Data Ethics for Business: Where the Law Stops Being Enough
Data ethics is what is left once the lawyers have finished. Compliance answers whether you may do something with personal data. Ethics answers whether you should, and 2026 has been a year of the law quietly widening that gap rather than closing it.
Automated decisions loosened: the Data (Use and Access) Act 2025 permits solely automated decisions with significant effects by default, subject to safeguards, rather than banning them with exceptions.
A statutory AI code is coming: regulations made on 16 April 2026 and in force from 12 May 2026 require the Information Commissioner to write a code of practice on AI and automated decision-making.
The EU pushed its deadline: high-risk obligations under Annex III of the AI Act now bite on 2 December 2027, though the Article 50 transparency duties applied from 2 August 2026.
Complaints became mandatory: from 19 June 2026 every organisation processing personal data must run a data protection complaints process, acknowledging within 30 days.
Why the gap is growing
For most of the last decade, UK and EU data law moved in one direction: more restriction, more documentation, more prohibition. An organisation that did the compliance work thoroughly could reasonably claim to be behaving well, because the law was drawing the ethical line for it.
Three changes in the last eighteen months have broken that arrangement.
First, the Data (Use and Access) Act 2025, which received royal assent on 18 June 2025 and has been commencing in phases since, rewrote the automated decision-making rules. Where Article 22 of the UK GDPR previously started from a prohibition on solely automated decisions with legal or similarly significant effects, the reformed regime starts from permission, with procedural safeguards attached and tighter treatment reserved for special category data. Nothing about the risk to the individual changed. Only the default did.
Second, the EU moved its own goalposts. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It defers the high-risk obligations for standalone Annex III systems from 2 August 2026 to 2 December 2027, and for AI inside regulated products under Annex I to 2 August 2028. The transparency obligations in Article 50 were left alone and applied from 2 August 2026. An organisation that had built a 2026 compliance programme now has a gap of sixteen months in which the law asks less of it than its own risk assessment did.
Third, and cutting the other way, the UK created a statutory hook for guidance. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 were made on 16 April 2026 and came into force on 12 May 2026. They require the Information Commissioner to prepare a code covering the development and use of AI and automated decision-making, with specific attention to children's personal data, under sections 124A and 124B of the Data Protection Act 2018 as inserted by the DUAA. The code will apply to processing under the UK GDPR and the Data Protection Act 2018, excluding the intelligence services provisions in Part 4.
Read together: the binding rules on automated decisions got looser, the binding deadline for high-risk AI moved further away, and the only thing filling the space is guidance that has not been published yet. That space is data ethics, and it is where the reputational risk now lives.
The four questions that make up a usable test
A data ethics framework that people actually use is short. Four questions, asked of any new use of personal data, before the build rather than after it.
- Would the person be surprised? Not "did we disclose it" but "would they have predicted it". Surprise is the single best predictor of complaint volume, and it is easy to test: describe the processing in one sentence to somebody outside the project and watch their face.
- Who carries the cost of an error? Every system is wrong sometimes. The ethical question is whether the person who bears the consequence is the same person who chose to run it. A fraud model that declines a legitimate customer costs the customer time and costs you nothing automatically, which is exactly why it drifts.
- Does it work equally well for everyone? Performance averages hide subgroup failure. A model that is 95 per cent accurate overall and 70 per cent accurate for a minority of users is not a good model with a rounding error, it is two models. See algorithmic bias explained.
- Can a person get a decision reversed? Not appeal into a void. A named route, a human with authority to overturn, and a timescale. With the automated decision default now reversed in law, this is the safeguard doing the real work.
Where lawful and ethical actually part company
- Inference. Data volunteered for one purpose predicting something never volunteered at all: health from purchase history, financial distress from payment timing, pregnancy from browsing. Legally this is a purpose limitation and lawful basis question. Ethically it is the sharpest one there is, because the person never disclosed the sensitive fact and cannot correct it.
- Secondary use for model training. Customer conversations, support tickets and uploaded documents are the most tempting training corpus in any business and the one customers least expect to be used. If the answer to "would they be surprised" is yes, an opt-out buried in updated terms does not fix it.
- Workplace monitoring. Productivity scoring, keystroke telemetry and location tracking are mostly lawful with the right notice and assessment. Whether they are proportionate to the problem being solved is a separate judgement, and one that boards should make rather than delegate to a tooling decision.
- Children. The incoming ICO code has been told to pay particular attention to children's data, which is a signal about where enforcement attention will land. Anything that processes data about under-18s should be assessed on the assumption that the standard rises.
- Design patterns. Consent interfaces engineered so that agreeing takes one click and refusing takes six. Compliant on paper, and the clearest possible statement of what an organisation thinks of its customers.
Build it into the processes you already run
Nobody needs a new committee. Three existing artefacts will carry data ethics if you let them.
The data protection impact assessment is already mandatory for high-risk processing and already asks about necessity and proportionality. Add the four questions above to the template and the DPIA becomes an ethics review with a legal spine. Our guide to running a DPIA covers the ICO's seven steps.
The AI use policy should say what data may and may not be put into which systems, and who decides. See how to write an AI use policy and how to build an AI governance framework.
The complaints process is now a statutory obligation and is also your best early warning system. From 19 June 2026, under section 103 of the DUAA, every organisation processing personal data must offer a way to complain about data protection, acknowledge within 30 days and respond without undue delay. Complaints are free field research into which of your data practices people find unacceptable. Route them to the same people who approve new processing, not to a separate queue.
What to write down
Three documents, none of them long. A one-page statement of what your organisation will not do with data, approved at board level, because a prohibition list is more useful than a values list. A decision register recording the judgement calls, the reasoning and who made them, because the value of an ethics process is almost entirely in being able to show the reasoning later. And a review trigger: any material change to a model, a data source or a purpose goes back through the four questions. The related guide on responsible AI principles covers the technical controls that sit under this.
Frequently Asked Questions
What is data ethics in business?
Data ethics is the set of judgements an organisation makes about personal data where the law leaves it a choice. Data protection law tells you whether you may process something; data ethics asks whether you should, given who is affected, what they would expect and what happens when the system is wrong. The two overlap but they are not the same discipline, and the space between them grew in 2026 rather than shrank.
Is data ethics the same as GDPR compliance?
No. Compliance is a floor and it is enforceable; ethics is a judgement and it is not. A great deal of processing is perfectly lawful and still corrosive: inferring a health condition from shopping data, scoring a job applicant on a proxy for age, retraining a model on customer conversations that were never offered for that purpose. None of those necessarily breaks the law. All of them lose customers when they surface.
What changed for automated decisions under the Data (Use and Access) Act 2025?
The Act, which received royal assent on 18 June 2025, reworked the automated decision-making regime so that decisions based solely on automated processing with legal or similarly significant effects are now permitted by default, subject to procedural safeguards, rather than prohibited with narrow exceptions. Tighter rules still apply where special category data is involved. The practical effect is that the question of whether a machine should decide has moved from the lawyer's desk to the ethics one.
Is the ICO writing a code of practice on AI?
Yes, and it is now a statutory requirement. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 were made on 16 April 2026 and came into force on 12 May 2026. They require the Information Commissioner to prepare a code on developing and using AI and automated decision-making, with particular attention to children's personal data, using powers inserted into the Data Protection Act 2018 by the Data (Use and Access) Act 2025.
Has the EU AI Act been delayed?
Parts of it. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It defers the high-risk obligations for standalone Annex III systems to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. The Article 50 transparency obligations, telling people they are dealing with a machine and labelling synthetic content, were not deferred and applied from 2 August 2026.
Do we have to have a complaints process for data protection?
Yes, from 19 June 2026, under section 103 of the Data (Use and Access) Act 2025. Every organisation processing personal data must provide a way for people to complain about data protection, acknowledge a complaint within 30 days and respond without undue delay. It applies whatever the size of the organisation, and an existing complaints route can be adapted rather than replaced.
Sources
- The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, for the date made, the coming into force date and the scope of the code
- Data (Use and Access) Act 2025, for royal assent and the complaints duty in section 103
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, for the deferred high-risk dates and the unchanged Article 50 transparency obligations
More from E-Business Ethics: AI ethics in business, the EU AI Act explained for UK business and how to write a code of conduct.
Checked on 12 September 2026. This is general guidance, not legal advice; confirm the position with your data protection officer or legal adviser before relying on it.