Practical guide
UK GDPR and AI: What Changed After Brexit
A practical guide to UK GDPR's new automated-decision rules, ICO guidance, international transfers, and dual UK-EU obligations for SMEs using AI.
Key takeaways
- UK GDPR Article 22 was replaced on 5 February 2026 by Articles 22A–22D. Documents that still rely on UK Article 22 need review.
- Articles 22A–22C distinguish significant decisions, meaningful human involvement, special-category-data restrictions, and safeguards for solely automated decisions.
- Many familiar UK GDPR duties remain: lawful basis, transparency, processor terms, records, security, rights handling, and risk-based DPIAs.
- UK-to-EEA transfers are covered by UK adequacy regulations. Other destinations may require the UK IDTA, the UK Addendum to the EU standard contractual clauses, another safeguard, or an exception.
- The ICO's AI guidance remains useful but is under review after the Data (Use and Access) Act. Updated automated-decision guidance is expected in Winter 2026.
UK and EU data-protection law began from a closely aligned position after Brexit, but they should no longer be treated as one regime. The clearest AI-related divergence arrived in February 2026, when the UK replaced Article 22's automated-decision rules.
For an SME, the practical response is to separate UK and EU assessments, update old citations, and trace what each AI-assisted workflow actually does.
What remains familiar
Much of the UK GDPR structure still resembles EU GDPR. For AI systems that process personal information, check at least:
- Article 5: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability;
- Article 6: the lawful basis for processing;
- Article 9: a condition for processing special-category information, where relevant;
- Article 13 or 14: privacy information;
- Article 28: required terms where an AI vendor acts as processor;
- Article 30: records of processing activities, subject to the provision's scope and exemptions;
- Article 35: a DPIA before processing likely to result in high risk; and
- Articles 33 and 34: breach notification to the ICO where the Article 33 risk threshold is met, where feasible within 72 hours, and communication to affected people where Article 34's high-risk threshold is met.
Do not turn those points into blanket rules. For example, AI and profiling can increase risk, but neither automatically makes every use a mandatory DPIA. Article 35 expressly captures systematic and extensive evaluation based on automated processing where significant decisions rely on it, as well as certain large-scale sensitive-data processing and public-area monitoring.
The main divergence: Articles 22A–22D
Section 80 of the Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with a new Section 4A, effective 5 February 2026.
Article 22A: identify the decision
Article 22A asks whether a decision is significant and based solely on automated processing.
A significant decision produces a legal effect or a similarly significant effect for the person. A decision is solely automated where there is no meaningful human involvement. The law directs organisations to consider, among other things, how far profiling determines the result.
A reviewer is not necessarily meaningful merely because a workflow diagram includes one. Check whether the person sees the underlying information, has time and competence to assess it, can depart from the recommendation, and actually exercises judgment before the result takes effect.
Article 22B: special-category restrictions
Where a significant decision is based wholly or partly on special-category personal information, Article 22B restricts making it solely through automated processing unless a statutory condition applies. The permitted routes and associated Article 9 conditions require careful, fact-specific analysis.
Remember that special-category information can be inferred. A tool might infer health, ethnicity, political views, or another protected characteristic even if the business never asks a person to provide it directly.
Article 22C: safeguards
For a significant decision based solely on automated processing, Article 22C requires safeguards. The controller must provide information about the decision and allow the person to:
- make representations;
- obtain human intervention; and
- contest the decision.
These safeguards apply more broadly than the Article 22B restriction. A significant solely automated decision using ordinary personal information can still require Article 22C protections.
Build an operational route, not just privacy wording. Assign a review owner, response channel, evidence available to the reviewer, authority to change the outcome, and a record of the result.
Article 22D: watch secondary legislation
Article 22D allows regulations on matters such as meaningful human involvement, significant effects, and safeguards. Date every assessment and check current legislation before relying on it.
The ICO guidance transition
The ICO's AI and data-protection guidance and risk toolkit provide useful questions on governance, lawfulness, transparency, fairness, accuracy, security, minimisation, and individual rights.
However, the ICO currently marks relevant guidance as under review following the Data (Use and Access) Act, and some pages still discuss the repealed Article 22. The ICO's guidance pipeline lists its automated-decision-making and profiling update as being drafted, with final guidance due in Winter 2026.
Use current Articles 22A–22D for the legal analysis. Use the existing toolkit for structured risk work, and record which version you used. Regulations made in 2026 also require the Information Commissioner to prepare an AI and automated-decision-making code of practice, including guidance on children's information; that code is a developing source to monitor, not a reason to postpone current compliance work.
International transfers after Brexit
When a UK organisation makes a restricted transfer, it needs UK adequacy regulations, an appropriate safeguard, or an exception.
The EEA has full adequacy under current UK regulations. A UK-to-EEA transfer is still a restricted transfer, but it generally does not need an IDTA or transfer risk assessment when the adequacy regulations cover it.
For a destination without applicable UK adequacy regulations, appropriate safeguards may include:
- the UK's International Data Transfer Agreement;
- the UK Addendum to the EU standard contractual clauses; or
- another safeguard permitted by UK GDPR.
An EU SCC by itself does not automatically satisfy the UK transfer requirement. Check the location and legal identity of the AI vendor and subprocessors, whether they receive or can remotely access the information, and which transfer mechanism covers each route. The AI vendor data-terms guide helps collect the facts before the UK legal review.
In the other direction, the EU renewed the UK's adequacy status in December 2025 through 27 December 2031, unless extended. That supports covered EU-to-UK flows without additional transfer safeguards. It does not merge the two legal regimes.
When both UK and EU rules apply
A UK company does not acquire every EU obligation merely because an EU resident visits its website. EU GDPR scope can arise through an EU establishment or by offering goods or services to, or monitoring the behaviour of, people in the EU. UK GDPR has its own scope rules.
Where both apply:
- Record each regime and the relevant supervisory contact.
- Keep the EU Article 22 analysis separate from the UK Articles 22A–22D analysis.
- Map transfers by direction and sender rather than using one generic “GDPR clauses” answer.
- Check EU AI Act scope separately. A UK business can be in scope as a provider or deployer even though the UK has no equivalent comprehensive risk-tier AI Act.
A practical update checklist
For each UK AI use involving personal information:
- Replace stale Article 22 citations with a fresh Articles 22A–22D assessment.
- Describe the specific decision, its effect, and the real human workflow.
- Identify lawful basis, special-category condition, controller/processor roles, and privacy information.
- Screen for a DPIA and complete it before deployment where required.
- Review Article 28 terms, subprocessors, retention, security, and training-data use.
- Map transfers and use UK instruments where adequacy does not cover the destination.
- Implement Article 22C information, representations, human intervention, and contest routes where applicable.
- Connect material failures to your AI incident response process.
- Review the record when the model, vendor, purpose, data, law, or ICO guidance changes.
Where the UK Pro Pack fits
The UK AI Governance Pro Pack includes a UK Automated Decision-Making Assessment for Articles 22A–22D, plus a UK GDPR AI Data Processing Register, UK AI Transparency Notice, vendor checklist, incident procedure, and UK DPIA Trigger Checklist.
The AI Governance Starter Pack covers the jurisdiction-neutral policy and employee layer. The free AI Vendor Review can organise an initial vendor review, but it does not decide legal scope or transfer compliance.
This article summarises UK GDPR, ICO guidance, and related EU considerations for SME owners. It is not legal advice and does not guarantee compliance. Scope and obligations depend on the organisation, processing, people, sector, locations, and current law. Obtain qualified advice for significant automated decisions or complex cross-border processing.