Start free trial of Lex HR →

Data regulation and AI: DSIT call

DSIT has opened a call for evidence on data regulation and AI UK, seeking examples on access, quality and governance; responses due 9 Sept 2026.

7 September 2026

The Department for Science, Innovation and Technology has launched a call for evidence on data regulation and AI UK, asking organisations to provide practical examples of how personal and non‑personal data rules interact with AI and other data‑intensive technologies.

The exercise opened on 15 July and runs until 11:59pm on 9 September 2026, the department said. DSIT is requesting evidence on five core areas: data access, data quality, data governance, transparency and the effectiveness of existing UK frameworks such as the UK General Data Protection Regulation and the Data Protection Act 2018.

DSIT frames the work as an attempt to gather real‑world case studies that will "feed into policy thinking about data regulation and AI in the UK," including where current rules work well and where they create barriers to innovation or risks to individuals. The call covers both personal data and non‑personal data used in model development, deployment and wider data‑intensive systems.

For HR teams and employers that use AI for recruiting, performance management, monitoring or people analytics, the questions DSIT highlights are immediately relevant. The department is expressly interested in examples that show how access to datasets is governed, how organisations assess and maintain data quality for model training, and how transparency obligations are met in practice — all areas that bear on lawful bases for processing, fairness and explainability in workplace systems.

The consultation comes amid a broader push in the UK to clarify how existing data protection law applies to AI while policymakers develop separate AI‑specific measures. Regulators and government departments have increasingly focused on how training data is sourced and shared, and on whether contractual and technical controls adequately protect workers and other data subjects. For vendors of HR technology, the exercise could sharpen expectations around documentation, data provenance and the evidential trail organisations must keep when deploying automated decision‑making.

DSIT's form asks respondents to supply specific examples, including the nature of the data and systems involved, the legal or commercial constraints encountered, and any mitigations used to address privacy, quality or governance concerns. The department also invites views on whether new regulatory tools or guidance are needed to support safe and effective data use in AI systems.

What DSIT has not set out in the call is a detailed timetable for next steps or how submissions will be handled beyond their role in policy development. The department does not, for example, specify whether responses will be published in full, anonymised, or held as confidential where firms flag commercially sensitive information. It also stops short of indicating whether this exercise will lead to changes to the statutory text of the UK GDPR or the Data Protection Act 2018, or to any transitional arrangements for companies that would need to adapt to fresh rules.

For employers, the immediate implication is procedural: now is a timely moment to document how datasets that feed HR‑facing AI tools are sourced, curated and governed, and to consider contributing evidence if they have practical experience to share. DSIT's call may presage tighter expectations for data access, quality assurance and transparency that will shape procurement criteria for talent platforms and the compliance checks of in‑house people analytics projects.

Responses must be submitted by 11:59pm on 9 September 2026. How DSIT translates the evidence it receives into policy — and whether that results in new guidance, regulatory interventions, or changes to existing statutes — will be a key signal for HR leaders planning AI deployments over the next 12–24 months.

Sources
  1. Data regulation in the age of AI and other data‑intensive technologies
  2. Data Protection Act 2018