# Data (Use and Access) Act 2025: Data (Use and Access) Act 2025 (2025 c. 18) — automated decision-making reform, section 80 and new UK GDPR Articles 22A to 22D

Source: https://www.bankingnewsai.com/ai-regulation/documents/uk-data-use-and-access-act-2025
Last updated: Oct 5, 2026

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 (2025 c. 18). Section 80 replaced Article 22 of the UK GDPR with new Articles 22A to 22D, which keep a restriction only for significant automated decisions based on special category data and otherwise permit solely automated significant decisions on any lawful basis, provided safeguards are in place. Section 80 came into force on 5 February 2026 under the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), and applies only to decisions taken on or after that date. For a bank the key duty is Article 22C: for any significant decision based solely on automated processing, provide information about the decision and enable the customer to make representations, obtain human intervention and contest it.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) |
| Type | Statute |
| Status | In force |
| Published | Jun 19, 2025 |
| Effective | Feb 5, 2026 |
| Applies to | Any controller subject to the UK GDPR that takes decisions about individuals using personal data, including UK banks, building societies, insurers and fintechs. Section 80 and Schedule 6 reform the rules on automated decisions; the Act is not an AI statute and does not name artificial intelligence, but its automated-decision rules govern most credit, fraud and onboarding models that decide without meaningful human involvement. |
| Official text | https://www.legislation.gov.uk/ukpga/2025/18/contents |

## Key points

- Royal Assent 19 June 2025; the Act is 2025 c. 18 on legislation.gov.uk. Section 80 (automated decision-making) and Schedule 6 (minor and consequential amendments) are the AI-relevant provisions.
- Article 22A: a decision is 'based solely on automated processing' if there is 'no meaningful human involvement in the taking of the decision'; a 'significant decision' is one that produces a legal effect or a 'similarly significant effect' for the data subject. Whether human involvement is meaningful must take account of the extent to which the decision is reached by means of profiling (Article 22A(2)).
- Article 22B(1): a significant decision based entirely or partly on special category data (Article 9(1)) may not be taken solely by automated means unless the data subject gave explicit consent to that processing (22B(2)) or the decision is necessary for a contract or required or authorised by law and Article 9(2)(g) (substantial public interest) applies (22B(3)).
- Article 22B(4): a significant decision may not be taken solely by automated means where the processing is carried out wholly or partly in reliance on Article 6(1)(ea), the recognised legitimate interests basis inserted by the Act.
- Article 22C: for solely automated significant decisions based on personal data, the controller must have safeguards in place that at least provide information about the decision, let the data subject make representations, let them obtain human intervention, and let them contest the decision (22C(2)(a) to (d)).
- Article 22D gives the Secretary of State powers, by regulations under the affirmative resolution procedure, to say when human involvement is or is not meaningful, which decisions have a similarly significant effect, and to add to or clarify the Article 22C safeguards; regulations may not amend Article 22C itself.
- Commencement: SI 2026/82, made 29 January 2026, brought section 80 and Schedule 6 into force on 5 February 2026. Regulation 5 provides that the amendments do not apply to decisions taken before that date to which old Article 22(3) or sections 14 or 50(2) of the Data Protection Act 2018 applied.
- The ICO's guidance on automated decision-making and profiling is being updated for the Act: a draft was consulted on from 31 March to 29 May 2026 and final guidance is listed as expected in winter 2026.

## What changed for banks

The old Article 22 prohibited solely automated decisions with legal or similarly significant effects unless a contract, law or explicit consent exception applied, which made lawful-basis and exception analysis the centre of every automated credit or fraud decision. The new regime inverts that for ordinary personal data: solely automated significant decisions are permitted on any lawful basis (including legitimate interests) as long as the Article 22C safeguards exist, while the prohibition-with-exceptions survives only for special category data and for processing relying on recognised legitimate interests. For banks this lowers the legal barrier to automated underwriting, fraud and onboarding decisions but moves the compliance weight to the safeguards: information, representations, human intervention and contestation, which must work in practice.

## Use cases it governs

- [Credit scoring & underwriting](https://www.bankingnewsai.com/ai-regulation/by-use-case#credit-underwriting)
- [Fraud detection](https://www.bankingnewsai.com/ai-regulation/by-use-case#fraud)
- [AML / KYC](https://www.bankingnewsai.com/ai-regulation/by-use-case#aml-kyc)
- [Data & privacy](https://www.bankingnewsai.com/ai-regulation/by-use-case#data-privacy)
- [Customer-facing chatbots](https://www.bankingnewsai.com/ai-regulation/by-use-case#customer-chatbots)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)

## What does the Data (Use and Access) Act 2025 require of banks making automated decisions?

The Data (Use and Access) Act 2025 (2025 c. 18, Royal Assent 19 June 2025) replaced Article 22 of the UK GDPR with Articles 22A to 22D through section 80, in force since 5 February 2026. A bank may take a significant decision (one with a legal or similarly significant effect) solely by automated means on any lawful basis, unless the decision is based wholly or partly on special category data or on processing relying on recognised legitimate interests (Article 6(1)(ea)), where Article 22B restricts it to narrow conditions such as explicit consent. In every solely automated significant decision based on personal data, Article 22C requires safeguards that provide information about the decision and let the customer make representations, obtain human intervention and contest the decision. The rules apply to decisions taken on or after 5 February 2026, and the Secretary of State can use Article 22D powers to define meaningful human involvement and add safeguard requirements.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Article 22A(1)(a) UK GDPR — solely automated | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | A decision is based solely on automated processing if there is no meaningful human involvement in taking it; whether involvement is meaningful must consider the extent to which the decision is reached by profiling (22A(2)). | In force since 5 Feb 2026 | [Data (Use and Access) Act 2025](https://www.bankingnewsai.com/ai-regulation/documents/uk-data-use-and-access-act-2025) |
| Article 22A(1)(b) UK GDPR — significant decision | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | A decision is significant if it produces a legal effect or a similarly significant effect for the data subject; the test brings in credit refusals, account closures and similar bank decisions. | In force since 5 Feb 2026 | [Data (Use and Access) Act 2025](https://www.bankingnewsai.com/ai-regulation/documents/uk-data-use-and-access-act-2025) |
| Article 22B(1) to (3) UK GDPR — special category data | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | A significant decision based entirely or partly on special category data may not be solely automated unless the data subject gave explicit consent, or the decision is necessary for a contract or required or authorised by law and Article 9(2)(g) applies. | In force since 5 Feb 2026 | [Data (Use and Access) Act 2025](https://www.bankingnewsai.com/ai-regulation/documents/uk-data-use-and-access-act-2025) |
| Article 22B(4) UK GDPR — recognised legitimate interests | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | A significant decision may not be solely automated where the processing relies wholly or partly on Article 6(1)(ea). | In force since 5 Feb 2026 | [Data (Use and Access) Act 2025](https://www.bankingnewsai.com/ai-regulation/documents/uk-data-use-and-access-act-2025) |
| Article 22C(1) UK GDPR — safeguards required | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | For a solely automated significant decision based on personal data, the controller must ensure safeguards for the data subject's rights, freedoms and legitimate interests are in place. | In force since 5 Feb 2026 | [Data (Use and Access) Act 2025](https://www.bankingnewsai.com/ai-regulation/documents/uk-data-use-and-access-act-2025) |
| Article 22C(2)(a) to (d) UK GDPR — minimum safeguards | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | The safeguards must include information about the decisions, the ability to make representations, to obtain human intervention from the controller and to contest the decision. | In force since 5 Feb 2026 | [Data (Use and Access) Act 2025](https://www.bankingnewsai.com/ai-regulation/documents/uk-data-use-and-access-act-2025) |
| Article 22D UK GDPR — regulation-making powers | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | The Secretary of State may by affirmative-procedure regulations define meaningful human involvement, which decisions are similarly significant, and further safeguard requirements; Article 22C itself may not be amended by them. | Powers in force; use of the powers to be checked on legislation.gov.uk | [Data (Use and Access) Act 2025](https://www.bankingnewsai.com/ai-regulation/documents/uk-data-use-and-access-act-2025) |
| SI 2026/82 regulation 5 — transitional provision | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | The section 80 and Schedule 6 amendments do not apply to decisions taken before 5 February 2026 to which old Article 22(3) UK GDPR or sections 14 or 50(2) of the Data Protection Act 2018 applied. | From 5 Feb 2026 | [official text](https://www.legislation.gov.uk/uksi/2026/82/made) |
| ICO draft ADM and profiling guidance | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | The ICO consulted from 31 March to 29 May 2026 on updated guidance on automated decision-making including profiling; the final version is listed as expected in winter 2026. | Consultation closed 29 May 2026 | [ICO Guidance on AI and data protection](https://www.bankingnewsai.com/ai-regulation/documents/ico-guidance-ai-data-protection) |

The reform changes the architecture of automated decision-making law rather than its vocabulary. Under old Article 22 a bank needed an exception (contract necessity, legal authorisation or explicit consent) for every solely automated significant decision. Under Articles 22A to 22D the starting point is permission: any lawful basis can support a solely automated significant decision on ordinary personal data, and the legal question moves to whether the Article 22C safeguards exist and work. The restrictions that remain target the riskier inputs, special category data and processing relying on recognised legitimate interests, which keeps the earlier exceptions alive for those cases.

The Act sits alongside, not in place of, the other UK rules that reach bank AI. The Consumer Duty and the PRA's model risk expectations still apply to the same decisions, and the ICO's guidance on AI and data protection continues to set expectations on fairness, transparency and accuracy while it is reviewed for the Act. The Act is technology-neutral and does not mention AI by name; the regulatory perimeter for AI in UK banking remains the existing legislation, applied by the PRA, FCA and ICO within their remits.

Enforcement of the UK GDPR provisions is by the Information Commissioner. Because section 80 applies only to decisions taken on or after 5 February 2026, a bank's records should show when each automated decision process was assessed against the new Articles, and which processes continue to rely on the older exceptions for special category data.

### What this means in practice

- Map every automated decision that produces a legal or similarly significant effect on a customer (credit, limits, account closure, fraud blocks, onboarding rejections) and test each against Article 22A: is there meaningful human involvement or not.
- For each solely automated significant decision, document the Article 22C safeguards: how the customer is informed, how they make representations, how they reach a human, and how a contest is decided.
- Identify decisions that use special category data or rely on recognised legitimate interests, because Article 22B still restricts them to explicit consent or contract or legal necessity with Article 9(2)(g).
- Do not treat a rubber-stamp reviewer as human involvement; Article 22A requires involvement to be meaningful and expects profiling to be considered when judging it.
- Watch the ICO's final ADM guidance (listed for winter 2026) and any Article 22D regulations, and update procedures when either lands.

## FAQ

### Does the Data (Use and Access) Act 2025 apply to banks?

Yes, to the extent that a bank takes decisions about individuals using personal data. Section 80 amends the UK GDPR, which applies to all controllers, so it governs bank decisions on credit, account opening, fraud flags and similar matters whenever they are made without meaningful human involvement and have a legal or similarly significant effect.

### When did the automated decision-making rules in the Data (Use and Access) Act 2025 take effect?

Section 80 and Schedule 6 came into force on 5 February 2026 under the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), made on 29 January 2026. They apply only to decisions taken on or after that date.

### What are UK GDPR Articles 22A to 22D?

They are the provisions inserted by section 80 of the Act in place of Article 22. Article 22A defines solely automated and significant decisions, 22B restricts such decisions based on special category data or recognised legitimate interests, 22C requires safeguards (information, representations, human intervention, contestation) and 22D gives the Secretary of State regulation-making powers.

### Can a bank now make automated credit decisions without human review?

For decisions that do not rely on special category data or on recognised legitimate interests, yes, on any valid lawful basis, provided the Article 22C safeguards are in place and the other UK GDPR principles (fairness, transparency, accuracy) are met. The decision must be genuinely solely automated for the rules to apply; a nominal human sign-off without meaningful involvement does not take it out of Article 22A.

### How does the Data (Use and Access) Act compare with the EU AI Act?

They address different things. The Act reforms data protection law for automated decisions about individuals and is technology-neutral, while the EU AI Act (Regulation (EU) 2024/1689) regulates AI systems by risk category and classifies creditworthiness scoring as high-risk. The UK has no AI-specific statute and relies on existing law and regulators.

## Related documents

- [Bailey: Frontier AI and the Question of Governance (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-bailey-frontier-ai-governance-2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey (Sep 30, 2026)
- [FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fca-frontier-ai-cyber-resilience-2026) — Frontier AI and Cyber Resilience (Sep 2, 2026)
- [HM Treasury Financial Services AI Adoption Plan (Jul 2026)](https://www.bankingnewsai.com/ai-regulation/documents/hmt-financial-services-ai-adoption-plan-2026) — Financial Services AI Adoption Plan (Jul 14, 2026)
- [2026 BoE/FCA AI survey](https://www.bankingnewsai.com/ai-regulation/documents/uk-ai-in-financial-services-survey-2026) — The Bank of England and FCA's 2026 AI Survey (Jun 5, 2026)
- [BoE/FCA/HMT joint statement on frontier AI and cyber resilience (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/uk-joint-statement-frontier-ai-cyber-resilience-2026) — The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilience (May 15, 2026)
- [BoE response to Treasury Committee AI inquiry (Apr 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-pra-response-tsc-ai-inquiry-2026) — Response to TSC inquiry report on AI in financial services (Apr 1, 2026)
- [BoE/PRA plan for safe AI innovation (Apr 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-pra-safe-ai-innovation-plan-letter-2026) — Letter from Sarah Breeden and Sam Woods to the Chancellor and Secretaries of State on enabling safe AI innovation (Apr 1, 2026)
- [DSIT/DBT strategic letters to regulators (Jan 2026)](https://www.bankingnewsai.com/ai-regulation/documents/gov-uk-dsit-dbt-safe-ai-innovation-letter-2026) — How will regulators enable safe AI-powered innovation: joint letter from DSIT Secretary of State and DBT Secretary of State (Jan 28, 2026)

Last reviewed Oct 5, 2026. Cite the official text (https://www.legislation.gov.uk/ukpga/2025/18/contents) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/uk-data-use-and-access-act-2025
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
