Guide · Data & Privacy

Automated decisions & profiling

Rights and safeguards around solely automated decisions with significant effects.

Automated decision-making rules now focus on safeguards around significant decisions, with special protection for sensitive data.

The DUAA 2025 changed the UK framework for solely automated significant decisions. The previous Article 22 structure was amended, so older summaries that say such decisions are generally prohibited unless an exception applies can now be misleading.

The current regime retains safeguards, including transparency and routes for human intervention/challenge in covered decisions. Decisions using special-category data remain subject to stricter conditions.

Key points

  • Ask whether the decision was solely automated or involved meaningful human review.
  • Ask what data and logic significantly influenced the result, subject to legal limits on disclosure.
  • A decision is significant where it produces legal effects or similarly significant effects.
  • Current ICO guidance should be checked because the DUAA significantly changed this area.

Profiling is broader than automated refusal

Profiling is automated processing used to evaluate personal aspects such as behaviour, reliability, interests or financial situation. Profiling can feed a human decision or a solely automated one.

Meaningful human involvement

A human rubber-stamping an algorithm without real authority or consideration may not amount to meaningful intervention. Ask what the reviewer could see, whether they could change the outcome and what factors they considered.

Challenging the data

If an automated decision uses inaccurate input data, rectification and restriction rights can be as important as the automated-decision safeguards. Fixing the input can change the result.

In practice

  • Ask for the decision route and whether a human reviewed it.
  • Challenge inaccurate input data separately.
  • Request meaningful human reconsideration where the statutory safeguards apply.

Evidence worth keeping

Notice or evidence that automation was used
Inputs or personal data apparently used
Decision or score produced
Practical effect on you
Request for explanation or human review
Response and any fresh human decision

Ask for a review that can actually change the decision.

Useful wording.

“Please confirm whether this was a significant decision based solely on automated processing, the principal personal data and factors used, and the lawful basis relied upon. I am asking to make representations, obtain meaningful human intervention and contest the decision. Please ensure the reviewer has authority to depart from the automated outcome.”

Keep the original decision, scores/reason codes if supplied, privacy notice, correspondence, the data you believe is wrong and the result of any human review. If the organisation does not address the data-protection issues, use its data-protection complaints process and then consider the ICO or court route as appropriate.

Challenge the input data as well as the algorithm.

A perfectly functioning model can still produce a harmful result from wrong, incomplete or outdated personal data. If the organisation says the score is correct, ask it to distinguish the accuracy of the model from the accuracy of the information fed into it. Exercise rectification or restriction rights where appropriate and identify the specific disputed fields.

This is especially important for credit, fraud, employment, insurance and eligibility decisions, where a seemingly small data error can materially alter an automated outcome.

A token human glance is not the same as meaningful human involvement.

A decision is not solely automated if a person meaningfully considers and can change the outcome. A process in which staff simply approve a score without examining the substance may still raise questions about whether human involvement is real. Ask who reviewed the decision, what information they considered, what discretion they had and whether the automated recommendation could realistically be overturned.

Ask the organisationWhy it matters
Was the decision solely automated?Identifies whether the specific automated-decision safeguards apply.
What data and factors drove the outcome?Helps identify inaccurate, irrelevant or unfair inputs.
What lawful basis was relied upon?Automated processing still needs a lawful basis.
How can I obtain human intervention and contest the outcome?These are core safeguards for significant solely automated decisions.

The law changed: significant solely automated decisions are now permitted more widely, but safeguards still matter.

The Data (Use and Access) Act 2025 changed the UK framework for significant decisions made solely by automated processing. The old regime restricted these decisions to narrower circumstances. The current regime permits them more widely where there is a valid lawful basis, but requires safeguards. Do not therefore assume that “a computer made the decision” automatically makes it unlawful.

The key questions are whether the decision was genuinely solely automated, whether it produced legal or similarly significant effects, what lawful basis was used, whether special-category data was involved, and whether the required safeguards were actually available.