What a data protection impact assessment has to record when candidate checks are automated

What a data protection impact assessment has to record when candidate checks are automated

Step 2 of the Information Commissioner's Office sample data protection impact assessment template carries one prompt: "What types of processing identified as likely high risk are involved?" One line in a Word document, with a box under it. Leave that box empty on an assessment covering automated candidate checks across a hospital group, and the rest of the document has nothing to stand on. The answer names the criterion that made the assessment mandatory.

It stays empty for a reason that is not the author's. The article governing automated decisions was replaced on 5 February 2026. No regulations define its central term, and the regulator's detailed guidance is still a draft. Whoever writes this document records their own reasoning, because nothing external supplies it.

Four separate grounds make this data protection impact assessment mandatory

Automated candidate checks at a hospital group hit four separate grounds, and the first three are each sufficient on their own.

The first two sit on the face of the Regulation. Article 35(3)(a) catches "a systematic and extensive evaluation of personal aspects" based on automated processing, where decisions "produce legal effects concerning the natural person or similarly significantly affect" them. Article 35(3)(b) catches large-scale processing of the special categories at Article 9(1) or of "personal data relating to criminal convictions and offences referred to in Article 10". A clinician's onboarding file contains both.

Two more grounds sit on the ICO's published list of high-risk processing. Its denial of service entry covers decisions about access to "a product, service, opportunity or benefit that is based to any extent on automated decision-making (including profiling) or involves the processing of special category data". The phrase "to any extent" catches a partly automated shortlisting step. The fourth ground is innovative technology, and the ICO requires that to be combined with one of the European guidelines criteria.

The statute changed on 5 February 2026 while the guidance stayed in draft

Section 80(1) of the Data (Use and Access) Act 2025 substituted Article 22 of the UK GDPR with Articles 22A to 22D. They came into force on 5 February 2026. Nothing in the new regime is future-dated.

Everything then turns on one definition. Article 22A(1)(a): "a decision is based solely on automated processing if there is no meaningful human involvement in the taking of the decision". A significant decision is one that "produces a legal effect for the data subject" or "has a similarly significant effect".

Safeguards attach as soon as that involvement is missing. Where a significant decision is solely automated, Article 22C(2) requires measures which "(a) provide the data subject with information about decisions described in paragraph 1 taken in relation to the data subject; (b) enable the data subject to make representations about such decisions; (c) enable the data subject to obtain human intervention on the part of the controller in relation to such decisions; (d) enable the data subject to contest such decisions". That is four separate measures, and the assessment has to name which system delivers each one.

No one outside your organisation can define meaningful human involvement for you. Article 22D(1) lets the Secretary of State define it by regulations. None had been made as at 23 August 2026. Article 22A(1)(a) is all there is. The ICO's draft guidance closed its consultation on 29 May 2026 and no final version has followed. Every ICO page cited here says it is under review because of the Data (Use and Access) Act.

Health data and criminal offence data sit under different tests

Special category data narrows the options. Article 22B(1) is the clause to read first. "A significant decision based entirely or partly on processing described in Article 9(1) (processing of special categories of personal data) may not be taken based solely on automated processing, unless one of the following conditions is met".

Only two conditions are available. The first is explicit consent. The second is a decision necessary for a contract with the data subject, or one required or authorised by law, and in either of those two cases Article 9(2)(g) must also apply. That brings in a substantial public interest condition from Schedule 1, Part 2 of the Data Protection Act 2018.

Occupational health output and work health assessments are Article 9 data. Disclosure and Barring Service output is not. Criminal offence data sits under Article 10, needing a lawful basis plus official or legal authority and a Schedule 1 condition. The ICO's draft guidance says the provisions apply "even if you use a small amount of special category data, including what is inferred".

A second prohibition sits at Article 22B(4), and it can invalidate a design. A significant decision may not be taken on a solely automated basis where the processing relies "entirely or partly" on Article 6(1)(ea). That is the recognised legitimate interests basis, inserted by the same Act on the same day. An assessment recording it for an automated check has recorded something that cannot lawfully be built.

What a data protection impact assessment must contain as a minimum

The minimum content is the spine of the document:

"The assessment shall contain at least: (a) a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller; (b) an assessment of the necessity and proportionality of the processing operations in relation to the purposes; (c) an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and (d) the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned."

The ICO's step 2 expands limb (a) into a checklist. It asks how the data is collected, stored and used, who has access to it and who it is shared with. Retention periods, security measures and the flagged screening criteria go in the same box.

The ICO says employees may count as a vulnerable group, because a power imbalance means they cannot easily consent to or object to their employer's processing. A candidate stands in the same relation earlier still.

There is no per-site carve-out. Where you cannot reliably separate the people who will experience a significant effect from those who will not, the draft guidance says to apply the safeguards to all the decisions.

Necessity is the section that thins out

Step 4 asks whether the plan achieves the purpose, and whether a less intrusive route reaches it. The record has to carry the lawful basis, how function creep will be prevented, how data quality and data minimisation will be ensured, and the measures ensuring processors comply. The draft guidance disposes of the commonest shortcut. "It's also not enough to argue that using ADM is 'necessary' because you choose to operate your business in a particular way. The question is whether this is objectively necessary for your stated purpose."

A compliance record that becomes a performance record is the drift information governance exists to catch. Minimisation has a timing dimension too. The ICO's draft recruitment guidance says that where possible only successful candidates' information should be verified, and that verifying earlier has to be justified. Across four sites, that changes which checks run at which stage.

A check will sometimes produce a discrepancy with what the candidate said. The same guidance expects a written process, a chance for the candidate to explain, and their explanation weighed in the decision. Both that guidance and the vetting guidance are draft, and both predate the Data (Use and Access) Act.

Two versions of the same sign-off meeting

A group takes its data protection impact assessment on an automated candidate-checking pilot to step 7 sign-off in week one. Three boxes have no answer in them. Step 2 names no high-risk screening criterion. Controllership is not split phase by phase, and a checking provider can be controller for some phases and processor for others. Nothing says whether human overrides of an automated outcome are logged. Without them the data protection officer cannot advise on the step 6 measures, so the residual risk against special category data stays unrated. An unrated risk on Article 9 processing reads as high risk, which brings Article 36 into play. The Commissioner has up to eight weeks to provide written advice, extendable by six. The pilot moves a quarter.

The same pilot with those three answers assembled first differs only in sequence. The criterion is named, controllership is recorded phase by phase, and the override log is named as a system output with a retention period. Residual risk is rated and the step 6 measures are approved. No Article 36 consultation arises, and the pilot starts on schedule.

What a platform can put into the record

The vendor question set is a separate artefact; this document is the buyer's own.

A logged activity trail records what happened on a candidate file, when, and under whose account. That is the step 2 answer on how the data is used. It is also the override record: each time a person reverses or confirms an automated outcome, a dated entry names them. Role-based access control records which roles can see which document types, which answers step 2 on who has access. Where the check set is configurable, the record shows which documents were requested for which post, the data minimisation entry at step 4.

Credentially's data processing agreement and security documentation supply the processor terms and security measures the record references. No platform supplies the lawful basis, the necessity reasoning, the significance finding, or the judgement about whether human involvement in a given check is meaningful. Those are the sections a signed-off data protection impact assessment is judged on.

Sequencing, and what has to happen before a pilot starts

The controller must seek the data protection officer's advice where one is designated, under Article 35(2).

Step 7 makes the ordering explicit. Measures approved by a named person, with actions written into the project plan against a date and an owner. Residual risks approved by a named person, with any accepted residual high risk meaning the ICO is consulted first. Advice provided, then accepted or overruled, with reasons recorded.

The draft guidance adds one further ordering point. The assessment decides whether the automated decision-making provisions apply at all, which puts it before the design decision.

Name the screening criterion, record the controllership split phase by phase, and get the data protection officer's advice onto the document before the first live candidate file enters the system. Article 36(3) requires a controller consulting the Commissioner to supply, where applicable, the respective responsibilities of the controller, joint controllers and processors involved in the processing. That applies "in particular for processing within a group of undertakings", which is where a multi-site group already sits.

References

  1. Data (Use and Access) Act 2025, section 80 (automated decision-making). https://www.legislation.gov.uk/ukpga/2025/18/section/80
  2. The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, S.I. 2026/82, regulation 2(j). https://www.legislation.gov.uk/uksi/2026/82/regulation/2/made
  3. UK GDPR, Article 22A. https://www.legislation.gov.uk/eur/2016/679/article/22A
  4. UK GDPR, Article 22B. https://www.legislation.gov.uk/eur/2016/679/article/22B
  5. UK GDPR, Article 22C. https://www.legislation.gov.uk/eur/2016/679/article/22C
  6. UK GDPR, Article 22D. https://www.legislation.gov.uk/eur/2016/679/article/22D
  7. UK GDPR, Article 6, including Article 6(1)(ea). https://www.legislation.gov.uk/eur/2016/679/article/6
  8. UK GDPR, Article 35. https://www.legislation.gov.uk/eur/2016/679/article/35
  9. UK GDPR, Article 36. https://www.legislation.gov.uk/eur/2016/679/article/36
  10. Information Commissioner's Office, "When do we need to do a DPIA?". https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/when-do-we-need-to-do-a-dpia/
  11. Information Commissioner's Office, "How do we do a DPIA?". https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/how-do-we-do-a-dpia/
  12. Information Commissioner's Office, "Examples of processing likely to result in high risk". https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/examples-of-processing-likely-to-result-in-high-risk/
  13. Information Commissioner's Office, sample DPIA template. https://ico.org.uk/media2/migrated/2553993/dpia-template.docx
  14. Information Commissioner's Office, "Automated decision-making, including profiling", draft guidance updated 31 March 2026. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making-and-profiling/
  15. Information Commissioner's Office, "When can we use special category data in our ADM?", draft. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/when-can-we-use-special-category-data-in-our-adm/
  16. Information Commissioner's Office, "What else do we need to consider?", draft. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/what-else-do-we-need-to-consider/
  17. Information Commissioner's Office, "How do we carry out ADM lawfully?", draft. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/how-do-we-carry-out-adm-lawfully/
  18. Information Commissioner's Office, consultation on the draft ADM guidance, 31 March to 29 May 2026, status closed. https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/2026/03/ico-consultation-on-the-draft-guidance-about-automated-decision-making-including-profiling/
  19. Information Commissioner's Office, "Verifying candidates", draft. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/recruitment-and-selection/verifying-candidates/
  20. Information Commissioner's Office, "Pre-employment vetting of candidates", draft. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/recruitment-and-selection/pre-employment-vetting-of-candidates/
  21. Information Commissioner's Office, "Automated decision-making and profiling for recruitment and selection", draft. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/recruitment-and-selection/automated-decision-making-and-profiling-for-recruitment-and-selection/

All sources accessed 23 August 2026.

What a data protection impact assessment has to record when candidate checks are automated
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.