More businesses now let software make decisions: who gets approved, who gets flagged, who moves to the next stage. The data protection rules around this used to start from a near-ban on fully automated decisions that had a serious effect on someone. As of 5 February 2026, the starting point has flipped.
From a ban to safeguards
The old rule, Article 22, has been replaced by a new set of rules, Articles 22A to 22D.[1] [3] Instead of mostly forbidding automated decisions, the law now mostly allows them, provided you put protections in place.
For ordinary personal data, a fully automated decision is now permitted as a starting point, as long as the required safeguards are there.[1] Decisions that use sensitive data, such as health or ethnicity, stay more tightly controlled.
This is a real shift. It gives businesses more room to automate, and in exchange it expects them to treat the people on the receiving end fairly.
The safeguards you have to provide
The protections are about transparency and the right to a human.[1] In practice that means:
telling people when a significant decision about them is made by software;
giving them a way to ask for a human to look at it;
and letting them challenge the decision or put their side.
The ICO is consulting on detailed guidance about exactly how to do this.[22] The direction is already clear: automation is fine, leaving people with no explanation and no way to object is not.
What this means for you
If no software makes meaningful decisions about your customers or staff, you can move on; this does not change much for you.
If it does, ask three questions. Where do we let software decide something that materially affects a person? Do we tell those people it is automated? Can they reach a human and challenge the outcome?
If the answer to the last two is no, that is your gap to close. The freedom to automate is genuine, but it comes with a duty to keep a person in the loop when someone asks for one.