The Information Commission and UK GDPR
Personal data in AI: lawful basis, transparency, fairness, accuracy, DPIAs, and the rules on solely automated decisions with significant effects.
Any organisation whose AI is trained on, fed with, or makes decisions about personal data — which is most enterprise AI, including assistants used on customer or staff information.
Latest check 27 Sep 2026 10 rules · See changes in the Ledger
The rules
The ICO's draft ADM guidance
The ICO consulted on draft guidance on automated decision-making including profiling, updated for the Data (Use and Access) Act, from 31 March to 29 May 2026.
Verified 27 Sep 2026 · Read the source
The new automated decision-making rules and their commencement
Section 80 of the Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with new Articles 22A to 22D. It came into force on 5 February 2026 (S.I. 2026/82, reg. 2(j)). Solely automated significant decisions are now permitted in wider circumstances, provided safeguards are in place.
Verified 27 Sep 2026 · Read the source
The safeguards required for solely automated significant decisions
Providing people with information about significant decisions taken about them; enabling them to make representations about and challenge those decisions; and enabling them to obtain human intervention in the decision.
Verified 27 Sep 2026 · Read the source
The limit that still applies to special category data
Solely automated significant decisions based entirely or partly on special category data (such as health or ethnicity) remain restricted to narrow conditions, such as the person's explicit consent.
Verified 27 Sep 2026 · Read the source
The ICO's guidance on AI and data protection
Structured around accountability and governance, transparency, lawfulness, accuracy and fairness, last updated 15 March 2023. The ICO says that due to changes made by the Data (Use and Access) Act, the guidance is under review and may be subject to change.
Verified 27 Sep 2026 · Read the source
Whether AI needs a DPIA
"In the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk to individuals' rights and freedoms, and will therefore trigger the legal requirement for you to undertake a DPIA."
Verified 27 Sep 2026 · Read the source
From ICO to Information Commission
The Information Commissioner's Office (ICO) is replaced by the Information Commission from 30 September 2026, under the Data (Use and Access) Act 2025. Its role is unchanged: guidance, complaints and enforcement.
Verified 27 Sep 2026 · Read the source
Who is accountable for AI data protection risk
"You cannot delegate these issues to data scientists or engineering teams. Your senior management, including DPOs, are also accountable for understanding and addressing them appropriately and promptly."
Verified 27 Sep 2026 · Read the source
The three conditions of the PECR soft opt-in
(a) the details were obtained in the course of a sale or negotiations for a sale to that person; (b) you market only similar products or services; (c) a simple, free opt-out is offered at collection and in every message.
Verified 27 Sep 2026 · Read the source
Maximum UK GDPR fine
The higher maximum is £17.5 million or, for an undertaking, 4% of total worldwide annual turnover if higher. The standard maximum is £8.7 million or 2%.
Verified 27 Sep 2026 · Read the source
What people get wrong
The four misreadings we see most often, and what follows from them.
The ICO's view is that most AI use triggers the legal requirement for a DPIA. A pilot on real personal data is processing, and the DPIA must come before it, not after.
It widened when solely automated significant decisions are allowed, but made safeguards mandatory: information, a way to challenge, and human intervention. Special category data stays tightly restricted.
The ICO is explicit that senior management and DPOs are accountable. A director who cannot explain how a model uses personal data is exposed when the regulator asks.
Whether human involvement is meaningful decides whether a decision is solely automated. A reviewer who never changes an outcome, or lacks the information to, does not take the decision out of Articles 22A to 22D.
The other four
Knowing the rule is not the same as having a process
Module 31, AI regulation: the EU AI Act and the UK approach, turns these into what you actually need: which rules apply to you, what they require and by when, and the steps to put in place.
This is education, not legal advice. Every rule links to its primary source so you can read the original for yourself.
