Research Library · United Kingdom

The Equality Act and Algorithmic Shortlisting: Why "The System Did It" Is Not a Defence

Summary: The Equality Act 2010 applies to algorithmic hiring exactly as it applies to human decision-making, and it runs independently of the data protection regime governing automated decisions. Under section 19, indirect discrimination occurs where a neutral provision, criterion, or practice puts people sharing a protected characteristic at a particular disadvantage, unless the employer can objectively justify it. An algorithmic screen is a provision, criterion, or practice. Intent is irrelevant, and liability sits with the employer regardless of who built the tool.

Two separate legal regimes, both live at once

Data protection law, the DUAA-amended UK GDPR framework, governs how automated decisions are made and what safeguards must surround them. The Equality Act governs whether the outcome of a decision, automated or not, discriminates against people with a protected characteristic. A tool can satisfy the first regime's process requirements, transparency, human intervention, contest rights, and still produce a discriminatory outcome that breaches the second.

Treating data protection compliance as equality compliance is a common and costly conflation. They test different things.

How indirect discrimination applies to a screening algorithm

Under section 19 of the Equality Act 2010, indirect discrimination occurs where A applies to B a provision, criterion, or practice that is discriminatory in relation to a relevant protected characteristic. An algorithmic scoring or ranking criterion is a provision, criterion, or practice in exactly this sense.

The test runs on effect, not intent. If the criterion puts people sharing a protected characteristic at a particular disadvantage compared with people who do not share it, and the employer cannot show it is a proportionate means of achieving a legitimate aim, that is indirect discrimination. A tool trained on historical hiring data that reproduces patterns favouring one group over another can trigger this without anyone having intended any such outcome.

Why intent does not matter here

This is the point that trips up employers who treat algorithmic screening as inherently neutral. A model trained to predict "who gets hired" based on historical outcomes learns whatever pattern exists in that history. If the history reflects a skew, explicit or through proxies, correlates for a protected characteristic that were never explicitly coded in, such as postcode, employment gaps, or specific universities, the model can reproduce that skew with no discriminatory intent anywhere in its design.

Liability under section 19 does not require anyone to have intended discrimination. It requires only the disadvantage and the absence of objective justification.

Objective justification, and its limits

An employer can defend an indirect discrimination claim by showing the provision, criterion, or practice was a proportionate means of achieving a legitimate aim. Relevant considerations include whether a less discriminatory alternative was available, which can include comparing the degree of bias the algorithmic system exhibits against the degree of bias a human decision-maker might have shown in the same role.

This defence exists, but case law has generally set a demanding bar for what counts as sufficient justification. Using an algorithm because it is faster or cheaper does not, by itself, establish that a specific disparate outcome was a proportionate means of achieving a legitimate business aim. The justification has to speak to the disparity itself, not just to the general business case for automation.

Why "the algorithm produced the shortlist" fails as a defence

The vendor built it, and the vendor sold it, but the employer used it to make an employment decision. The Equality Act attaches liability to the party using the tool to evaluate candidates, not to the party that built the underlying software. A tribunal assessing an indirect discrimination claim will look at the outcome the employer's process produced, not at who wrote the code that produced it.

This mirrors the position under Local Law 144 and the EU AI Act, where responsibility for outcomes similarly does not transfer to the vendor. Across all three regimes, buying a tool does not buy indemnity for what it does.

Where this intersects with the black-box problem

Once a candidate raises a prima facie case of discrimination, the burden can shift to the employer to show the treatment was not because of a protected characteristic. Opaque, complex scoring models make this genuinely difficult to demonstrate. An employer who cannot explain why a tool scored particular candidates lower is poorly placed to show that a protected characteristic, or a close proxy for one, was not doing the work.

This is a practical argument for explainability and bias testing that goes beyond what data protection law technically requires, because it is what makes an Equality Act defence possible at all.

Practical steps

  1. Test outcomes by protected characteristic, not just overall accuracy, before and after deployment, and on an ongoing basis.
  2. Document the objective justification case for any disparity found, specifically, rather than relying on a general rationale for using automation.
  3. Retain explainability sufficient to answer a discrimination claim, since a black-box system that cannot be interrogated leaves the employer unable to mount a defence.
  4. Do not treat data protection compliance as a proxy for equality compliance. Meeting Article 22C's safeguards says nothing about whether the underlying decision criterion is discriminatory.
  5. Assume liability sits with you, not your vendor, when structuring contracts and internal accountability.

Frequently asked questions

Does the Equality Act apply differently to AI-driven decisions than human ones? No. The same legal tests apply. What differs is the practical difficulty of demonstrating why a decision was made, which can cut against the employer when the process is opaque.

Can we defend a disparity by pointing to our vendor's bias testing? It can be useful evidence, but it does not transfer liability. The employer remains responsible for the outcome its use of the tool produces.

Is passing a Local Law 144-style bias audit the same as Equality Act compliance? No. A bias audit measures selection rate disparities using a specific methodology under a specific US law. It is useful evidence but is not itself an Equality Act defence, and the legal tests are not identical.

What counts as a protected characteristic under the Equality Act? Age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, and sexual orientation.

Does DUAA compliance protect us from an Equality Act claim? No. DUAA compliance addresses data protection process requirements. It does not address, and does not defend against, a discrimination claim based on outcomes.

PeopleNotResumes tests AI screening tools against Equality Act indirect discrimination risk, not just data protection compliance. Our methodology is grounded in behavioural science research from the London School of Economics.