UK GDPR Article 22 After the Data (Use and Access) Act 2025
9 min read · updated August 11, 2026
The UK has changed the operative rule on automated decision-making, and the change is structural rather than cosmetic. Where the EU keeps a prohibition with three exemptions, the UK now has a permission with safeguards, plus a narrower prohibition that survives for special-category data.
Where the UK started
On leaving the EU the UK retained the GDPR as the UK GDPR, sitting alongside the Data Protection Act 2018. Article 22 came across essentially unchanged, and sections 14 and 49 to 50 of the DPA 2018 supplied the domestic detail for the “authorised by law” route and for law-enforcement and intelligence-services processing. For several years the UK and EU positions on Article 22 were the same provision applied by two regulators.
Two rounds of reform were attempted. The Data Protection and Digital Information Bill fell when Parliament was dissolved in May 2024. Its successor, the Data (Use and Access) Bill, was introduced in October 2024 and received Royal Assent on 19 June 2025 as the Data (Use and Access) Act 2025. The Act as enacted is published on legislation.gov.uk, which is the text to work from rather than any summary of the Bill, because the Bill changed materially during passage.
The 22A to 22D structure
The Act removes Article 22 from the UK GDPR and inserts a group of articles in its place. In outline:
- Article 22A supplies the definitions. It defines a “significant decision” as one producing legal effects or similarly significant effects for the data subject, and defines when a decision is taken based solely on automated processing — turning on the absence of meaningful human involvement, with the article directing attention to the extent to which the decision is reached by means of profiling.
- Article 22B contains the surviving restriction. A significant decision based entirely on automated processing is restricted where it is based on special-category data, and permitted outside that case subject to the safeguards.
- Article 22C sets out the safeguards the controller must put in place: informing the data subject that such a decision has been taken, enabling them to make representations, enabling them to obtain human intervention, and enabling them to contest the decision.
- Article 22D confers powers on the Secretary of State to make regulations, including on what does and does not constitute meaningful human involvement and on the safeguards themselves.
Read together, the effect is that for the ordinary commercial case — significant automated decisions not resting on special-category data — the UK moves from “prohibited unless one of three gateways applies” to “permitted provided the safeguards are delivered”.
Where this diverges from the EU
Four differences are worth stating precisely, because they are the ones that change what a compliance team has to build.
The default inverts, for most decisions. Under EU Article 22 a controller must first identify a gateway in Article 22(2). Under the UK provisions it must first ask whether special-category data is involved; if not, the question becomes whether the safeguards are in place. The safeguards themselves closely resemble the EU’s Article 22(3) list, so the substantive protections for the individual are less different than the structure is — but the compliance analysis starts in a different place and lands in a different place for the case where no EU gateway was available.
Special-category processing keeps the harder rule.Article 22B preserves a restriction where the decision rests on special categories, so the divergence does not reach health, biometric or similar decisions. An organisation whose automated decisions are in those categories gains little from the change.
Meaningful human involvement becomes definable by regulations. Article 22D gives the Secretary of State power to specify what does and does not count. That is a different constitutional arrangement from the EU, where the content of the concept is being worked out by the Court of Justice and the EDPB. It creates the possibility of a UK definition that is clearer and the possibility of one that moves with the government of the day; both are real. The underlying concept is discussed in meaningful human involvement.
The transparency duties are not what changed. The information duties in Articles 13, 14 and 15 remain, and the safeguards in Article 22C include telling the person a decision was taken. So a controller that relaxes its automated decision-making design should not also relax its explanation-of-logic disclosures; see what those provisions actually require.
The adequacy question sits behind all four and is not settled. The European Commission’s adequacy decisions for the UK were adopted in June 2021, were extended pending the outcome of the UK reform, and are reviewed against whether UK law continues to provide essentially equivalent protection. Whether the DUAA changes affect that assessment is a matter of opinion at the time of writing, not a matter of record. Anyone who tells you confidently that adequacy is safe, or that it is lost, is telling you a prediction.
Commencement, and why it matters
Royal Assent on 19 June 2025 is the date the Act became law. It is not the date its provisions took effect. The Act commences by regulations made by the Secretary of State, and the data-protection provisions were expected to be brought into force in stages, with transitional arrangements. This is the single most common error in commentary about the Act: describing the new Articles 22A to 22D as though they governed decisions taken the week after Assent.
Practically, that means two things. First, check the commencement position on legislation.gov.uk for the specific provision, since the site records which sections are in force. Second, if a decision was taken before the relevant commencement date, the law that applied to it is the old Article 22, and a complaint about it will be assessed on that basis. Compliance records need to note which regime a decision was made under, which sounds pedantic until an audit spans the boundary.
What to do if you operate in both
For most organisations serving both markets, the pragmatic answer is to build to the EU rule and treat the UK relaxation as unused headroom. The EU analysis satisfies the UK on every point where they differ, since the UK is the more permissive regime outside special-category decisions, and maintaining two decision-making designs for one product costs more than the flexibility is worth in almost every case.
The exception is the case the change was designed for: a decision that has no available EU gateway — not necessary for a contract, not authorised by law, and where consent would not be freely given — but which can be delivered with genuine human-intervention, representation and contest routes. That is now potentially lawful in the UK and not in the EU. If you intend to run it, run it as a UK-only decision path with the geographic scoping enforced in code rather than in policy, document the safeguards against Article 22C item by item, and revisit when the Article 22D regulations appear.
Watch the ICO output specifically rather than general commentary. The ICO consulted on updated automated decision-making and profiling guidance to reflect the Act, and its published guidance at ico.org.uk is the regulator’s own statement of how it will approach the new articles. The broader UK approach to AI regulation, which is not contained in this Act at all, is covered in UK AI regulation.