The employer must tell workers when their information is used for solely automated decision-making, giving meaningful information about the logic involved and the significance and envisaged consequences, including in response to a subject access request; it must explain the processing to workers, offer easy routes to ask for human review or contest a decision, and check regularly that systems work as intended. Law since the guidance: the Data (Use and Access) Act 2025, s 80, replaced UK GDPR Article 22 with Articles 22A to 22D (fully in force 5 February 2026): solely automated significant decisions are now restricted only where they rest on special category data (explicit consent, or contract or law plus Article 9(2)(g)) or on recognised legitimate interests, and in every case the controller must provide safeguards: information about the decision, a way to make representations, human intervention and a way to contest it. The ICO flags this guidance as under review.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.