Svennis AI

UK GDPR: the articles that matter when you use AI, annotated

The UK GDPR articles that matter when a business uses artificial intelligence (AI): lawful basis, consent, special category data, transparency, individual rights, the new automated decision-making rules in Articles 22A to 22D, inserted by the Data (Use and Access) Act 2025 and in force since 5 February 2026, plus data protection by design, processor contracts, DPIAs, security and the current international transfers regime. This is the retained, amended UK GDPR as it stands today, not the EU original. The text is official and verbatim; the note beside each article is our explanation.

Updated 4 July 2026 · Official current text on legislation.gov.uk

The article text is the official current text from legislation.gov.uk. Only the articles relevant to using AI are selected. The 'What it means' notes and examples are informational explanations by Svennis, not legal advice; the binding source is the official text.

Principles and lawful basis

Article 5 · Principles relating to processing of personal data

What it meansRelevance for businesses: high

This article sets the core principles every use of personal data must follow, including when the data passes through an AI system: lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, and security. You, as the organisation in control, are accountable and must be able to demonstrate compliance. The UK text adds a clarification: just because a new use is compatible with the original purpose does not by itself make it lawful, you still need a proper legal basis.

Example: A used car dealer in Leeds connects an AI assistant to its customer database to draft follow-up messages. Under these principles the dealer feeds the assistant only the fields needed for the message (name, enquiry, vehicle of interest), not the full purchase and finance history, deletes chat logs on a set schedule, and keeps a short written note showing why each data field is used.

Official text

1. Personal data shall be: (a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’); (b) collected (whether from the data subject or otherwise) for specified, explicit and legitimate purposes and not further processed by or on behalf of a controller in a manner that is incompatible with the purposes for which the controller collected the data (‘purpose limitation’); (c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’); (d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’); (e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 84B (‘storage limitation’); (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’). 2. The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’). 3. For the avoidance of doubt, processing is not lawful by virtue only of being processing in a manner that is compatible with the purposes for which the personal data was collected.

Article 6 · Lawfulness of processing

What it meansRelevance for businesses: high

Processing personal data, including sending it to an AI tool, is only lawful if you have at least one legal basis: consent, contract, legal obligation, vital interests, public task, a recognised legitimate interest, or ordinary legitimate interests. The UK version adds the new recognised legitimate interest basis (point ea, tied to Annex 1) and expressly lists direct marketing, intra-group data sharing for admin, and network security as examples of processing that may qualify as a legitimate interest. Before an AI assistant touches customer data, decide and record which basis you rely on.

Example: An online retailer in Manchester wants an AI assistant to answer order questions on its website. Answering a customer about their own order sits comfortably on the contract basis, while using the same chat history to send personalised offers later would rest on legitimate interests, which the article now expressly says can cover direct marketing, provided the retailer does a short balancing check and offers an opt out.

Official text

1. Processing shall be lawful only if and to the extent that at least one of the following applies: (a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes; (b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; (c) processing is necessary for compliance with a legal obligation to which the controller is subject; (d) processing is necessary in order to protect the vital interests of the data subject or of another natural person; (e) processing is necessary for the performance of a task of the controller carried out in the public interest or a task carried out in the exercise of official authority vested in the controller; (ea) processing is necessary for the purposes of a recognised legitimate interest; (f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. Points (ea) and (f) of the first subparagraph shall not apply to processing carried out by public authorities in the performance of their tasks. 2. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3. The basis for the processing referred to in point (c) ... of paragraph 1 shall be laid down by domestic law. The basis for the processing referred to in point (e) of paragraph 1 must be laid down by domestic law or relevant international law (see section 9A of the 2018 Act). The purpose of the processing shall be determined in that legal basis or, as regards the processing referred to in point (e) of paragraph 1, shall be necessary for the performance of a task of the controller carried out in the public interest or a task carried out in the exercise of official authority vested in the controller. That legal basis may contain specific provisions to adapt the application of rules of this Regulation, inter alia: the general conditions governing the lawfulness of processing by the controller; the types of data which are subject to the processing; the data subjects concerned; the entities to, and the purposes for which, the personal data may be disclosed; the purpose limitation; storage periods; and processing operations and processing procedures, including measures to ensure lawful and fair processing such as those for other specific processing situations as provided for in Chapter IX. The domestic lawor relevant international law shall meet an objective of public interest and be proportionate to the legitimate aim pursued. 4. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5. For the purposes of paragraph 1(ea), processing is necessary for the purposes of a recognised legitimate interest only if it meets a condition in Annex 1. 6. The Secretary of State may by regulations amend Annex 1 by— (a) adding or varying provisions, or (b) omitting provisions added by regulations made under this paragraph. 7. The Secretary of State may only make regulations under paragraph 6 where— (a) the requirement in paragraph 8 is satisfied, and (b) if the regulations add a case to Annex 1, the requirement in paragraph 9 is also satisfied. 8. The requirement in this paragraph is that the Secretary of State considers it appropriate to make the regulations having regard to, among other things— (a) the interests and fundamental rights and freedoms of data subjects which require protection of personal data, and (b) where relevant, the fact that children merit specific protection with regard to their personal data because they may be less aware of the risks and consequences associated with processing of personal data and of their rights in relation to such processing. 9. The requirement in this paragraph is that the Secretary of State considers that processing in the case to be added to Annex 1 is necessary to safeguard an objective listed in Article 23(1)(c) to (j). 10. Regulations under paragraph 6 are subject to the affirmative resolution procedure. 11. For the purposes of paragraph 1(f), examples of types of processing that may be processing that is necessary for the purposes of a legitimate interest include— (a) processing that is necessary for the purposes of direct marketing, (b) intra-group transmission of personal data (whether relating to clients, employees or other individuals) where that is necessary for internal administrative purposes, and (c) processing that is necessary for the purposes of ensuring the security of network and information systems. 12. In paragraph 11— “intra-group transmission” means transmission between members of a group of undertakings or between members of a group of institutions affiliated to a central body; “security of network and information systems” has the same meaning as in the Network and Information Systems Regulations 2018 (S.I. 2018/506) (see regulation 1(3)(g)).

Article 7 · Conditions for consent

What it meansRelevance for businesses: medium

Where you rely on consent, you must be able to prove the person actually gave it, the request must be clearly separated from other text and written in plain language, and withdrawing consent must be as easy as giving it. Consent is not freely given if you make a service conditional on agreeing to data uses the service does not actually need. For AI features, this means no consent buried in general terms and no all-or-nothing gates.

Example: A gym chain adds an AI coach that analyses members' training habits to suggest classes. It asks for consent in a separate, plainly worded toggle at sign-up, logs the timestamp of each consent, and lets members switch the AI coach off from their profile with one tap, without cancelling their membership.

Official text

1. Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data. 2. If the data subject's consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding. 3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent. 4. When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.

Article 9 · Processing of special categories of personal data

What it meansRelevance for businesses: high

Data revealing racial or ethnic origin, political opinions, religion, trade union membership, genetics, biometrics used to identify someone, health, sex life or sexual orientation is banned from processing by default. You may only process it under a specific exception, most commonly explicit consent, employment law obligations, or substantial public interest with a basis in domestic law. AI systems can collect or infer this kind of data without you planning it, which is exactly when businesses get caught out.

Example: A recruitment agency in Birmingham uses an AI tool to screen CVs. A candidate mentions a health condition to explain a career gap. The moment that text is processed, Article 9 is engaged, so the agency configures the tool to filter such passages out of scoring, and only processes health details where employment law requires it, for instance to arrange reasonable adjustments.

Official text

1. Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited. 2. Paragraph 1 shall not apply if the processing is based on Article 6(1) and one of the following applies: (a) the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where domestic law provides that the prohibition referred to in paragraph 1 may not be lifted by the data subject; (b) processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law in so far as it is authorised by domestic law or a collective agreement pursuant to domestic law providing for appropriate safeguards for the fundamental rights and the interests of the data subject; (c) processing is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent; (d) processing is carried out in the course of its legitimate activities with appropriate safeguards by a foundation, association or any other not-for-profit body with a political, philosophical, religious or trade union aim and on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes and that the personal data are not disclosed outside that body without the consent of the data subjects; (e) processing relates to personal data which are manifestly made public by the data subject; (f) processing is necessary for the establishment, exercise or defence of legal claims or whenever courts or tribunals are acting in their judicial capacity; (g) processing is necessary for reasons of substantial public interest, on the basis of domestic law, or relevant international law, which shall be proportionate to the aim pursued ... and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject; (h) processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of domestic law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3; (i) processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of domestic law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy; (j) processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes , is carried out in accordance with Article 84B and is based on domestic law which shall be proportionate to the aim pursued ... and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject. 3. Paragraph 1 is only disapplied by point (h) of paragraph 2 if the personal data is processed by or under the responsibility of a professional subject to the obligation of professional secrecy under domestic law or rules established by national competent bodies or by another person also subject to an obligation of secrecy under domestic law or rules established by national competent bodies. 3A.. In paragraph 3, ‘national competent bodies’ means competent bodies of the United Kingdom or a part of the United Kingdom. 4. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5.. In the 2018 Act— (za) section 9A makes provision about when the requirement in paragraph 2(g) of this Article for a basis in relevant international law is met; (a) section 10 makes provision about when the requirement in paragraph 2(b), (g), (h), (i) or (j) of this Article for authorisation by, or a basis in, domestic law is met; (b) section 11(1) makes provision about when the processing of personal data is carried out in circumstances described in paragraph 3 of this Article.

Transparency and information

Article 12 · Transparent information, communication and modalities for the exercise of the rights of the data subject

What it meansRelevance for businesses: medium

Everything you tell people about their data, privacy notices and responses to their rights requests, must be concise, transparent, intelligible and in plain language, and normally free of charge. You must act on rights requests within the applicable time period, and if you refuse you must explain why and point the person to complaint routes, including complaining to your own organisation and to the Information Commissioner. You can charge or refuse only for manifestly unfounded or excessive requests, and the burden of proving that is on you.

Example: A lettings agency deploys a WhatsApp AI assistant for tenants. A tenant asks what data the bot keeps about them. The agency answers in plain English within the deadline, at no charge, rather than sending the tenant a lawyerly document, and its privacy page explains the assistant in language a non-technical tenant can follow.

Official text

1. The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication made under or by virtue of Articles 15 to 22D and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The information shall be provided in writing, or by other means, including, where appropriate, by electronic means. When requested by the data subject, the information may be provided orally, provided that the identity of the data subject is proven by other means. 2. The controller shall facilitate the exercise of data subject rights arising under or by virtue of Articles 15 to 22D. In the cases referred to in Article 11(2), the controller shall not refuse to act on the request of the data subject for exercising those rights, unless the controller demonstrates that it is not in a position to identify the data subject. 3. The controller shall provide information on action taken on a request made under or by virtue of Articles 15 to 22D to the data subject without undue delay and in any event before the end of the applicable time period (see Article 12A). ... Where the data subject makes the request by electronic form means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject. 4. If the controller does not take action on the request of the data subject, the controller shall inform the data subject without undue delay, and in any event before the end of the applicable time period (see Article 12A), of the reasons for not taking action and on the possibility of making a complaint to the controller under section 164A of the 2018 Act, making a complaint to the Commissioner under section 165 of that Act and seeking a judicial remedy. 5. Subject to Article 15(3), information provided under Articles 13 and 14 and any communication and any actions taken under or by virtue of Articles 15 to 22D and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may either: (a) charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or (b) refuse to act on the request. The controller shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request. 6. Without prejudice to Article 11, where the controller has reasonable doubts concerning the identity of the natural person making the request made under or by virtue of Articles 15 to 22D, the controller may — (a) request the provision of additional information necessary to confirm the identity of the data subject , and (b) delay dealing with the request until the identity is confirmed. 6A.. The Commissioner may publish (and amend or withdraw)— (a) standardised icons for use in combination with information provided to data subjects under Articles 13 and 14; (b) a notice stating that other persons may publish (and amend or withdraw) such icons, provided that the icons satisfy requirements specified in the notice as to the information to be presented by the icons and the procedures for providing the icons. 6B.. The Commissioner must not publish icons or a notice under paragraph 6A unless satisfied (as appropriate) that the icons give a meaningful overview of the intended processing in an easily visible, intelligible and clearly legible manner or that the notice will result in icons that do so. 7. If standardised icons are published as described in paragraph 6A (and not withdrawn), the information to be provided to data subjects pursuant to Articles 13 and 14 may be provided in combination with the icons. Where the icons are presented electronically they shall be machine-readable. 8. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Article 13 · Information to be provided where personal data are collected from the data subject

What it meansRelevance for businesses: high

When you collect personal data directly from a person, for instance through a chatbot or web form, you must tell them at that moment who you are, why you process the data and on what legal basis, who receives it, and whether it goes overseas. You must also state retention periods, their rights, and, critically for AI, the existence of automated decision-making subject to the Article 22C safeguards, with meaningful information about the logic and consequences. If you later reuse the data for a new purpose, you must tell them before you do.

Example: A car dealer's website assistant collects a visitor's name, budget and phone number to arrange a drive test. The chat window links to a short notice saying the dealer processes the details to handle the enquiry, that an AI vendor hosts the assistant, how long transcripts are kept, and that any automated finance pre-screening comes with an explanation and a route to a human review.

Official text

1. Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information: (a) the identity and the contact details of the controller and, where applicable, of the controller's representative; (b) the contact details of the data protection officer, where applicable; (c) the purposes of the processing for which the personal data are intended as well as the legal basis for the processing; (d) where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party; (e) the recipients or categories of recipients of the personal data, if any; (f) where applicable, the fact that the controller intends to transfer personal data to a third country or international organisation and the existence or absence of relevant regulations under Article 45A, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), the safeguards relied on and the means by which to obtain a copy of them or where they have been made available. 2. In addition to the information referred to in paragraph 1, the controller shall, at the time when personal data are obtained, provide the data subject with the following further information necessary to ensure fair and transparent processing: (a) the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period; (b) the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability; (c) where the processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal; (ca) the right to make a complaint to the controller under section 164A of the 2018 Act; (d) the right to make a complaint to the Commissioner under section 165 of the 2018 Act; (e) whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the data subject is obliged to provide the personal data and of the possible consequences of failure to provide such data; (f) the existence of automated decision-making, including profiling, which is subject to the requirement to provide safeguards under Article 22C and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. 3. Where the controller intends to further process the personal data for a purpose other than that for which the personal data were collected, the controller shall provide the data subject prior to that further processing with information on that other purpose and with any relevant further information as referred to in paragraph 2. 4. Paragraphs 1, 2 and 3 do not apply to the extent that the data subject already has the information. 5.. Paragraph 3 does not apply to the extent that— the controller intends to further process the personal data— (i) for (and only for) the purposes of scientific or historical research, the purposes of archiving in the public interest or statistical purposes, and (ii) in accordance with Article 84B, and (b) providing the information is impossible or would involve a disproportionate effort. 6. For the purposes of paragraph 5(b), whether providing the information would involve a disproportionate effort depends on, among other things, the number of data subjects, the age of the personal data and any appropriate safeguards applied to the processing. 7. A controller relying on paragraph 5 must take appropriate measures to protect the data subject’s rights, freedoms and legitimate interests, including by making the information available publicly.

Article 14 · Information to be provided where personal data have not been obtained from the data subject

What it meansRelevance for businesses: medium

If you obtain personal data about someone from a source other than the person, bought lists, public websites, data enrichment tools, you must still inform them: who you are, what categories of data you hold, the purpose and legal basis, and where the data came from. You normally have at most one month, or the first contact if sooner. Exceptions exist, for example where informing everyone is impossible or a disproportionate effort, but you then must protect people in other ways, such as publishing the information.

Example: A B2B services firm uses an AI prospecting tool that scrapes public directories to build a list of garage owners, then drafts outreach emails. The first email must tell each owner where their details came from and how to object, and the firm's website must carry the full notice, because silence about the data source is itself a breach.

Official text

1. Where personal data have not been obtained from the data subject, the controller shall provide the data subject with the following information: (a) the identity and the contact details of the controller and, where applicable, of the controller's representative; (b) the contact details of the data protection officer, where applicable; (c) the purposes of the processing for which the personal data are intended as well as the legal basis for the processing; (d) the categories of personal data concerned; (e) the recipients or categories of recipients of the personal data, if any; (f) where applicable, that the controller intends to transfer personal data to a recipient in a third country or international organisation and the existence or absence of relevant regulations under Article 45A, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), the safeguards relied on and the means to obtain a copy of them or where they have been made available. 2. In addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following information necessary to ensure fair and transparent processing in respect of the data subject: (a) the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period; (b) where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party; (c) the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject and to object to processing as well as the right to data portability; (d) where processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal; (da) the right to make a complaint to the controller (see section 164A of the 2018 Act); (e) the right to make a complaint to the Commissioner under section 165 of the 2018 Act; (f) from which source the personal data originate, and if applicable, whether it came from publicly accessible sources; (g) the existence of automated decision-making, including profiling, which is subject to the requirement to provide safeguards under Article 22C and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. 3. The controller shall provide the information referred to in paragraphs 1 and 2: (a) within a reasonable period after obtaining the personal data, but at the latest within one month, having regard to the specific circumstances in which the personal data are processed; (b) if the personal data are to be used for communication with the data subject, at the latest at the time of the first communication to that data subject; or (c) if a disclosure to another recipient is envisaged, at the latest when the personal data are first disclosed. 4. Where the controller intends to further process the personal data for a purpose other than that for which the personal data were obtained, the controller shall provide the data subject prior to that further processing with information on that other purpose and with any relevant further information as referred to in paragraph 2. 5. Paragraphs 1 to 4 do not apply to the extent that: (a) the data subject already has the information; (b) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . (c) obtaining or disclosure is expressly laid down by a provision of domestic law which provides appropriate measures to protect the data subject's legitimate interests; ... (d) ... the personal data must remain confidential subject to an obligation of professional secrecy regulated by domestic law, including a statutory obligation of secrecy. (e) providing the information is impossible or would involve a disproportionate effort, or (f) the obligation referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of the processing for which the personal data are intended. 6. For the purposes of paragraph 5(e), whether providing the information would involve a disproportionate effort depends on, among other things, the number of data subjects, the age of the personal data and any appropriate safeguards applied to the processing. 7. A controller relying on paragraph 5(e) or (f) must take appropriate measures to protect the data subject’s rights, freedoms and legitimate interests, including by making the information available publicly.

Rights of individuals

Article 15 · Right of access by the data subject

What it meansRelevance for businesses: high

Anyone can ask you to confirm whether you hold their personal data and get a copy, plus the purposes, recipients, retention period, their other rights, and meaningful information about any automated decision-making subject to the Article 22C safeguards. The UK text adds a practical limit: you only need to provide what a reasonable and proportionate search turns up. A first copy is free; electronic requests get electronic answers in a commonly used format.

Example: A customer of an online retailer sends a subject access request after chatting with the AI support assistant. The retailer must include the chat transcripts and any AI-generated profile notes attached to the customer's account, and if an automated system decides who gets credit terms, it must explain the logic in plain terms.

Official text

1. The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information: (a) the purposes of the processing; (b) the categories of personal data concerned; (c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations; (d) where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period; (e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; (ea) the right to make a complaint to the controller under section 164A of the 2018 Act; (f) the right to make a complaint to the Commissioner under section 165 of the 2018 Act; (g) where the personal data are not collected from the data subject, any available information as to their source; (h) the existence of automated decision-making, including profiling, which is subject to the requirement to provide safeguards under Article 22C and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. 1A. Under paragraph 1, the data subject is only entitled to such confirmation, personal data and other information as the controller is able to provide based on a reasonable and proportionate search for the personal data and other information described in that paragraph. 2. Where personal data are transferred to a third country or to an international organisation in reliance on Article 46, the data subject shall have the right to be informed of the safeguards provided in accordance with Article 46(1A)(a)(i) or (b)(i) for the purposes of the transfer. 3. The controller shall provide a copy of the personal data undergoing processing to which the data subject is entitled under paragraph 1. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form. 4. The right to obtain a copy referred to in paragraph 3 shall not adversely affect the rights and freedoms of others.

Article 16 · Right to rectification

What it meansRelevance for businesses: low

People have the right to have inaccurate personal data about them corrected without undue delay, and to have incomplete data completed. If an AI system stores or generates notes about a customer, wrong outputs that you keep become inaccurate personal data you must fix. Build a simple way to correct records that also updates whatever the AI reads from.

Example: A car dealer's AI assistant logged a customer as having rejected a part-exchange offer when the customer actually asked for time to think. The customer asks for a correction; the dealer must fix the CRM note promptly so future AI-drafted follow-ups stop working from the wrong fact.

Official text

The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

Article 17 · Right to erasure (‘right to be forgotten’)

What it meansRelevance for businesses: medium

People can require you to erase their personal data without undue delay in defined cases: the data is no longer needed, they withdraw consent, they object and you have no overriding grounds, the processing was unlawful, or the law requires deletion. The UK text adds a specific ground for data arising from allegations made by a malicious person, such as a convicted stalker. There are exceptions, for example legal claims and legal obligations. For AI, erasure must reach everywhere the data lives, including chat logs and copies held by your AI vendor.

Example: A former customer of an estate agency withdraws consent to marketing and asks for erasure. The agency deletes her from the CRM, and because its AI assistant vendor stores conversation history as a processor, it instructs the vendor to delete those transcripts too, relying on the deletion clause in the processing contract.

Official text

1. The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies: (a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; (b) the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing; (c) the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2); (d) the personal data have been unlawfully processed; (e) the personal data have to be erased for compliance with a legal obligation under domestic law; (f) the personal data have been collected in relation to the offer of information society services referred to in Article 8(1). (g) the personal data have been processed as a result of an allegation about the data subject— (i) which was made by a person who is a malicious person in relation to the data subject (whether they became such a person before or after the allegation was made), (ii) which has been investigated by the controller, and (iii) in relation to which the controller has decided that no further action is to be taken. 2. Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data. 3. Paragraphs 1 and 2 shall not apply to the extent that processing is necessary: (a) for exercising the right of freedom of expression and information; (b) for compliance with a legal obligation which requires processing under domestic law or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; (c) for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3); (d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 84B in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or (e) for the establishment, exercise or defence of legal claims. 4.. For the purposes of paragraph (1)(g), a person who has made an allegation about a data subject is a “malicious person” in relation to the data subject if the person— (a) has been convicted of an offence specified in column 1 of the table in paragraph 5 in relation to which the data subject is a person specified in the corresponding entry in column 2 of that table, or (b) is subject to a stalking protection order under section 2 of the Stalking Protection Act 2019 or section 8 of the Protection from Stalking Act (Northern Ireland) 2022 (c. 17 (N.I.)) made to protect the data subject from a risk associated with stalking (see section 2(1)(c) of the 2019 Act and section 8(2)(c) of the 2022 Act). 5.. The table is as follows—

Article 18 · Right to restriction of processing

What it meansRelevance for businesses: low

In certain situations a person can force you to pause processing rather than delete: while you verify contested accuracy, where processing is unlawful but they prefer restriction to erasure, where they need the data for legal claims, or while an objection is being weighed. During restriction you may basically only store the data, and you must tell the person before lifting the restriction. Practically, you need a way to freeze a record so automated and AI-driven processes skip it.

Example: A customer disputes the accuracy of notes an insurance broker's AI intake assistant recorded about their claims history. While the broker verifies, it flags the record as restricted so the AI renewal-pricing workflow and marketing automations exclude that customer until the dispute is resolved.

Official text

1. The data subject shall have the right to obtain from the controller restriction of processing where one of the following applies: (a) the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data; (b) the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead; (c) the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims; (d) the data subject has objected to processing pursuant to Article 21(1) pending the verification whether the legitimate grounds of the controller override those of the data subject. 2. Where processing has been restricted under paragraph 1, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest ... . 3. A data subject who has obtained restriction of processing pursuant to paragraph 1 shall be informed by the controller before the restriction of processing is lifted.

Article 21 · Right to object

What it meansRelevance for businesses: medium

People can object to processing based on public task, recognised legitimate interests or ordinary legitimate interests, including profiling, and you must stop unless you show compelling overriding grounds. For direct marketing the right is absolute: once someone objects, all marketing processing, including AI-driven profiling for marketing, must stop, no balancing test. You must point this right out clearly at the first communication, separately from other information.

Example: An online retailer uses AI to score customers for personalised offer emails. A customer clicks unsubscribe and objects to profiling. The retailer must not only stop the emails but also remove the customer from the AI scoring pipeline that feeds the marketing, because profiling related to direct marketing is covered by the absolute objection right.

Official text

1. The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) , (ea) or (f) of Article 6(1), including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims. 2. Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing. 3. Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes. 4. At the latest at the time of the first communication with the data subject, the right referred to in paragraphs 1 and 2 shall be explicitly brought to the attention of the data subject and shall be presented clearly and separately from any other information. 5. In the context of the use of information society services, ... the data subject may exercise his or her right to object by automated means using technical specifications , notwithstanding domestic law made before IP completion day implementing Directive 2002/58/EC of the European Parliament and of the Council of 12th July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector. 6. Where personal data are processed for scientific or historical research purposes or statistical purposes ..., the data subject, on grounds relating to his or her particular situation, shall have the right to object to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

Automated decision-making (Articles 22A-22D, DUAA 2025)

Article 22A · Automated processing and significant decisions

What it meansRelevance for businesses: highApplies from 5 February 2026

This article, inserted by the Data (Use and Access) Act 2025, defines the terms for the UK's new automated decision-making regime. A decision is based solely on automated processing when there is no meaningful human involvement, and it is a significant decision when it produces a legal effect or a similarly significant effect on the person. When judging whether human involvement is meaningful, you must consider how far the decision is reached by profiling, so a human who just rubber-stamps an AI score does not count.

Example: A car dealer runs AI finance pre-screening: the system scores each applicant and a staff member glances at the result before it is sent. Because the staff member never genuinely reviews the underlying case, there is no meaningful human involvement, so refusing finance is a significant decision based solely on automated processing and the 22B and 22C rules apply.

Official text

1. For the purposes of Articles 22B and 22C— (a) a decision is based solely on automated processing if there is no meaningful human involvement in the taking of the decision, and (b) a decision is a significant decision, in relation to a data subject, if— (i) it produces a legal effect for the data subject, or (ii) it has a similarly significant effect for the data subject. 2. When considering whether there is meaningful human involvement in the taking of a decision, a person must consider, among other things, the extent to which the decision is reached by means of profiling.

Article 22B · Restrictions on automated decision-making

What it meansRelevance for businesses: highApplies from 5 February 2026

This is where the UK now differs sharply from the EU default, which prohibits solely automated significant decisions unless an exception applies. Under the UK regime such decisions are generally permitted, subject to the Article 22C safeguards. Restrictions remain in two cases: if the decision involves special category data it needs explicit consent, or a contract or legal authorisation combined with substantial public interest; and a solely automated significant decision may not rest on the recognised legitimate interest basis in Article 6(1)(ea).

Example: A car dealer can let an AI system automatically pre-approve or decline finance pre-screening for buyers, something the EU default would prohibit without an exception, as long as the safeguards are in place and no health, biometric or other special category data feeds the decision. If an applicant's disclosed medical condition were used in the scoring, the dealer would need explicit consent or another Article 22B condition.

Official text

1. A significant decision based entirely or partly on processing described in Article 9(1) (processing of special categories of personal data) may not be taken based solely on automated processing, unless one of the following conditions is met. 2. The first condition is that the decision is based entirely on processing of personal data to which the data subject has given explicit consent. 3. The second condition is that— (a) the decision is— (i) necessary for entering into, or performing, a contract between the data subject and a controller, or (ii) required or authorised by law, and (b) point (g) of Article 9(2) applies. 4. A significant decision may not be taken based solely on automated processing if the processing of personal data carried out by, or on behalf of, the decision-maker for the purposes of the decision is carried out entirely or partly in reliance on Article 6(1)(ea).

Article 22C · Safeguards for automated decision-making

What it meansRelevance for businesses: highApplies from 5 February 2026

Whenever a significant decision about a person is based on their personal data and taken solely by automated processing, you must have safeguards in place. At minimum these must let the person know the decision was made, make representations about it, obtain human intervention from your organisation, and contest the decision. This is the price of the UK's permissive regime: automation is allowed, but the person must always have a route to a human.

Example: The car dealer's automated finance pre-screening declines an applicant. The dealer's process sends the applicant a notice that an automated check produced the outcome, invites them to submit additional context, and guarantees that a named member of staff will re-examine any contested case and can overturn the automated result.

Official text

1. Where a significant decision taken by or on behalf of a controller in relation to a data subject is— (a) based entirely or partly on personal data, and (b) based solely on automated processing, the controller must ensure that safeguards for the data subject’s rights, freedoms and legitimate interests are in place which comply with paragraph 2 and any regulations under Article 22D(3). 2. The safeguards must consist of or include measures which— (a) provide the data subject with information about decisions described in paragraph 1 taken in relation to the data subject; (b) enable the data subject to make representations about such decisions; (c) enable the data subject to obtain human intervention on the part of the controller in relation to such decisions; (d) enable the data subject to contest such decisions.

Article 22D · Further provision about automated decision-making

What it meansRelevance for businesses: highApplies from 5 February 2026

This article gives the Secretary of State power to fine-tune the automated decision-making regime by regulations: defining when human involvement counts as meaningful, which kinds of decisions have a similarly significant effect, and adding to or tightening the required safeguards. Regulations cannot amend Article 22C itself and need affirmative parliamentary approval. For a business the practical point is that the goalposts can move, so whoever owns your AI decision workflows should watch for these regulations.

Example: A recruitment agency builds fully automated AI shortlisting and treats a quick recruiter glance as human involvement. If regulations later specify that such review is not meaningful human involvement, the agency's shortlisting instantly falls under the solely automated rules, so it designs its safeguards, notice, representations, human review, contest route, from day one rather than waiting.

Official text

1. The Secretary of State may by regulations provide that, for the purposes of Article 22A(1)(a), there is, or is not, to be taken to be meaningful human involvement in the taking of a decision in cases described in the regulations. 2. The Secretary of State may by regulations provide that, for the purposes of Article 22A(1)(b)(ii), a description of decision is, or is not, to be taken to have a similarly significant effect for the data subject. 3. The Secretary of State may by regulations make the following types of provision about the safeguards required under Article 22C(1)— (a) provision requiring the safeguards to include measures in addition to those described in Article 22C(2), (b) provision imposing requirements which supplement what Article 22C(2) requires the safeguards to consist of or include (including, for example, provision about how and when things described in Article 22C(2) must be done or be capable of being done), and (c) provision about measures which are not to be taken to satisfy one or more of points (a) to (d) of Article 22C(2). 4. Regulations under paragraph 3 may not amend Article 22C. 5. Regulations under this Article are subject to the affirmative resolution procedure.

Technical and organisational duties

Article 25 · Data protection by design and by default

What it meansRelevance for businesses: medium

Data protection must be designed into your systems from the start and applied by default, not bolted on later. You must use measures such as pseudonymisation and data minimisation appropriate to the risk, and by default process only the data each purpose actually needs. The UK text adds that online services likely to be accessed by children must take account of children's higher protection needs. When you commission or configure an AI tool, this article is your build checklist.

Example: Before launching a customer service AI assistant, an online retailer configures it so the model receives order numbers and first names but not full addresses or payment details, sets transcripts to auto-delete after 90 days, and turns off any vendor option that would use its customers' chats for the vendor's own purposes, all before the first customer ever types a message.

Official text

1. Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects. 1A. In the case of processing carried out in the course of providing information society services which are likely to be accessed by children, when assessing what are appropriate technical and organisational measures in accordance with paragraph 1, the controller must take into account the children’s higher protection matters. 1B. The children’s higher protection matters are— (a) how children can best be protected and supported when using the services, and (b) the fact that children— (i) merit specific protection with regard to their personal data because they may be less aware of the risks and consequences associated with processing of personal data and of their rights in relation to such processing, and (ii) have different needs at different ages and at different stages of development. 2. The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons. 3. An approved certification mechanism pursuant to Article 42 may be used as a means of demonstrating compliance with the requirements set out in paragraphs 1 to 2 of this Article. 4. Paragraphs 1A and 1B are not to be read as implying anything about the matters that may be relevant to the assessment of what are appropriate technical and organisational measures for the purposes of paragraph 1 in cases other than those described in paragraph 1A. 5. In this Article, “information society services” does not include preventive or counselling services.

Article 28 · Processor

What it meansRelevance for businesses: high

When another company processes personal data on your behalf, and an AI vendor hosting your assistant is exactly that, you may only use one offering sufficient guarantees, and you must have a written contract covering the mandatory points: the processor acts only on your documented instructions, keeps data confidential, secures it, needs your authorisation for sub-processors, helps you with rights requests and breaches, deletes or returns the data at the end, and submits to audits. A vendor that starts using your data for its own purposes becomes a controller and takes on controller liability.

Example: A car dealer signs up to a hosted AI WhatsApp assistant. Before going live it puts a data processing agreement in place with the provider covering instructions, confidentiality, security, sub-processors and deletion, and checks the settings so customer conversations are not used to train the provider's models for other clients, since that would exceed the dealer's instructions.

Official text

1. Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject. 2. The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes. 3. Processing by a processor shall be governed by a contract or other legal act under domestic law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor: (a) processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by domestic law; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest; (b) ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; (c) takes all measures required pursuant to Article 32; (d) respects the conditions referred to in paragraphs 2 and 4 for engaging another processor; (e) taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III; (f) assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor; (g) at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless domestic law requires storage of the personal data; (h) makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller. With regard to point (h) of the first subparagraph, the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other domestic law relating to data protection. 4. Where a processor engages another processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor as referred to in paragraph 3 shall be imposed on that other processor by way of a contract or other legal act under domestic law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of this Regulation. Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor's obligations. 5. Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as a means of demonstrating sufficient guarantees as referred to in paragraphs 1 and 4 of this Article. 6. Without prejudice to an individual contract between the controller and the processor, the contract or the other legal act referred to in paragraphs 3 and 4 of this Article may be based, in whole or in part, on standard contractual clauses referred to in paragraph 8 of this Article, including when they are part of a certification granted to the controller or processor pursuant to Articles 42 and 43. 7. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8. The Commissioner may adopt standard contractual clauses for the matters referred to in paragraph 3 and 4 of this Article ... . 9. The contract or the other legal act referred to in paragraphs 3 and 4 shall be in writing, including in electronic form. 10. Without prejudice to Articles 82, 83 and 84, if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing.

Article 30 · Records of processing activities

What it meansRelevance for businesses: medium

Controllers and processors must keep a written record of their processing activities: purposes, categories of people and data, recipients, any overseas transfers, retention periods and security measures. Organisations under 250 staff are exempt, but not where the processing is more than occasional, carries risk, or involves special category or criminal offence data, and routine AI processing of customer data is not occasional. Keeping this record is also the fastest way to know exactly what data your AI tools touch.

Example: A 12-person accountancy firm adds an AI assistant that reads client emails to draft replies. Because this runs continuously, the small-business exemption does not apply, so the firm adds a row to its processing record: purpose (drafting replies), data (client contact details and email content), recipient (the AI hosting provider), retention (30 days), and the security measures agreed with the provider.

Official text

1. Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information: (a) the name and contact details of the controller and, where applicable, the joint controller, the controller's representative and the data protection officer; (b) the purposes of the processing; (c) a description of the categories of data subjects and of the categories of personal data; (d) the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations; (e) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards; (f) where possible, the envisaged time limits for erasure of the different categories of data; (g) where possible, a general description of the technical and organisational security measures referred to in Article 32(1) or, as appropriate, the security measures referred to in section 28(3) of the 2018 Act. 2. Each processor and, where applicable, the processor's representative shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing: (a) the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller's or the processor's representative, and the data protection officer; (b) the categories of processing carried out on behalf of each controller; (c) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards; (d) where possible, a general description of the technical and organisational security measures referred to in Article 32(1) or, as appropriate, the security measures referred to in section 28(3) of the 2018 Act. 3. The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form. 4. The controller or the processor and, where applicable, the controller's or the processor's representative, shall make the record available to the Commissioner on request. 5. The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.

Article 32 · Security of processing

What it meansRelevance for businesses: high

You and your processors must apply security measures appropriate to the risk, including pseudonymisation and encryption where suitable, resilience of systems, the ability to restore data after an incident, and regular testing of your measures. Anyone acting under your authority may only process data on your instructions. For AI deployments this covers both your side (access controls, what staff paste into AI tools) and the vendor's side (encryption in transit and at rest).

Example: A garage chain rolls out an AI booking assistant. It restricts which staff can export chat data, ensures the vendor encrypts conversations in transit and at rest, sets an internal rule that mechanics never paste customers' card details into any AI chat window, and tests the recovery process for the booking data twice a year.

Official text

1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: (a) the pseudonymisation and encryption of personal data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing. 2. In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed. 3. Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as a means of demonstrating compliance with the requirements set out in paragraph 1 of this Article. 4. The controller and processor shall take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data does not process them except on instructions from the controller, unless he or she is required to do so by domestic law.

Article 35 · Data protection impact assessment

What it meansRelevance for businesses: high

Before starting any processing likely to result in a high risk to people, especially using new technologies, you must carry out a data protection impact assessment: describe the processing, assess necessity and proportionality, identify the risks and set out the measures to address them. It is expressly required for systematic and extensive automated evaluation of people, including profiling, that feeds significant decisions. Deploying AI that scores, profiles or decides about customers or candidates is the textbook trigger.

Example: Before switching on AI finance pre-screening, a car dealer writes a short DPIA: what data the system uses, why automated scoring is proportionate for low-value pre-checks, the risk of biased or wrong declines, and the mitigations, human review on request, periodic accuracy checks, and clear notices. The document is reviewed whenever the model or the data changes.

Official text

1. Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks. 2. The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment. 3. A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of: (a) a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person; (b) processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or (c) a systematic monitoring of a publicly accessible area on a large scale. 4. The Commissioner shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. ... 5. The Commissioner may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. ... 6. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7. The assessment shall contain at least: (a) a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller; (b) an assessment of the necessity and proportionality of the processing operations in relation to the purposes; (c) an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and (d) the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned. 8. Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment. 9. Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations. 10. In the case of processing pursuant to point (c) or (e) of Article 6(1), paragraphs 1 to 7 of this Article do not apply if a data protection impact assessment has already been carried out for the processing as part of a general impact assessment required by domestic law, unless domestic law provides otherwise. 11. Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.

International transfers

Article 44A · General principles for transfers

What it meansRelevance for businesses: high

You may transfer personal data outside the UK only if one of three conditions is met: the transfer is approved by regulations under Article 45A, it is covered by appropriate safeguards such as approved contract clauses under Article 46, or a specific derogation applies under Article 49. If your AI provider stores or processes data on servers overseas, sending customer data to that provider is a transfer and needs one of these routes. This replaces the old adequacy-decision framework with a regulations-based UK system.

Example: A car dealer's AI assistant is hosted by a provider whose servers sit outside the UK. Before launch the dealer checks which route covers the transfer: either the destination country is approved by UK regulations, or the processing contract includes recognised safeguard clauses. Without one of these, every customer chat sent to those servers is an unlawful transfer.

Official text

1. A controller or processor may transfer personal data to a third country or an international organisation only if— (a) the condition in paragraph 2 is met, and (b) the transfer is carried out in compliance with the other provisions of this Regulation. 2. The condition is met if the transfer— (a) is approved by regulations under Article 45A that are in force at the time of the transfer, (b) is made subject to appropriate safeguards (see Article 46), or (c) is made in reliance on a derogation for specific situations (see Article 49). 3. A transfer may not be made in reliance on paragraph 2(b) or (c) if, or to the extent that, it would breach a restriction in regulations under Article 49A.

Article 45A · Transfers approved by regulations

What it meansRelevance for businesses: medium

The Secretary of State can approve transfers to a third country or international organisation by regulations, the UK's replacement for EU-style adequacy decisions, and may only do so if the data protection test in Article 45B is met. Approvals can be granular: limited to a sector, a region, particular kinds of recipients or particular types of transfer, and the government may consider the desirability of facilitating data flows. For businesses, this is the easiest transfer route: if your AI provider's country is covered by such regulations, no extra transfer paperwork is needed for what the regulations approve.

Example: An online retailer wants an AI analytics provider based abroad. Its adviser first checks whether transfers to that country are approved by UK regulations under this article. If they are, the retailer can send customer data within the scope of the approval without standard contractual clauses; if not, it falls back to Article 46 safeguards.

Official text

1. For the purposes of Article 44A, the Secretary of State may by regulations approve transfers of personal data to— (a) a third country, or (b) an international organisation. 2. The Secretary of State may only make regulations under this Article approving transfers to a third country or international organisation if the Secretary of State considers that the data protection test is met in relation to the transfers (see Article 45B). 3. In making regulations under this Article, the Secretary of State may have regard to any matter which the Secretary of State considers relevant, including the desirability of facilitating transfers of personal data to and from the United Kingdom. 4. Regulations under this Article may, among other things— (a) make provision in relation to a third country or international organisation specified in the regulations or a description of country or organisation; (b) approve all transfers of personal data to a third country or international organisation or only transfers specified or described in the regulations; (c) identify a transfer of personal data by any means, including by reference to— (i) a sector or geographic area within a third country, (ii) the controller or processor, (iii) the recipient of the personal data, (iv) the personal data transferred, (v) the means by which the transfer is made, or (vi) relevant legislation, schemes, lists or other arrangements or documents, as they have effect from time to time; (d) confer a discretion on a person. 5. Regulations under this Article are subject to the negative resolution procedure.

Article 45B · The data protection test

What it meansRelevance for businesses: medium

This sets the test the Secretary of State applies before approving a destination under Article 45A: the protection for individuals there must not be materially lower than the standard under the UK regime, judged as a whole. Relevant factors include the rule of law and human rights, whether there is an enforcement authority, redress for individuals, onward transfer rules and international commitments. The deliberately flexible 'not materially lower' wording is looser than the EU's essentially equivalent standard, which is why the UK can approve destinations the EU has not.

Example: A recruitment agency considers an AI screening vendor in a country recently approved by UK regulations. Understanding that approval reflects this whole-system test, the agency can rely on it for candidate data flowing to that country, but it still keeps its processor contract tight, because the approval covers the country's regime, not the vendor's individual behaviour.

Official text

1. For the purposes of Article 45A, the data protection test is met in relation to transfers of personal data to a third country or international organisation if the standard of the protection provided for data subjects with regard to general processing of personal data in the country or by the organisation is not materially lower than the standard of the protection provided for data subjects by or under— (a) this Regulation, (b) Part 2 of the 2018 Act, and (c) Parts 5 to 7 of that Act, so far as relevant to general processing. 2. In considering whether the data protection test is met in relation to transfers of personal data to a third country or international organisation, the Secretary of State must consider, among other things— (a) respect for the rule of law and for human rights in the country or by the organisation, (b) the existence, and powers, of an authority responsible for enforcing the protection of data subjects with regard to the processing of personal data in the country or by the organisation, (c) arrangements for judicial or non-judicial redress for data subjects in connection with such processing, (d) rules about the transfer of personal data from the country or by the organisation to other countries or international organisations, (e) relevant international obligations of the country or organisation, and (f) the constitution, traditions and culture of the country or organisation. 3. In paragraphs 1 and 2— (a) the references to the protection provided for data subjects are to that protection taken as a whole, (b) the references to general processing are to processing to which this Regulation applies or equivalent types of processing in the third country or by the international organisation (as appropriate), and (c) the references to processing of personal data in the third country or by the international organisation are references only to the processing of personal data transferred to the country or organisation by means of processing to which this Regulation applies as described in Article 3. 4. When the data protection test is applied only to certain transfers to a third country or international organisation that are specified or described, or to be specified or described, in regulations (in accordance with Article 45A(4)(b))— (a) the references in paragraphs 1 to 3 to personal data are to be read as references only to personal data likely to be the subject of such transfers, and (b) the reference in paragraph 2(d) to transfer to other countries or international organisations is to be read as including transfer within the third country or international organisation.

Enforcement and penalties

Article 83 · General conditions for imposing administrative fines

What it meansRelevance for businesses: high

The Information Commissioner can impose fines that must be effective, proportionate and dissuasive, weighed against factors like the nature and duration of the breach, intent or negligence, mitigation, cooperation and past record. There are two tiers: up to £8,700,000 or 2 percent of total worldwide annual turnover for breaches of duties such as security, records and impact assessments, and up to £17,500,000 or 4 percent, whichever is higher, for breaches of the core principles, individuals' rights, the automated decision-making rules in Articles 22B and 22C, and international transfer rules. Note that AI-specific failures sit squarely in the top tier.

Example: A car dealer runs automated finance pre-screening with no notice, no human review route and no way to contest outcomes, and its overseas AI vendor has no transfer safeguards. Both failures, Articles 22B to 22C and the transfer rules, fall in the top band of up to £17.5 million or 4 percent of worldwide turnover, so a 20-minute compliance setup is protecting the business against its most expensive category of fine.

Official text

1. The Commissioner shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive. 2. Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following: (a) the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them; (b) the intentional or negligent character of the infringement; (c) any action taken by the controller or processor to mitigate the damage suffered by data subjects; (d) the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32; (e) any relevant previous infringements by the controller or processor; (f) the degree of cooperation with the Commissioner, in order to remedy the infringement and mitigate the possible adverse effects of the infringement; (g) the categories of personal data affected by the infringement; (h) the manner in which the infringement became known to the Commissioner, in particular whether, and if so to what extent, the controller or processor notified the infringement; (i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures; (j) adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and (k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement. 3. If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement. 4. Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to £8,700,000, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher: (a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43; (b) the obligations of the certification body pursuant to Articles 42 and 43; (c) the obligations of the monitoring body pursuant to Article 41(4). 5. Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to £17,500,000, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher: (a) the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9; (b) the data subjects' rights pursuant to Articles 12 to 21; (ba) Article 22B or 22C (restrictions on, and safeguards for, automated decision-making); (c) the transfers of personal data to a recipient in a third country or an international organisation pursuant to Articles 44A to 49; (d) any obligations under Part 5 or 6 of Schedule 2 to the 2018 Act or regulations made under section 16(1)(c) of the 2018 Act; (e) non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the Commissioner pursuant to Article 58(2) or failure to provide access in violation of Article 58(1). 6. Non-compliance with an order by the Commissioner as referred to in Article 58(2) shall, in accordance with paragraph 2 of this Article, be subject to administrative fines up to £17,500,000, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher. 7. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10.. In the 2018 Act, section 115(9) makes provision about the exercise of the Commissioner's functions under this Article.

Annexes