Insights

When automated decisions touch sensitive data, the rules get stricter

1 July 2026

The new UK automated decision-making regime treats special category data differently, and the difference is significant enough to change whether a given automated process is lawful at all. This is a general explanation of that distinction, not sector-specific guidance.

The narrower set of lawful bases

For ordinary personal data, Articles 22A–22D (in force since 5 February 2026) permit significant solely automated decisions provided transparency, meaningful human review, and a right to contest are documented. For special category data — health information, biometric data used for identification, and similarly sensitive categories — the same permissive default does not apply. Automated decisions built on that kind of data remain restricted to three narrow lawful bases: explicit consent from the individual, necessity for entering into or performing a contract, or a specific statutory authorisation. An organisation cannot rely on "legitimate interests" or a general business justification for this category of processing.

Why this catches organisations by surprise

Special category data is not always obvious at the point of collection. A scoring model that uses income source, address history, or behavioural data can indirectly reveal health status, disability, or other sensitive characteristics even where none of those fields were deliberately collected. The test is whether the data is capable of revealing that information, not whether an organisation intended to process it. That means a system built without special category data in mind can still trigger the stricter regime, depending on what its inputs are actually capable of inferring.

This is general awareness content, not legal advice, and does not cover the specific circumstances of any organisation or sector.

Have a compliance challenge we should be solving?

When automated decisions touch sensitive data, the rules get stricter | Workplace Compliance Co