the UK GDPR?
A decision is solely automated when there is no meaningful human involvement. It is significant when it produces a legal or similarly significant effect on the person. Section 80 of the Data (Use and Access) Act 2025 inserts those definitions in UK GDPR Article 22A. A person merely approving an output without genuine ability to assess and alter it does not resolve the central question.
Can a UK business now make a significant decision by algorithm?
Potentially, yes, in wider circumstances after the DUAA changes, but safeguards still apply. The ICO says any lawful basis other than recognised legitimate interests may potentially support such processing. The business must also test whether special-category data is involved and provide information, a challenge route and human intervention. Permission cannot be inferred from the tool's availability alone.
Does a human click make a decision non-automated?
A click is not enough by itself. UK GDPR Article 22A asks whether there is meaningful human involvement in the decision. A reviewer needs the context and authority to consider the individual case and change the result. If the employee routinely accepts an algorithm's outcome without examining it, the organisation should assess the process as potentially solely automated.
Can recognised legitimate interests support significant automated decisions?
The ICO's DUAA summary expressly excludes recognised legitimate interests from the lawful bases that may potentially be used for significant solely automated decisions. Other bases still require their own conditions to be met. A business should document the actual basis for each use case instead of treating the change as a universal exemption for algorithmic decisions.
What must a person be able to do after an automated decision?
The government's DUAA guidance names information about significant decisions, a way to make representations and challenge the decision, and a way to obtain human intervention. The business should make those routes usable by the affected person, with a team able to review the specific outcome. A generic contact form without a decision review process would leave a practical gap.

Sources

  1. 1.Data (Use and Access) Act 2025 — legislation.gov.uk · 2025
  2. 2.The Data (Use and Access) Act 2025 (DUAA) – summary of the changes — ICO · 2025
  3. 3.Data (Use and Access) Act 2025: data protection and privacy changes — GOV.UK · 2025

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.