sota.io
Join the waitlist
2026-08-07·13 min read·sota.io team

UK GDPR Article 22 Is Gone: What DUAA Section 80 Means for Automated Decision-Making in 2026

UK GDPR Article 22 Is Gone: What DUAA Section 80 Means for Automated Decision-Making in 2026

If your product makes automated credit, fraud, pricing, moderation, or scoring decisions about people, and any of those people are in the United Kingdom, the rule you've been building against for years no longer exists. On February 5, 2026, the UK repealed Article 22 of UK GDPR — the "right not to be subject to a decision based solely on automated processing" — and replaced it with four new articles, 22A through 22D, inserted by Section 80 of the Data (Use and Access) Act 2025 ("DUAA"). Nothing changed in EU GDPR. If you serve both UK and EU users, you now run two different automated-decision-making regimes on the same feature, and most compliance write-ups on this topic gloss over the one subsection most likely to bite you: a new, blanket restriction that has nothing to do with special category data.

We read the primary legislation directly — the Act, its commencement regulations, and the pre-amendment Article 22 text for comparison — rather than relying on law-firm summaries, because the two most-repeated claims about this change ("automated decisions are now generally permitted" and "the special category restriction is the only new limit") are each half-right in a way that matters for how you gate a decision engine.

Timeline: what actually happened, and when

DateEvent
June 19, 2025DUAA receives Royal Assent. Section 80 comes into force only "for specified purposes" — the regulation-making power, not the substantive repeal (s.142(1)(2)(h))
February 5, 2026Section 80 and Schedule 6 fully commence via The Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026, SI 2026/82, reg. 2(j). Article 22 UK GDPR is repealed; Articles 22A-22D and the new "recognised legitimate interest" lawful basis (Article 6(1)(ea)) take effect the same day
March 31, 2026The ICO publishes a coordinated package on solely automated decision-making, including draft updated ADM/profiling guidance and a recruitment-sector report, and opens it for consultation
May 29, 2026, 23:59 GMTICO consultation on the draft ADM guidance closes
Today (August 7, 2026)Final ICO guidance has not yet been published. Until it is, the statutory text of Articles 22A-22D is the only authoritative interpretation available

What Article 22 UK GDPR actually said (and still says — for the EU)

Before repeal, Article 22(1) of UK GDPR was a prohibition by default:

"The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her."

That prohibition lifted only for three narrow exceptions — contract necessity, authorisation by law, or explicit consent — and even then, Article 22(3) required "suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision" for the contract and consent routes. Article 22(4) added a further block on using special category data (Article 9(1)) for these decisions, unless explicit consent or substantial public interest applied.

This is still the law for EU data subjects. EU GDPR Article 22 was not touched by DUAA — the UK's data protection statute has no authority to amend an EU regulation, and the DUAA amendments apply exclusively to "UK GDPR," the UK's own post-Brexit domestic version of the retained regulation. If your product has EU users, the old prohibition-with-exceptions model above is still exactly what applies to them.

What replaces it: Articles 22A-22D

Section 80 inserts a new Section 4A into UK GDPR containing four articles. Read together, they flip the structure from prohibition-with-exceptions to permission-with-mandatory-safeguards, but only for non-special-category data — and one subsection restricts a specific lawful basis regardless of data category.

Article 22A sets the vocabulary the rest of the framework depends on. A decision "is based solely on automated processing if there is no meaningful human involvement in the taking of the decision" (22A(1)(a)), and a "significant decision" is one that "produces a legal effect for the data subject" or "has a similarly significant effect for the data subject" (22A(1)(b)) — language carried over unchanged from the old Article 22(1) test. When assessing whether human involvement is meaningful, "a person must consider, among other things, the extent to which the decision is reached by means of profiling" (22A(2)) — rubber-stamping an algorithmic score without engaging with it does not count as meaningful involvement.

Article 22B ("Restrictions on automated decision-making") does two separate things, and conflating them is the most common way to get this wrong:

  1. Subsections (1)-(3) restrict significant decisions based entirely or partly on special category data (Article 9(1)) — these may not be solely automated unless the decision is based entirely on explicit consent, or is necessary for a contract or required/authorised by law and the substantial-public-interest condition in Article 9(2)(g) applies.
  2. Subsection (4) is a freestanding, general restriction that has nothing to do with special category data: "A significant decision may not be taken based solely on automated processing if the processing of personal data carried out by, or on behalf of, the decision-maker for the purposes of the decision is carried out entirely or partly in reliance on Article 6(1)(ea)." Article 6(1)(ea) is DUAA's brand-new seventh lawful basis, "recognised legitimate interest" — a closed list of purposes (defined in a new Annex to UK GDPR) that skips the balancing test ordinary legitimate interest (Article 6(1)(f)) requires. Article 22B(4) applies this restriction to any significant fully-automated decision, on any kind of personal data, not just special category data. If your lawful basis for the processing behind an automated decision is "recognised legitimate interest," the decision cannot be solely automated — full stop, regardless of what data it uses.

Article 22C is the safeguards article, and it applies to every significant automated decision that Articles 22A-22B permit, not just the old exception cases. Controllers must ensure measures that "(a) provide the data subject with information about decisions taken in relation to the data subject, (b) enable the data subject to make representations about such decisions, (c) enable the data subject to obtain human intervention on the part of the controller in relation to such decisions, and (d) enable the data subject to contest such decisions." This is structurally the same four-part list as old Article 22(3) — but where that list only applied when you relied on the contract or consent exception, Article 22C applies across the board, to every significant solely-automated decision permitted under the new regime.

Article 22D gives the Secretary of State power to make regulations clarifying "meaningful human involvement" and "similarly significant effect," and to add further safeguard requirements — but those regulations "may not amend Article 22C" itself. The core four-part safeguard list is fixed at the primary-legislation level; it cannot be watered down by statutory instrument.

The actual shift, stated precisely

The one-sentence version repeated in most commentary — "the UK relaxed the ban on automated decisions" — is directionally right but imprecise about scope. What actually changed:

Old Article 22 (still applies for EU data subjects)New Articles 22A-22D (UK data subjects, from Feb 5, 2026)
Default postureProhibited unless you fit an exception (contract / law / consent)Permitted for non-special-category data, subject to mandatory safeguards
When are safeguards requiredOnly for the contract and consent exceptions (Art.22(3))For every significant solely-automated decision (Art.22C)
Special category dataBlocked unless explicit consent or substantial public interest (Art.22(4))Same structure carried forward (Art.22B(1)-(3))
New restrictionBlanket ban on using "recognised legitimate interest" (Art.6(1)(ea)) as the basis for any significant solely-automated decision (Art.22B(4)), independent of data category
Human-in-the-loop barAny human sign-off satisfied the old exception route in practice for many teamsExplicit "meaningful human involvement" test tied to how much the human actually engages with profiling output (Art.22A(2))

The practical upshot for a typical SaaS: you no longer need to shoehorn every fully-automated significant decision into "necessary for the contract" or "the user consented" to make it lawful in the UK — but you must implement all four Article 22C safeguards for every such decision, you still cannot fully automate a significant decision built on special category data outside the narrow exceptions, and you cannot use the new no-balancing-test legitimate interest basis to justify full automation of a significant decision at all.

Schedule 6: the consequential changes that touch your privacy notice

Schedule 6 rewrites every cross-reference to the old Article 22 elsewhere in UK GDPR, and two of those changes affect what you have to disclose:

If your privacy notice currently references "Article 22" for its automated-decision-making section, that citation is now wrong for UK users — the correct reference for the safeguards obligation is Article 22C, and your notice should say so if it's going to survive a UK data subject access request that touches this.

Building for both regimes: a jurisdiction-aware decision gate

Because EU GDPR Article 22 and UK GDPR Articles 22A-22D are now genuinely different rules, a decision engine that serves both regions needs to branch on data-subject jurisdiction, not just on data category. A minimal shape for that gate:

type Jurisdiction = "EU" | "UK" | "OTHER";

type AdmContext = {
  jurisdiction: Jurisdiction;
  isSignificantDecision: boolean;      // legal effect or similarly significant effect
  usesSpecialCategoryData: boolean;    // Art.9(1) / UK GDPR Art.9(1)
  lawfulBasis:
    | "consent"
    | "contract"
    | "legal-obligation"
    | "vital-interests"
    | "public-task"
    | "legitimate-interest"
    | "recognised-legitimate-interest"; // UK-only, Art.6(1)(ea)
  hasMeaningfulHumanInvolvement: boolean;
};

function canFullyAutomate(ctx: AdmContext): { allowed: boolean; reason?: string } {
  if (!ctx.isSignificantDecision || ctx.hasMeaningfulHumanInvolvement) {
    return { allowed: true }; // outside scope of Art.22 / Art.22A-D entirely
  }

  if (ctx.jurisdiction === "EU") {
    // Old prohibition-with-exceptions model: still applies unchanged.
    const exceptionApplies =
      ctx.lawfulBasis === "contract" || ctx.lawfulBasis === "consent";
    if (!exceptionApplies) return { allowed: false, reason: "EU GDPR Art.22(1): no exception applies" };
    if (ctx.usesSpecialCategoryData) {
      return { allowed: false, reason: "EU GDPR Art.22(4): special category data requires explicit consent/substantial public interest" };
    }
    return { allowed: true }; // safeguards (Art.22(3)) still required downstream
  }

  if (ctx.jurisdiction === "UK") {
    // UK GDPR Art.22B(4): recognised legitimate interest can NEVER support full automation.
    if (ctx.lawfulBasis === "recognised-legitimate-interest") {
      return { allowed: false, reason: "UK GDPR Art.22B(4): Art.6(1)(ea) basis blocks solely automated significant decisions" };
    }
    if (ctx.usesSpecialCategoryData) {
      const permitted =
        ctx.lawfulBasis === "consent" ||
        ctx.lawfulBasis === "contract" ||
        ctx.lawfulBasis === "legal-obligation";
      if (!permitted) return { allowed: false, reason: "UK GDPR Art.22B(1)-(3): special category restriction not met" };
    }
    return { allowed: true }; // Art.22C safeguards mandatory regardless — see checklist below
  }

  return { allowed: true }; // outside UK/EU scope — check local law separately
}

Two things worth calling out about this shape: first, recognised-legitimate-interest only exists as an option in the UK branch — it's a UK-only lawful basis, so an EU-jurisdiction decision should never reach that code path in practice. Second, allowed: true on the UK branch is not the end of the compliance work — Article 22C requires you to actually build the four safeguards, not just clear the gate.

The Article 22C safeguards, as an engineering checklist

For every significant, solely-automated decision that clears the gate above (UK) or that already fell under the contract/consent exception (EU), you need concrete, testable implementations of:

  1. Information about the decision — a notice explaining that a decision was automated, what data drove it, and what its outcome/effect is. This has to exist before or at the point of the decision, not buried three clicks deep in a settings page.
  2. A representations channel — a way for the person to submit their side before or shortly after the decision takes effect, that a human actually reads. A contact-form black hole does not satisfy this.
  3. Human intervention on request — a defined escalation path to a person with actual authority to review and, if warranted, overturn the automated output. This needs an SLA and a named responsible role, not just a theoretical possibility.
  4. A contest mechanism — distinct from the representations channel: an explicit way to formally dispute the decision after the fact, with a tracked outcome.

None of these are new concepts if you already built for the old Article 22(3) exception cases — but under the new regime you can no longer scope them to "just the decisions where we relied on contract or consent." Every significant automated decision needs all four, which for most products means auditing every scoring, ranking, or auto-action feature you have — not just the ones you previously flagged as "Article 22-relevant."

What's still unsettled

The ICO's final guidance on Articles 22A-22D — including its interpretation of "meaningful human involvement" and "similarly significant effect" in practice — was still pending as of this writing; the draft guidance published March 31, 2026 went through consultation that closed May 29, 2026, but no final version has been published yet. The draft package's specific focus on recruitment (an accompanying sector report) signals where the ICO expects the most scrutiny first, but until final guidance lands, the statutory text above is the only binding reference. Treat any "the ICO says X counts as meaningful human involvement" claim you encounter before final publication as provisional.

The practical takeaway

If you have UK users and any feature that scores, ranks, approves, rejects, or prices something about a person without a human meaningfully reviewing the specific output, you have two jobs, not one: confirm whether it's a "significant decision" under the Article 22A test, and then run it through the correct regime for where that person is — the old prohibition-with-exceptions model for the EU, the new permission-with-mandatory-safeguards model (plus the recognised-legitimate-interest trap) for the UK. Both regimes converge on the same four safeguard categories once a decision is permitted to be automated, so the Article 22C checklist above is worth building once and reusing across both branches. What you can't do is treat "we're GDPR compliant" as covering both — since February 5, 2026, that's two separate statutory tests with two separate texts, and only one of them lives in a regulation the EU controls.

See Also

EU-Native Hosting

Ready to move to EU-sovereign infrastructure?

sota.io is a German-hosted PaaS — no CLOUD Act exposure, no US jurisdiction, full GDPR compliance by design. Deploy your first app in minutes.