UK GDPR Arts. 22A–22D: permission-plus-safeguards model for significant, solely automated decisions (Data (Use and Access) Act 2025)
A permission-plus-safeguards model for significant, solely automated decisions, with tighter conditions where special-category data is used
AIGE-OBL-UK-ADM. Drawn from chapter 08.
Text alternative
- Clause: UK DUAA, UK GDPR Arts. 22A–22D.
- Duty holder: Not stated.
- Applies from: 2026-02-05, In force.
- Artefact: ADM safeguards.
- Layers: Layer 04, Layer 02.
- Evidence record: Evidence record v1.
- Record schema: Evidence record.
- The same topic in 18 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-UK-ADM- Instrument
- UK Data (Use and Access) Act 2025 law
- Clause
- UK GDPR Arts. 22A–22D
- Applies from
- In force
The artefact that evidences it
ADM safeguards: meaningful-human-review path, contest and representation channel, decision notice.
Patterns that build it
- Decision Notice & Contest Path (layer 4 and 5)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Human oversight
- EU AI Act Art. 14 Human oversight (core)
- ISO 42001 A.9 Use of AI systems (core)
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use (core)
- TC260 Framework 3.0 TC260 App. 2 II.3 Strengthen human approval (core)
- GDPR Art. 22 Automated individual decision-making, including profiling (core)
- NIST AI RMF MAP 3.5 MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function (core)
- CSA AICM GRC-15 Human supervision (core)
- Korea AI Act Art. 34(1)(4) Human management and supervision (core)
- UK ATRS ATRS 2.3.2 Human review (core)
- Singapore Agentic Agentic 2.2.2 Design for meaningful human oversight (core)
- GAO AI Accountability 3.9 Human supervision: define and develop procedures for human supervision of the AI system (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- NIST AI RMF GOVERN 3.2 GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems
- China Algo. Rec. AlgoRec Art. 17 User option to switch off
- China GenAI Measures GenAI Art. 10 User guidance and protection
- EU AI Act Art. 14(4)(b) Awareness of automation bias
- OWASP Agentic ASI09 Human-Agent Trust Exploitation
- CoE Convention CoE Art. 8 Transparency and oversight
- OECD AI Principles OECD 1.2(b) Human agency and oversight safeguards
Privacy and data protection
- GDPR Art. 5 Principles relating to processing of personal data (core)
- GDPR Art. 6 Lawfulness of processing (core)
- GDPR Art. 25 Data protection by design and by default (core)
- NIST AI RMF MEASURE 2.10 MEASURE 2.10: Privacy risk of the AI system as identified in the MAP function is examined and documented (core)
- CSA AICM DSP-08 Data Privacy by Design and Default (core)
- OWASP LLM LLM02:2026 Sensitive Information Disclosure (core)
- CoE Convention CoE Art. 11 Privacy and personal data protection (core)
- China GenAI Measures GenAI Art. 7(3) Consent or another lawful basis for personal information in training data (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- GAO AI Accountability 2.8 Security and privacy: assess data security and privacy for the AI system (core)
- EU AI Act Art. 59 Further processing of personal data in the AI regulatory sandbox
- EU AI Act Art. 4a Special-category data for bias detection
- GDPR Art. 35 Data protection impact assessment
- ISO 42001 A.7 Data for AI systems
- CSA AICM DSP-22 Privacy Enhancing Technologies
- Singapore GenAI GenAI 2 Data
- OECD AI Principles OECD 1.2 Rule of law, human rights and democratic values, including fairness and privacy
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property
Explainability and right to explanation
- EU AI Act Art. 86 Right to explanation of individual decision-making (core)
- EU AI Act Art. 13(3)(b)(iv)–(v) Information relevant to explain output; performance for specific persons or groups (core)
- GDPR Art. 15(1)(h) Meaningful information about the logic involved (core)
- NIST AI RMF MEASURE 2.9 MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance (core)
- CSA AICM GRC-13 Explainability Requirement (core)
- CSA AICM GRC-14 Explainability Evaluation (core)
- Korea AI Act Art. 34(1)(2) Explanation plan: result, main criteria, training-data overview (core)
- OECD AI Principles OECD 1.3 Transparency and explainability (core)
- GDPR Art. 13(2)(f) Existence of automated decision-making
- GDPR Art. 22(3) Right to obtain human intervention and to contest the decision
- ISO 42001 A.8.2 System documentation and information for users (clause not verified)
- NIST AI RMF MEASURE 2.8 MEASURE 2.8: Risks associated with transparency and accountability as identified in the MAP function are examined and documented
- UK ATRS ATRS 2.3.5 Appeals and review
- Singapore GenAI GenAI 3 Trusted Development and Deployment
- CoE Convention CoE Art. 14(2) Documentation sufficient to contest decisions; complaint to authorities
- China Algo. Rec. AlgoRec Art. 17 Explain where an algorithm significantly affects user rights
Source
Chapter 08, section United Kingdom, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-uk-adm.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). UK GDPR Arts. 22A–22D: permission-plus-safeguards model for significant, solely automated decisions (Data (Use and Access) Act 2025) (AIGE-OBL-UK-ADM). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-uk-adm. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{UK GDPR Arts. 22A–22D: permission-plus-safeguards model for significant, solely automated decisions (Data (Use and Access) Act 2025) (AIGE-OBL-UK-ADM)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-uk-adm},
note = {Version 0.5.0}
}