A more permissive framework, with conditions
The ICO describes the Data (Use and Access) Act 2025 as creating a more permissive framework for solely automated significant decisions under UK GDPR, provided appropriate safeguards are in place. The government's own guidance uses similar language. This is a real shift from the previous, more restrictive default, but it is conditional, not unconditional.
What counts as a significant decision
Articles 22A to 22D concern decisions that produce legal effects or similarly significant effects on a person, made without meaningful human involvement. Special category data carries additional restrictions. Recognising when a decision crosses this line, rather than assuming it never applies to your system, is the first practical step.
Meaningful human involvement is not a rubber stamp
A human who reviews an AI recommendation without genuinely being able to challenge or change it is decision-support in name only. Meaningful human involvement requires real capacity to intervene, understand the basis for the recommendation, and override it when appropriate.
Safeguards affected people can actually use
The mandatory safeguards include giving affected people information about the decision, a right to make representations, a right to obtain human intervention, and a right to contest the decision. These need to exist in practice, not only in a privacy notice nobody reads.
Recruitment as a working example
An AI recruitment tool that scores and rejects candidates raises exactly this question: is the rejection solely automated, what safeguards are in place, and what does meaningful human involvement look like for the recruiter reviewing it? Walking through a real scenario like this is a more reliable test than reading the Act in the abstract.
We work through UK GDPR, DUAA and automated decision-making scenarios like this one in the AI Governance, Risk & Compliance Practitioner programme.