UK AI and Data Protection Regulations
Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026
United Kingdom
RAI-GB-NA-SI20264-2026SI 2026/425
These UK Regulations require the ICO to develop a code of practice for AI and automated decision-making, ensuring data protection and safeguarding rights.
Summary
Read full text ↗Plain English
Overview
The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 establish a statutory requirement for the Information Commissioner's Office (ICO) to develop and publish a comprehensive code of practice. These Regulations, made on 16 April 2026 and coming into force on 12 May 2026, aim to provide essential guidance on good practice for organizations processing personal data when developing and utilizing Artificial Intelligence (AI) and automated decision-making (ADM) systems. The overarching goal is to ensure that the rapid advancements in AI technology are balanced with robust data protection principles, safeguarding individual rights and freedoms as enshrined in the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
This legislative instrument is a critical component of the United Kingdom's broader strategy to foster a pro-innovation regulatory environment for AI while maintaining public trust and ensuring ethical development and deployment. It builds upon existing ICO guidance on AI and data protection, formalizing the need for a statutory code that will serve as a definitive reference point for businesses, public bodies, and third-sector organizations. The Regulations specifically mandate the inclusion of guidance on the processing of children's personal data, acknowledging the particular vulnerabilities of this demographic in the context of AI and ADM. The implementation of these Regulations and the subsequent Code of Practice will play a pivotal role in shaping how AI systems are designed, developed, and used across the UK, emphasizing fairness, transparency, and accountability throughout the AI lifecycle.
Definitions
The Regulations leverage definitions established within the UK GDPR and the Data Protection Act 2018, which collectively form the cornerstone of data protection law in the United Kingdom. Key terms such as 'personal data' refer to any information relating to an identified or identifiable living individual. 'Processing' encompasses a wide array of operations performed on personal data, including collection, recording, storage, alteration, retrieval, use, disclosure, and erasure. 'Data subject' denotes the living individual to whom the personal data relates, and 'controller' and 'processor' define the entities responsible for determining the purposes and means of processing personal data, or processing it on behalf of a controller, respectively.
While the Regulations themselves do not introduce entirely new definitions for Artificial Intelligence (AI) or Automated Decision-Making (ADM), they build upon the understanding of these concepts as they relate to data protection. Automated decision-making is defined by reference to provisions in the UK GDPR and the Data Protection Act 2018, particularly those inserted through the Data (Use and Access) Act 2025. The ICO's existing guidance, which this Code of Practice will formalize, often adopts an academic definition of AI as 'the theory and development of computer systems able to perform tasks normally requiring human intelligence,' with a focus on machine learning-based systems. The Code will elaborate on how these AI and ADM systems interact with personal data, especially in scenarios involving inferences, affinity groups, and special category data, which require stringent handling under Article 9 of the UK GDPR.
Governance and Institutional Framework
The primary institutional responsibility for developing and overseeing the Code of Practice falls upon the Information Commissioner's Office (ICO). The Regulations explicitly place a duty on the ICO to prepare this code, leveraging its expertise as the independent authority responsible for upholding information rights in the public interest. The ICO's role extends beyond mere drafting; it is tasked with providing ongoing guidance, promoting good practice, and ensuring compliance with data protection legislation in the context of AI and ADM. This includes conducting audits, offering guidance on bias mitigation strategies, and engaging with stakeholders to address ethical challenges.
The governance framework also involves the Secretary of State, who makes these Regulations and has consulted with the Commissioner and other appropriate persons. While the ICO is responsible for the content of the Code, certain procedural aspects, such as panel requirements for preparing or amending the code, are specified, with an exclusion for matters relating to national security. This collaborative yet distinct allocation of responsibilities underscores the UK's multi-faceted approach to AI governance, integrating data protection oversight within a broader regulatory landscape that aims to be pro-innovation while protecting fundamental values.
Key Focus Areas
The Code of Practice on Artificial Intelligence and Automated Decision-Making is expected to focus on several critical areas to ensure the responsible and compliant use of AI systems that process personal data. A central theme will be the application of core data protection principles to AI, including lawfulness, fairness, and transparency. This involves ensuring that AI systems have a clearly defined lawful basis for processing personal data, providing clear privacy information to individuals, and addressing potential biases that could lead to unfair or discriminatory outcomes.
Another key area is risk management, with the Code likely providing frameworks and tools to help organizations identify, assess, and mitigate data protection risks associated with AI systems. The ICO's existing AI and Data Protection Risk Toolkit, designed to assist organizations in this regard, is a strong indicator of the practical support the Code will offer. Furthermore, the Code will emphasize accountability and governance, requiring organizations to implement robust internal processes, conduct Data Protection Impact Assessments (DPIAs) where appropriate, and ensure that human oversight is maintained, especially for solely automated decisions. The specific inclusion of guidance on children's personal data highlights a focus on protecting vulnerable groups from the unique risks posed by AI and ADM.
Implementation Framework
The implementation framework for the Code of Practice will guide organizations on how to integrate good practices into their AI and ADM systems. This will involve a lifecycle approach, addressing data protection considerations from the initial design and development phases through to deployment and decommissioning. Organizations will be encouraged to embed data protection by design and by default, ensuring that privacy considerations are central to every stage of AI development. The Code will likely provide practical steps for conducting thorough data mapping, identifying the types of personal data used by AI systems, and assessing their sensitivity, particularly concerning special category data.
Furthermore, the implementation framework will detail requirements for documenting AI systems, including their purpose, logic, and the datasets used for training and testing. This documentation will be crucial for demonstrating compliance and facilitating audits by the ICO. The Code will also provide guidance on developing internal policies and procedures for AI governance, outlining roles and responsibilities within organizations for ensuring data protection compliance. This could include the appointment of Data Protection Officers (DPOs) and the establishment of internal review boards for high-risk AI applications. The aim is to create a structured approach that enables organizations of all sizes to navigate the complexities of AI and data protection effectively, fostering innovation while upholding individual rights.
Monitoring and Evaluation
Monitoring and evaluation of compliance with the Code of Practice will be a continuous process, primarily overseen by the Information Commissioner's Office (ICO). The ICO will utilize its existing powers under the UK GDPR and DPA 2018 to assess how organizations are adhering to the principles and guidelines set out in the Code. This includes conducting investigations, audits, and issuing enforcement notices where non-compliance is identified. The ICO's proactive engagement with AI, including its AI and Data Protection Risk Toolkit and audits on specific AI applications like recruitment tools, demonstrates its commitment to active monitoring.
Organizations themselves will be expected to implement internal monitoring and evaluation mechanisms. This includes regular internal audits of AI systems, privacy impact assessments, and ongoing reviews of their data processing activities to ensure continued alignment with the Code. The Code will likely provide recommendations for performance metrics related to data protection, such as bias detection rates, transparency scores, and the effectiveness of consent mechanisms. Feedback mechanisms for data subjects to raise concerns or exercise their rights will also be a critical component, enabling continuous improvement and accountability. The dynamic nature of AI technology means that the Code itself will be subject to periodic review and updates by the ICO to ensure its continued relevance and effectiveness in addressing emerging challenges.
Penalties, Liability, and Appeals
The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, by operating under the umbrella of the DPA 2018 and UK GDPR, means that non-compliance with the Code of Practice can lead to significant penalties. The DPA 2018 and UK GDPR establish a robust enforcement regime, granting the Information Commissioner's Office (ICO) powers to issue substantial fines for breaches of data protection principles. These penalties can be up to £17.5 million or 4% of an organization's annual global turnover, whichever is higher, for the most serious infringements. The Code of Practice, while providing guidance, will define what constitutes good practice, and failure to adhere to it could be a factor in determining the severity of a breach and the corresponding penalty.
Liability for data protection infringements in the context of AI and ADM will typically rest with the data controller, who determines the purposes and means of processing personal data. Data processors, who process data on behalf of a controller, also bear responsibilities and can face liability under certain circumstances. The Code will likely clarify how liability applies to different actors in the AI supply chain, particularly when multiple entities are involved in the development, deployment, and operation of AI systems. Individuals whose data protection rights have been violated due to non-compliant AI systems will have avenues for redress, including the right to lodge a complaint with the ICO and the right to seek judicial remedy. The Code is expected to provide guidance on the processes for appeals and complaints, ensuring that data subjects can effectively challenge decisions made by or with the assistance of AI.
Relationship to Other Instruments
The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 are intrinsically linked to, and derive their authority from, the Data Protection Act 2018 (DPA 2018) and the UK General Data Protection Regulation (UK GDPR). The DPA 2018 complements the UK GDPR, providing the domestic framework for data protection in the UK and making specific provisions where the UK GDPR allows for national derogations. The Code of Practice will therefore elaborate on how the principles and requirements of these foundational data protection laws apply specifically to the unique challenges posed by AI and ADM systems.
Furthermore, these Regulations operate within the broader context of the UK's evolving AI regulatory landscape. They are expected to align with the UK government's National AI Strategy, which aims to foster innovation while ensuring responsible AI governance. The Code will also consider the implications of the Data (Use and Access) Act 2025, which introduced amendments to the DPA 2018 and UK GDPR, particularly concerning automated decision-making. While distinct from sector-specific AI regulations or broader AI safety legislation that may emerge, this Code will provide a crucial data protection lens, ensuring consistency and coherence across the regulatory ecosystem. It will also complement other ICO guidance, such as the AI and Data Protection Risk Toolkit and guidance on explaining decisions made with AI.
International Alignment
The Code of Practice on Artificial Intelligence and Automated Decision-Making, while a domestic UK instrument, is developed with an awareness of international standards and best practices in AI and data protection. The UK GDPR, which forms a core part of UK data protection law, is a transposed version of the EU GDPR, ensuring a high degree of alignment with European data protection standards. This foundational alignment facilitates cross-border data flows and ensures that UK organizations operating internationally can maintain consistent data protection practices.
Beyond the GDPR framework, the ICO actively engages with international partners, including through the Digital Regulation Cooperation Forum (DRCF), to address AI's ethical challenges and ensure alignment with global data protection standards. The UK's National AI Strategy also emphasizes the importance of international collaboration and the development of global technical standards for AI. Therefore, the Code of Practice is expected to reflect principles found in international frameworks such as the OECD Principles on AI, which promote responsible innovation, human-centric values, and robust governance. This international alignment is crucial for the UK's ambition to be a global leader in AI while upholding strong ethical and data protection safeguards.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Regulations Made | 2026-04-16 | The Secretary of State issued the Regulations. |
| Regulations Laid Before Parliament | 2026-04-21 | Formal presentation of the Regulations to Parliament. |
| Regulations Come into Force | 2026-05-12 | The Regulations officially became active, requiring the ICO to prepare the Code of Practice. |
| ICO Publishes Draft Code of Practice | 2026-11-30 | Anticipated publication of the initial draft for public consultation. |
| Public Consultation Period Ends | 2027-02-28 | Period for stakeholders to provide feedback on the draft Code. |
| ICO Publishes Final Code of Practice | 2027-08-31 | Expected publication of the finalized Code after incorporating feedback. |
| Full Compliance Expected | 2028-02-29 | Organizations are expected to be fully compliant with the Code of Practice. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Lawful Basis for Processing | Ensure all personal data processed by AI/ADM systems has a clearly defined lawful basis under UK GDPR. |
| Transparency and Explainability | Provide clear, concise, and accessible information to individuals about how their data is used by AI/ADM systems and how decisions are made. |
| Data Minimization | Limit the collection and processing of personal data to what is strictly necessary for the AI/ADM system's purpose. |
| Accuracy and Data Quality | Implement measures to ensure the accuracy and reliability of personal data used in AI/ADM systems, including training data. |
| Fairness and Bias Mitigation | Conduct regular assessments for bias and discrimination in AI/ADM systems and implement strategies to mitigate unfair outcomes. |
| Data Protection Impact Assessments (DPIAs) | Carry out DPIAs for high-risk AI/ADM systems that process personal data, documenting risks and mitigation strategies. |
| Security Measures | Implement appropriate technical and organizational measures to ensure the security and confidentiality of personal data within AI/ADM systems. |
| Individual Rights | Establish clear processes for individuals to exercise their data protection rights, including access, rectification, erasure, and objection to automated decisions. |
| Governance and Accountability | Implement internal governance structures, policies, and training to ensure accountability for AI/ADM systems and data protection compliance. |
| Children's Data Protection | Develop specific safeguards and adhere to good practices when processing children's personal data with AI/ADM systems. |
Sources and References
| Source | Type |
|---|---|
| The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 | official |
| Artificial intelligence | ICO | government |
| Guidance on AI and data protection | ICO | government |
| AI and data protection risk toolkit | ICO | government |
| National AI Strategy - GOV.UK | government |
| Data Protection Act 2018 - Legislation.gov.uk | legal |
| The UK's data protection legislation - GOV.UK | government |
This UK regulation mandates the Information Commissioner's Office (ICO) to create a Code of Practice for organizations using Artificial Intelligence (AI) and automated decision-making (ADM) systems that process personal data, ensuring robust data protection and individual rights.
The new rules apply to any UK-based business, public body, or third-sector organization that develops or uses AI and ADM systems involving personal data. This includes both data controllers, who determine how data is used, and data processors, who handle data on their behalf. The core aim is to balance AI innovation with strong data protection principles, drawing on the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Once the Code is finalized, organizations will face several key obligations: - Ensuring a clear, lawful basis for processing personal data and providing transparent information to individuals about how AI systems use their data. - Proactively identifying, assessing, and mitigating data protection risks, including conducting Data Protection Impact Assessments (DPIAs) for high-risk AI systems. - Implementing strong internal governance, accountability measures, and maintaining human oversight, especially for fully automated decisions. - Paying particular attention to safeguarding children's personal data, given their unique vulnerabilities.
While the Regulations themselves came into force on May 12, 2026, the ICO will publish a draft Code for public consultation by November 30, 2026, with the final version expected by August 31, 2027. Full compliance with the Code is anticipated by February 29, 2028.
Failing to adhere to the Code of Practice can lead to significant penalties under existing data protection laws, potentially up to £17.5 million or 4% of an organization's annual global turnover, whichever is higher. Liability typically rests with the data controller, but processors also have responsibilities. A key takeaway is that while the Code provides guidance, it effectively sets the standard for "good practice," meaning non-compliance could be a critical factor in determining the severity of any data protection breach.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 10 marked completePlain-English obligations under UK AI and Data Protection Regulations. Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Feb 29, 2028
Applies to: Organizations processing personal data with AI/ADM systems.
“Ensure all personal data processed by AI/ADM systems has a clearly defined lawful basis under UK GDPR.”
- #2Critical⏰ Feb 29, 2028
Applies to: Organizations using AI/ADM systems that process personal data.
“Provide clear, concise, and accessible information to individuals about how their data is used by AI/ADM systems and how decisions are made.”
- #3Critical⏰ Feb 29, 2028
Applies to: Organizations developing or using AI/ADM systems.
“Limit the collection and processing of personal data to what is strictly necessary for the AI/ADM system's purpose.”
- #4Critical⏰ Feb 29, 2028
Applies to: Organizations using personal data in AI/ADM systems.
“Implement measures to ensure the accuracy and reliability of personal data used in AI/ADM systems, including training data.”
- #5Critical⏰ Feb 29, 2028
Applies to: Organizations developing or deploying AI/ADM systems.
“Conduct regular assessments for bias and discrimination in AI/ADM systems and implement strategies to mitigate unfair outcomes.”
- #6Critical⏰ Feb 29, 2028
Applies to: Organizations operating high-risk AI/ADM systems.
“Carry out DPIAs for high-risk AI/ADM systems that process personal data, documenting risks and mitigation strategies.”
- #7Critical⏰ Feb 29, 2028
Applies to: Organizations using AI/ADM systems that process personal data.
“Implement appropriate technical and organizational measures to ensure the security and confidentiality of personal data within AI/ADM systems.”
- #8Critical⏰ Feb 29, 2028
Applies to: Organizations using AI/ADM systems that process personal data.
“Establish clear processes for individuals to exercise their data protection rights, including access, rectification, erasure, and objection to automated decisions.”
- #9Critical⏰ Feb 29, 2028
Applies to: Organizations developing or using AI/ADM systems.
“Implement internal governance structures, policies, and training to ensure accountability for AI/ADM systems and data protection compliance.”
- #10Critical⏰ Feb 29, 2028
Applies to: Organizations processing children's personal data with AI/ADM systems.
“Develop specific safeguards and adhere to good practices when processing children's personal data with AI/ADM systems.”
Related Regulations
Information Commissioner's Office - Strategic approach to AI
United Kingdom89% similar
ICO guidance: AI and data protection (updated guidance and AI risk toolkit)
United Kingdom87% similar
United Kingdom AI Regulation Overview
United Kingdom87% similar
Age appropriate design: a code of practice for online services
United Kingdom87% similar
Data (Use and Access) Act 2025
United Kingdom87% similar
© Regulations.AI — created on 27-May-2026 using Gemini 2.5 Flash