The provision everybody quotes has been repealed
Almost every page on GDPR and automated chasing quotes Article 22 UK GDPR and its three exceptions. That text has gone, substituted by new Articles 22A to 22D by section 80 of the Data (Use and Access) Act 2025, fully in force on 5 February 2026.
The structure was inverted. The old provision banned solely automated significant decisions except on contract, authorisation by law or explicit consent. The new one allows them on any lawful basis except the recognised legitimate interests basis in Article 6(1)(ea), provided the Article 22C(2) safeguards are in place: information about the decision, the ability to make representations, to obtain human intervention, and to contest it.
Article 22B leaves two narrow prohibitions, for special category data and for processing relying on Article 6(1)(ea). Debt recovery isn't among the recognised legitimate interests, so your chasing runs on ordinary legitimate interests or on contract, and the ICO's worked example treats debt recovery as an interest your customers would expect.
The regulator's site currently says both things
That's a fact about the state of the guidance and not a criticism of the ICO. Its page on Article 22 and fairness in AI still sets out the three repealed exceptions, under a notice saying it's under review, while its Act pages say the Act "opens up the full range of reasons, or 'lawful bases', that you can rely on" for significant automated decisions. The replacement guidance on automated decision-making is draft, and its consultation closed on 29 May 2026 with no final version we could find.
Does a reminder engage that regime? Our reading
No regulator has addressed invoice chasing by name in anything we could find, so what follows is our reading. Article 22A(1) sets two tests, and a reminder looks weak against both.
Escalation is the genuinely unsettled part
An automated decision to stop an account, add a fee or refer a debt to an agency alters what your customer owes or can buy, and against a sole trader it resembles the ICO's own example of a similarly significant effect, an online credit application refused automatically. Our view is that it may well be a significant decision, and no more firmly than that.
Article 22D lets the Secretary of State define both "meaningful human involvement" and what counts as a similarly significant effect by regulations, and so far as we could establish none had been made when this was written.
Confidentiality, and the junior colleague standard
If you're a practice, the sharper risk is your choice of tool. The PCRT bodies' guidance on the ethical use of AI tools of 19 January 2026 says at 4.2 that "the input of client data into publicly available AI tools is likely to constitute a breach of client confidentiality, unless the client has consented".
For the output, 3.4 gives the best practical standard available: treat it "as if it were prepared by a less experienced junior colleague and reviewed with appropriate scepticism". You'd read a junior's draft of a client letter before it went out.
The extra sentence that changes the legal category
A neutral payment reminder is a service message, so PECR's consent rules don't touch it. The ICO's direct marketing guidance counts reminders as service messages, and adds that "if your service message has elements that are direct marketing, even if that is not the main purpose of your message, then it will count as direct marketing".
Now think about what a generative model does when you ask it to make your reminder warmer. It adds a line about what else you offer, and that moves your email inside the direct marketing definition, where PECR wants consent or a soft opt-in for electronic mail to individual subscribers. The rule "does not apply to corporate subscribers", but sole traders and most partnerships are individual subscribers, who make up much of a practice's book.
Do you have to say the email was written by AI?
No UK rule requires it, on anything we could find. The ICO's transparency guidance for AI is about how you process personal data, and not about who composed a message.
The EU AI Act carries the duty people have heard about, and it doesn't reach you if you're a UK business chasing UK customers. Article 50(1) obliges providers to design systems that interact directly with people so those people know "that they are interacting with an AI system", an instruction to whoever builds the system, in the EU.
| AI Act milestone | Date |
|---|---|
| Entry into force | 1 August 2024 |
| Prohibitions and AI literacy apply | 2 February 2025 |
| Governance and general-purpose model rules apply | 2 August 2025 |
| General application, including Article 50 transparency | 2 August 2026 |
| Digital Omnibus on AI in force | 27 July 2026 |
| Annex III high-risk obligations apply | 2 December 2027 |
| Annex I high-risk obligations apply | 2 August 2028 |
Dates from the European Commission and Regulation (EU) 2026/1744, which moved them again on 27 July 2026, so plenty of what you'll read about them is now wrong in a new way.
Where to put the gate, and what to keep
Our reasoning follows, and those four safeguards make a sensible target even outside Article 22C. Set your boundary by consequence. A first reminder on a small, undisputed invoice is the safest thing to run unattended, while a fee, an account stop or a threat of proceedings changes your customer's position, so a person signs those. Hold back anything to a customer who has raised a dispute, anything quoting an interest or fee figure, and your first send after any template change.
Retention has a principle and no number: Article 5(1)(e) wants personal data kept "no longer than is necessary", and no source we found gives a period for chasing correspondence. Your reasons are evidential, since what was demanded, of whom and when is what a money claim needs, so record what went out, on what trigger and who approved it.
Adfin's Customer Agents work on that split: you set the rules of engagement, and your messages send from your own domain with a reply that reaches you. Whether that collects more than your current sequence is not something anybody can show you yet, and what is agentic credit control? covers where boundaries go, while AI for credit control goes stage by stage.
Common questions
Routine reminders are ordinary processing, and February 2026 moved UK law towards permitting automated decisions with safeguards. Keep client data out of public AI tools, read the copy, and keep a person in front of anything that changes your customer's position.
No. Articles 22A to 22D replaced Article 22 on 5 February 2026, and solely automated significant decisions are allowed on any lawful basis but one. Our reading is that your reminder isn't one.
It may be, particularly against a sole trader, since it resembles the ICO's example of a credit application refused automatically. That's our reading and not a ruling, and regulations could still redefine the deciding terms.
The PCRT bodies' January 2026 guidance says the input of client data into publicly available AI tools "is likely to constitute a breach of client confidentiality, unless the client has consented", and anything you do put in should be anonymised.
No UK legal duty requires it. The EU AI Act's transparency obligation binds providers of AI systems in the EU, so a UK business chasing UK customers falls outside it. Your professional body points at your engagement letter.
A neutral reminder is a service message, so the consent rules don't apply. Add a promotional line and the ICO's own wording puts it inside the direct marketing definition, where the rule reaches your sole trader customers.
Sources
Reviewed by the Adfin team. This is information about data protection law and professional conduct as at August 2026, not legal advice. UK law on automated decisions changed on 5 February 2026, the ICO's replacement guidance was still in draft, and regulations could still redefine two of the terms deciding whether automated escalation is caught. If you're planning to let software apply fees, stop accounts or refer debts unattended, take advice first.
