Research Library · United Kingdom

The DUAA and AI Hiring: What Changed for UK Employers on 5 February 2026

Summary: The Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR, which treated solely automated decisions as largely prohibited, with a new framework at Articles 22A to 22D permitting them subject to mandatory safeguards. The change took effect on 5 February 2026. For employers using AI to screen candidates, automation is now allowed in more circumstances than before, and scrutinised more closely than before.

The old position and the new one

Under Article 22 of the UK GDPR, a decision based solely on automated processing that produced legal or similarly significant effects was prohibited, subject to narrow exceptions. Recruitment decisions generally qualify as significant, so the practical effect was that fully automated screening sat in awkward territory. Many employers responded by asserting that a human was in the loop, which removed the decision from Article 22 without requiring anyone to examine whether the human was doing anything.

The DUAA reframes this. Rather than a general prohibition with exceptions, the new Articles 22A to 22D create a right to challenge automated decisions supported by mandatory safeguards. Employers gain scope to automate. They also lose the ability to treat the human-in-the-loop assertion as an unexamined escape hatch, because the regulator has now stated clearly what that assertion requires.

One carve-out remains. Where special category data is in scope, the previous and more restrictive rules continue to apply. The ICO confirmed in a January 2026 training note that while the DUAA broadened the circumstances in which solely automated significant decisions may be made, it preserved the restrictions on special category personal data in automated decision-making.

The four safeguards

Article 22C requires four things where a decision is solely automated.

  1. Transparency to the candidate before the decision. They must know automated decision-making is happening, in advance.
  2. A right to human intervention. A route to a person with authority to change the outcome.
  3. A right to make representations and contest the decision. The candidate can put forward their case.
  4. The right to meaningful information about the decision. Not the model weights, but enough for the candidate to understand and challenge the basis.

Alongside these, employers running automated candidate decisions will generally need a Data Protection Impact Assessment, a valid lawful basis, and documented bias monitoring.

On lawful basis, the ICO's 2026 position is that legitimate interests is likely to be the most appropriate basis in many recruitment contexts, particularly where employers process large volumes of applications.

What "meaningful human involvement" now requires

This is the pivot point of the whole regime, because a process with meaningful human involvement is not solely automated and the Article 22C safeguards do not bite in the same way.

The DUAA does not define the term. The Explanatory Notes indicate it may be clarified by secondary legislation. In the meantime the ICO's draft guidance, published 31 March 2026, is the closest available regulatory steer.

The ICO's position is that meaningful human involvement means review by a competent person who has the authority, the information, and the time to overturn the tool's output, and who actually considers the individual case.

Two things expressly do not count. Designing or building the system is not involvement in the decision. Rubber-stamping the output is not review. A recruiter who only ever confirms what the model suggested is not meaningful human involvement, which means the process remains solely automated and the safeguards apply.

The ICO's consultation on the draft guidance closed on 29 May 2026, with final guidance expected in summer 2026. The regime itself is already in force, so waiting for the final text is not a neutral choice.

The enforcement signal

In March 2026 the ICO wrote to 16 organisations it believed were carrying out automated decision-making on candidates, and signalled that enforcement would follow.

That is an unusually direct move for a regulator publishing draft guidance simultaneously. Read together, the report and the letters say that the ICO does not regard the current state of employer practice as acceptable and does not intend to wait for final guidance to act.

What London employers should do now

  1. Establish whether you are carrying out ADM at all. The ICO's central finding was that most employers did not recognise that they were making solely automated decisions. Start by testing your human review against the ICO's standard rather than assuming it qualifies.
  2. Check whether reviewers have the information to overturn. A reviewer who cannot see why the tool scored a candidate as it did cannot meaningfully consider the case. This is the most common structural failure.
  3. Complete or refresh a DPIA for each tool touching candidate data.
  4. Document your lawful basis, with reasoning, rather than defaulting to consent, which is rarely appropriate in a recruitment context given the imbalance of power.
  5. Run documented bias monitoring. The ICO cites regular review against protected characteristics as good practice, and documentation is what makes it defensible.

The Equality Act runs alongside

The Equality Act 2010 operates independently of the data protection regime and applies to every AI recruitment tool a UK employer uses, regardless of where the vendor is based.

Employer liability for indirect discrimination arising from an algorithmic process is not displaced by the tool. "The system produced the shortlist" is not a defence in an Employment Tribunal. Data protection compliance and equality compliance are two separate exercises, and a tool can satisfy the first while creating exposure under the second.

Frequently asked questions

Does the DUAA make AI screening easier or harder? Both. It permits solely automated significant decisions in more circumstances, which is a liberalisation. It also attaches mandatory safeguards and has prompted an active regulator, which raises the compliance floor.

If a recruiter reviews every AI-generated shortlist, are we outside the ADM rules? Only if that review is meaningful by the ICO's standard: authority to overturn, access to the reasoning, time to consider the individual case, and actual consideration rather than confirmation.

Does this apply to recruitment agencies as well as employers? Yes. Agencies screening, ranking, or shortlisting candidates using automated tools are within scope.

What about candidates outside the UK? The UK regime follows UK GDPR territorial scope. An employer processing UK candidate data is in scope. Employers hiring across the UK and EU face two regimes at once, since the EU AI Act classifies recruitment and candidate evaluation tools as high-risk under Annex III.

Is special category data still treated differently? Yes. The stricter pre-DUAA rules continue to apply where special category data is in play, which includes inferences about health or disability that assessment tools can generate without intending to.

Further reading: The EU AI Act and Hiring: Why Recruitment AI Is High-Risk and What Article 10 Requires.

PeopleNotResumes advises UK employers and agencies on automated decision-making in recruitment, including ICO readiness and human review design. Our methodology is grounded in behavioural science research from the London School of Economics.