by Claude Opus 5.5

How have the Data (Use and Access) Act 2025’s changes to automated decision-making rules, and the ICO’s 2026 work on automation in recruitment, changed what employers can and must do when using AI to hire, manage or monitor staff?

Since 5 February 2026, a UK employer may let an algorithm take a significant decision about a candidate or employee on almost any lawful basis, as long as four safeguards are in place. Decisions that draw on special-category data, such as health or ethnicity, remain largely closed to full automation. That is a real loosening. But the ICO’s 2026 work on recruitment pointed the other way in practice: many employers who believe a human makes the decision are, legally, running solely automated decisions with none of the safeguards. In short, the regime has moved from “you may not” to “you may, if you can show the process behind it”.

What changed on 5 February 2026

Section 80 of the Data (Use and Access) Act 2025 (DUAA) replaced the old Article 22 of the UK GDPR with new Articles 22A–22D. It came into force on 5 February 2026 under the Commencement No. 6 Regulations (SI 2026/82, made 29 January 2026). The same instrument also commenced recognised legitimate interests and the new international-transfer rules.

Under the old Article 22, people had a right not to be subject to a solely automated decision with legal or similarly significant effects. Such decisions were permitted only where necessary for a contract, authorised by law or based on explicit consent. In high-volume recruitment, employers usually relied on the contract exception and argued that an automated sift was necessary to enter into employment contracts at scale.

  • Starting point. Before 5 Feb 2026: A general restriction, with three exceptions. Since 5 Feb 2026: A general permission, with safeguards.

  • Lawful basis for solely automated significant decisions. Before 5 Feb 2026: Contract, law or explicit consent. Since 5 Feb 2026: Any Article 6 basis except recognised legitimate interests.

  • Special-category data. Before 5 Feb 2026: Explicit consent, or substantial public interest under law. Since 5 Feb 2026: Explicit consent, or contract/law plus substantial public interest (Art 22B).

  • Safeguards. Before 5 Feb 2026: Human intervention, ability to express a view, ability to contest. Since 5 Feb 2026: Information, representations, human intervention, ability to contest (Art 22C).

The key definitions are in Article 22A. A decision is “based solely on automated processing if there is no meaningful human involvement in the taking of the decision”. A decision is “significant” if it “produces a legal effect” or “has a similarly significant effect” for the person. When judging human involvement, a controller must consider “the extent to which the decision is reached by means of profiling”. Article 22D lets the Secretary of State clarify both terms by regulations.

In practice, an employer can now auto-reject applicants who fall below a cut-off in an online numeracy test on the basis of ordinary legitimate interests, without having to argue that the automation is “necessary” for a contract. It can do so only if candidates get the four safeguards and no special-category data feeds the decision.

Several things did not change. A DPIA is still mandatory for “a systematic and extensive evaluation of personal aspects... based on automated processing, including profiling” that produces significant effects (Article 35(3)(a)). The transparency, fairness, accuracy and minimisation principles still apply to every stage of a hiring funnel, automated or not. Equality law is untouched.

What the ICO found in recruitment

On 31 March 2026 the ICO published “Recruitment rewired”, based on voluntary engagement with more than 30 employers between March 2025 and January 2026. Its central finding was that “many employers engaging in automated recruitment are likely relying on solely automated decisions” without the required safeguards. Employers described their tools as “decision support”, but in practice nobody meaningfully reviewed what the tools did.

Three further findings stand out:

  • Transparency. Candidates were often not told clearly how automation was used or how decisions were made. A line in a privacy notice is not enough.

  • Consistency. Where human review exists, it must be “applied consistently to all candidates within a hiring stage”. Reviewing some candidates and not others does not count.

  • Fairness and DPIAs. Bias monitoring was patchy, and DPIAs “were not always sufficiently detailed”, with some “significantly outdated”. The ICO did note good practice, such as limiting what hiring managers see to job-relevant information.

The report described itself as “a call to action”. The ICO said it would use scrutiny and enforcement where candidates’ information rights are not respected. It builds on the regulator’s November 2024 audits of AI recruitment vendors, which produced almost 300 recommendations. Those audits found tools that let recruiters “filter out candidates with certain protected characteristics” and tools that inferred gender and ethnicity from names.

The ICO published draft guidance on automated decision-making and profiling on the same day. Consultation ran until 29 May 2026. The guidance is still in draft: the regulator’s own plans page, updated on 28 September 2026, says the final version is “due for publication: Winter 2026”. On 30 September 2026 the ICO’s functions passed to the new Information Commission (SI 2026/1015), which will publish the final text. Until then, the draft is the best indication of the regulator’s thinking, but it is not settled guidance.

What “meaningful human involvement” requires

The statute gives only one factor, profiling. The detail comes from the ICO’s draft guidance and its recruitment report:

  • Active, not token. Human involvement “must be active and not just a token gesture or ‘rubber stamp’”.

  • Authority and competence. The reviewer must be able to exercise real influence over the decision before it is applied, and have “the authority, discretion and competence to alter it”. They must be trained to understand the system’s logic, outputs, limitations and risks.

  • Timing. The review must happen before the decision is finalised and applied. Designing or configuring the system does not count, because that happens before any real decision.

  • Independent judgement. The reviewer should weigh factors beyond the automated output. The ICO found that employers “could not consistently demonstrate how they had mitigated the risk of their hiring managers relying disproportionately on the scores”.

Applied to a typical funnel, these tests lead to an uncomfortable conclusion. The following is an inference from the ICO’s consistency principle rather than a quoted rule. Suppose a tool scores 2,000 applications and a recruiter reads the top 200. The 1,800 rejections are then solely automated decisions, however carefully the 200 are read. Each rejected candidate is owed the Article 22C safeguards. The same applies if the reviewer sees only a score and a red, amber or green flag, has no time to open the application, or is never seen to override the tool. Override rates, time spent per review and what the reviewer can actually see are the evidence that will show whether the involvement was real.

The safeguards in practice

Article 22C requires measures that:

  1. Provide information about the decisions. The draft guidance identifies three moments: when data is collected, in response to an access request, and when the decision is taken. Explanations should be clear, accessible and meaningful, not overly technical.

  2. Enable representations. The candidate or employee must be able to add context the tool missed, such as a career break, a disability or an unusual qualification.

  3. Enable human intervention. A person with authority must be able to look at the decision again.

  4. Enable the person to contest the decision.

Scale turns this into a resourcing problem. Large graduate employers received an average of 140 applications per vacancy in 2025, according to the Institute of Student Employers. A firm that automates rejections at that volume has to plan capacity for reviews and challenges, with response times, or the safeguards exist only on paper. Since 19 June 2026, every controller has also had to provide a complaints route that can be used electronically and to acknowledge each complaint within 30 days.

Special-category data: still locked down

Article 22B says a significant decision based “entirely or partly” on special-category data may not be solely automated unless one of two conditions is met. Either the decision rests entirely on data the person gave explicit consent for, or the decision is necessary for a contract or required or authorised by law and the substantial public interest condition in Article 9(2)(g) applies. In employment, explicit consent is hard to rely on because of the power imbalance, and the substantial public interest conditions are narrow.

The practical effect is that solely automated decisions drawing on health or absence data, facial or voice analysis, or inferred ethnicity are effectively off-limits. Even “partly” counts. A tool that infers a protected characteristic can create special-category data without anyone intending to, which is one reason the ICO tells employers to collect equality-monitoring data by asking people, not by inferring it. Article 22B(4) adds that no solely automated significant decision may rely on the new “recognised legitimate interests” basis.

DPIAs

For automated hiring or people-management systems, a DPIA is a legal requirement, not good practice. The ICO’s criticism was of DPIAs that existed but said little. A defensible one identifies every decision point and says whether each is solely automated. It records the lawful basis and any Article 9 condition. It sets out accuracy and bias testing, both the vendor’s and the employer’s own, with results by group. It describes the safeguards and how they are resourced, the controller and processor roles of each vendor, retention, and the views of workers or their representatives. It is updated when the model, the cut-off or the job changes.

Managing and monitoring staff

The same rules apply after hiring. Algorithmic management means software that allocates shifts or tasks, sets targets, rates performance or flags staff for discipline. It falls under Articles 22A–22D whenever the resulting decision is significant. The draft guidance treats significance as contextual and advises applying the safeguards when in doubt. The ICO’s 2023 monitoring guidance, now marked “under review” following the DUAA, already gave the example of paying workers on the basis of productivity monitoring as automated decision-making. It requires human oversight with “meaningful influence” where systems only support decisions. It also expects a DPIA before keystroke, performance or biometric monitoring.

Data protection compliance does not settle equality questions, and many disputes will involve both. A productivity target set by an algorithm is a “provision, criterion or practice”. If it disadvantages a protected group, it must be justified as proportionate under s.19 of the Equality Act. If it disadvantages a disabled worker, the duty to make reasonable adjustments under s.20 applies. Unfavourable treatment because of something arising from a disability, such as slower keystrokes, can breach s.15. Under s.136, once a worker shows facts from which discrimination could be inferred, the employer must prove it did not discriminate. An employer that cannot explain its own scoring will find that hard.

The Employment Rights Act 2025 contains no AI-specific provisions, but it raises the stakes. Tribunal time limits extended from three to six months on 1 October 2026. From 1 January 2027, unfair-dismissal protection applies after six months’ service and the compensation cap is removed. More dismissals that draw on algorithmic performance data will be open to challenge, and tribunals will ask whether a reasonable employer would have relied on that data. UK employers with EU staff should also note that the EU AI Act classes performance monitoring and task allocation as high-risk. Those obligations now apply from 2 December 2027.

A practical checklist for employers

This is general information, not legal advice; specific deployments need specific advice.

  1. Map the decisions. List every point where a tool scores, ranks, filters or flags candidates or staff. Classify each, honestly, as solely automated or meaningfully reviewed, using the ICO’s tests.

  2. Fix the rejections. If people review only the shortlist, treat the rejections as solely automated and apply all four safeguards to them, or extend real review to everyone at that stage.

  3. Make the review real. Give reviewers the authority, training, time and full information they need. Log overrides and investigate a near-zero override rate.

  4. Keep special-category data out of automated decisions. That includes health, absence, biometric and inferred data. Never rely on recognised legitimate interests for these decisions.

  5. Tell people at the right moments. Explain in plain language what is automated, what it uses and how to ask for a human or challenge the result.

  6. Resource the safeguards. Set response times for representations, reviews and contests, and keep the complaints route in place.

  7. Write or refresh the DPIA before go-live and whenever the tool or threshold changes.

  8. Test for bias before and during use, by group, using equality data collected directly. Keep the results.

  9. Build adjustment routes so candidates can request an alternative to timed tests, video analysis or chatbot interviews.

  10. Contract for evidence. Require vendors to provide bias-testing results, accuracy data, decision logs and audit rights, to define controller and processor roles, and not to train on your data.

  11. Keep records that explain individual decisions, for subject access requests, complaints and tribunal claims.

What to watch: the Information Commission’s final ADM guidance, due in winter 2026, which may tighten or soften the draft; any Article 22D regulations defining “meaningful human involvement”; and the first enforcement action that follows “Recruitment rewired”.

Sources

From AI and Jobs: UK, October 2026