UK Data Protection Act 2018 — Automated Decision-Making

Jurisdiction:
United Kingdom
enforcing
Effective:
May 25, 2018
Authority:
Information Commissioner's Office
Official text Verified May 15, 2026

Obligations Covered

Human Oversight Transparency & Disclosure

Provisions (2)

Automated Decision-Making Rights (Articles 22A-22D UK GDPR) #

Obligation:
Human Oversight
enforcing
Effective:
Feb 5, 2026
Risk tier:
all
Scope:
deployers

Requirements

RequirementDetails
ADM definitionDecisions based solely on automated processing (including profiling) with legal or similarly significant effects
Permitted basesADM allowed on any Article 6 basis except Recognised Legitimate Interests; stricter rules for special category data
Right to informationIndividuals must be clearly informed when ADM is used and the logic/criteria in meaningful terms
Right to human interventionRight to obtain genuine human review of automated decisions
Right to contestRight to make representations and challenge automated decisions
Suitable safeguardsControllers must implement safeguards including transparency, practical exercise of rights, and DPIA for high-risk ADM
Special category restrictionADM using special category data (health, biometrics, etc.) remains prohibited except under narrow conditions

Penalties

ViolationFine
Non-complianceUp to GBP 17.5M or 4% global turnover

Transparency in Automated Processing #

Obligation:
Transparency
enforcing
Effective:
May 25, 2018
Risk tier:
all
Scope:
deployers

Requirements

RequirementDetails
Logic disclosureMust provide meaningful information about the logic of automated decision-making
Significance and consequencesMust explain the significance and envisaged consequences of processing
Privacy noticeMust include ADM information in privacy notices

Penalties

ViolationFine
Non-complianceUp to GBP 17.5M or 4% global turnover