Information between 12th July 2026 - 1st August 2026
Note: This sample does not contain the most recent 2 weeks of information. Up to date samples can only be viewed by Subscribers.
Click here to view Subscription options.
| Division Votes |
|---|
|
13 Jul 2026 - Immigration and Asylum Bill - View Vote Context Grahame Morris voted No - in line with the party majority and in line with the House One of 282 Labour No votes vs 0 Labour Aye votes Tally: Ayes - 97 Noes - 358 |
|
13 Jul 2026 - Immigration and Asylum Bill - View Vote Context Grahame Morris voted Aye - in line with the party majority and in line with the House One of 263 Labour Aye votes vs 14 Labour No votes Tally: Ayes - 264 Noes - 90 |
|
14 Jul 2026 - Public Office (Accountability) Bill - View Vote Context Grahame Morris voted No - in line with the party majority and in line with the House One of 328 Labour No votes vs 0 Labour Aye votes Tally: Ayes - 102 Noes - 409 |
|
14 Jul 2026 - Public Office (Accountability) Bill - View Vote Context Grahame Morris voted No - in line with the party majority and in line with the House One of 329 Labour No votes vs 0 Labour Aye votes Tally: Ayes - 104 Noes - 412 |
|
14 Jul 2026 - Public Office (Accountability) Bill - View Vote Context Grahame Morris voted Aye - against a party majority and against the House One of 7 Labour Aye votes vs 321 Labour No votes Tally: Ayes - 93 Noes - 323 |
| Written Answers |
|---|
|
Department for Science, Innovation and Technology: Data Protection
Asked by: Grahame Morris (Labour - Easington) Monday 13th July 2026 Question to the Department for Science, Innovation & Technology: To ask the Secretary of State for Science, Innovation and Technology, what steps her Department is taking to ensure compliance with data protection requirements under the Data (Use and Access) Act 2025 relating to the processing of special category data, including data relating to health and protected characteristics. Answered by Ian Murray - Minister of State (Department for Digital, Culture, Media and Sport) All organisations in the UK that process personal data, including government departments, must comply with the UK’s data protection legislation (UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA)). Under the UK GDPR, special category data is personal data that needs more protection because it is sensitive, and so is subject to additional conditions and safeguards.
My department ensures that all processing of special category personal data is undertaken in compliance with data protection legislation. Data Protection Impact Assessments are completed where required and are reviewed by the Data Protection Officer’s team to ensure that special category data is processed only where a valid condition for processing applies, processing is necessary and proportionate, and appropriate technical and organisational safeguards are in place. The Department has published an Appropriate Policy Document on GOV.UK. |
|
Department for Science, Innovation and Technology: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Wednesday 15th July 2026 Question to the Department for Science, Innovation & Technology: To ask the Secretary of State for Science, Innovation and Technology, whether her Department maintains a public register or internal inventory of automated decision-making systems. Answered by Ian Murray - Minister of State (Department for Digital, Culture, Media and Sport) The Government is committed to the safe, ethical and transparent use of algorithmic decision-making and wider algorithmic tools. Transparency is essential to building public trust, enabling accountability, and improving understanding of how algorithms influence decisions and services. The Department for Science, Innovation and Technology (DSIT) does not maintain a public register or internal inventory of automated decision-making systems. However, DSIT supports transparency through the Algorithmic Transparency Recording Standard (ATRS), which establishes a standardised way for public sector organisations to publish information about how and why they are using algorithmic tools. The ATRS is mandatory for all government departments, and for ALBs which deliver public or frontline services, or directly interact with the general public. It applies to algorithmic tools which have a significant influence on a decision-making process with public effect or directly interact with the general public. The scope of the ATRS encompasses many of the most significant uses of automated decision-making and algorithmic tools, and those of the greatest interest to citizens and stakeholders. The ATRS template, scope and exemptions policy, and the repository of published records are hosted on the ATRS Hub on GOV.UK. |
|
Ministry of Defence: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Monday 13th July 2026 Question to the Ministry of Defence: To ask the Secretary of State for Defence, how individuals are informed that decisions have been taken in (a) whole and (b) part by automated means in the context of the Data (Use and Access) Act 2025. Answered by Luke Pollard - Minister of State (Ministry of Defence) The Ministry of Defence (MOD) ensures compliance with legal requirements regarding Automated Decision-Making (ADM) through a range of measures. The MOD provides clear information about its use of ADM in its public Privacy Notice. When personal data is processed through ADM, individuals are informed in accordance with applicable data protection legislation and MOD internal policies. The public Privacy Notice details the circumstances under which automated decision-making may be employed and outlines the rights available to individuals. In cases where a significant decision is made solely by automated means, individuals are notified prior to the processing and, where required by law, are given the opportunity to request a human review or reconsideration of the decision. The MOD strictly ensures that no individual is subject to decisions producing significant effects based solely on automated decision-making unless there is a lawful basis for such processing and all relevant statutory safeguards are fully implemented. The Data Protection Impact Assessment process is used to assess risks and ensure that appropriate safeguards are in place. |
|
Ministry of Defence: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Monday 13th July 2026 Question to the Ministry of Defence: To ask the Secretary of State for Defence, to what extent are automated decision-making systems used in relation to civil service employment, including recruitment, performance management, discipline, or allocation of work. Answered by Calvin Bailey - Parliamentary Under-Secretary (Ministry of Defence) (Minister for Veterans and People) The Ministry of Defence (MOD) engages with Trade Unions on all key matters that impact staff. We have engaged with all recognised Trade Unions where we have pursued automation in systems that impact staff employment and will continue such engagement when future automation is proposed.
The MOD utilises automated decision-making systems to streamline labour-intensive processes and deliver more efficient services. Examples include the processing of annual leave requests on HR systems following management approval and notifying job applicants that they do not meet the nationality requirements for security-sensitive roles, with contact details provided to discuss alternative opportunities. The MOD may also utilise psychometric testing to assess candidates during recruitment, with automated processes generating and communicating the results. |
|
Ministry of Defence: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Monday 13th July 2026 Question to the Ministry of Defence: To ask the Secretary of State for Defence, what consultation has taken place with recognised trade unions regarding the introduction or use of automated decision-making systems affecting staff. Answered by Calvin Bailey - Parliamentary Under-Secretary (Ministry of Defence) (Minister for Veterans and People) The Ministry of Defence (MOD) engages with Trade Unions on all key matters that impact staff. We have engaged with all recognised Trade Unions where we have pursued automation in systems that impact staff employment and will continue such engagement when future automation is proposed.
The MOD utilises automated decision-making systems to streamline labour-intensive processes and deliver more efficient services. Examples include the processing of annual leave requests on HR systems following management approval and notifying job applicants that they do not meet the nationality requirements for security-sensitive roles, with contact details provided to discuss alternative opportunities. The MOD may also utilise psychometric testing to assess candidates during recruitment, with automated processes generating and communicating the results. |
|
Ministry of Defence: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Monday 13th July 2026 Question to the Ministry of Defence: To ask the Secretary of State for Defence, whether the Department maintains a public register or internal inventory of automated decision-making systems; and whether it plans to publish such information. Answered by Luke Pollard - Minister of State (Ministry of Defence) There are different interpretations of what constitutes Automated Decision-Making (ADM). The Ministry of Defence does not hold a central database on all activities and systems that might meet the definition of ADM within the Department.
|
|
Ministry of Defence: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Friday 17th July 2026 Question to the Ministry of Justice: To ask the Secretary of State for Justice, whether the Department maintains a public register or internal inventory of automated decision-making systems. Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice) The Government is committed to the safe, ethical and transparent use of algorithmic decision-making and wider algorithmic tools. Transparency is essential to building public trust, enabling accountability, and improving understanding of how algorithms influence decisions and services. The Ministry of Justice does not hold a separate public register of automated decision-making systems. Where tools fall within scope of the Algorithmic Transparency Recording Standard, information is published in line with that standard. The Department also has internal governance and assurance arrangements, including an internal inventory of AI-enabled tools and products. The Algorithmic Transparency Recording Standard (ATRS) is a UK Government standard designed to promote transparency and accountability in the use of algorithmic tools, including artificial intelligence (AI) and automated or algorithm-assisted decision-making systems, across the public sector. It provides a standardised template that enables public bodies to explain what a tool does, why it is being used, how it supports or informs decision-making, the data it uses, the potential risks and impacts that have been identified, and the governance and safeguards in place to manage those risks. On the basis of current records, the Department does not use AI-enabled tools to take decisions without human involvement. These tools support, rather than replace, professional judgement. Their outputs are reviewed by a suitably qualified person and checked against authoritative sources before being relied upon. |
|
Ministry of Defence: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Friday 17th July 2026 Question to the Ministry of Defence: To ask the Secretary of State for Defence, what measures are in place to ensure that human oversight is substantive and effective, rather than limited to formal or nominal review. Answered by Luke Pollard - Minister of State (Ministry of Defence) The Ministry of Defence (MOD) ensures substantive and effective human oversight of automated decisions involving personal data through meaningful human involvement in the process. Automated outputs undergo thorough human review and do not form the sole basis for significant decisions unless there is a lawful basis and all statutory safeguards are met.
The MOD’s Data Protection Impact Assessment process identifies and mitigates risks, alongside which staff receive appropriate training to fulfil their oversight responsibilities. These measures ensure that human review is genuine and compliant with data protection requirements.
|
|
Ministry of Justice: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Tuesday 14th July 2026 Question to the Ministry of Justice: To ask the Secretary of State for Justice, what steps has the Department taken to assess and mitigate risks of bias or discrimination arising from the use of automated decision-making systems. Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice) Reforms to the solely auromated decision-making (ADM) rules in the Data (Use and Access) Act make clear that these are decisions without any meaningful human involvement. This is to prevent ‘rubber stamping’ of decisions qualifying as having a ‘human in the loop’. To future-proof the legislation, the Act introduced a number of regulation-making powers to ensure the Government can keep these safeguards effective and up to date in light of evolving technology and changing societal expectations. The ICO as the independent data protection regulator sets out in its guidance that “human involvement [in the decision making] has to be active and not just a token gesture” to be meaningful”. The ICO is working on updating its guidance in the light of the recent reforms and is working on a Code of Practice on AI and ADM which will provide authoritative guidance in data protection compliance in this area. The UK’s data protection legislation does not lay down specific rules regarding particular employment systems. It is for each organisation to determine how it applies the data protection framework in its operational context. Where individuals are subject to significant decisions based solely on automated processing, the legislation provides safeguards including rights to information, challenge and human intervention. The UK’s data protection legislation is a principles-based framework and does not prescribe specific consultation requirements for particular operational systems. Organisations are responsible for applying the requirements of the legislation within their own operational context and must ensure any processing of personal data complies with applicable legal requirements. The UK’s data protection legislation applies to any processing of personal data regardless of the technology being used and is underpinned by principles of fairness, transparency and accountability. Organisations using automated decision-making or profiling must ensure processing is fair, lawful and transparent, and may be required to undertake a Data Protection Impact Assessment where processing is likely to result in a high risk to individuals’ rights and freedoms. |
|
Civil Service: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Tuesday 14th July 2026 Question to the Ministry of Justice: To ask the Secretary of State for Justice, to what extent are automated decision-making systems used in relation to civil service employment, including recruitment, performance management, discipline, or allocation of work. Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice) Reforms to the solely auromated decision-making (ADM) rules in the Data (Use and Access) Act make clear that these are decisions without any meaningful human involvement. This is to prevent ‘rubber stamping’ of decisions qualifying as having a ‘human in the loop’. To future-proof the legislation, the Act introduced a number of regulation-making powers to ensure the Government can keep these safeguards effective and up to date in light of evolving technology and changing societal expectations. The ICO as the independent data protection regulator sets out in its guidance that “human involvement [in the decision making] has to be active and not just a token gesture” to be meaningful”. The ICO is working on updating its guidance in the light of the recent reforms and is working on a Code of Practice on AI and ADM which will provide authoritative guidance in data protection compliance in this area. The UK’s data protection legislation does not lay down specific rules regarding particular employment systems. It is for each organisation to determine how it applies the data protection framework in its operational context. Where individuals are subject to significant decisions based solely on automated processing, the legislation provides safeguards including rights to information, challenge and human intervention. The UK’s data protection legislation is a principles-based framework and does not prescribe specific consultation requirements for particular operational systems. Organisations are responsible for applying the requirements of the legislation within their own operational context and must ensure any processing of personal data complies with applicable legal requirements. The UK’s data protection legislation applies to any processing of personal data regardless of the technology being used and is underpinned by principles of fairness, transparency and accountability. Organisations using automated decision-making or profiling must ensure processing is fair, lawful and transparent, and may be required to undertake a Data Protection Impact Assessment where processing is likely to result in a high risk to individuals’ rights and freedoms. |
|
Ministry of Justice: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Tuesday 14th July 2026 Question to the Ministry of Justice: To ask the Secretary of State for Justice, what measures are in place to ensure that human oversight is substantive and effective, rather than limited to formal or nominal review. Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice) Reforms to the solely auromated decision-making (ADM) rules in the Data (Use and Access) Act make clear that these are decisions without any meaningful human involvement. This is to prevent ‘rubber stamping’ of decisions qualifying as having a ‘human in the loop’. To future-proof the legislation, the Act introduced a number of regulation-making powers to ensure the Government can keep these safeguards effective and up to date in light of evolving technology and changing societal expectations. The ICO as the independent data protection regulator sets out in its guidance that “human involvement [in the decision making] has to be active and not just a token gesture” to be meaningful”. The ICO is working on updating its guidance in the light of the recent reforms and is working on a Code of Practice on AI and ADM which will provide authoritative guidance in data protection compliance in this area. The UK’s data protection legislation does not lay down specific rules regarding particular employment systems. It is for each organisation to determine how it applies the data protection framework in its operational context. Where individuals are subject to significant decisions based solely on automated processing, the legislation provides safeguards including rights to information, challenge and human intervention. The UK’s data protection legislation is a principles-based framework and does not prescribe specific consultation requirements for particular operational systems. Organisations are responsible for applying the requirements of the legislation within their own operational context and must ensure any processing of personal data complies with applicable legal requirements. The UK’s data protection legislation applies to any processing of personal data regardless of the technology being used and is underpinned by principles of fairness, transparency and accountability. Organisations using automated decision-making or profiling must ensure processing is fair, lawful and transparent, and may be required to undertake a Data Protection Impact Assessment where processing is likely to result in a high risk to individuals’ rights and freedoms. |
|
Ministry of Justice: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Tuesday 14th July 2026 Question to the Ministry of Justice: To ask the Secretary of State for Justice, what consultation has taken place with recognised trade unions regarding the introduction or use of automated decision-making systems affecting staff. Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice) Reforms to the solely auromated decision-making (ADM) rules in the Data (Use and Access) Act make clear that these are decisions without any meaningful human involvement. This is to prevent ‘rubber stamping’ of decisions qualifying as having a ‘human in the loop’. To future-proof the legislation, the Act introduced a number of regulation-making powers to ensure the Government can keep these safeguards effective and up to date in light of evolving technology and changing societal expectations. The ICO as the independent data protection regulator sets out in its guidance that “human involvement [in the decision making] has to be active and not just a token gesture” to be meaningful”. The ICO is working on updating its guidance in the light of the recent reforms and is working on a Code of Practice on AI and ADM which will provide authoritative guidance in data protection compliance in this area. The UK’s data protection legislation does not lay down specific rules regarding particular employment systems. It is for each organisation to determine how it applies the data protection framework in its operational context. Where individuals are subject to significant decisions based solely on automated processing, the legislation provides safeguards including rights to information, challenge and human intervention. The UK’s data protection legislation is a principles-based framework and does not prescribe specific consultation requirements for particular operational systems. Organisations are responsible for applying the requirements of the legislation within their own operational context and must ensure any processing of personal data complies with applicable legal requirements. The UK’s data protection legislation applies to any processing of personal data regardless of the technology being used and is underpinned by principles of fairness, transparency and accountability. Organisations using automated decision-making or profiling must ensure processing is fair, lawful and transparent, and may be required to undertake a Data Protection Impact Assessment where processing is likely to result in a high risk to individuals’ rights and freedoms. |
|
Ministry of Justice: Data Protection
Asked by: Grahame Morris (Labour - Easington) Tuesday 14th July 2026 Question to the Ministry of Justice: To ask the Secretary of State for Justice, what steps his Department is taking to help ensure compliance with data protection requirements relating to the processing of special category data, including data relating to health or protected characteristics. Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice) All organisations in the UK that process personal data, including government departments, must comply with the UK’s data protection legislation (UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA)). Under the UK GDPR, special category data is personal data that needs more protection because it is sensitive, and so is subject to additional conditions and safeguards. The Ministry of Justice is committed to ensuring compliance with data protection legislation, including requirements relating to the processing of special category data such as information concerning health or protected characteristics. The Department has established governance, policies and procedures to support lawful, fair and transparent processing of personal data. This includes the provision of data protection guidance, mandatory training and access to specialist advice from data protection professionals. Where processing is likely to result in a high risk to individuals’ rights and freedoms, the Department undertakes Data Protection Impact Assessments and implements appropriate technical and organisational measures to safeguard personal data. The Department also maintains arrangements for monitoring compliance, reporting and managing personal data incidents, and reviewing processing activities to ensure they remain compliant with legal requirements. |
|
Data Protection: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Tuesday 14th July 2026 Question to the Ministry of Justice: To ask the Secretary of State for Justice, what safeguards he has implemented to ensure compliance with statutory requirements relating to automated decision-making, including rights to information, human review and challenge in the context of the Data (Use and Access) Act 2025. Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice) The UK’s data protection legislation applies to the private and public sector alike. Where significant decisions are taken solely based on automated processing, Departments must provide safeguards including rights to information, challenge and human intervention and comply with the relevant transparency obligations. The Data (Use and Access) Act 2025 maintains safeguards for individuals who are subject to significant decisions based solely on automated processing. Organisations must provide individuals with the right to contest such decisions, obtain human intervention and make representations to the controller. These safeguards apply where solely automated decision-making (ADM) has legal or similarly significant effects on an individual. Transparency requirements on organisations apply as soon as organisations obtain individuals’ data for solely ADM. Articles 13-14 of the UK GDPR require organisations to provide data subjects privacy information (usually in a privacy notice) about the existence of solely ADM including profiling, meaningful information about the logic involved, and the significance and the envisaged consequence of such automated processing for the individual. After a decision has been based solely on automated processing, the reformed Article 22 includes safeguards that must be applied once a legal or similarly significant decision has been made about the data subject. Organisations are required to provide data subjects with information related to significant decisions that have been taken about them based solely on automated processing and enable them to obtain human intervention or challenge a decision. Where a partly automated decision is taken in which the human input influences the final decision, it is likely that the human input would be considered to be meaningful. Consequently, it would not be necessary to provide the additional safeguards set out under the automated decision-making provisions. Article 22C of the UK GDPR contains safeguards for solely automated decisions that have legal or similarly significant effects on individuals. Where organisations have made such decisions, must comply with these safeguards which include: providing information about the decision taken, the right for individuals to contest the decision, make representations, and obtain human intervention for the decision. The Data (Use and Access) Act 2025 introduced reforms to the rules on solely automated decision-making, while maintaining safeguards for individuals. The Act clarifies that organisations must inform individuals when significant decisions are taken solely by automated means, and individuals retain rights to challenge such decisions and obtain human intervention. The Government has required the Information Commissioner’s Office (ICO) as the independent data protection regulator to produce a Code of Practice on AI and ADM. This Code will provide authoritative guidance to support organisations with their data protection compliance in this area. |
|
Ministry of Justice: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Tuesday 14th July 2026 Question to the Ministry of Justice: To ask the Secretary of State for Justice, what internal guidance his Department has issued on the potential impact of the Data (Use and Access) Act 2025 on automated decision-making. Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice) The UK’s data protection legislation applies to the private and public sector alike. Where significant decisions are taken solely based on automated processing, Departments must provide safeguards including rights to information, challenge and human intervention and comply with the relevant transparency obligations. The Data (Use and Access) Act 2025 maintains safeguards for individuals who are subject to significant decisions based solely on automated processing. Organisations must provide individuals with the right to contest such decisions, obtain human intervention and make representations to the controller. These safeguards apply where solely automated decision-making (ADM) has legal or similarly significant effects on an individual. Transparency requirements on organisations apply as soon as organisations obtain individuals’ data for solely ADM. Articles 13-14 of the UK GDPR require organisations to provide data subjects privacy information (usually in a privacy notice) about the existence of solely ADM including profiling, meaningful information about the logic involved, and the significance and the envisaged consequence of such automated processing for the individual. After a decision has been based solely on automated processing, the reformed Article 22 includes safeguards that must be applied once a legal or similarly significant decision has been made about the data subject. Organisations are required to provide data subjects with information related to significant decisions that have been taken about them based solely on automated processing and enable them to obtain human intervention or challenge a decision. Where a partly automated decision is taken in which the human input influences the final decision, it is likely that the human input would be considered to be meaningful. Consequently, it would not be necessary to provide the additional safeguards set out under the automated decision-making provisions. Article 22C of the UK GDPR contains safeguards for solely automated decisions that have legal or similarly significant effects on individuals. Where organisations have made such decisions, must comply with these safeguards which include: providing information about the decision taken, the right for individuals to contest the decision, make representations, and obtain human intervention for the decision. The Data (Use and Access) Act 2025 introduced reforms to the rules on solely automated decision-making, while maintaining safeguards for individuals. The Act clarifies that organisations must inform individuals when significant decisions are taken solely by automated means, and individuals retain rights to challenge such decisions and obtain human intervention. The Government has required the Information Commissioner’s Office (ICO) as the independent data protection regulator to produce a Code of Practice on AI and ADM. This Code will provide authoritative guidance to support organisations with their data protection compliance in this area. |
|
Ministry of Justice: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Tuesday 14th July 2026 Question to the Ministry of Justice: To ask the Secretary of State for Justice, whether significant Automated Decision-Making is taking place or planned within his Department, and if he will make a statement. Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice) The UK’s data protection legislation applies to the private and public sector alike. Where significant decisions are taken solely based on automated processing, Departments must provide safeguards including rights to information, challenge and human intervention and comply with the relevant transparency obligations. The Data (Use and Access) Act 2025 maintains safeguards for individuals who are subject to significant decisions based solely on automated processing. Organisations must provide individuals with the right to contest such decisions, obtain human intervention and make representations to the controller. These safeguards apply where solely automated decision-making (ADM) has legal or similarly significant effects on an individual. Transparency requirements on organisations apply as soon as organisations obtain individuals’ data for solely ADM. Articles 13-14 of the UK GDPR require organisations to provide data subjects privacy information (usually in a privacy notice) about the existence of solely ADM including profiling, meaningful information about the logic involved, and the significance and the envisaged consequence of such automated processing for the individual. After a decision has been based solely on automated processing, the reformed Article 22 includes safeguards that must be applied once a legal or similarly significant decision has been made about the data subject. Organisations are required to provide data subjects with information related to significant decisions that have been taken about them based solely on automated processing and enable them to obtain human intervention or challenge a decision. Where a partly automated decision is taken in which the human input influences the final decision, it is likely that the human input would be considered to be meaningful. Consequently, it would not be necessary to provide the additional safeguards set out under the automated decision-making provisions. Article 22C of the UK GDPR contains safeguards for solely automated decisions that have legal or similarly significant effects on individuals. Where organisations have made such decisions, must comply with these safeguards which include: providing information about the decision taken, the right for individuals to contest the decision, make representations, and obtain human intervention for the decision. The Data (Use and Access) Act 2025 introduced reforms to the rules on solely automated decision-making, while maintaining safeguards for individuals. The Act clarifies that organisations must inform individuals when significant decisions are taken solely by automated means, and individuals retain rights to challenge such decisions and obtain human intervention. The Government has required the Information Commissioner’s Office (ICO) as the independent data protection regulator to produce a Code of Practice on AI and ADM. This Code will provide authoritative guidance to support organisations with their data protection compliance in this area. |
|
Ministry of Justice: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Tuesday 14th July 2026 Question to the Ministry of Justice: To ask the Secretary of State for Justice, how does the Department define and ensure meaningful human involvement in decisions supported or made by automated systems. Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice) The Government does not wish to be overly prescriptive by defining meaningful human involvement, as it is context specific. ICO guidance can be more appropriate than legislation for providing such a definition or interpretation, given guidance can be more easily updated and can provide detail and nuances that legislation would not usually capture. Current ICO guidance sets out that “human involvement [in the decision making] has to be active and not just a token gesture” to be meaningful”. It is for each data controller to determine and be able to demonstrate whether their processing includes meaningful human involvement, as this is context specific. As such, the Government believes in the importance of the ICO continuing to provide its views on interpretation of terms used in the legislation. Our reforms do not remove the ICO's ability to do this, or to advise Parliament or the government if it considers that the law needs clarification. |
|
Ministry of Justice: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Tuesday 14th July 2026 Question to the Ministry of Justice: To ask the Secretary of State for Justice, what processes are in place to enable individuals to seek human review and to challenge decisions made by automated systems in the context of the Data (Use and Access) Act 2025. Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice) The UK’s data protection legislation applies to the private and public sector alike. Where significant decisions are taken solely based on automated processing, Departments must provide safeguards including rights to information, challenge and human intervention and comply with the relevant transparency obligations. The Data (Use and Access) Act 2025 maintains safeguards for individuals who are subject to significant decisions based solely on automated processing. Organisations must provide individuals with the right to contest such decisions, obtain human intervention and make representations to the controller. These safeguards apply where solely automated decision-making (ADM) has legal or similarly significant effects on an individual. Transparency requirements on organisations apply as soon as organisations obtain individuals’ data for solely ADM. Articles 13-14 of the UK GDPR require organisations to provide data subjects privacy information (usually in a privacy notice) about the existence of solely ADM including profiling, meaningful information about the logic involved, and the significance and the envisaged consequence of such automated processing for the individual. After a decision has been based solely on automated processing, the reformed Article 22 includes safeguards that must be applied once a legal or similarly significant decision has been made about the data subject. Organisations are required to provide data subjects with information related to significant decisions that have been taken about them based solely on automated processing and enable them to obtain human intervention or challenge a decision. Where a partly automated decision is taken in which the human input influences the final decision, it is likely that the human input would be considered to be meaningful. Consequently, it would not be necessary to provide the additional safeguards set out under the automated decision-making provisions. Article 22C of the UK GDPR contains safeguards for solely automated decisions that have legal or similarly significant effects on individuals. Where organisations have made such decisions, must comply with these safeguards which include: providing information about the decision taken, the right for individuals to contest the decision, make representations, and obtain human intervention for the decision. The Data (Use and Access) Act 2025 introduced reforms to the rules on solely automated decision-making, while maintaining safeguards for individuals. The Act clarifies that organisations must inform individuals when significant decisions are taken solely by automated means, and individuals retain rights to challenge such decisions and obtain human intervention. The Government has required the Information Commissioner’s Office (ICO) as the independent data protection regulator to produce a Code of Practice on AI and ADM. This Code will provide authoritative guidance to support organisations with their data protection compliance in this area. |
|
Data Protection: Artificial Intelligence
Asked by: Grahame Morris (Labour - Easington) Tuesday 14th July 2026 Question to the Ministry of Justice: To ask the Secretary of State for Justice, how individuals are informed that decisions have been taken in (a) whole and (b) part by automated means in the context of the Data (Use and Access) Act 2025. Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice) The UK’s data protection legislation applies to the private and public sector alike. Where significant decisions are taken solely based on automated processing, Departments must provide safeguards including rights to information, challenge and human intervention and comply with the relevant transparency obligations. The Data (Use and Access) Act 2025 maintains safeguards for individuals who are subject to significant decisions based solely on automated processing. Organisations must provide individuals with the right to contest such decisions, obtain human intervention and make representations to the controller. These safeguards apply where solely automated decision-making (ADM) has legal or similarly significant effects on an individual. Transparency requirements on organisations apply as soon as organisations obtain individuals’ data for solely ADM. Articles 13-14 of the UK GDPR require organisations to provide data subjects privacy information (usually in a privacy notice) about the existence of solely ADM including profiling, meaningful information about the logic involved, and the significance and the envisaged consequence of such automated processing for the individual. After a decision has been based solely on automated processing, the reformed Article 22 includes safeguards that must be applied once a legal or similarly significant decision has been made about the data subject. Organisations are required to provide data subjects with information related to significant decisions that have been taken about them based solely on automated processing and enable them to obtain human intervention or challenge a decision. Where a partly automated decision is taken in which the human input influences the final decision, it is likely that the human input would be considered to be meaningful. Consequently, it would not be necessary to provide the additional safeguards set out under the automated decision-making provisions. Article 22C of the UK GDPR contains safeguards for solely automated decisions that have legal or similarly significant effects on individuals. Where organisations have made such decisions, must comply with these safeguards which include: providing information about the decision taken, the right for individuals to contest the decision, make representations, and obtain human intervention for the decision. The Data (Use and Access) Act 2025 introduced reforms to the rules on solely automated decision-making, while maintaining safeguards for individuals. The Act clarifies that organisations must inform individuals when significant decisions are taken solely by automated means, and individuals retain rights to challenge such decisions and obtain human intervention. The Government has required the Information Commissioner’s Office (ICO) as the independent data protection regulator to produce a Code of Practice on AI and ADM. This Code will provide authoritative guidance to support organisations with their data protection compliance in this area. |
| Early Day Motions |
|---|
|
Monday 13th July 57 signatures (Most recent: 16 Jul 2026) Tabled by: Grahame Morris (Labour - Easington) That this House celebrates Richard Pengelly and his 37 years of dedicated service to the House of Commons; notes that he began his parliamentary career in the Pugin Room before becoming one of the best-known and best-loved faces behind the bar in the Strangers’ Bar; recognises that his warmth, kindness, … |
| Early Day Motions Signed |
|---|
|
Wednesday 15th July Grahame Morris signed this EDM on Thursday 16th July 2026 Prohibiting Members of Parliament from having paid second jobs 31 signatures (Most recent: 16 Jul 2026)Tabled by: Richard Burgon (Labour - Leeds East) That this House welcomes the presentation of the Members of Parliament (Prohibition of Second Jobs) (Motion) Bill as a positive contribution to the debate on ending paid second jobs for MPs; notes with concern that MPs have reportedly received more than £11 million in outside earnings since the last General … |
|
Monday 13th July Grahame Morris signed this EDM on Tuesday 14th July 2026 London South Bank University industrial dispute 23 signatures (Most recent: 16 Jul 2026)Tabled by: John McDonnell (Labour - Hayes and Harlington) That this House notes with concern the escalating industrial dispute between London South Bank University (LSBU) and University and College Union (UCU) over fire and rehire proposals to terminate the contracts of all academic staff and require them to compete in a redundancy selection process as part of a restructuring … |
|
Thursday 9th July Grahame Morris signed this EDM on Monday 13th July 2026 Strike action and industrial dispute at Tower Hamlets leisure centres 25 signatures (Most recent: 16 Jul 2026)Tabled by: Apsana Begum (Labour - Poplar and Limehouse) That this House expresses solidarity with members of Unite the Union taking strike action at Tower Hamlets’ public leisure centres; notes that workers have been waiting for over two years for in-house contracts to be issued after the commitment to insourcing rightly made by Tower Hamlets Council in May 2024; … |