For Heads-of · Practitioner
Automated decision-making without safeguards
AI is used to make solely-automated decisions with legal or similarly significant effects on individuals, without the safeguards UK GDPR requires.
- critical
- data-protection
- automated-decisions
- uk-gdpr
How it happens
A credit, employment, or benefits decision is generated entirely by an AI system with no meaningful human involvement, and the individual isn't given the right to obtain human review, express their view, or contest the outcome.
Why it matters
This isn't a best-practice gap, it's a specific, actionable breach of UK GDPR Article 22, and it's exactly the pattern regulators look for first when investigating an AI-driven decision system.
Mitigating controls
The controls that address this risk, ranked by effectiveness.
Automated decision-making safeguards
Process guaranteeing a right to human review, an ability to contest, and a documented rationale for any solely-automated decision with significant effect.
Human-in-the-loop review
Mandatory human approval gate for high-consequence or irreversible AI-generated actions before they take effect.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| Guidance on AI and data protection | Individual rights | Individual rights |
| UK General Data Protection Regulation | Article 22 | Automated individual decision-making, including profiling |
Related resources
The external sources behind this risk, from the Resources library.