What counts as an automated decision
An automated decision, in the legal sense that matters here, is one made about a person with no meaningful human involvement in shaping the result. The concern is not that a computer is involved somewhere in the process, since almost every police decision today involves some computer system, but that a system's output becomes the actual decision affecting someone, rather than one input a human then genuinely considers before deciding for themselves. A risk score that a custody officer glances at without it affecting their judgement is different in law from a risk score that automatically determines bail conditions with no real opportunity for a human to reach a different conclusion.
Policing in England and Wales is governed here by a specific and separate part of data protection law from the general rules that apply to most automated decisions elsewhere in the economy. Where consumer facing businesses are generally subject to the automated decision-making provisions of the UK GDPR, law enforcement processing of this kind falls instead under Part 3 of the Data Protection Act 2018, and specifically sections 50A to 50C, which apply their own test of what counts as a significant decision requiring safeguards.
The general law changed significantly in 2026, but policing runs on its own track
It matters to understand that the wider legal landscape shifted substantially in early 2026, even though the change did not directly rewrite the police specific rules. Section 80 of the Data (Use and Access) Act 2025 replaced the old Article 22 of the UK GDPR, which operated as a near prohibition on solely automated decisions with significant effects, permitted only in narrow circumstances such as explicit consent or a specific legal authorisation. In its place, new Articles 22A to 22D, which came into force on 5 February 2026, establish what is best described as a safeguards regime: automated decisions with significant effects are now permitted for most ordinary personal data provided the required safeguards are in place, a materially more permissive default than before, though special category data, the classification that covers biometric information such as facial images, fingerprints and DNA, continues to be treated more restrictively.
The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, made in April and in force from 12 May 2026, gave the Information Commissioner's Office a statutory duty to produce a code of practice covering this area. Because policing sits under the separate sections 50A to 50C test rather than the reformed general Article 22 regime, the practical question for any policing system is not whether it falls foul of the newly liberalised general rule, but whether it produces an adverse legal effect, or a similarly significant adverse effect, on the person concerned under the law enforcement specific test, which has not been relaxed in the same way.
Where this actually arises in policing
The provisions bite hardest where a system's output could plausibly determine, on its own, something that matters to a person's liberty or legal position: a risk assessment tool that flags someone as high risk of reoffending and thereby shapes a bail or sentencing recommendation, an algorithm used to prioritise which reports of crime receive active investigation and which are effectively filed without one, or automated triage systems in custody or in call handling that assign a priority level a human then follows without independently reassessing the underlying facts. Whether any specific system crosses the line into requiring the statutory safeguards depends heavily on how much genuine, documented discretion the human reviewer retains at the point the decision is actually made, not merely on whether a human's name appears somewhere in the process.
Where the safeguards regime does apply, the individual affected is generally entitled to be given information about the processing, an opportunity to make representations, meaningful human intervention rather than a token review, and a right to contest the outcome. Enforcement of what counts as meaningful human intervention in a policing context, as distinct from a rubber stamp on a machine generated output, remains one of the more contested practical questions in this area, since a busy officer under time pressure reviewing a system's recommendation does not always have the time, training or organisational incentive to genuinely second guess it.
What is not settled
Whether current policing practice around automated triage, risk scoring and prioritisation tools genuinely satisfies the meaningful human involvement test, as opposed to functioning as automated decision-making in substance while retaining a human sign off in form, has not been comprehensively tested through litigation or regulatory enforcement in the way the Bridges judgment tested facial recognition. The Information Commissioner's forthcoming statutory code of practice, mandated by the 2026 regulations, is expected to give clearer operational guidance, but had not been published in final form as this was written. Because the general UK data protection regime became more permissive toward automated decisions in February 2026 while the police specific test under the Data Protection Act 2018 was left unchanged, there is also a growing gap between how these questions are analysed for policing systems and for equivalent automated decisions made elsewhere in public life, a divergence that is likely to generate its own confusion and disputes as both frameworks continue to develop separately.
Follow the coverage
PoliceAI News tracks every automated decision-making story from across the English-speaking world as it breaks: new deployments, court rulings, parliamentary debates, academic research, and community responses. The feed refreshes every 30 minutes.
View Live Automated Decision-Making StoriesYou can also browse every automated decision-making story in the feed, or explore every subject PoliceAI News covers.