ICO Data Protection Register

Can you use AI to screen job applicants or decide about customers? The rules changed in February 2026

Yes, you can — since 5 February 2026 you may take a significant decision about someone by solely automated means on almost any lawful basis, provided you apply four safeguards. The old Article 22 ban has gone, but the ICO's finding from its recruitment work is that many employers using AI screening have not recognised that they are making automated decisions at all.

Last updated 31 July 2026. This page explains the law as it stands on that date. It is general information, not legal advice.

The bottom line

Automated decision-making is no longer prohibited by default. From 5 February 2026, UK GDPR Article 22 was replaced by Articles 22A to 22D. You may now take a significant decision about a person using solely automated processing on any Article 6 lawful basis except recognised legitimate interests — but you must give them information about the decision, let them make representations, let them obtain human intervention, and let them contest it. Special category data is still restricted.

What changed on 5 February 2026

Section 80 of, and Schedule 6 to, the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with four new articles: 22A (automated processing and significant decisions), 22B (restrictions on automated decision-making), 22C (safeguards) and 22D (further provision, including regulation-making powers). They were commenced by SI 2026/82, regulation 2(j).

The ICO describes the effect as reframing the provisions "from a prohibition with exceptions to a right of challenge with safeguards". The UK GDPR was amended, not replaced. Nothing in section 80 changes your DPO, ROPA or DPIA obligations, and the Article 33 breach deadline is untouched.

Before 5 February 2026 From 5 February 2026
Starting point Prohibited unless an exception applied Permitted, provided safeguards are applied
Lawful basis In practice, consent, contract necessity or authorisation by law Any Article 6 basis except recognised legitimate interests (Art 22B(4))
Safeguards Suitable measures: human intervention, express a point of view, contest the decision Four measures listed in Article 22C(2)
Special category data Explicit consent, or substantial public interest under UK law with safeguards Retained, in substance, in Article 22B(1)-(3)
'Solely automated' Not defined in the Article Defined: no meaningful human involvement (Art 22A(1)(a))

Old decisions stay under the old law

Regulation 5 of SI 2026/82 says the amendments made by section 80 of, and Schedule 6 to, the Act "do not apply in relation to any decision taken before 5th February 2026" to which the old Article 22(3) of the UK GDPR, or section 14 or 50(2) of the Data Protection Act 2018, applied. A complaint about a rejection issued in 2025 is still judged against the old Article 22, exception test and all.

Which lawful basis can you use, and what is still off-limits

For a solely automated significant decision that does not involve special category data, you no longer need a separate Article 22 exception. You need a lawful basis under Article 6, and it can be any of them except the new recognised legitimate interests basis at Article 6(1)(ea). Article 22B(4) rules that one out expressly.

The ICO's view, set out in its recruitment work, is that legitimate interests is likely to be the most appropriate lawful basis for employers to rely on in practice for recruitment ADM. It told employers that consent is unlikely to be appropriate at most stages, because a candidate who fears that refusing will end their application is not giving consent freely, and that contract only works once a job offer has been made and accepted.

Special category data: the restriction stayed

If the decision is based entirely or partly on special category data — health, ethnicity, trade union membership, biometrics used for identification and the rest of the Article 9(1) list — Article 22B(1) says it may not be taken by solely automated means unless one of two conditions is met:

You still need an Article 9 condition for the special category processing itself. The Article 22B condition is additional, not a substitute. And the four safeguards in Article 22C apply either way.

The four safeguards, in practice

Article 22C(2) requires the controller to have measures that do four things. They are not optional extras and they are not satisfied by a general privacy notice.

  1. Step 1 Tell the person about the decision Not just that you use automation somewhere, but information about the actual decision taken about them. The ICO's finding was that employers who mentioned ADM in a privacy notice still fell short, because the information was too general for a candidate to understand how ADM featured in the process.
  2. Step 2 Let them make representations A route for the person to put forward their side — extra information, context the system did not have. This has to work in practice, not just be described in a policy.
  3. Step 3 Let them obtain human intervention A real review by a person. The ICO found that safeguards allowing candidates to seek a human review were applied inconsistently, and in some cases there was no working method for handling such requests at all.
  4. Step 4 Let them contest the decision A way to challenge the outcome, not merely comment on it. Say who handles challenges and how quickly.

Three separate transparency duties

The ICO treats Articles 13 and 14 (right to be informed), Article 15 (right of access) and the Article 22C information safeguard as separate obligations. You owe information at three points: when you collect the data, when someone asks for it, and when you take the decision. The ICO also warns against overly technical or complex explanations that leave people no better informed.

Does a manager signing off the AI shortlist count?

Often not. Article 22A(1)(a) says a decision is based solely on automated processing if there is no meaningful human involvement in the taking of the decision, and Article 22A(2) says that when you assess this you must consider, among other things, the extent to which the decision is reached by means of profiling.

The ICO frames the test as whether the human involvement is active and genuine rather than a token step or a rubber stamp — whether the reviewer has the "authority, discretion, and competence to change the outcome" before the decision takes effect.

In its recruitment work the ICO found that human involvement was often inconsistent: some candidates received a genuine review while others were rejected on the strength of an automated score alone. Where a reviewer simply endorses the system's output, the ICO's position is that the decision remains solely automated. Things that do not amount to meaningful human involvement:

You have a genuine choice here. Either build in meaningful human involvement at every decision, about every person, at every stage — which takes the processing outside the ADM provisions — or accept that you are doing ADM and apply the Article 22C safeguards. What does not work is assuming the first and doing neither.

What the ICO has said about AI in recruitment

On 31 March 2026 the ICO published Recruitment rewired, an update on its work on the fair and responsible use of automation in recruitment. It draws on evidence from over 30 employers who talked to the ICO voluntarily between March 2025 and January 2026, alongside public perceptions research, and on its review of their privacy notices, DPIAs and records of processing.

It wrote to 16 organisations it considered likely to be using ADM to make decisions about candidates, with recommendations; those organisations have committed to acting on them. The findings arise from voluntary engagement and are not an audit or an investigation, and no employer is named. Its headline findings:

The ICO's published expectations for anyone using ADM in hiring are: proactively monitor and test regularly for biased outputs and mitigate them; be clear with candidates that ADM is used and how it works; apply human involvement consistently where it is relied on; and make sure candidates know how to challenge a decision and request a human review, with a process that actually functions.

Not everything automated is a 'decision'

The ICO's draft guidance treats a system that merely applies a rule a human has already set — its example is accepting or declining payment cards by type — as falling outside these provisions, because there is no consideration, evaluation or analysis of the person. A binary eligibility filter, such as a right-to-work or required-qualification question, works the same way. Scoring and ranking is a different matter.

Where AI meeting notetakers fit

There is a common belief that you need every participant's consent before an AI notetaker can join. That is not what the ICO says. Consent is one lawful basis among seven in Article 6(1), and in a hiring or workplace setting it is usually the weakest, for exactly the reason the ICO gave about candidates: refusal carries a perceived cost, so the consent is not freely given.

In its innovation advice, the ICO has addressed this directly. Where an organisation uses an AI tool for meeting recordings, summaries and notes, is not using it for any new purpose and is not making decisions about people with it, its answer is that the organisation can continue to rely on the lawful bases it has already identified for each processing activity. The practical points that follow:

What is still to come, and what not to commit to yet

Article 22D lets the Secretary of State make regulations about what is and is not meaningful human involvement, what counts as a similarly significant effect, and what further safeguards are required — including what does not satisfy Article 22C(2). No such regulations had been identified as at 31 July 2026. Until they are made, the statute and the ICO's guidance are what you have.

What Status at 31 July 2026
ICO ADM and profiling guidance Consultation ran from 31 March to 23:59 on 29 May 2026 and has closed. The published version is still a draft; final guidance is expected during 2026.
ICO recruitment and selection guidance The ICO has said it will update this guidance during 2026, informed by responses to the ADM consultation.
Statutory AI and ADM code of practice SI 2026/425, made 16 April 2026 and in force 12 May 2026, requires the Commissioner to prepare it, including guidance on children's personal data. The SI sets no deadline.
Article 22D regulations None identified.
DSIT call for evidence on data regulation and AI Open 15 July to 11:59pm on 9 September 2026.

Two things you can do now without waiting: work out honestly whether any of your tools are taking decisions rather than supporting them, and check that a person who is rejected by one of them can actually reach a human being who is able to change the answer.

Common questions

Do we still need consent to use AI to sift job applications?

No. Since 5 February 2026 you can rely on any Article 6 lawful basis except recognised legitimate interests. The ICO's view is that legitimate interests is likely to be the most appropriate basis for recruitment ADM, and that consent is unlikely to be valid at most stages because candidates do not feel free to refuse. Contract only becomes available once a job offer has been made and accepted.

Our hiring manager reviews the AI scores before shortlisting. Does that take us out of the rules?

Only if the review is real. The ICO's test is whether the human involvement is active and genuine rather than a token step or a rubber stamp, and whether the reviewer has the authority, discretion and competence to change the outcome before the decision takes effect. Its report found human involvement was often inconsistent, with some candidates genuinely reviewed and others rejected on an automated score alone — which remains solely automated decision-making. Human involvement has to be applied consistently to every candidate at each stage, not just to the ones who score well.

Does this apply to decisions we made before February 2026?

No. Regulation 5 of SI 2026/82 says the amendments made by section 80 of, and Schedule 6 to, the Act do not apply to any decision taken before 5 February 2026 to which the old Article 22(3) of the UK GDPR, or section 14 or 50(2) of the Data Protection Act 2018, applied. Those decisions are still assessed under the old Article 22, which prohibited solely automated significant decisions unless contract necessity, authorisation by law or explicit consent applied.

We use AI to score psychometric or behavioural assessments. Is that automated decision-making?

It depends on whether the score decides anything and whether a person meaningfully intervenes. Scoring and ranking is profiling, and Article 22A(2) requires you to weigh how far the decision is reached by profiling when assessing human involvement. If low scorers are rejected without a person genuinely considering whether the outcome was right, that is ADM and the four safeguards apply. Simple yes/no eligibility filters that apply a rule a human has already set, such as right-to-work questions, are unlikely to be decisions of this kind.

Do we need everyone's consent to run an AI notetaker in a meeting?

Not necessarily. The ICO's innovation advice is that if you are not using the tool for any new purpose and are not making decisions about people with it, you can rely on the lawful bases you already identified. What you do need is transparency before the meeting, accuracy checks on the output, and a clear contractual position on whether the vendor uses your meeting data for its own purposes such as model training — which is separate data sharing needing its own lawful basis. Consent from the meeting organiser is not a substitute for informing the other participants.

Has the ICO started fining employers over AI recruitment?

Not from this piece of work. The ICO says the findings in Recruitment rewired arise from voluntary engagement and are not an audit or investigation. It wrote to 16 organisations it considered likely to be using ADM with recommendations, and they have committed to acting on them. Commentators have read the report as a signal that enforcement could follow if practice does not improve.

Sources

This page summarises the following primary sources. Where they disagree with this summary, they take precedence.

Related guidance