UK Data Protection Act 2018 — Automated Decision-Making

Jurisdiction:
United Kingdom
enforcing
Effective:
May 25, 2018
Authority:
Information Commissioner's Office
Official text Verified Mar 26, 2026

Obligations Covered

Human Oversight Transparency & Disclosure

Provisions (2)

Automated Decision-Making Rights (Article 22 UK GDPR) #

Obligation:
Human Oversight
enforcing
Effective:
May 25, 2018
Risk tier:
all
Scope:
deployers

Requirements

RequirementDetails
Right not to be subject to ADMIndividuals have the right not to be subject to decisions based solely on automated processing with legal or significant effects
Human reviewRight to obtain human intervention and contest automated decisions
ExplanationRight to meaningful information about the logic involved
Data Protection Impact AssessmentRequired when automated processing may result in high risk

Penalties

ViolationFine
Non-complianceUp to GBP 17.5M or 4% global turnover

Transparency in Automated Processing #

Obligation:
Transparency
enforcing
Effective:
May 25, 2018
Risk tier:
all
Scope:
deployers

Requirements

RequirementDetails
Logic disclosureMust provide meaningful information about the logic of automated decision-making
Significance and consequencesMust explain the significance and envisaged consequences of processing
Privacy noticeMust include ADM information in privacy notices

Penalties

ViolationFine
Non-complianceUp to GBP 17.5M or 4% global turnover