Information Commission / UK GDPR

The Information Commission and UK GDPR

Personal data in AI: lawful basis, transparency, fairness, accuracy, DPIAs, and the rules on solely automated decisions with significant effects.

Who it applies to

Any organisation whose AI is trained on, fed with, or makes decisions about personal data — which is most enterprise AI, including assistants used on customer or staff information.

Latest check 27 Sep 2026 10 rules · See changes in the Ledger


The rules

The ICO's draft ADM guidance

The ICO consulted on draft guidance on automated decision-making including profiling, updated for the Data (Use and Access) Act, from 31 March to 29 May 2026.

Verified 27 Sep 2026 · Read the source

The new automated decision-making rules and their commencement

Section 80 of the Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with new Articles 22A to 22D. It came into force on 5 February 2026 (S.I. 2026/82, reg. 2(j)). Solely automated significant decisions are now permitted in wider circumstances, provided safeguards are in place.

Verified 27 Sep 2026 · Read the source

The safeguards required for solely automated significant decisions

Providing people with information about significant decisions taken about them; enabling them to make representations about and challenge those decisions; and enabling them to obtain human intervention in the decision.

Verified 27 Sep 2026 · Read the source

The limit that still applies to special category data

Solely automated significant decisions based entirely or partly on special category data (such as health or ethnicity) remain restricted to narrow conditions, such as the person's explicit consent.

Verified 27 Sep 2026 · Read the source

The ICO's guidance on AI and data protection

Structured around accountability and governance, transparency, lawfulness, accuracy and fairness, last updated 15 March 2023. The ICO says that due to changes made by the Data (Use and Access) Act, the guidance is under review and may be subject to change.

Verified 27 Sep 2026 · Read the source

Whether AI needs a DPIA

"In the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk to individuals' rights and freedoms, and will therefore trigger the legal requirement for you to undertake a DPIA."

Verified 27 Sep 2026 · Read the source

From ICO to Information Commission

The Information Commissioner's Office (ICO) is replaced by the Information Commission from 30 September 2026, under the Data (Use and Access) Act 2025. Its role is unchanged: guidance, complaints and enforcement.

Verified 27 Sep 2026 · Read the source

Who is accountable for AI data protection risk

"You cannot delegate these issues to data scientists or engineering teams. Your senior management, including DPOs, are also accountable for understanding and addressing them appropriately and promptly."

Verified 27 Sep 2026 · Read the source

The three conditions of the PECR soft opt-in

(a) the details were obtained in the course of a sale or negotiations for a sale to that person; (b) you market only similar products or services; (c) a simple, free opt-out is offered at collection and in every message.

Verified 27 Sep 2026 · Read the source

Maximum UK GDPR fine

The higher maximum is £17.5 million or, for an undertaking, 4% of total worldwide annual turnover if higher. The standard maximum is £8.7 million or 2%.

Verified 27 Sep 2026 · Read the source


What people get wrong

The four misreadings we see most often, and what follows from them.

Deploying an AI tool on customer or staff data without a DPIA because "it's only a pilot".

The ICO's view is that most AI use triggers the legal requirement for a DPIA. A pilot on real personal data is processing, and the DPIA must come before it, not after.

Reading the Data (Use and Access) Act as having removed the protection against automated decisions.

It widened when solely automated significant decisions are allowed, but made safeguards mandatory: information, a way to challenge, and human intervention. Special category data stays tightly restricted.

Delegating AI data protection to the data science team.

The ICO is explicit that senior management and DPOs are accountable. A director who cannot explain how a model uses personal data is exposed when the regulator asks.

Offering "human review" that is a rubber stamp.

Whether human involvement is meaningful decides whether a decision is solely automated. A reviewer who never changes an outcome, or lacks the information to, does not take the decision out of Articles 22A to 22D.


The other four

The EU AI ActThe UK's approach to AI regulationAI management standardsSector regulators and AI
Next step

Knowing the rule is not the same as having a process

Module 31, AI regulation: the EU AI Act and the UK approach, turns these into what you actually need: which rules apply to you, what they require and by when, and the steps to put in place.

This is education, not legal advice. Every rule links to its primary source so you can read the original for yourself.