🎉 New: check if your data transfers to US/overseas tools meet UK GDPR rules — many businesses miss this.
AI & Tech

Automated Decision-Making (AI) Compliance Check

Check whether your use of AI or algorithms to make decisions about customers or staff meets UK GDPR's reformed automated decision-making rules.

✅ Free ⏱ 7 minutes 🤖 AI-powered 🔥 Trending

Why this matters

The Data (Use and Access) Act 2025, which received Royal Assent in June 2025, reformed Article 22 of UK GDPR — the rule governing decisions made solely by automated means, including AI and algorithms, that have a legal or similarly significant effect on a person. Previously, solely automated decision-making was banned by default outside narrow exceptions. The reformed rules instead permit it more widely — including for credit scoring, recruitment screening, and customer eligibility decisions — provided businesses put specific safeguards in place: meaningful information about the logic involved, the ability for the person to contest the decision, and a route to obtain human intervention. Special category data (health, ethnicity, religion, etc) remains far more tightly restricted.

This matters for any business using AI tools that screen job applicants, score creditworthiness, price products dynamically, flag insurance claims, or make other decisions affecting customers or staff without a human reviewing the outcome. Businesses that adopted AI tools assuming “a human technically approves it” or that haven’t revisited their automated decision-making safeguards since the reform are at risk of falling short of the new requirements — and the Information Commissioner’s Office (transitioning to the Information Commission under the same Act) has signalled increased scrutiny of AI-driven decisions as adoption grows across recruitment, lending, and customer service.

What you'll need

  • A list of any tools or systems that make decisions about customers or staff without a human reviewing the outcome
  • Knowledge of whether those decisions involve special category data (health, ethnicity, religion, etc)
  • Your current privacy policy and any existing automated decision-making disclosures

What you'll get

A personalised compliance report covering: a score out of 100, an executive summary, a list of findings ranked by severity, and a prioritised action plan with timeframes.

This check reviews your use of AI and automated decision-making against the reformed UK GDPR Article 22 rules introduced by the Data (Use and Access) Act 2025 — covering required safeguards, high-risk use cases, and transparency obligations.

General guidance only — not legal advice. Consult a qualified UK solicitor for specific issues.