Compliance

Voice AI automated decisions: UK GDPR Articles 22A to 22D

Dilr Voice is enterprise voice AI built for the UK GDPR automated decision rules. The Data (Use and Access) Act 2025 repealed Article 22 and, from 5 February 2026, replaced it with Articles 22A to 22D. This guide explains when a voice agent decision is solely automated, which decisions Article 22B restricts, and the four Article 22C safeguards.

DILR.AI ENGINEERING / UK GDPR SECTION 4A Voice AI and solely automated decisions The Data (Use and Access) Act 2025 replaced Article 22 22A No meaningful human involvement 22B Restrictions on ADM 22C Four safeguards for the person 22D Secretary of State powers

Roughly 88% of enterprises now use AI somewhere, yet only about 6% are what McKinsey calls AI-mature in its State of AI report (November 2025). The gap is rarely a modelling problem. It is a governance problem, and nowhere is that clearer than in the decisions an AI system makes about a person without a human in the loop. A voice agent that scores a caller, blocks a transaction, refuses a booking or routes someone to a lower-priority queue is making an automated decision, and UK law changed how those decisions are governed on 5 February 2026.

On that date the Data (Use and Access) Act 2025 finished replacing UK GDPR Article 22 with a new Chapter 3 Section 4A: Articles 22A, 22B, 22C and 22D. If your compliance position still rests on the old Article 22 prohibition, it is describing a regime that no longer exists. The new rules are more permissive for ordinary automated decisions and, at the same time, harder-edged where it counts, with the safeguards now a positive duty backed by the highest tier of fine.

This guide is the practitioner version. It sets out what a solely automated decision now means, which decisions Article 22B still restricts, the four safeguards Article 22C makes mandatory, and how a voice deployment stays inside the line without pretending the risk away.

This guide is shipped by the team behind Dilr Voice, enterprise voice AI built for regulated deployments. Or see DATS, our five-stage AI consulting system.

What did the DUAA change about automated decisions under UK GDPR?

The Data (Use and Access) Act 2025 repealed UK GDPR Article 22 and replaced it with Articles 22A to 22D, in force from 5 February 2026. The old blanket prohibition on solely automated significant decisions is gone. In its place, such decisions are permitted provided the controller builds statutory safeguards, except where special-category data or recognised legitimate interests are involved, where restrictions still apply.

That is a genuine reframe, not a tidy-up. The change was made by section 80 of the Data (Use and Access) Act 2025, commenced by SI 2026/82, which inserted the new Section 4A into the retained UK GDPR. Where the pre-DUAA position started from a right not to be subjected to automated decisions, the new starting point is that they are allowed with guardrails. For anyone building a voice AI agent that decides anything about a caller, the compliance question shifts from "are we allowed to do this at all?" to "have we built the safeguards, and does a restriction bite?".

The screening logic below is how our engineers walk a proposed voice use case through the new regime before it ships. It is the same discipline that sits underneath our AI execution office.

Screening a voice AI decision against UK GDPR Section 4A
01Significant decision?Legal or similarly significant effect on the person (Art 22A…02Solely automated?No meaningful human involvement in the decision (Art 22A(1)(…03Special-category data?Art 22B(1): barred unless explicit consent or an Art 9(2)(g)…04Relies on Art 6(1)(ea)?Art 22B(4): absolute bar, no exception route05Otherwise permittedBut only with the four Article 22C safeguards in place
Each gate is a question a controller must answer before a solely automated significant decision can proceed.

What does "no meaningful human involvement" mean under Article 22A?

Article 22A(1)(a) defines a decision as based solely on automated processing where there is no meaningful human involvement in the taking of the decision. The test is not whether a human exists somewhere in the system. It is whether a person meaningfully shapes the specific outcome for the specific individual. A human who rubber-stamps whatever the model outputs, without the authority or information to change it, does not make the decision non-automated.

"a decision is based solely on automated processing if there is no meaningful human involvement in the taking of the decision" Article 22A(1)(a), UK GDPR, inserted by the Data (Use and Access) Act 2025.

The statute also ties this to profiling. Article 22A(2) states that when considering whether there is meaningful human involvement, a person must consider, among other things, the extent to which the decision is reached by means of profiling. The more the outcome is driven by an automated profile of the caller, the harder it is to claim a human genuinely intervened. In its draft guidance out for consultation until 29 May 2026, the Information Commissioner's Office signalled that a reviewer must be able to change the outcome before it takes effect, and must do so each time, for the involvement to count. That guidance is not yet final, so treat the direction of travel as strong but the detail as provisional. This is the single biggest trap for voice teams: a "human review" screen that nobody has time to use is still a solely automated decision in law.

What makes a voice AI decision a "significant decision"?

Under Article 22A(1)(b), a decision is significant where it produces a legal effect for the person or has a similarly significant effect. A legal effect changes someone's rights or legal status. A similarly significant effect reaches decisions with a comparable weight on a person's circumstances: refusing credit, cancelling a service, blocking a payment, or denying access to a benefit. Only decisions of that weight engage the Section 4A safeguards regime at all.

Most of what a well-designed voice agent does never reaches that bar. Reading out an account balance, booking a routine appointment, or answering an FAQ has no significant effect. The line matters because it is where the compliance load actually falls. A Dilr Voice deployment that triages an inbound call and hands anything consequential to a human has, by design, kept its automated decisions below the significance threshold. Where an outbound programme uses a model to decide who is eligible for an offer, or a fraud model to freeze an account mid-call, you are squarely inside the regime and the Article 22C safeguards become mandatory. The discipline of drawing that line deliberately, rather than discovering it in an audit, is core to our approach to any enterprise deployment.

Which automated decisions does Article 22B still restrict?

Article 22B keeps hard restrictions in two situations, and they are not the same kind of gate. A solely automated significant decision that uses special-category data under Article 9(1), such as health or biometric data, may not be taken unless a condition is met: the person's explicit consent, or a contract or legal basis with an Article 9(2)(g) condition. Separately, Article 22B(4) sets an absolute bar where the decision relies on recognised legitimate interests.

The special-category gate in Article 22B(1) is conditional. There is a route through it if you can land explicit consent or the contract or legal grounds, which is why capturing and evidencing that basis matters so much on a live call. The Article 22B(4) bar is different. It reads that a significant decision may not be taken based solely on automated processing where the processing relies, entirely or partly, on Article 6(1)(ea), the recognised legitimate interests lawful basis the DUAA introduced. There is no unless-clause. If your voice agent leans on recognised legitimate interests to justify the processing behind an automated significant decision, that decision cannot be solely automated at all. A human with real authority must make it. Vendors that market fully autonomous decisioning, from platforms like Vapi, Retell AI, Bland AI, Synthflow or PolyAI, do not change this: the duty sits with you as controller, whoever supplies the model.

The same screening logic runs through our AI execution office, where governance is treated as a build requirement rather than a document written after launch.

What are the four Article 22C safeguards you must build?

Where a significant decision is based solely on automated processing, Article 22C requires the controller to ensure that safeguards for the data subject's rights, freedoms and legitimate interests are in place. The statute sets four measures: information about the decision, a route to make representations, a route to obtain human intervention, and a route to contest the decision. These are not optional design niceties. They are the price of taking the decision automatically at all.

The four safeguards map cleanly onto how a voice deployment should be instrumented, and each one is a concrete build task rather than a policy line.

The four Article 22C safeguards for a solely automated decision
01InformTell the person about …02RepresentLet them make represen…03Human reviewHuman intervention by …04ContestLet them contest the d…
Article 22C(2) requires all four measures for a significant decision taken by solely automated means.

In practice, the third safeguard is the one voice teams underbuild. Article 22C(2)(c) requires a route to obtain human intervention on the part of the controller, which means a real person with authority, reachable in a realistic timeframe, not a callback queue that never clears. On a voice channel that usually means the agent must be able to escalate to a named human path, log the decision and its reasons, and surface the contest route in language the caller can act on. Our DATS methodology treats these four as acceptance criteria before a decisioning use case goes live, in the same way we treat latency or accuracy. It is also why Dilr Voice keeps a full, exportable decision log rather than a transcript alone.

How large is the fine for breaching Article 22B or 22C?

Breaching Article 22B or 22C sits in the upper fine tier. The DUAA amended UK GDPR Article 83(5) to add a new point (ba) covering "Article 22B or 22C (restrictions on, and safeguards for, automated decision-making)", which carries administrative fines of up to 17.5 million pounds or 4% of total worldwide annual turnover, whichever is higher. That is the same maximum tier as breaching the core data-protection principles, not the lower 8.7 million pound band.

Note the precision here, because it is easy to overstate. Article 22A is definitional and Article 22D is a regulation-making power for the Secretary of State, so neither carries a standalone penalty. The enforceable duties are the restrictions in Article 22B and the safeguards in Article 22C, and those are what the upper tier attaches to. The Information Commissioner's Office enforces this in the UK, and its recruitment-focused messaging in 2026 made clear that automated decisions can be efficient only where the safeguards are genuinely in place. For a large enterprise, a 4% turnover exposure on a governance gap is a board-level number, which is why decisioning governance belongs in the AI operating model from day one, not in a remediation project after an ICO query lands.

Is the old Article 22 still the law?

No. The original UK GDPR Article 22 was repealed by the Data (Use and Access) Act 2025 and no longer applies from 5 February 2026. Guidance, contracts or internal policies that still quote the old Article 22 right, or its three-limbed exemptions, are describing a superseded regime. The substance carries over in a reshaped form through Articles 22A to 22D, but the statutory hooks, the defined terms and the enforcement references have all moved.

For reference, the pre-DUAA Article 22 position, which our earlier guide to the repealed Article 22 regime describes in full, opened from a prohibition:

"The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her." Article 22(1), UK GDPR, repealed by the Data (Use and Access) Act 2025.

The most important practical consequence is that any control mapping written before 2026 needs re-checking against the new numbering. The right not to be subject to purely automated decisions has not vanished, but it now lives inside a permission-plus-safeguards structure rather than a prohibition-plus-exemptions one. Read alongside the EU AI Act for any programme touching the EU, the transparency and human-oversight expectations point the same way even though the instruments differ.

What is the best way to govern voice AI automated decisions in 2026?

The best approach in 2026 is to govern by decision, not by system. That means cataloguing every point where the voice agent could produce a significant effect, deciding deliberately which stay human, and building the four Article 22C safeguards only where a solely automated significant decision genuinely remains. It is more work than a blanket policy, and for a small, low-risk deployment a simpler rule of keeping every consequential decision human may serve you better.

There is no single best vendor here, because the obligation is yours as controller regardless of the stack. A team that already runs Dilr Voice with human-in-the-loop escalation and full decision logging is closer to compliant than a team on a faster, cheaper autonomous platform that treats governance as an afterthought. Where a competitor wins is speed to a first prototype: tools like Synthflow or Bland AI will stand up a demo quickly, and if your use case never crosses the significance threshold, that may be all you need. The moment a real automated significant decision enters scope, the calculus flips to auditability, and that is the ground our AI execution office is built for. Integrations with your existing stack, whether Twilio for telephony or Salesforce and HubSpot for the record of the decision, should be designed so the safeguards travel with the data rather than bolting on later.

Does routing a caller to a department trigger the ADM rules?

Usually no. Routing a caller to the right department or queue rarely produces a legal or similarly significant effect, so it falls outside the Article 22A significance threshold. It only starts to engage the rules where the routing itself determines something consequential, for example steering a vulnerable caller away from a remedy, or where the routing is really an eligibility decision in disguise. When in doubt, our team assesses each decision point on its actual effect, not on its label.

Who is responsible if the voice AI vendor makes the decision?

The controller is responsible, not the platform vendor. Under Section 4A the duty to avoid a prohibited automated decision and to build the Article 22C safeguards falls on the controller, almost always the enterprise deploying the agent rather than the voice AI supplier acting as processor. A vendor cannot absorb this liability. This is why a controller and sub-processor mapping matters before launch, and why a named data protection officer should own the decision catalogue.

Want to see this in production? Try Dilr Voice live, book an AI placement diagnostic, see our DATS methodology, or read about our approach to placing AI inside regulated systems.

Service
AI Placement Diagnostic
Service
AI Operating Model
Guide
Recognised Legitimate Interests
Talk to the operators

Automate the decision, keep the safeguard.

30-min scoping call · No deck · Confidential. We will map your voice AI decisions against UK GDPR Section 4A and tell you which ones need a human.

Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. This article is general information, not legal advice; verify any statutory position against the current text on legislation.gov.uk. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.

voice AI automated decision making Article 22AUK GDPR automated decision making DUAAsolely automated decision voice AIArticle 22C safeguards voice AIvoice AI compliance redditbest voice AI compliance 2026Dilr Voice

Questions this article answers

What did the DUAA change about automated decisions under UK GDPR?

The Data (Use and Access) Act 2025 repealed UK GDPR Article 22 and replaced it with Articles 22A to 22D, in force from 5 February 2026. The old blanket prohibition on solely automated significant decisions is gone. In its place, such decisions are permitted provided the controller builds statutory safeguards, except where special-category data or recognised legitimate interests are involved, where restrictions still apply.

What does "no meaningful human involvement" mean under Article 22A?

Article 22A(1)(a) defines a decision as based solely on automated processing where there is no meaningful human involvement in the taking of the decision. The test is not whether a human exists somewhere in the system. It is whether a person meaningfully shapes the specific outcome for the specific individual. A human who rubber-stamps whatever the model outputs, without the authority or information to change it, does not make the decision non-automated.

What makes a voice AI decision a "significant decision"?

Under Article 22A(1)(b), a decision is significant where it produces a legal effect for the person or has a similarly significant effect. A legal effect changes someone's rights or legal status. A similarly significant effect reaches decisions with a comparable weight on a person's circumstances: refusing credit, cancelling a service, blocking a payment, or denying access to a benefit. Only decisions of that weight engage the Section 4A safeguards regime at all.

Which automated decisions does Article 22B still restrict?

Article 22B keeps hard restrictions in two situations, and they are not the same kind of gate. A solely automated significant decision that uses special-category data under Article 9(1), such as health or biometric data, may not be taken unless a condition is met: the person's explicit consent, or a contract or legal basis with an Article 9(2)(g) condition. Separately, Article 22B(4) sets an absolute bar where the decision relies on recognised legitimate interests.

What are the four Article 22C safeguards you must build?

Where a significant decision is based solely on automated processing, Article 22C requires the controller to ensure that safeguards for the data subject's rights, freedoms and legitimate interests are in place. The statute sets four measures: information about the decision, a route to make representations, a route to obtain human intervention, and a route to contest the decision. These are not optional design niceties. They are the price of taking the decision automatically at all.

How large is the fine for breaching Article 22B or 22C?

Breaching Article 22B or 22C sits in the upper fine tier. The DUAA amended UK GDPR Article 83(5) to add a new point (ba) covering "Article 22B or 22C (restrictions on, and safeguards for, automated decision-making)", which carries administrative fines of up to 17.5 million pounds or 4% of total worldwide annual turnover, whichever is higher. That is the same maximum tier as breaching the core data-protection principles, not the lower 8.7 million pound band.

Is the old Article 22 still the law?

No. The original UK GDPR Article 22 was repealed by the Data (Use and Access) Act 2025 and no longer applies from 5 February 2026. Guidance, contracts or internal policies that still quote the old Article 22 right, or its three-limbed exemptions, are describing a superseded regime. The substance carries over in a reshaped form through Articles 22A to 22D, but the statutory hooks, the defined terms and the enforcement references have all moved.

What is the best way to govern voice AI automated decisions in 2026?

The best approach in 2026 is to govern by decision, not by system. That means cataloguing every point where the voice agent could produce a significant effect, deciding deliberately which stay human, and building the four Article 22C safeguards only where a solely automated significant decision genuinely remains. It is more work than a blanket policy, and for a small, low-risk deployment a simpler rule of keeping every consequential decision human may serve you better.

Compliance

Deploy voice AI without failing an audit

Dilr Voice ships per-country TCPA and GDPR rules, and the UK AI compliance changelog tracks ICO, FCA, and EU AI Act changes as they land.

Related articles

← Previous
AI voice for funeral services: the first-call guide

One email, once a month. No hype. Just what we learned shipping.