Within Decisions
What rights apply to automated AI decisions?
UK data-protection rules give people extra safeguards when automated processing has legal or similarly significant effects.
On this page
- When a decision is solely automated
- What legal or similarly significant effects mean
- How explanation, challenge and human intervention fit together
Page outline Jump by section
Introduction
When artificial intelligence or other automated systems make decisions about people, UK data-protection law provides additional safeguards if those decisions happen without meaningful human involvement and have serious consequences. Under the UK GDPR framework, individuals are protected when a decision is made solely through automated processing and produces legal effects or similarly significant effects on their lives. These protections matter because automated systems can influence access to jobs, credit, insurance, housing, services, and other important opportunities. The law therefore seeks to ensure that people are not left subject to opaque machine decisions without a way to understand, question, or challenge the outcome. [ICO+2ICO]ico.org.ukhose based on profiling, that have a legal or similarly significant effect on…Read more…
When a decision is solely automated
A decision is considered solely automated when it is made without meaningful human involvement. The key issue is not whether a human appears somewhere in the process, but whether that person genuinely reviews the case and has the authority and ability to alter the outcome before it takes effect. A superficial or rubber-stamp review does not usually count as meaningful human oversight. [Lexology+2LegalVision UK]lexology.comAutomated decision making: ICO consults on updated…20 May 2026 — Under the UK GDPR, a decision is “solely automated” where it…
Examples can include:
- An online credit application that is automatically approved or rejected by a scoring system.
- A recruitment platform that automatically excludes applicants based on algorithmic criteria.
- An automated fraud system that freezes an account without human review.
- Insurance pricing or eligibility decisions generated entirely by automated profiling. [ICO+2ICO]ico.org.ukThis refers to decisions made without any human involvement, for example: an online decision after you have applied for…
The distinction between automated assistance and automated decision-making is important. If a human decision-maker actively evaluates the evidence, questions the system’s recommendation, and can change the result, the decision may fall outside the category of solely automated decision-making. If the human merely confirms what the system recommends, the legal safeguards are more likely to apply. [Lexology]lexology.comAutomated decision making: ICO consults on updated…20 May 2026 — Under the UK GDPR, a decision is “solely automated” where it…
What legal or similarly significant effects mean
The special protections do not apply to every automated action. They focus on decisions that have a legal effect on a person or otherwise significantly affect them.
A legal effect directly changes a person’s legal rights or obligations. Examples include decisions affecting contractual rights, entitlement to benefits, immigration status, or eligibility for financial products. [GDPR]gdpr-info.euOpen source on gdpr-info.eu.
A similarly significant effect may not change legal rights directly but can still have a major impact on someone’s circumstances, opportunities, or behaviour. Examples often cited by regulators include decisions affecting employment prospects, access to education, access to credit, insurance terms, or the ability to use essential services. Whether an effect is significant can depend on context and on the practical consequences for the individual. [ICO+2Inside Privacy]ico.org.ukhose based on profiling, that have a legal or similarly significant effect on…Read more…
This threshold is important because it separates routine automation from situations where human dignity, fairness, and accountability become particularly important. A recommendation about which advertisement to display is unlikely to qualify. A system that automatically rejects a job applicant may well do so. [ICO]ico.org.ukhose based on profiling, that have a legal or similarly significant effect on…Read more…
How explanation, challenge and human intervention fit together
The core purpose of the UK GDPR safeguards is not simply transparency. It is to give people practical ways to understand and contest significant automated outcomes.
Access to meaningful information
Individuals are entitled to know when relevant automated decision-making is taking place and to receive meaningful information about the logic involved, along with information about the significance and likely consequences of the processing. The aim is not necessarily to disclose source code or proprietary algorithms. Instead, organisations should provide explanations that help people understand how relevant factors contributed to the outcome and what the decision means for them. [Crowell & Moring - Home+2Fieldfisher]crowell.com& MoringArticle 15 of the GDPR sets forth the data subject's right of …Read more
The Information Commissioner’s Office (ICO) has repeatedly stressed that technical complexity is not a valid excuse for failing to explain important automated decisions in an understandable way. [Fieldfisher]fieldfisher.comwhat constitutes meaningful information about automated decision makingWhat constitutes "meaningful information" about automated…18 Nov 2024 — The controller must provide meaningful information…
The right to challenge
A central safeguard is the ability to contest a decision. If an automated outcome appears incorrect, unfair, or based on inaccurate data, the affected person should have a route to challenge it. This recognises that automated systems can make mistakes, rely on outdated information, or apply rules in ways that create unintended consequences. [OUP Academic+2GDPR Local]academic.oup.comOUP AcademicMeaningful information and the right to explanationby AD Selbst · 2017 · Cited by 832 — Most important for this discussion, A…
Challenge rights are especially important because many AI-driven systems rely on statistical predictions rather than certainties. A person may therefore need an opportunity to explain circumstances that the system could not adequately capture. [arXiv]arxiv.orgConceptualising Contestability: Perspectives on Contesting Algorithmic DecisionsFebruary 23, 2021…
The right to human intervention
The law also links contestability to human review. Where the safeguards apply, individuals can seek meaningful human intervention rather than being left entirely at the mercy of an automated process. The reviewer should be capable of assessing the case independently, considering additional information, and changing the outcome where appropriate. [OUP Academic+2Autoriteit Persoonsgegevens]academic.oup.comOUP AcademicMeaningful information and the right to explanationby AD Selbst · 2017 · Cited by 832 — Most important for this discussion, A…
This requirement reflects a broader governance principle in AI oversight: human involvement should be genuine and effective, not merely symbolic. A reviewer who cannot question the system or lacks authority to alter the result provides little real protection. [Lexology]lexology.comAutomated decision making: ICO consults on updated…20 May 2026 — Under the UK GDPR, a decision is “solely automated” where it…
Why these safeguards matter in AI systems
Modern AI systems increasingly perform tasks that influence hiring, lending, fraud detection, customer screening, and access to services. As these systems become more sophisticated, it can become harder for affected individuals to understand why a particular outcome occurred. UK GDPR protections are intended to preserve accountability in these situations by ensuring that important decisions remain understandable and contestable. [ICO+2ICO]ico.org.uking to protect data subjects from solely automated decision making.Read more…
The safeguards do not prohibit all automation. Rather, they recognise that some decisions have consequences serious enough to justify additional protections. The combination of transparency, challenge rights, and meaningful human intervention aims to prevent important life outcomes from becoming unreviewable products of algorithmic processes. [ICO+2ICO]ico.org.ukhose based on profiling, that have a legal or similarly significant effect on…Read more…
A practical example
Imagine an AI-assisted recruitment system that automatically rejects candidates whose assessment scores fall below a threshold. If no recruiter meaningfully reviews those applications and the rejection determines whether a candidate can progress, the decision may qualify as a solely automated decision with a similarly significant effect. In that situation, the applicant may have rights relating to explanation, challenge, and human review under the UK GDPR framework. [ICO+2Keystone]ico.org.ukThis refers to decisions made without any human involvement, for example: an online decision after you have applied for…
This example illustrates the broader principle behind the law: when automated systems make consequential decisions about people, individuals should not be left without a way to understand what happened, question the outcome, and obtain meaningful human consideration of their case. [ICO+2ICO]ico.org.ukhose based on profiling, that have a legal or similarly significant effect on…Read more…
Endnotes
-
Source: ico.org.uk
Link: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/rights-related-to-automated-decision-making-including-profiling/Source snippet
hose based on profiling, that have a legal or similarly significant effect on...Read more...
-
Source: ico.org.uk
Link: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/explaining-decisions-made-with-artificial-intelligence/part-1-the-basics-of-explaining-ai/legal-framework/Source snippet
Legal frameworkArticle 22 of the GDPR gives individuals the right not to be subject to a solely automated decision producing legal or sim...
-
Source: gdpr-info.eu
Link: https://gdpr-info.eu/art-22-gdpr/ -
Source: lexology.com
Link: https://www.lexology.com/library/detail.aspx?g=0c02e28e-4a1e-4e8f-8bbe-88cb7f61547bSource snippet
Automated decision making: ICO consults on updated...20 May 2026 — Under the UK GDPR, a decision is “solely automated” where it...
Published: May 2026
-
Source: ico.org.uk
Link: https://ico.org.uk/for-the-public/your-rights-relating-to-decisions-being-made-about-you-without-human-involvement/Source snippet
This refers to decisions made without any human involvement, for example: an online decision after you have applied for...
-
Source: crowell.com
Title: & Moring
Link: https://www.crowell.com/en/insights/client-alerts/europes-highest-court-compels-[disclosureSource snippet
Article 15 of the GDPR sets forth the data subject's right of...Read more...
-
Source: fieldfisher.com
Title: what constitutes meaningful information about automated decision making
Link: https://www.fieldfisher.com/en/insights/what-constitutes-meaningful-information-about-automated-decision-makingSource snippet
What constitutes "meaningful information" about automated...18 Nov 2024 — The controller must provide meaningful information...
-
Source: academic.oup.com
Link: https://academic.oup.com/idpl/article/7/4/233/4762325Source snippet
OUP AcademicMeaningful information and the right to explanationby AD Selbst · 2017 · Cited by 832 — Most important for this discussion, A...
-
Source: arxiv.org
Link: https://arxiv.org/abs/2103.01774Source snippet
Conceptualising Contestability: Perspectives on Contesting Algorithmic DecisionsFebruary 23, 2021...
Published: February 23, 2021
-
Source: arxiv.org
Link: https://arxiv.org/abs/1803.07540 -
Source: ico.org.uk
Link: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-do-we-ensure-fairness-in-ai/what-is-the-impact-of-article-22-of-the-uk-gdpr-on-fairness/Source snippet
ing to protect data subjects from solely automated decision making.Read more...
-
Source: ico.org.uk
Link: https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/03/automated-decisions-can-streamline-the-hiring-process-with-the-right-safeguards-in-place/Source snippet
Automated decisions can streamline the hiring process31 Mar 2026 — We are calling on businesses to review their use of automated decision...
-
Source: legalvision.co.uk
Title: article 22 uk gdpr
Link: https://legalvision.co.uk/data-privacy-it/article-22-uk-gdpr/Source snippet
Automated Decision-Making31 Mar 2025 — Under Article 22 of the UK GDPR, individuals have the right not to be subject to a decision based...
-
Source: keystonelaw.com
Link: https://keystonelaw.com/keynotes/what-does-the-icos-warning-against-automated-decision-making-mean-for-ai-recruitment-and-employers/Source snippet
KeystoneWhat does the ICO's warning against automated decision-...This means they're using solely automated systems without meaningful h...
-
Source: insideprivacy.com
Link: https://www.insideprivacy.com/united-kingdom-2/uk-ico-consults-on-draft-automated-decision-making-guidance-and-sets-expectations-for-adm-in-recruitment/Source snippet
UK ICO Consults on Draft Automated Decision-Making...24 Apr 2026 — The Draft Guidance also clarifies that whether a decision has “signif...
-
Source: gdprlocal.com
Title: automated decision making gdpr
Link: https://gdprlocal.com/automated-decision-making-gdpr/Source snippet
Automated Decision Making: Overview of GDPR Article 224 Sept 2025 — Individuals have the right to obtain human intervention, express thei...
-
Source: autoriteitpersoonsgegevens.nl
Title: right to human intervention in decision making processes
Link: https://www.autoriteitpersoonsgegevens.nl/en/themes/basic-gdpr/privacy-rights-under-the-gdpr/right-to-human-intervention-in-decision-making-processesSource snippet
Right to human intervention in decision-making processes9 Apr 2025 — GDPR gives people the right to human intervention in automated decis...
-
Source: ico.org.uk
Link: https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/2026/03/ico-consultation-on-the-draft-guidance-about-automated-decision-making-including-profiling/Source snippet
It isn't intended to cover every data protection concept and provides links to...Read more...
-
Source: ico.org.uk
Link: https://ico.org.uk/media2/bibhz1gs/existing-guidance-automated-decision-making-and-profiling.pdfSource snippet
Automated decision- making and profilingThe UK GDPR gives people the right not to be subject to solely automated decisions, including pro...
-
Source: ico.org.uk
Link: https://ico.org.uk/for-organisations/law-enforcement/guide-to-le-processing/individual-rights/right-not-to-be-subject-to-automated-decision-making/Source snippet
Right not to be subject to automated decision-makingPart 3 provides safeguards for individuals against the risk that a potentially damagi...
-
Source: bratby.law
Title: ai automated decision making
Link: https://bratby.law/practice-areas/data-protection/ai-automated-decision-making/Source snippet
Automated Decision-Making | UK GDPR and DUAA 2025Solely automated decisions with significant effects are now permitted for most personal...
Additional References
-
Source: freeths.co.uk
Link: https://www.freeths.co.uk/insights-events/legal-articles/2026/ico-consults-on-updated-automated-decision-making-and-profiling-guidance/Source snippet
ICO consults on updated automated decision making and...2 days ago — The updated guidance is intended to help organisations understand w...
-
Source: linkedin.com
Link: https://www.linkedin.com/posts/information-commissioner%27s-office_yesterday-we-published-our-new-draft-automated-activity-7445095815812964352-G3P5Source snippet
UK GDPR Update: Automated Decision-Making Guidance... UK GDPR's article 22A provisions that relate to solely automated decisions with sig...
-
Source: edpb.europa.eu
Link: https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/automated-decision-making-and-profiling_enSource snippet
decision-making and profilingAutomated decision-making and profiling... During its first plenary meeting the European Data Protection Bo...
-
Source: handleygill.co.uk
Link: https://www.handleygill.co.uk/handley-gill-blog/section-80-data-use-and-access-act-2025-article-22a-uk-gdpr-automated-decision-making-automated-processing-meaningful-human-involvementSource snippet
What do we mean by meaningful?20 Mar 2026 — Article 22B UK GDPR imposes restrictions on significant decisions based partly or entirely on...
-
Source: linkedin.com
Link: https://www.linkedin.com/posts/privacy-partnership_privacy-partnership-briefing-art-22-new-rules-activity-7427315838250295297-YGmoSource snippet
UK GDPR Article 22 Changes: Automated Decision...11 Feb 2026 — — The safeguards at Article 22C are mandatory for all significant solely...
-
Source: globalpolicywatch.com
Link: https://www.globalpolicywatch.com/2026/04/uk-ico-consults-on-draft-automated-decision-making-guidance-and-sets-expectations-for-adm-in-recruitment/Source snippet
UK ICO Consults on Draft Automated Decision-Making...29 Apr 2026 — The Draft Guidance is the ICO's first detailed interpretation of the...
-
Source: twobirds.com
Link: https://www.twobirds.com/en/insights/2026/ico-launches-consultation-on-draft-guidance-on-automated-decision-making-and-profilingSource snippet
decision; and; which has a legal or similarly significant effect on a data subject. (Art. 22A). When is ADM allowed under new Articles 22...
-
Source: trilateralresearch.com
Link: https://trilateralresearch.com/emerging-technology/how-to-provide-meaningful-information-about-the-logic-involved-in-automated-decisionsSource snippet
How to provide meaningful information about the logic...15 Jun 2020 — This article outlines a step-by-step guidance to ensure GDPR compl...
-
Source: inquisitiveminds.bristows.com
Title: dsars trade secrets and automated decision making what counts as meaningful i
Link: https://inquisitiveminds.bristows.com/post/102jjlq/dsars-trade-secrets-and-automated-decision-making-what-counts-as-meaningful-iSource snippet
bristows.comDSARs, trade secrets, and automated decision-making20 Sept 2024 — If an individual is subject to automated decision-making, i...
-
Source: europeanlawblog.eu
Title: radical rewriting of article 22 gdpr on machine decisions in the ai era
Link: https://www.europeanlawblog.eu/pub/radical-rewriting-of-article-22-gdpr-on-machine-decisions-in-the-ai-eraSource snippet
Radical rewriting of Article 22 GDPR on machine decisions...13 Oct 2021 — Our proposal is to clarify and simplify Article 22 and to stre...
Topic Tree



