Does UK Data Protection Act 2018 — Automated Decision-Making require Human Oversight?

United Kingdom • enforcing

Yes — 1 provision

Requirements at a glance

This regulation imposes 7 specific requirements for Human Oversight across 1 provision:

Automated Decision-Making Rights (Articles 22A-22D UK GDPR) #

Obligation:
Human Oversight
enforcing
Effective:
Feb 5, 2026
Risk tier:
all
Scope:
deployers

Requirements

RequirementDetails
ADM definitionDecisions based solely on automated processing (including profiling) with legal or similarly significant effects
Permitted basesADM allowed on any Article 6 basis except Recognised Legitimate Interests; stricter rules for special category data
Right to informationIndividuals must be clearly informed when ADM is used and the logic/criteria in meaningful terms
Right to human interventionRight to obtain genuine human review of automated decisions
Right to contestRight to make representations and challenge automated decisions
Suitable safeguardsControllers must implement safeguards including transparency, practical exercise of rights, and DPIA for high-risk ADM
Special category restrictionADM using special category data (health, biometrics, etc.) remains prohibited except under narrow conditions

Penalties

ViolationFine
Non-complianceUp to GBP 17.5M or 4% global turnover
View full regulation View obligation Obligation matrix