The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026

Type Statutory-Instrument
Publication 2026-04-16
State In force
Department King's Printer of Acts of Parliament
PDF Download
articles Not indexed
Reform history JSON API

Made: 16th April 2026

Laid before Parliament: 21st April 2026

Coming into force: 12th May 2026

The Secretary of State makes these Regulations in exercise of the powers conferred by section 124A(1) and (2) and section 124B(11) of the Data Protection Act 2018[^f00001]. In accordance with section 182(2) of that Act, the Secretary of State has consulted the Commissioner and such other persons as the Secretary of State considers appropriate.

Citation, commencement, extent and interpretation

1

The code of practice

2

Modification to panel requirements

3

Section 124B of the 2018 Act applies to the preparation or amendment of the code of practice required under regulation 2 as if after subsection (7) there were inserted—

(7A) The panel must not consider or report on any aspect of the code relating to national security.

Signed

Ian Murray — Minister of State — Department for Science, Innovation and Technology — 16th April 2026

Explanatory note

(This note is not part of the Regulations)

Explanatory Note

These Regulations require the Information Commissioner (“the Commissioner”) to prepare a code of practice on the processing of personal data under relevant data protection legislation in relation to developing and using artificial intelligence and automated decision-making. Relevant data protection legislation is defined in regulation 2 as the UK GDPR and the Data Protection Act 2018 (“the 2018 Act”), except Part 4 (intelligence services processing).

Regulation 3 modifies the requirements under section 124B of the 2018 Act for the Commissioner to establish a panel of individuals to consider the code of practice by providing that the panel must not consider or report on any aspect of the code of practice relating to national security.

A full impact assessment has not been produced for this instrument as no, or no significant, impact on the private, voluntary or public sector is foreseen as a result of the instrument itself. The Commissioner is required to produce an impact assessment when preparing the code of practice under these Regulations.

Footnotes

[^f00001]: 2018 c. 12. Sections 124A and 124B were inserted by sections 92(2) and 93, respectively, of the Data (Use and Access) Act 2025 (c. 18). Commissioner is defined in section 3(8) of the Data Protection Act 2018 as the Information Commissioner.

[^f00002]: See section 124A(7) of the Data Protection Act 2018 for the meaning of “good practice in the processing of personal data”.

[^f00003]: Article 22C was inserted by section 80 of the Data (Use and Access) Act 2025. See section 3(10) of the Data Protection Act 2018 for the meaning of “the UK GDPR”.

[^f00004]: Section 50C was inserted by section 80 of the Data (Use and Access) Act 2025.

Reading this document does not replace reading the official text published on legislation.gov.uk. Contains public sector information licensed under the Open Government Licence v3.0. We assume no responsibility for any inaccuracies arising from the conversion of the original CLML XML to this format.

This text is published under legislation.gov.uk's own terms of reuse, not a Legalize or public-domain licence. legislation.gov.uk
Open Government Licence v3.0 (attribution required)
© Crown and database right. Derived from content available under the Open Government Licence v3.0 from legislation.gov.uk.