TemporraTemporra← Back to Temporra

AI and automated decisions about workers: what changed on 5 February 2026

By · · 13 min read

A groundworks firm switches on a feature in its new site app: anyone who clocks in outside the site boundary after 07:30 loses fifteen minutes' pay. On a wet Monday in March a labourer's phone puts him 300 metres away, in the car park of the builders' merchant across the road. He was stood at the gate. The deduction goes through with the rest of the week's pay and nobody at the firm ever looks at it.

A clock-in flag passing to a person before it becomes a decision, with the shortcut that skips the person struck through.

Whether that app calls itself AI doesn't matter. The law doesn't ask what's inside the box. It asks whether a person made the decision, and whether the decision mattered to the worker. That law changed on 5 February 2026, and the ICO's own guidance for employers is still being rewritten to catch up.

This guide is about what happens after the data is collected: the moment software acts on it. Whether you're allowed to collect location or face data in the first place is a separate question, covered in our guide to GPS tracking and UK law.

What changed on 5 February 2026

Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with four new articles, 22A to 22D. The Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026 (SI 2026/82) brought it fully into force on 5 February 2026. They also brought in the new lawful basis of "recognised legitimate interests" on the same day, which matters below.

The old Article 22 was written as a right not to be subject to a decision based solely on automated processing that had legal or similarly significant effects. You could only take one where it was necessary for a contract with the person, authorised by law, or based on their explicit consent.

The new version turns that round. A solely automated significant decision is now allowed in general, as long as safeguards are in place. The outright restriction survives only in two places: decisions that rest on special category data, and decisions where the processing relies on a recognised legitimate interest. For a firm running clock-in software with a face check, the first of those is the one that bites.

One transitional point. Regulation 5 of SI 2026/82 keeps the old rules for any decision taken before 5 February 2026 that fell under the old Article 22(3). Anything your system has done since then is judged under the new articles.

Is it a decision, and did a person make it?

Article 22A gives two tests. A decision is based solely on automated processing if there's "no meaningful human involvement" in taking it. And it's a significant decision if it has a legal effect on the worker or a similarly significant effect. When you weigh up whether the human involvement was meaningful, you have to consider how far the decision was reached by profiling.

"Meaningful" is the word everything turns on. The ICO's guidance on monitoring tools that use solely automated processes is specific about it. The person has to check the system's recommendation rather than routinely apply it. They need the authority and the competence to go against it. And they should be weighing it up against everything else they know, not just reading it.

The ICO gives two examples that fit a field workforce almost exactly. A firm that pays workers based entirely on automated productivity monitoring is taking solely automated significant decisions. A courier firm whose HR manager reads the tracking data, talks to the driver about the late deliveries and then issues a warning is not, even though the tracker supplied the evidence. The data can be entirely automatic. The decision has to be a person's.

So a supervisor who approves forty flagged timesheets in one click on a Friday afternoon, without opening any of them, probably isn't meaningful involvement. It's a rubber stamp with a name on it.

Which decisions are significant?

The legislation doesn't list them. The ICO's examples of a similarly significant effect are a decision that significantly affects someone's finances, such as raising or cutting pay based on performance, and one that affects their employment opportunities, such as dismissal. Applied to a site-based firm, it sorts roughly like this:

What the software does on its ownLikely position
Deducts pay for a late or out-of-boundary clock-inSignificant. It changes what the worker is paid.
Rejects a timesheet so those hours aren't paid until someone fixes itVery likely significant, for the same reason.
Locks a worker out of clocking in after a failed face matchSignificant if it costs them a shift or pay, and restricted outright if it rests on the face match (see below).
Issues a formal warning, or suspends app access, after a set number of flagsSignificant. It affects their employment.
Decides who is offered the next job from a score or rankingLikely significant, and profiling counts against any claim of human involvement.
Sends a manager an alert that someone clocked in lateNot a decision about the worker. The manager's next step might be.
Shows a geofence flag on a timesheet for a supervisor to checkNot a decision, provided the supervisor genuinely checks it.

The bottom two rows are where you want most of your automation to live. A flag that a person reads is decision support. A flag that moves money is a decision.

What you must have in place if software does decide

Where a significant decision about a worker is based solely on automated processing, Article 22C requires safeguards that let the worker:

Those are minimums. Article 22D lets the Secretary of State add to them by regulations, and also define by regulations what does or doesn't count as meaningful human involvement or a similarly significant effect. Those regulations need a vote in both Houses. Keep an eye out for them, because they could change what counts as enough.

In practice, on a building site, this means the labourer in the car park finds out about the deduction on the day it happens, not from his payslip three weeks later. He has a named person to ring. That person can reverse it, and has done so before, which is the best evidence you'll ever have that the right to human intervention is real. The ICO also says you mustn't leave people who ask for a human review worse off than people who don't.

Face checks: where it's still restricted

This is the part most clock-in vendors won't mention. Under Article 22B, a significant decision based entirely or partly on special category data can't be taken solely by automated processing unless one of two conditions is met. The ICO's guidance on biometric time and access control is clear that biometric data used to identify a specific worker, which is what a face check at clock-in does, is special category data.

The two conditions are narrow. The first is that the decision is based entirely on data the worker has given explicit consent for. Read literally, that means every piece of data behind the decision. A lockout that uses the face match and also the GPS reading you collect under legitimate interests is hard to fit inside it. The second needs the decision to be necessary for a contract or required or authorised by law, and the substantial public interest condition in Article 9(2)(g) to apply. Ordinary timekeeping won't get there.

So a failed face match shouldn't, on its own, cost anybody a shift. The ICO's guidance says so in terms: manual review must be available if an automated process results in a possible access denial, and workers who ask for one mustn't be disadvantaged. Its worked example is a site with an intercom at the gate, so a worker the camera doesn't recognise can call a supervisor who lets them in and enters their arrival time by hand. That's the model. A PIN route on a site tablet does the same job.

It's worth knowing why the matches fail, too. A face check compares a live photo with a template stored at setup. Hard hats, a week's beard, low winter sun and a cracked phone camera all make that harder. None of it is the worker's fault, and none of it should reach their pay without a person in between.

The crime-prevention trap

The 5 February changes added a new lawful basis, Article 6(1)(ea), for processing necessary for a "recognised legitimate interest". The list is in Annex 1 to the UK GDPR, and one entry is detecting, investigating or preventing crime. That will look attractive to a firm using telematics or fuel-card data to catch diesel going missing, because it avoids the balancing test that ordinary legitimate interests needs.

Article 22B(4) closes a door behind it. A significant decision can't be taken solely by automated processing where the processing behind it relies, even partly, on a recognised legitimate interest. If an automated fuel-theft alert suspends a driver's fuel card and stands him down before anyone looks, and you're relying on the crime basis, that's barred. Have a person look first.

What you have to tell workers

Article 13(2)(f) now requires you to tell people about automated decision-making that's subject to the Article 22C safeguards, including "meaningful information about the logic involved", the significance and the envisaged consequences. Article 15(1)(h) repeats the duty when a worker makes a subject access request.

"Meaningful information about the logic" doesn't mean the source code. It means something like: "If your clock-in is more than 200 metres from the site boundary and after your start time, the system deducts 15 minutes. You'll get a notification. Ring the site office on the number in the app to have it reviewed." A worker can act on that. A paragraph saying you use "advanced analytics to support workforce decisions" tells them nothing.

A DPIA before you switch it on

Article 35 requires a data protection impact assessment before any processing likely to result in a high risk, and names one case in particular: systematic and extensive evaluation of people, based on automated processing including profiling, where decisions with legal or similarly significant effects follow. Automatic pay deductions across a whole workforce sit squarely inside that. The ICO separately says a DPIA is required before you use biometric data to identify workers.

The basics of writing one are in our GPS tracking guide. The extra questions for automated decisions are short. Which of the system's actions change pay or work without a person? Could any of them be moved to "flag for review" instead? Who reviews, how quickly, and what can they overrule? How often do you check the system is getting it right? The ICO expects regular checks that it's working as intended, and a spreadsheet of how many flags were overturned last month is a decent one.

Complaints: a duty since 19 June 2026

Section 164A of the Data Protection Act 2018 came into force on 19 June 2026. Any worker who thinks you've broken the UK GDPR in handling their data can now complain to you directly, and you must make that easy, for example with a complaint form that can be filled in electronically and by other means. You must acknowledge each complaint within 30 days, look into it without undue delay, keep them told how it's going and tell them the outcome.

That's separate from the Article 22C right to contest a decision, but on a building site the two will usually arrive as the same angry phone call. One route that handles both, with a date written against every step, saves arguing later about which one it was.

The guidance hasn't caught up yet

Every page of the ICO's Employment practices and data protection: monitoring workers guidance now carries a banner saying it is under review because of the Data (Use and Access) Act. The page on automated processes still describes the old Article 22, including the three gateways that no longer apply to ordinary decisions. Its examples and its account of meaningful human oversight still hold up, because the statute now uses the same idea. Its list of when you're allowed to decide automatically does not.

So for now you're working from legislation that has already changed and guidance that says it will. Two more pieces could still move: the ICO's rewritten guidance, and any regulations under Article 22D. Neither has a date I could confirm from a primary source, and I'm not going to guess one. What won't change is the direction. The Act made automated decisions easier to take and kept the duty to have a person on the other end.

What to do this month

Common questions

Can an employer use AI to make decisions about workers in the UK?

Yes, with conditions. Since 5 February 2026 a significant decision about a worker can be taken with no meaningful human involvement only if the safeguards in Article 22C of the UK GDPR are in place: telling the worker about the decision, and letting them make representations, get a human to intervene and contest it. Article 22B still bars it where the decision rests on special category data such as biometrics, unless one of two narrow conditions is met.

What changed on 5 February 2026?

Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D, brought into force by SI 2026/82. The old Article 22 gave people a right not to be subject to solely automated significant decisions, with three exceptions. The new version allows them in general, provided the Article 22C safeguards exist, and keeps a restriction for special category data and for processing that relies on a recognised legitimate interest.

Does a manager clicking approve count as human involvement?

Only if it is meaningful. Article 22A says a decision is solely automated if there is no meaningful human involvement. The ICO's monitoring guidance says the person must actually weigh up the recommendation and have the authority and competence to go against it. A manager who approves every flag in a batch without looking is not that.

Is docking pay for a late clock-in a significant decision?

It is likely to be. A significant decision is one with a legal effect or a similarly significant effect, and the ICO gives changing a worker's pay as an example of a similarly significant effect. If software deducts the money and nobody reviews it first, treat it as a solely automated significant decision and have the Article 22C safeguards in place.

Can a failed face check stop someone clocking in?

Not with nothing behind it. Facial recognition used to identify a worker is special category biometric data, and Article 22B restricts significant solely automated decisions based on it. The ICO's guidance says manual review must be available when an automated check denies access, and workers who ask for one must not be disadvantaged. A PIN route or a supervisor who can clock the person in covers it.

Do I have to tell workers we use automated decision-making?

Yes, where the decisions fall under Article 22C. Articles 13(2)(f) and 15(1)(h) require meaningful information about the logic involved and the significance and envisaged consequences for the worker, in your privacy notice and again in answer to a subject access request.

Do I need a DPIA for automated decisions about staff?

Usually. Article 35(3)(a) requires one for systematic and extensive evaluation of people based on automated processing, including profiling, where decisions with legal or similarly significant effects follow. The ICO says a DPIA is required before using biometric data to identify workers.

How quickly must an employer acknowledge a data protection complaint from a worker?

Within 30 days. Section 164A of the Data Protection Act 2018, in force from 19 June 2026, requires a controller to make complaints easy to submit, including electronically, acknowledge each one within 30 days, look into it without undue delay and tell the complainant the outcome.

Where hours fit in

Temporra records the hours people actually work: clock-in and clock-out against a job and a site, on a phone or a shared site tablet, with the location checked against the site's geofence at those two moments. It sends alerts for things like late arrivals and overtime, and timesheets go to a manager to approve. It doesn't score or rank workers, and it doesn't decide anything about them. Every one of those calls stays with a person at your firm.

The face check is optional and needs each worker's explicit consent at setup. It compares a live photo, processed on the device, against a stored template of 128 numbers. It isn't a liveness test, so treat it as one control against buddy punching, not proof of identity. There's a PIN route on the site kiosk for anyone who'd rather not use it. Temporra doesn't build your rota either.

Related guides

All Temporra guides →

Track hours in Temporra →

No card needed for the trial. One flat monthly price by team size, from £39 for up to five workers, VAT included. See pricing.