Automated decisions about employees: UK GDPR Article 22 explained
When an AI-supported decision about a worker counts as solely automated, what safeguards UK GDPR requires, what meaningful human review looks like, and how to answer an employee who challenges a score.
Algorithmic management — scheduling engines, productivity scores, attrition-risk flags, automated rejections — puts employers squarely inside the UK GDPR rules on automated decision-making. Those rules are narrower than people assume, and the safeguards are more demanding.
The rule
Article 22 gives individuals the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects them. In an employment context, decisions that clear the "significant effect" bar include:
- rejecting a job application
- terminating employment or ending an assignment
- pay, bonus or promotion outcomes
- allocation of work where it materially affects earnings
- triggering a formal capability or disciplinary process
Decisions that usually do not: suggesting a training course, ranking an internal knowledge search, drafting a first-pass document a manager rewrites.
Solely automated decisions are permitted only where they are necessary for a contract, authorised by law, or based on explicit consent — and consent is unreliable in employment. Where special-category data is involved, the grounds are narrower still.
"Solely" is doing the heavy lifting
A decision is not solely automated if there is meaningful human involvement. The bar the ICO applies:
- the reviewer has the authority and competence to change the outcome
- they consider all relevant data, not just the score
- the review is a genuine assessment, not a formality
Signs your "human review" would fail: the reviewer sees only a pass/fail flag; they have no access to the underlying evidence; approval rates are effectively 100%; they are measured on throughput; or they have no documented route to overrule the system. Adding a manager's signature at the end of an automated pipeline does not take you outside Article 22 — it simply creates a record of who agreed.
Safeguards when automated decisions are permitted
Where a solely automated decision is lawful, you must give the individual at least:
- the right to obtain human intervention
- the right to express their point of view
- the right to contest the decision
Plus the transparency duties: meaningful information about the logic involved, and the significance and envisaged consequences. "Meaningful information about the logic" does not mean disclosing source code. It means explaining, in terms the person can act on, which factors were used, how they were weighted in broad terms, and what would have changed the outcome.
Get the paperwork right before deployment
- DPIA. Systematic evaluation of workers with legal or significant effects requires one.
- Lawful basis and, where relevant, an Article 9 condition. Record it in the DPIA and the record of processing.
- Privacy information. The staff privacy notice must describe the automated decision-making, not just the data collection.
- Accuracy. Inferences and scores are personal data, and the accuracy principle applies. Have a route to correct a wrong input.
- Retention. Scores that drive employment decisions should be retained long enough to explain a decision and no longer.
Answering a challenge
Employees can make a subject access request covering their scores and the data behind them, and can ask for human review. A workable internal process:
- Log the challenge and pause reliance on the disputed output where the decision has not yet taken effect.
- Pull the input data, the score and the version of the model or rules used.
- Have someone independent of the original decision reassess on the underlying facts.
- Give a written outcome that explains the factors, not just the conclusion.
- Correct the underlying data if it was wrong, and check whether the same error affected other workers.
That last step matters: a systematic input error usually affects a cohort, and dealing with it once is cheaper than defending a series of claims.
Overlap with employment law
Article 22 is not the only exposure. The same decision can be:
- unfair dismissal if the process was not reasonable — a manager who cannot explain why the system flagged someone will struggle to show a fair procedure
- discrimination if the output disadvantages a protected group, or if a disabled worker's adjustment was not reflected in the inputs
- a breach of trust and confidence, particularly where scoring is opaque and pervasive
Tribunals do not defer to model output. The employer must justify the decision on its own terms.
A short compliance checklist
- Inventory of automated and semi-automated decisions affecting staff
- For each: is it solely automated? Evidence of meaningful human involvement if not
- Lawful basis and DPIA in place before use
- Staff privacy notice describes the processing and the logic
- Documented override route, with overrides logged and reviewed
- Challenge process with a defined response time
- Periodic accuracy and adverse-impact review, results recorded
The practical takeaway
You can use algorithms to manage people in the UK. You cannot use them to decide about people without a human who understands the decision, can change it, and can explain it. Build that human step properly and most of Article 22 takes care of itself.
This guide is general information for HR professionals, not legal advice. Take advice on your own facts before acting.
Related guides
EU AI Act for HR
How the EU AI Act classifies recruitment, monitoring and people-management systems as high risk, which obligations fall on employers as deployers, and the compliance deadlines that matter for HR.
UK employee monitoring law
A practical guide to lawful workplace monitoring in the UK — the UK GDPR lawful basis, ICO expectations, when a DPIA is mandatory, covert monitoring, and how AI-driven productivity tracking changes the analysis.
AI hiring and discrimination law
How the Equality Act 2010 applies to CV screening, video interviews and candidate scoring, what a defensible bias audit looks like, and the vendor questions that protect employers from tribunal claims.
Get AI & HR insights every week
One email a week with the latest cases, regulations and practical guidance on AI in the workplace.