Duty

Letting software decide: automated decisions under UK GDPR

The old near-ban on fully automated decisions about people has been replaced by a system of safeguards. If you use software or AI to make decisions about customers or staff, here is what changed and what you must now put in place.

TheDutyDesk Editorial9 March 20263 min readReviewed 7 June 2026

More businesses now let software make decisions: who gets approved, who gets flagged, who moves to the next stage. The data protection rules around this used to start from a near-ban on fully automated decisions that had a serious effect on someone. As of 5 February 2026, the starting point has flipped.

From a ban to safeguards

The old rule, Article 22, has been replaced by a new set of rules, Articles 22A to 22D.[1] [3] Instead of mostly forbidding automated decisions, the law now mostly allows them, provided you put protections in place.

For ordinary personal data, a fully automated decision is now permitted as a starting point, as long as the required safeguards are there.[1] Decisions that use sensitive data, such as health or ethnicity, stay more tightly controlled.

This is a real shift. It gives businesses more room to automate, and in exchange it expects them to treat the people on the receiving end fairly.

The safeguards you have to provide

The protections are about transparency and the right to a human.[1] In practice that means:

telling people when a significant decision about them is made by software;

giving them a way to ask for a human to look at it;

and letting them challenge the decision or put their side.

The ICO is consulting on detailed guidance about exactly how to do this.[22] The direction is already clear: automation is fine, leaving people with no explanation and no way to object is not.

What this means for you

If no software makes meaningful decisions about your customers or staff, you can move on; this does not change much for you.

If it does, ask three questions. Where do we let software decide something that materially affects a person? Do we tell those people it is automated? Can they reach a human and challenge the outcome?

If the answer to the last two is no, that is your gap to close. The freedom to automate is genuine, but it comes with a duty to keep a person in the loop when someone asks for one.

Sources used in this article

  • [1]Data (Use and Access) Act 2025
  • [3]UK GDPR (retained EU regulation)
  • [22]ICO automated decision-making guidance and consultation, 2026

Source verification and SHA-256 hashes are maintained in our sources index.

Last reviewed: 7 June 2026. Next review: 9 September 2026, or sooner if relevant guidance changes.

TheDutyDesk helps you manage data protection complaints with a structured process and an audit trail.