Automated decisions in a broker inbox: what changed for UK brokerages in February 2026
On 5 February 2026 the UK replaced Article 22 with Articles 22A to 22D. What a brokerage running AI replies, risk scores and lifecycle triggers must now show.
Article 35 does not care that your AI only drafts replies. The screening test a brokerage should run before switching it on, and what to write down after.
Every brokerage that puts AI anywhere near its client inbox eventually gets the same question from its compliance lead, its network or its professional indemnity broker: did you do a DPIA? The honest answer in most firms is "we opened the template and it stalled", usually because the first section asked about training data and the firm does not train anything. That is the wrong place to start. A data protection impact assessment under Article 35 of the UK GDPR is not a questionnaire about machine learning. It is a written argument about whether one specific processing operation is likely to result in a high risk to the people whose data you hold, and what you did about it.
Here is the version that fits a brokerage: what triggers the obligation, how to run the screening test feature by feature, what the assessment must contain, and — the part firms skip — what to record when you conclude that you do not need one.
Article 35(1) requires a DPIA where processing is likely to result in a high risk to the rights and freedoms of individuals. Article 35(3) names three cases that always qualify: systematic and extensive automated evaluation of personal aspects producing legal or similarly significant effects; large-scale processing of special category or criminal offence data; and large-scale systematic monitoring of a publicly accessible area.
On top of that, the ICO publishes its own list of processing that requires a DPIA in the UK and points to the nine screening criteria from the European guidelines. Two of those criteria touch almost every broker AI project: use of innovative technology, and profiling or automated decision-making used to help decide someone's access to a service. The ICO's position is that innovative technology combined with any other criterion takes you into DPIA territory, and the European guidance suggests two or more criteria normally does — though a single criterion can be enough where the risk is plain. Note what is absent from all of this: any question about whether you built the model. Buying it changes nothing.
Firms in Ireland, the Netherlands, Germany and the rest of the EU sit under the same Article 35 in the EU GDPR, with the added step that their own supervisory authority publishes a national list of processing operations for which a DPIA is mandatory. Read that list before you rely on a UK-shaped conclusion.
The common mistake is to assess "the AI" as one thing. A typical deployment in a brokerage is three or four distinct operations, and they do not score the same.
| What the system does | Criteria it touches | Realistic conclusion |
|---|---|---|
| Drafts a reply that a named adviser reads, edits and sends | Innovative technology only | Usually no DPIA — but record the reasoning |
| Classifies inbound messages by sentiment and intent, and routes them to a queue | Innovative technology; systematic evaluation | Borderline; the assessment is cheap insurance |
| Scores clients for attrition risk and engagement, and those scores build a campaign list | Innovative technology; profiling; systematic evaluation | Do the DPIA |
| Sends replies automatically, with no person reading them first | Innovative technology; automated decision-making affecting service | Do the DPIA, and define the escalation rules inside it |
| Any of the above across health, life or protection conversations | Adds special category data | Do the DPIA; the health data changes the answer |
That last row catches more brokers than expect it. A private medical or protection client who describes a diagnosis on WhatsApp so you can check an exclusion has handed you special category data, and it now sits in a system a model reads. Whether a book of a few thousand health clients is processed "on a large scale" is arguable; whether you want to have that argument for the first time in front of the ICO is not.
The scoring row deserves the same care. An attrition risk score is profiling in the Article 4 sense the moment it is computed automatically to evaluate a client. It only becomes an Article 22 decision if it produces legal or similarly significant effects with no human involvement — which it usually does not when the output is a call list. Write down which of the two you are doing, because that sentence is the one an auditor will look for.
Article 35(7) sets the minimum, and it is shorter than most vendor templates suggest. Translated into broker language, seven things:
Consult your data protection officer if you have one. The ICO also expects you to seek the views of the people affected where appropriate — for a brokerage that rarely means a client survey, but it does mean your client-facing staff, who will tell you exactly which conversations should never be automated.
Article 36 requires prior consultation with the ICO where a DPIA indicates a high risk that you cannot mitigate. Brokers almost never need to file, because the mitigation that removes the risk is the obvious one: keep a person on the send button for anything carrying sentiment, money or cover. If you find yourself writing "residual risk: high" next to automatic replies, the fix is to narrow the rules, not to write to the regulator.
This is also where the DPIA stops being a data protection document and starts overlapping with your conduct paperwork. The Consumer Duty governance questions and, for EU-facing firms, the classification work in the EU AI Act ask about the same controls from different angles. Write the controls once and cite them three times, rather than maintaining three versions that drift apart.
Accountability under Article 5(2) means you can demonstrate the decision, not just make it. Keep a one-page screening note per feature: what it does, which criteria you considered, why the answer was no, who decided and when. That page is what you hand to your network or the ICO when asked, and it is what makes the next decision fast — the day someone widens the rules so replies go out unread, you reopen the note and the answer flips.
In ORIS the inputs a DPIA asks for are visible rather than inferred: auto-reply rules carry a cooldown and a cap per client, a negative-sentiment message produces a draft in the queue instead of an outgoing message, risk and engagement scores sit on the customer record, and audit logs plus CSV export give you evidence to attach to the assessment. None of that writes the DPIA for you, but it means describing the flow is a matter of reading settings rather than guessing. If you want to see those controls before you commit them to paper, ask for a walkthrough, and browse the rest of our writing on AI in a brokerage.
Usually not, but you should still run and record the screening. Assisted drafting with a person reviewing every message touches the innovative technology criterion alone, which the ICO generally treats as insufficient on its own. Add health conversations or automatic sending and the answer changes.
No. The obligation sits with you as controller and the assessment has to describe your processing: your book, your lawful basis, your retention, your escalation rules. A supplier document is useful evidence for the processor section and nothing more.
Yes. Article 35 requires it prior to the processing, which is the whole point — it is a design tool. A DPIA written after go-live is a remediation record, and regulators read it that way.
There is no obligation to publish, though the ICO encourages publishing at least a summary where it would build trust. Most brokerages keep it internal and reference its existence in the privacy notice section covering automated processing.
If you already know your data flows, a focused half day per feature is realistic, plus review. The time sink is never the form; it is discovering that nobody could say where WhatsApp media files were stored or for how long.
Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.
On 5 February 2026 the UK replaced Article 22 with Articles 22A to 22D. What a brokerage running AI replies, risk scores and lifecycle triggers must now show.
EIOPA's opinion on AI governance covers intermediaries, not only insurers. What its six areas ask of a brokerage running AI in a shared WhatsApp inbox.
Your brokerage runs AI-assisted replies. What MIPRU 3.2 obliges you to hold, and what the Insurance Act 2015 duty of fair presentation means at renewal.