by Claude Opus 5.5
How do UK data protection and privacy expectations affect AI use at work (employee data, monitoring, customer data), and which roles tend to grow because of these constraints?
UK data protection law rarely stops an employer using AI. What it does is shape what the AI is used for and how. Each use needs a lawful basis chosen at the outset, monitoring must be proportionate and assessed in advance, and workers and customers should not be surprised by what is done with their data. The Data (Use and Access) Act 2025 loosened some edges in February 2026, but the core principles and the ICO’s 2023 monitoring guidance (now under review) still set the rules. The roles that grow are those that turn these expectations into routine practice: DPOs, privacy engineers, AI governance staff and information governance teams.
Employee data: lawful basis is a design decision
Consent rarely works for employment data, because the power imbalance between employer and worker makes it hard to show consent was freely given. Most workplace AI therefore relies on the employment contract, a legal obligation or legitimate interests. The ICO’s monitoring guidance says employers “must identify a lawful basis at the outset”, and warns: “Try to get it right first time, as you should not change it later without good reason.”
The Data (Use and Access) Act 2025 (DUAA) added a new basis on 5 February 2026: “recognised legitimate interests” (Article 6(1)(ea)). Under it, a listed purpose needs no balancing test. The list in Annex 1 is narrow, though. It covers disclosures to public bodies, national security and defence, emergencies, crime, and safeguarding vulnerable people. None of these is an ordinary HR purpose, so most AI use on employee data still rests on standard legitimate interests, with the balancing test documented. The Act did add examples of legitimate interests that help employers at the margin. These include “intra-group transmission of personal data (whether relating to clients, employees or other individuals)” for internal administration, and network security. There is also an important limit. A significant decision taken solely by automated means cannot rely on recognised legitimate interests (Article 22B(4)). That matters for recruitment and performance tools, which question 2.12 covers in detail.
Monitoring: the 2023 guidance is still the rulebook
The ICO’s “Employment practices and data protection: monitoring workers” guidance was published on 3 October 2023. It is now marked “under review” following the DUAA, but no replacement has been published. Its tests are necessity, proportionality and transparency. Employers should use “the least intrusive means” and tell workers about “the nature, extent and reasons for monitoring”. They should also seek the views of workers or their representatives unless there is a good reason not to. A DPIA is expected before high-risk monitoring, such as keystroke logging, performance monitoring, monitoring email content or processing biometrics. The guidance says continuous audio and video recording is “unlikely” to be justifiable in most circumstances.
Public attitudes explain the caution. In the ICO’s research for the guidance, 70% of people said they would find monitoring by an employer intrusive. Only 19% would be comfortable taking a new job that involved monitoring.
AI makes this harder because it creates monitoring by default. Copilot usage dashboards, meeting transcription, sentiment scoring of customer calls and “productivity” analytics all produce data about named individuals that was never collected for a performance purpose. The usual pattern is function creep: data is collected for security, then used for productivity, then for discipline. The guidance treats paying workers on the basis of productivity monitoring as automated decision-making and requires human oversight with “meaningful influence”.
The clearest enforcement precedent is Serco Leisure. On 23 February 2024 the ICO ordered Serco and seven associated leisure trusts to stop using facial recognition and fingerprint scanning to record the attendance of more than 2,000 employees at 38 sites. Biometric attendance systems are a mature technology, not cutting-edge AI. The lesson is that the regulator asks whether a less intrusive alternative exists, not how sophisticated the tool is.
Special-category data: where AI creates it without anyone asking
Special-category data includes health, ethnicity, religion, sexual orientation and biometrics used to identify someone. Processing it needs an Article 9 condition as well as a lawful basis. AI tools often generate such data as a by-product. The ICO’s November 2024 audit of AI recruitment tools found some “inferring characteristics, including gender and ethnicity, from a candidate’s name instead of asking for this information”. Monitoring email content can capture health or union information incidentally, and the guidance says that still counts. The DUAA adds a hard limit. A significant decision based even partly on special-category data cannot be solely automated unless the person gave explicit consent, or the decision is contractually necessary or legally required and meets the substantial public interest condition. In employment, the practical answer is to keep a meaningful human in such decisions. Equality monitoring data should be collected by asking people, not by inferring it.
Customer data: purpose limitation meets the prompt box
For customer data, the main constraints are purpose limitation and minimisation. Using a customer’s call recording to resolve their complaint is one purpose. Using it to fine-tune a model is another, and needs its own justification. In practice the biggest exposure is staff using unapproved tools. Deloitte’s 2026 survey of 25,000 UK workers found that 31% of generative AI users use it without their employer knowing, and 46% use free tools. Customer data pasted into a free chatbot raises purpose, security and transfer problems all at once.
International transfers matter because most frontier AI vendors host outside the UK. On 5 February 2026 the DUAA replaced the transfer tests with a “data protection test”. Protection abroad must be “not materially lower” than in the UK, and controllers must act “reasonably and proportionately”, taking account of “the nature and volume of the personal data transferred”. In practice this probably makes routine transfers to established vendors less of a struggle. Firms still need a transfer mechanism, and the contract still has to stop the vendor training its models on customer data.
Rights that generate workload
Two changes affect HR operations. First, the DUAA confirmed, with retrospective effect from 1 January 2024, that a subject access request requires only “a reasonable and proportionate search”. That is useful, because AI tools create new personal data: transcripts, prompts, scores and summaries. Some of it may come within a request from an employee in a dispute. Second, since 19 June 2026 controllers must offer a complaints route that can be used electronically and acknowledge complaints within 30 days. The regulator itself changed on 30 September 2026, when the ICO’s functions passed to the new Information Commission. This is general information rather than legal advice for any particular situation.
Roles that grow
Hiring data for specific privacy roles is not available, so the evidence here is about where the workload falls rather than counts of vacancies. The pattern is still clear:
Data protection officers. The DUAA kept the DPO role, which an earlier bill had proposed to replace. DPOs now handle ADM safeguards, the complaints duty and the new transfer test on top of their existing work.
Privacy engineers. They build redaction, pseudonymisation, retention rules, prompt logging and data-loss prevention for generative AI. Their job is to make the approved tool safer and easier to use than the free one.
AI governance leads. They keep the register of AI systems, run DPIAs and vendor due diligence, and test tools for bias. They often sit between legal, risk and technology.
Information governance and records staff. Every AI tool produces new records, and these staff handle the resulting subject access requests, complaints and retention schedules. Demand is especially strong in the NHS and local government.
Employee relations specialists. They consult workers and unions on monitoring, which the guidance expects.
More broadly, PwC counted 180,000 UK postings for specialist AI roles in 2025, up 61%. Governance and assurance roles are part of that wider growth, though PwC does not break them out.
Bottom line: in UK workplaces, privacy rules work less as a brake on AI and more as a filter on how it is designed. Employers who set the lawful basis, the proportionality case and the human checkpoint before switching a tool on tend to move faster than those who try to justify them afterwards.
Sources
Employment practices and data protection: monitoring workers — ICO, 3 Oct 2023
ICO publishes guidance to ensure lawful monitoring in the workplace — ICO, 3 Oct 2023
UK ICO releases new guidance for monitoring at work — Covington Inside Privacy, Oct 2023
UK GDPR Article 6 (lawfulness of processing) — legislation.gov.uk
UK GDPR Annex 1 (recognised legitimate interests) — legislation.gov.uk
UK GDPR Article 45B (the data protection test) — legislation.gov.uk
UK GDPR Article 46 (transfers subject to appropriate safeguards) — legislation.gov.uk
UK GDPR Article 37 (designation of the data protection officer) — legislation.gov.uk
Data (Use and Access) Act 2025, section 103 (complaints) — legislation.gov.uk
GenAI workforce survey: shadow AI — Deloitte UK, 2026 (fieldwork May–Jun 2026)