Section 80 of the Data (Use and Access) Act 2025 repealed Article 22 of the UK GDPR. It did this on 5 February 2026, under a commencement order most independent psychology practices never saw: the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026. In its place, four new articles now sit in UK GDPR: Article 22A, 22B, 22C and 22D. The trade coverage that noticed at all described this as the automated decision-making ban being relaxed, and for most personal data that is correct. It is not the whole statute.

Article 22B is the part the "ban relaxed" headline skips. It applies specifically to special category data, the UK GDPR's term for health data among other sensitive categories, and it keeps a restriction that reads almost identically to the rule it replaced. A PHQ-9 or GAD-7 response is a client stating something about their own mental health. The resulting score is a derived piece of health data. If your practice runs that score through a system that then acts on it without a clinician looking at the individual case first, Article 22B, not the relaxed general rule, is the provision that governs you.

What actually changed on 5 February

Before the repeal, Article 22(1) gave a data subject "the right not to be subject to a decision based solely on automated processing... which produces legal effects concerning him or her or similarly significantly affects him or her." That was a default prohibition with three narrow exceptions: the decision was necessary for a contract, authorised by law, or based on explicit consent.

Articles 22A to 22D flip that default. Article 22A now defines the two building blocks: a decision is "based solely on automated processing" if there is no meaningful human involvement in taking it, and it is a "significant decision" if it produces a legal effect or a similarly significant effect for the person. Article 22C then says that where a significant decision is based solely on automated processing, the controller must have safeguards in place, information for the person, a way to make representations, a route to human intervention, and a right to contest, rather than needing a specific legal ground to make the decision at all. For ordinary personal data, solely automated significant decisions moved from banned-unless-excepted to permitted-if-safeguarded.

So what for you: if your practice's only encounter with automated decisions is something like an AI tool auto-generating an appointment reminder or a waiting-list position, the position genuinely eased in February, and Article 22C's four safeguards are what now applies, not a search for a lawful basis under the old three-exception list.

The rule that didn't move

Article 22B sits beside Article 22A and 22C and carries the old logic forward for one specific case: "a significant decision based entirely or partly on processing described in Article 9(1) (processing of special categories of personal data) may not be taken based solely on automated processing, unless one of the following conditions is met." The two conditions are the decision being based entirely on the data subject's explicit consent, or the decision being necessary for a contract or required by law and Article 9(2)(g)'s substantial public interest condition also being satisfied.

Article 9(1) lists health data among the categories it covers, and mental health status is health data under any reasonable reading of that term. Compare the two old exceptions removed for special category data ("authorised by law" alone was never enough, explicit consent or substantial public interest were the only routes) with the two conditions in the new Article 22B, and they are structurally the same test. The general loosening in Article 22C simply does not reach special category data on its own; Article 22B has to be satisfied first, and only once it is does Article 22C's safeguards layer on top.

So what for you: a vendor telling you that "the UK's AI decision-making rules were relaxed this year" is describing Article 22C accurately and describing your situation inaccurately. Anything scoring a validated mental health measure and acting on the result sits under Article 22B, which reads almost exactly like the provision it replaced.

Where the line actually sits for PHQ-9 and GAD-7

PHQ-9 and GAD-7 are the two outcome measures used across NHS Talking Therapies (formerly IAPT) services in England and widely adopted in independent practice alongside them, scored at intake and at every session to track caseness and progress toward recovery. Most AI tools marketed against these instruments do one of two things: total the item scores and apply the instrument's published severity bands (a deterministic calculation, not really a judgement at all), or go further and flag or recommend a change in care, a step up in intensity, a discharge, a referral, based on where the score lands.

The first case is unlikely to be a "significant decision" under Article 22A at all. A number appearing on a dashboard for a clinician to weigh alongside everything else they know about the client does not, on its own, produce a legal or similarly significant effect; the clinician's own judgement is still what determines the outcome. This is a genuine case where the cautious reading and the practical reading agree: simple automated scoring of a standard instrument, reviewed by a clinician before any action follows, does not obviously trigger Article 22B.

The second case is where the risk concentrates. If a system is configured to auto-close a case, auto-decline booking a further session, or auto-escalate a risk flag purely because a score crossed a threshold, with no clinician looking at that specific client's result before it takes effect, that is both solely automated (no meaningful human involvement in that decision) and significant (it changes what care the person receives). Built on a PHQ-9 or GAD-7 score, it is also built on special category data. That combination is exactly what Article 22B was written for.

So what for you: the question to ask any vendor is not "does your tool use AI on outcome measures", it is "does anything happen automatically, without a clinician looking at this client's result first, once the score crosses a number you've set." If the honest answer is yes, you are in Article 22B territory, not the general safeguards regime.

The lawful basis problem this creates for a small practice

Assume a practice does want an automated step, for example auto-flagging a case for urgent clinician review (not auto-closing it, which is the harder case) when a score crosses a clinical risk threshold outside office hours. Article 22B gives exactly two routes in. The substantial public interest condition under Article 9(2)(g) requires the processing to meet one of the specific public interest conditions set out in Schedule 1 of the Data Protection Act 2018, most of which are written for public bodies, regulators and specific statutory functions, and it typically requires an appropriate policy document to be in place. That is a heavy compliance instrument for a small independent psychology group to stand up convincingly, and it is not obviously available to a private practice's routine clinical operations in the way it might be to, say, a safeguarding referral to a local authority.

That leaves explicit consent as the realistic route for almost every independent practice: consent to the entire automated decision, not a general consent to using an AI tool, recorded, specific, and capable of being withdrawn. Article 22C's safeguards then apply on top of that consent, not instead of it: the client still needs to be told the decision is automated, given a way to make representations about it, given a route to human intervention, and given a right to contest it. Consent gets you past Article 22B. It does not excuse you from Article 22C.

So what for you: if a vendor's compliance answer to "how is this lawful" stops at "we rely on legitimate interests" or "consent to use the platform", that is not the same as explicit, specific consent to the automated decision itself, and it will not satisfy Article 22B on its own. We have covered the same distinction, a general practice-management consent not covering a specific downstream use, in the context of HCPC's binding consent standard, which sits alongside this data protection question rather than replacing it.

ICO's own guidance hasn't caught up

Checking the position directly rather than relying on secondary summaries turns up something worth knowing before you rely on any of this. ICO's own published page on rights related to automated decision-making and profiling, the foundational public guidance on this exact right, still describes the pre-reform position in full: it states plainly that Article 22 "has additional rules to protect individuals" and lists the old three exceptions, contract necessity, legal authorisation, explicit consent, with no reference anywhere on the page to Article 22A, 22B, 22C or 22D. That page carries a metadata date of 17 August 2026, more than six months after the law it describes was repealed.

This is not an isolated oversight. ICO ran a consultation on draft updated guidance reflecting the Data (Use and Access) Act 2025 changes, with final guidance originally expected by spring 2026. As of this article, that final guidance has not been published, and separately, ICO has not indicated what interpretation it will take of "meaningful human involvement" under the new Article 22A, a phrase the statute uses but does not define. The Secretary of State also holds a power under Article 22D to define both "meaningful human involvement" and "similarly significant effect" by regulation; no such regulations have been made.

So what for you: this is not a case where reading the regulator's guidance instead of the statute gets you a shortcut, because the regulator's own public guidance has not been updated to reflect the statute. Read the legislation itself, or a source that has, before assuming a compliance page written for the old regime still describes your obligations.

What "meaningful human involvement" means until someone says otherwise

With no new regulations and no finalised new guidance, the only articulated standard available is ICO's pre-reform interpretation, developed under the old Article 22 and its separate AI and data protection guidance. That standard requires a reviewer with genuine authority and competence to overrule the system, involvement in each individual decision rather than a general policy sign-off, review that happens before the decision is applied rather than as a formality afterward, and a reviewer who actually weighs the case rather than routinely applying whatever the system recommends. A clinician who glances at a discharge letter an AI tool has already sent is not meeting that bar. A clinician who is shown the score, the client's history and the proposed action, and who has to actively approve it before anything is sent, plausibly is.

So what for you: build your workflow around the stricter, pre-reform standard now. If ICO's eventual guidance turns out to permit a lighter touch, you can relax the process later. If you build around a lighter assumption and ICO's guidance lands where its pre-reform position already sat, you will have been non-compliant in the gap, which is the more expensive way round.

The recommendation

Audit every outcome-measure tool in the practice against one question: does anything happen automatically, without a named clinician actively reviewing that specific client's result, once a PHQ-9 or GAD-7 score crosses a number the system has been set to watch for. If the answer is genuinely no, simple scoring reviewed by a clinician before any action, you are very likely outside Article 22B and Article 22C's safeguards duties are the more relevant read. If the answer is yes for any feature, discharge, session limits, risk escalation, treat it as a solely automated significant decision on special category data: get explicit, specific, recorded consent to that exact automated step, and build in the information, representation, human intervention and contest routes Article 22C requires regardless of which lawful basis you use.

Do not wait for ICO's updated guidance to decide this is settled. It has been over six months since the law changed and the regulator's own public page has not caught up; treat that gap as a reason for more caution in your own documentation, not less.

If you want a clinician-by-clinician, tool-by-tool audit of exactly where this applies in your practice, our AI Opportunity and Growth Assessment covers data protection lawful basis alongside clinical workflow, so nothing gets missed because it fell between the two. Or book a 20-minute call and we will tell you honestly whether that is worth doing yet.

The Clinical AI Briefing

One practical AI insight for healthcare practices every week. No hype. Evidence and outcomes only.

Related: HCPC's consent standard is binding. BPS's AI guidance isn't.  ·  CQC names 5 regulations for AI. Safeguarding isn't one.  ·  NHS's AI scribe guidance isn't binding

This article is for informational purposes only and does not constitute legal advice. It summarises Section 80 of the Data (Use and Access) Act 2025 and Articles 22A to 22D of the UK GDPR as inserted with effect from 5 February 2026 under SI 2026/82, together with ICO's current published guidance on automated decision-making, checked directly against ico.org.uk on the date of publication. Whether a specific tool or workflow engages Article 22B, and what lawful basis and safeguards apply, depends on your practice's exact configuration. Confirm your own position with a data protection professional or the ICO before relying on any interpretation above.