Back to Blog

Data protection, privacy and retention

ICO Guidance on Automated Decision Making: Key Lessons for Organisations

ICO Guidance on Automated Decision‑Making: Key Lessons for Organisations

The Information Commissioner’s Office (ICO) has published updated guidance on Automated Decision Making (ADM) [1], ahead of further guidance on AI. The purpose is to help organisations understand when ADM applies, how it may be used lawfully, and what safeguards must be in place.

What is Automated Decision Making?

ADM is defined in Article 22A UK GDPR [2]. It refers to a significant decision made solely by automated processing, including profiling, that produce a legal effect or a similarly significant effect on an individual.

A significant decision compared to a decision is one that produces a legal effect or an effect that is similarly significant for the data subject. A legal effect impacts a person’s legal rights or status. For example, a legal effect could include enforcement actions, such as issuing a penalty, fine or charge or approving or refusing access to a public service, benefit or licence.

A similarly significant effect has an equivalent practical impact such as on financial position, health, access to services or employment opportunities or circumstances.

In deciding whether a decision is significant context matters. In particular, a small decision may still be significant where individuals are vulnerable, such as children and this would include any decision that impacted the child’s rights, freedoms and legitimate interests. Where ADM is carried out at scale and affected individuals cannot easily be separated, safeguards must apply consistently.

Solely Automated Processing and Human Involvement

ADM applies only where there is no meaningful human involvement. Human involvement must be active and capable of changing the outcome. The ICO expects that any human review:

  • takes place before the decision is applied, and
  • occurs at a stage where the decision can still be changed.

 

An example of meaningful human involvement could be where a customer’s application for a credit account is flagged due to an automated credit-score system identifying the applicant as high risk. However, although it is flagged, a human reviews the data along with any additional information before making a decision to reject the application. Token gestures or ad‑hoc spot checks do not qualify. The ICO emphasises the importance of organisations documenting how human involvement works in practice.

Profiling

Profiling, defined in UK GDPR, involves analysing or predicting aspects of a person’s behaviour, characteristics or preferences. It may use data collected directly or from third‑party sources, including online activity or location data from mobile devices. Where profiling leads to decisions about individuals without meaningful human involvement, it may constitute ADM. Many modern profiling systems use AI, but the legal obligations apply regardless of the technology used.

Lawful Use of ADM

Under Article 5(1)(a) UK GDPR, ADM must be lawful, fair and transparent. Organisations must identify a lawful basis under Article 6 UK GDPR and clearly explain their use of ADM to individuals. As the ICO guidance states no lawful basis is prioritised and the correct choice depends on the purpose of the processing and the relationship with the individual.

However, two restrictions apply. Recognised Legitimate Interest cannot be used for ADM and Special Category Data is only permitted to be used in ADM if one of the following conditions apply:

  • The decision is based entirely on the person’s explicit consent
  • The decision is necessary for a contract between the individual and the organisation and a substantial public interest (SPI) condition applies
  • The decision is required or authorised by law, and a substantial public interest (SPI) condition applies

It is made clear that prohibition on using Recognised Legitimate Interest as a lawful basis applies regardless of the purpose, including fraud prevention. Other lawful bases remain available, but all ADM carries heightened risk and often requires a Data Protection Impact Assessment (DPIA) under Article 35 UK GDPR.

Common Lawful Bases

Below are some of the common lawful bases used for ADM. The ICO has stated when these lawful bases may be used and the conditions to be met when using these as the lawful basis for ADM.

  • Contract (Article 6(1)(b)) UK GDPR – ADM must be objectively necessary to perform a contract with the individual or take steps at their request. This basis is narrow and does not apply where data is reused for broader business purposes or applied to non‑contracting individuals.
  • Public Task (Article 6(1)(e)) UK GDPR – Relevant mainly to public authorities performing tasks laid down by law. ADM must be a reasonable and proportionate means of achieving the statutory objective.
  • Legitimate Interests (Article 6(1)(f)) UK GDPR – ADM can take place, but the three-part legitimate interest assessment (LIA) must be carried out. This assessment includes the purpose test, the necessity test and the balancing test. The outcome of the tests may depend on how you intend to carry out ADM. It is harder to justify the use of legitimate interests for intrusive or invisible profiling or tracking.

It is important to note that legitimate interests differ from recognised legitimate interests. Legitimate interests cover a broad range of situations whereas recognised legitimate interests are much narrower. For further detail please see our blog on Recognised Legitimate Interests.

Other bases, such as legal obligation or vital interests, apply only in limited circumstances.

Please contact Jose Saras for detailed advice on the above.

The material contained in this article is only for general review of the topics covered and does not constitute any legal advice. No legal or business decision should be based on its content.

This article is written in the English language. Preiskel & Co LLP is not responsible for any translation of all or part of its content into any language.

 

[1] ICO – Automated Decision-Making, Including Profiling

[2] UK GDPR

[3] Data Protection Act 2018

A practical way forward

Tell us about the matter.

Speak to us