Research Library · United Kingdom
The Four Article 22C Safeguards: A Practical Checklist for AI Screening
Summary: Where a UK employer's AI screening qualifies as a solely automated significant decision, Article 22C requires four specific safeguards: information about the decision, the ability to make representations, the right to human intervention, and the ability to contest the decision. Article 22C was substituted into the UK GDPR by the Data (Use and Access) Act 2025, commenced by SI 2026/82 from 5 February 2026. Each safeguard has a specific, checkable content, not just a general spirit to satisfy.
Where Article 22C sits
Section 80 of, and Schedule 6 to, the Data (Use and Access) Act 2025 replaced the old Article 22 of the UK GDPR with four new articles. Article 22A defines when a decision is solely automated and significant. Article 22B restricts automated decisions involving special category data. Article 22C sets out the safeguards that apply once a decision is solely automated and significant. Article 22D allows the Secretary of State to specify by regulation what counts as meaningful human involvement.
The ICO describes the shift as moving from a prohibition with exceptions to a right of challenge with safeguards. That reframing is precise. Automation is now permitted more broadly. The four safeguards are what makes it lawful.
Safeguard one: information about the decision
Under Article 22C(2)(a), this reinforces existing transparency duties under Articles 13 and 14: candidates must be told that automated decision-making, including profiling, is happening, and where the decision has a legal or similarly significant effect, given meaningful information about the logic involved and the significance and likely consequences for them.
In practice: a generic privacy policy mention buried in a footer link does not satisfy this. The information needs to be specific to the screening decision, not just the existence of data processing generally.
Safeguard two: the ability to make representations
Candidates must be able to put their case forward before or in response to the decision, not merely be informed of it after the fact with no route to respond.
In practice: this requires an actual channel, an email address, a form, a named contact, that a candidate can use, and a process on your side for genuinely considering what they submit rather than filing it unread.
Safeguard three: the right to human intervention
Candidates must be able to obtain intervention from a person at the controller. This is the safeguard most often satisfied only on paper. The ICO's separate guidance on fairness makes clear that for human review to be meaningful, it should come after the automated decision and relate to the actual outcome, not a token step upstream of it.
In practice: the reviewer needs actual authority to change the outcome, not just the ability to note a concern. A process where a human "reviews" the decision but cannot overturn it does not satisfy this safeguard, whatever it is called internally.
Safeguard four: the ability to contest the decision
Distinct from making representations beforehand, this is the ability to challenge the outcome after it has been reached, in a timely manner, through a defined process.
In practice: candidates need to know who handles a contest, how, and on what timeline. A generic "contact us" link with no defined process for AEDT-related challenges specifically is a weak version of this safeguard.
What triggers these safeguards in the first place
The safeguards apply where a decision is both solely automated and significant. Solely automated turns on whether there is meaningful human involvement, which Article 22A(2) directs you to assess partly by considering how much the decision is reached through profiling. A decision that produces a legal or similarly significant effect for the candidate, such as rejection from a role, generally meets the significance threshold.
If genuine, meaningful human involvement is built into your screening process, the decision may fall outside solely automated processing altogether, in which case Article 22C's specific safeguards are not the operative framework, though ordinary fairness and transparency obligations still apply.
A practical audit sequence
- Determine whether each screening step is solely automated, honestly, against the meaningful human involvement standard, not against how the process is described internally.
- For each solely automated step, check all four safeguards exist as concrete, usable mechanisms, not policy statements.
- Test the human intervention safeguard specifically, since it is the one most commonly present in name only. Ask whether the assigned reviewer can actually change the outcome.
- Confirm the information safeguard is specific to the decision, not folded into general privacy documentation no candidate is likely to read in context.
- Document the contest process with a named owner and a timeline, so it functions rather than existing only as a policy line.
Frequently asked questions
Do these safeguards apply to every use of AI in recruitment? Only where the specific decision is solely automated and significant. A process with genuine, meaningful human involvement at the decision point may sit outside this framework, though other data protection obligations still apply.
Is a human "reviewing" the AI's shortlist enough to avoid Article 22C entirely? Only if that review is meaningful: after the decision, related to the actual outcome, and with real authority to change it. A nominal review does not remove the decision from solely automated processing.
When did Article 22C take effect? It was commenced by SI 2026/82 from 5 February 2026, replacing the previous Article 22 regime.
What happens if special category data is involved? Article 22B applies additional restrictions on solely automated decisions involving special category data, on top of the Article 22C safeguards.
Who defines what counts as meaningful human involvement? Article 22D allows the Secretary of State to specify this by regulation. In the meantime, the ICO's guidance is the operative steer.
PeopleNotResumes helps UK employers implement the Article 22C safeguards where a screening process is genuinely solely automated. Our methodology is grounded in behavioural science research from the London School of Economics.