Asked by: Grahame Morris (Labour - Easington)
Question to the Ministry of Justice:
To ask the Secretary of State for Justice, whether the Department maintains a public register or internal inventory of automated decision-making systems.
Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice)
The Government is committed to the safe, ethical and transparent use of algorithmic decision-making and wider algorithmic tools. Transparency is essential to building public trust, enabling accountability, and improving understanding of how algorithms influence decisions and services.
The Ministry of Justice does not hold a separate public register of automated decision-making systems. Where tools fall within scope of the Algorithmic Transparency Recording Standard, information is published in line with that standard. The Department also has internal governance and assurance arrangements, including an internal inventory of AI-enabled tools and products.
The Algorithmic Transparency Recording Standard (ATRS) is a UK Government standard designed to promote transparency and accountability in the use of algorithmic tools, including artificial intelligence (AI) and automated or algorithm-assisted decision-making systems, across the public sector. It provides a standardised template that enables public bodies to explain what a tool does, why it is being used, how it supports or informs decision-making, the data it uses, the potential risks and impacts that have been identified, and the governance and safeguards in place to manage those risks.
On the basis of current records, the Department does not use AI-enabled tools to take decisions without human involvement. These tools support, rather than replace, professional judgement. Their outputs are reviewed by a suitably qualified person and checked against authoritative sources before being relied upon.
Asked by: Grahame Morris (Labour - Easington)
Question to the Ministry of Defence:
To ask the Secretary of State for Defence, what measures are in place to ensure that human oversight is substantive and effective, rather than limited to formal or nominal review.
Answered by Luke Pollard - Minister of State (Ministry of Defence)
The Ministry of Defence (MOD) ensures substantive and effective human oversight of automated decisions involving personal data through meaningful human involvement in the process. Automated outputs undergo thorough human review and do not form the sole basis for significant decisions unless there is a lawful basis and all statutory safeguards are met.
The MOD’s Data Protection Impact Assessment process identifies and mitigates risks, alongside which staff receive appropriate training to fulfil their oversight responsibilities. These measures ensure that human review is genuine and compliant with data protection requirements.
Asked by: Grahame Morris (Labour - Easington)
Question to the Department for Science, Innovation & Technology:
To ask the Secretary of State for Science, Innovation and Technology, whether her Department maintains a public register or internal inventory of automated decision-making systems.
Answered by Ian Murray - Minister of State (Department for Digital, Culture, Media and Sport)
The Government is committed to the safe, ethical and transparent use of algorithmic decision-making and wider algorithmic tools. Transparency is essential to building public trust, enabling accountability, and improving understanding of how algorithms influence decisions and services.
The Department for Science, Innovation and Technology (DSIT) does not maintain a public register or internal inventory of automated decision-making systems. However, DSIT supports transparency through the Algorithmic Transparency Recording Standard (ATRS), which establishes a standardised way for public sector organisations to publish information about how and why they are using algorithmic tools.
The ATRS is mandatory for all government departments, and for ALBs which deliver public or frontline services, or directly interact with the general public. It applies to algorithmic tools which have a significant influence on a decision-making process with public effect or directly interact with the general public.
The scope of the ATRS encompasses many of the most significant uses of automated decision-making and algorithmic tools, and those of the greatest interest to citizens and stakeholders.
The ATRS template, scope and exemptions policy, and the repository of published records are hosted on the ATRS Hub on GOV.UK.
Asked by: Grahame Morris (Labour - Easington)
Question to the Ministry of Justice:
To ask the Secretary of State for Justice, what steps has the Department taken to assess and mitigate risks of bias or discrimination arising from the use of automated decision-making systems.
Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice)
Reforms to the solely auromated decision-making (ADM) rules in the Data (Use and Access) Act make clear that these are decisions without any meaningful human involvement. This is to prevent ‘rubber stamping’ of decisions qualifying as having a ‘human in the loop’. To future-proof the legislation, the Act introduced a number of regulation-making powers to ensure the Government can keep these safeguards effective and up to date in light of evolving technology and changing societal expectations.
The ICO as the independent data protection regulator sets out in its guidance that “human involvement [in the decision making] has to be active and not just a token gesture” to be meaningful”. The ICO is working on updating its guidance in the light of the recent reforms and is working on a Code of Practice on AI and ADM which will provide authoritative guidance in data protection compliance in this area.
The UK’s data protection legislation does not lay down specific rules regarding particular employment systems. It is for each organisation to determine how it applies the data protection framework in its operational context. Where individuals are subject to significant decisions based solely on automated processing, the legislation provides safeguards including rights to information, challenge and human intervention.
The UK’s data protection legislation is a principles-based framework and does not prescribe specific consultation requirements for particular operational systems. Organisations are responsible for applying the requirements of the legislation within their own operational context and must ensure any processing of personal data complies with applicable legal requirements.
The UK’s data protection legislation applies to any processing of personal data regardless of the technology being used and is underpinned by principles of fairness, transparency and accountability. Organisations using automated decision-making or profiling must ensure processing is fair, lawful and transparent, and may be required to undertake a Data Protection Impact Assessment where processing is likely to result in a high risk to individuals’ rights and freedoms.
Asked by: Grahame Morris (Labour - Easington)
Question to the Ministry of Justice:
To ask the Secretary of State for Justice, to what extent are automated decision-making systems used in relation to civil service employment, including recruitment, performance management, discipline, or allocation of work.
Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice)
Reforms to the solely auromated decision-making (ADM) rules in the Data (Use and Access) Act make clear that these are decisions without any meaningful human involvement. This is to prevent ‘rubber stamping’ of decisions qualifying as having a ‘human in the loop’. To future-proof the legislation, the Act introduced a number of regulation-making powers to ensure the Government can keep these safeguards effective and up to date in light of evolving technology and changing societal expectations.
The ICO as the independent data protection regulator sets out in its guidance that “human involvement [in the decision making] has to be active and not just a token gesture” to be meaningful”. The ICO is working on updating its guidance in the light of the recent reforms and is working on a Code of Practice on AI and ADM which will provide authoritative guidance in data protection compliance in this area.
The UK’s data protection legislation does not lay down specific rules regarding particular employment systems. It is for each organisation to determine how it applies the data protection framework in its operational context. Where individuals are subject to significant decisions based solely on automated processing, the legislation provides safeguards including rights to information, challenge and human intervention.
The UK’s data protection legislation is a principles-based framework and does not prescribe specific consultation requirements for particular operational systems. Organisations are responsible for applying the requirements of the legislation within their own operational context and must ensure any processing of personal data complies with applicable legal requirements.
The UK’s data protection legislation applies to any processing of personal data regardless of the technology being used and is underpinned by principles of fairness, transparency and accountability. Organisations using automated decision-making or profiling must ensure processing is fair, lawful and transparent, and may be required to undertake a Data Protection Impact Assessment where processing is likely to result in a high risk to individuals’ rights and freedoms.
Asked by: Grahame Morris (Labour - Easington)
Question to the Ministry of Justice:
To ask the Secretary of State for Justice, what measures are in place to ensure that human oversight is substantive and effective, rather than limited to formal or nominal review.
Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice)
Reforms to the solely auromated decision-making (ADM) rules in the Data (Use and Access) Act make clear that these are decisions without any meaningful human involvement. This is to prevent ‘rubber stamping’ of decisions qualifying as having a ‘human in the loop’. To future-proof the legislation, the Act introduced a number of regulation-making powers to ensure the Government can keep these safeguards effective and up to date in light of evolving technology and changing societal expectations.
The ICO as the independent data protection regulator sets out in its guidance that “human involvement [in the decision making] has to be active and not just a token gesture” to be meaningful”. The ICO is working on updating its guidance in the light of the recent reforms and is working on a Code of Practice on AI and ADM which will provide authoritative guidance in data protection compliance in this area.
The UK’s data protection legislation does not lay down specific rules regarding particular employment systems. It is for each organisation to determine how it applies the data protection framework in its operational context. Where individuals are subject to significant decisions based solely on automated processing, the legislation provides safeguards including rights to information, challenge and human intervention.
The UK’s data protection legislation is a principles-based framework and does not prescribe specific consultation requirements for particular operational systems. Organisations are responsible for applying the requirements of the legislation within their own operational context and must ensure any processing of personal data complies with applicable legal requirements.
The UK’s data protection legislation applies to any processing of personal data regardless of the technology being used and is underpinned by principles of fairness, transparency and accountability. Organisations using automated decision-making or profiling must ensure processing is fair, lawful and transparent, and may be required to undertake a Data Protection Impact Assessment where processing is likely to result in a high risk to individuals’ rights and freedoms.
Asked by: Grahame Morris (Labour - Easington)
Question to the Ministry of Justice:
To ask the Secretary of State for Justice, what consultation has taken place with recognised trade unions regarding the introduction or use of automated decision-making systems affecting staff.
Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice)
Reforms to the solely auromated decision-making (ADM) rules in the Data (Use and Access) Act make clear that these are decisions without any meaningful human involvement. This is to prevent ‘rubber stamping’ of decisions qualifying as having a ‘human in the loop’. To future-proof the legislation, the Act introduced a number of regulation-making powers to ensure the Government can keep these safeguards effective and up to date in light of evolving technology and changing societal expectations.
The ICO as the independent data protection regulator sets out in its guidance that “human involvement [in the decision making] has to be active and not just a token gesture” to be meaningful”. The ICO is working on updating its guidance in the light of the recent reforms and is working on a Code of Practice on AI and ADM which will provide authoritative guidance in data protection compliance in this area.
The UK’s data protection legislation does not lay down specific rules regarding particular employment systems. It is for each organisation to determine how it applies the data protection framework in its operational context. Where individuals are subject to significant decisions based solely on automated processing, the legislation provides safeguards including rights to information, challenge and human intervention.
The UK’s data protection legislation is a principles-based framework and does not prescribe specific consultation requirements for particular operational systems. Organisations are responsible for applying the requirements of the legislation within their own operational context and must ensure any processing of personal data complies with applicable legal requirements.
The UK’s data protection legislation applies to any processing of personal data regardless of the technology being used and is underpinned by principles of fairness, transparency and accountability. Organisations using automated decision-making or profiling must ensure processing is fair, lawful and transparent, and may be required to undertake a Data Protection Impact Assessment where processing is likely to result in a high risk to individuals’ rights and freedoms.
Asked by: Grahame Morris (Labour - Easington)
Question to the Ministry of Justice:
To ask the Secretary of State for Justice, what steps his Department is taking to help ensure compliance with data protection requirements relating to the processing of special category data, including data relating to health or protected characteristics.
Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice)
All organisations in the UK that process personal data, including government departments, must comply with the UK’s data protection legislation (UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA)).
Under the UK GDPR, special category data is personal data that needs more protection because it is sensitive, and so is subject to additional conditions and safeguards.
The Ministry of Justice is committed to ensuring compliance with data protection legislation, including requirements relating to the processing of special category data such as information concerning health or protected characteristics.
The Department has established governance, policies and procedures to support lawful, fair and transparent processing of personal data. This includes the provision of data protection guidance, mandatory training and access to specialist advice from data protection professionals.
Where processing is likely to result in a high risk to individuals’ rights and freedoms, the Department undertakes Data Protection Impact Assessments and implements appropriate technical and organisational measures to safeguard personal data. The Department also maintains arrangements for monitoring compliance, reporting and managing personal data incidents, and reviewing processing activities to ensure they remain compliant with legal requirements.
Asked by: Grahame Morris (Labour - Easington)
Question to the Ministry of Justice:
To ask the Secretary of State for Justice, what safeguards he has implemented to ensure compliance with statutory requirements relating to automated decision-making, including rights to information, human review and challenge in the context of the Data (Use and Access) Act 2025.
Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice)
The UK’s data protection legislation applies to the private and public sector alike. Where significant decisions are taken solely based on automated processing, Departments must provide safeguards including rights to information, challenge and human intervention and comply with the relevant transparency obligations.
The Data (Use and Access) Act 2025 maintains safeguards for individuals who are subject to significant decisions based solely on automated processing. Organisations must provide individuals with the right to contest such decisions, obtain human intervention and make representations to the controller. These safeguards apply where solely automated decision-making (ADM) has legal or similarly significant effects on an individual.
Transparency requirements on organisations apply as soon as organisations obtain individuals’ data for solely ADM. Articles 13-14 of the UK GDPR require organisations to provide data subjects privacy information (usually in a privacy notice) about the existence of solely ADM including profiling, meaningful information about the logic involved, and the significance and the envisaged consequence of such automated processing for the individual.
After a decision has been based solely on automated processing, the reformed Article 22 includes safeguards that must be applied once a legal or similarly significant decision has been made about the data subject. Organisations are required to provide data subjects with information related to significant decisions that have been taken about them based solely on automated processing and enable them to obtain human intervention or challenge a decision.
Where a partly automated decision is taken in which the human input influences the final decision, it is likely that the human input would be considered to be meaningful. Consequently, it would not be necessary to provide the additional safeguards set out under the automated decision-making provisions.
Article 22C of the UK GDPR contains safeguards for solely automated decisions that have legal or similarly significant effects on individuals. Where organisations have made such decisions, must comply with these safeguards which include: providing information about the decision taken, the right for individuals to contest the decision, make representations, and obtain human intervention for the decision.
The Data (Use and Access) Act 2025 introduced reforms to the rules on solely automated decision-making, while maintaining safeguards for individuals. The Act clarifies that organisations must inform individuals when significant decisions are taken solely by automated means, and individuals retain rights to challenge such decisions and obtain human intervention.
The Government has required the Information Commissioner’s Office (ICO) as the independent data protection regulator to produce a Code of Practice on AI and ADM. This Code will provide authoritative guidance to support organisations with their data protection compliance in this area.
Asked by: Grahame Morris (Labour - Easington)
Question to the Ministry of Justice:
To ask the Secretary of State for Justice, what internal guidance his Department has issued on the potential impact of the Data (Use and Access) Act 2025 on automated decision-making.
Answered by Jake Richards - Parliamentary Under-Secretary (Ministry of Justice)
The UK’s data protection legislation applies to the private and public sector alike. Where significant decisions are taken solely based on automated processing, Departments must provide safeguards including rights to information, challenge and human intervention and comply with the relevant transparency obligations.
The Data (Use and Access) Act 2025 maintains safeguards for individuals who are subject to significant decisions based solely on automated processing. Organisations must provide individuals with the right to contest such decisions, obtain human intervention and make representations to the controller. These safeguards apply where solely automated decision-making (ADM) has legal or similarly significant effects on an individual.
Transparency requirements on organisations apply as soon as organisations obtain individuals’ data for solely ADM. Articles 13-14 of the UK GDPR require organisations to provide data subjects privacy information (usually in a privacy notice) about the existence of solely ADM including profiling, meaningful information about the logic involved, and the significance and the envisaged consequence of such automated processing for the individual.
After a decision has been based solely on automated processing, the reformed Article 22 includes safeguards that must be applied once a legal or similarly significant decision has been made about the data subject. Organisations are required to provide data subjects with information related to significant decisions that have been taken about them based solely on automated processing and enable them to obtain human intervention or challenge a decision.
Where a partly automated decision is taken in which the human input influences the final decision, it is likely that the human input would be considered to be meaningful. Consequently, it would not be necessary to provide the additional safeguards set out under the automated decision-making provisions.
Article 22C of the UK GDPR contains safeguards for solely automated decisions that have legal or similarly significant effects on individuals. Where organisations have made such decisions, must comply with these safeguards which include: providing information about the decision taken, the right for individuals to contest the decision, make representations, and obtain human intervention for the decision.
The Data (Use and Access) Act 2025 introduced reforms to the rules on solely automated decision-making, while maintaining safeguards for individuals. The Act clarifies that organisations must inform individuals when significant decisions are taken solely by automated means, and individuals retain rights to challenge such decisions and obtain human intervention.
The Government has required the Information Commissioner’s Office (ICO) as the independent data protection regulator to produce a Code of Practice on AI and ADM. This Code will provide authoritative guidance to support organisations with their data protection compliance in this area.