Data regulation in the age of AI and other data‑intensive technologies
Published 15 July 2026
Call for evidence
This call for evidence seeks practical examples of how personal and non-personal data regulation interacts with AI and other data-intensive technologies, and insights on how technological progress may change how data is used in the economy. We are interested in where legal, technical, and governance arrangements could enable data use and re-use and manage potential harms. We want to understand what is working well, where uncertainty remains, and where stakeholders see friction or challenge now and in future. This will help us assess whether further guidance, targeted changes or more fundamental reform is needed to ensure regulatory frameworks remain fit for this technological age.
Introduction
The Government is committed to making the UK the fastest-adopting AI economy in the G7, using AI across the public and private sectors to improve services and outcomes for citizens. We have already developed AI adoption plans in priority sectors, showing our ambition to maximise the benefits of these technologies. Delivering this will depend on technological capability, strong use cases, and the skills and resources to deploy AI effectively. Crucially, it will also depend on how well data is accessed, shared, governed and reused.
Data is essential to the development and deployment of AI and other data-intensive technologies. While most firms handle (83%) and analyse data (73%) and some even share or sell data (15%), few companies harness its full potential. Data driven companies operate across most sectors of the UK economy, contributing £85 billion in GVA in 2022 and employing 1.5m people2 in 2023. That is why the Government has positioned data as an asset and driver of economic growth, including through last year’s Industrial Strategy and sector plans. As these technologies evolve rapidly in scale and complexity, they offer significant benefits, whilst posing new risks and harms.
Different UK legal frameworks already govern how personal and non-personal data can be used. These include data protection law (UK GDPR, the Data Protection Act (DPA) and Privacy and Electronic Communications Regulations), parts of the Digital Economy Act, and sector-specific regulation and requirements such as in Health and Social Care sector, where de-identification, restricted access for approved purposes, and data minimisation are central to safeguarding of patient data. We have taken steps to modernise parts of this framework, including through the Data (Use and Access) Act, which made targeted amendments to data protection law, as well as setting up initiatives such as smart data schemes, to enable greater innovative uses of data.
However, advances in AI and other data-intensive technologies, alongside new supply chains and uses of data, may test how these rules are interpreted and applied in practice. If left unaddressed, this could create unintended consequences limiting positive benefits of new technology, or have implications for how we protect people, and levels of public trust.
In recognising this challenge, the government has begun gathering evidence on issues at the intersection of data, privacy and AI, such as through DSIT’s AI Growth Lab call for evidence. The Information Commissioner’s Office (ICO) has also examined how the existing data protection framework applies to AI, including through its generative AI consultation, and published guidance to support safe development and adoption. This reflects a wider international trend, with governments and regulators also considering how to respond to rapid technological change, as seen in aspects of the EU’s recent proposed digital omnibus package.
This work suggests that organisations face challenges in developing and adopting AI and other data-intensive technologies. For example, we are aware of issues in applying elements of the UK data protection framework, which plays an important role in safeguarding and regulating the use of personal data across the economy. Evidence gathered through the AI Growth Lab call for evidence highlighted challenges relating to lawful bases for large-scale personal data use (including special category data), data minimisation, purpose limitation, data subject rights, and roles and responsibilities across data-intensive supply chains. Uncertainty about compliance and legal risk may discourage AI adoption and limit the potential benefits to UK citizens of responsible AI use. Data regulation that provides effective and meaningful protections is essential in building public trust in AI and other data-intensive technologies, giving people confidence that innovations are being developed and deployed responsibly. We therefore want to ensure that organisations and individuals have confidence and clarity in the data protection regime providing important rights and protections, underpinning these innovative uses of data.
Beyond data protection, businesses and innovators have highlighted that AI creates more demanding personal and non-personal data requirements: larger and more diverse datasets, clearer provenance and permissions, metadata usable by both people and machines, and governance that works across the AI lifecycle and between organisations. Barriers to data access, sharing and interoperability may therefore constrain effective development and deployment. We want to better understand whether these are primarily technical or cultural adoption issues, or whether regulation is itself creating barriers to responsible data use. We also want to consider where other activities could further complement regulation in technology adoption, such as market-led data-sharing infrastructure initiatives, as seen in energy markets for example.
Taken together, this points to the need for a clearer understanding of how the UK’s approach to data should adapt to modern data-intensive technologies in practice.
The Government also recognises AI and data processing technologies are rapidly developing. Emerging capability, like agentic AI create new opportunities for the UK and highlight tensions with our existing data regulation. Through this Call for Evidence, we want to understand what those opportunities and tensions are, so that we can ensure our data regulation keeps the right balance between societal expectations of how people want to use data about themselves, while promoting innovation and growth in these technical capabilities.
We are interested in understanding where evolving technologies, such as synthetic data or privacy enhancing techniques (PETs) can enhance privacy, and where technological advancements may support in identifying and mitigating harms and improving regulatory compliance. We also seek views on where technological advancements in AI could make compliance more difficult, create unnecessary regulatory barriers to innovation and growth, or expose gaps in existing protections. Looking to the future in this way will help ensure that the UK’s data framework remains effective, proportionate and adaptable.
What we are asking for
We are seeking evidence from organisations and individuals with practical experience of developing, deploying, using, or enabling AI or other data‑intensive technologies. We welcome contributions from businesses and innovators with insight into the opportunities and regulatory challenges associated with these technologies. In addition to current experiences, we are interested in understanding how future technological developments may affect the operation of data regulation and its application in practice. This call for evidence focuses on gathering practical examples and insights into how personal and non-personal data regulation interacts with AI and data intensive technologies, including how these shape decisions, and support or inhibit data use.
Data-intensive technologies enable applications where the volume, velocity and complexity of the data are the primary engineering challenge, rather than compute. They include distributed databases and stream processing technologies that underpin applications such as ride-sharing services, video streaming and e-commerce. The call for evidence does not focus on AI issues relating to copyright or IP, on which separate public documents have sought views.
In addition to specific organisational knowledge, we are seeking evidence and views from researchers, civil society organisations, academics, and individuals to gain insight of those experiencing these technologies, as well as those analysing or observing their impacts.
You may respond to as many or as few themes as are relevant to your experience. We particularly welcome:
- short case studies or worked examples - explaining what you did, or what you would like to do but were unable to pursue, or are unsure how to approach;
- descriptions of governance or decision‑making processes (what you do in practice);
- operational detail on implementation of the relevant technology product or tool (technical, organisational, contractual); and
- any existing analysis, data, research, or evaluations you can share (including unpublished material).
Scope of this call for evidence
This call for evidence relates to:
- how personal and non-personal data regulation operates in practice, including: data protection law (including the UK GDPR and relevant provisions of the Data Protection Act 2018, including Part 3);
- personal and non-personal data access, governance and sharing arrangements; and
- sector‑specific and cross economy governance frameworks.
In this Call for Evidence, references to “data” may include both personal and non-personal data. Where relevant, we refer specifically to “personal data” to reflect the application of data protection legislation. Different legal frameworks apply depending on the nature of the data and how it is used, and respondents therefore may wish to distinguish between these in their answers. It would also be helpful if you could tell us where you are unsure which legal frameworks may apply to you or your organisation, as this will help us understand where uncertainty exists.
How this call for evidence is structured
This call for evidence is organised around five themes. These are:
- Accessing and using data;
- Data quality, accuracy and downstream impacts;
- Governing data use across organisations;
- Transparency and rights in complex data environments;
- Effectiveness of data frameworks in regulating AI.
Each theme includes:
- a short description of what we are seeking evidence on;
- prompt question(s) to help structure responses; and
- a short list of areas where we are particularly interested in evidence (to help you decide what to include).
You are free to submit evidence in the way that works best for you. You can respond to as many or as few themes as are relevant to your experience. If you only have evidence on one theme, a focused response is welcome.
How to respond
This call for evidence is open from 15 July 2026 and will close on 11:59pm on 9 September 2026.
To help us analyse the responses, please use the online system wherever possible and ensure you have submitted your response before exiting the question.
If you are not able to submit responses using the online form, please contact dataregulationandai@dsit.gov.uk for alternative ways to contribute.
In exceptional circumstances, if you need to submit a hard copy, please contact us at dataregulationandai@dsit.gov.uk and we will advise how to do this. Should you require another format (e.g. braille or large font) please contact alt.formats@dsit.gov.uk.
About you / your organisation (for context)
This section asks a small number of background questions to help us interpret evidence. You can skip any questions that are not relevant.
1. Are you responding as:
- an individual
- on behalf of an organisation
2. Name or organisation name (if responding on behalf of an organisation):
3. Organisation size (if applicable):
- Micro (fewer than 10)
- SME (10 to 249 employees)
- large enterprise (250+ employees)
- don’t know
4. Sector(s) you operate in (if applicable):
- Professional, Scientific, Technical
- Information and Communication
- Human Health, Social Care and Social Work
- Finance and Insurance
- Education
- Goods-producing sectors, manufacturing and construction
- Wholesale, Retail and storage
- Transport and Logistics
- Public sector
- Third/ charity sector
- Other
- Don’t know
5. Your role in relation to AI and other data‑intensive technologies (tick all that apply):
- developing AI or data-intensive systems
- deploying AI or data-intensive systems
- operating AI or data-intensive systems
- procuring AI or data-intensive systems
- providing enabling services (e.g. data brokerage, cloud, MLOps)
- none of the above/ role has no relation to AI
- other:
6. Which stages best describe your activities? (tick all that apply):
- data collection
- training/pre‑training
- fine-tuning
- evaluation/testing
- deployment/adoption
- monitoring
- none related to AI or other data-intensive technologies
- other (please state):
7. May we contact you to follow up on points in your response in more detail?
- yes
- no
If yes, please provide a contact email:
Themes
Theme 1 - Accessing and using data
Technological advancements are transforming how data is used across the economy. It is important that the UK’s data regulatory approach keeps pace with these developments, ensuring it matches societal expectations on data use, and has the right protections for individuals while supporting innovation and economic growth. This theme seeks evidence on how organisations access, prepare and use data (both personal and non-personal) in practice for AI systems and other data‑intensive technologies. We would like views based on current and likely future technological developments.
We understand that decisions about using data are shaped by a combination of practical constraints (such as what data is available, how it can be accessed, and how reuse is governed), legal requirements for personal data (such as data minimisation, purpose limitation, selecting a lawful basis) and organisational risk appetite. We are interested in how decisions about lawful use are made in practice, and how these interact with other issues such as data availability, reuse, interoperability and commercial arrangements. This evidence may inform wider work on public sector data infrastructure, including the National Data Library, where relevant.
Prompt question 1: What are the challenges you face, or can foresee emerging, when accessing and using personal and non-personal data when developing or using AI and data‑intensive technologies?
Prompt question 2: Regarding data protection, how do you assess and justify the lawful use of personal data in these contexts?
Prompt question 3: How appropriate are the data protection framework’s definitions/obligations outlined above and are they likely to remain fit for purpose as data-intensive technologies continue to evolve?
We are particularly interested in evidence relating to:
For all data (personal and non-personal):
- how ease of access to data for AI and other data intensive technologies differs compared to other uses;
- how permissions, licensing terms and legal requirements shape data use and reuse;
- the extent to which existing publicly available guidance supports decision making around data access;
- how provenance and metadata support confidence, traceability and appropriate use;
- how interoperability and system constraints affect data sharing, linkage and reuse across organisations and sectors (and where data sharing infrastructure could play a role);
- approaches to standardisation and simplification to enable innovative uses of data;
- what delivery models are used, and how these work in practice (e.g. APIs, intermediaries, accreditation arrangements, consent mechanisms, access controls or operational standards use);
- how access to public sector data supports the use of data‑intensive technologies, which public data sets are most valuable, and what barriers exist;
- how Smart Data schemes or other structured data access models could help address barriers;
- whether there are any specific regulatory barriers that impact an organisation’s ability to access and use data.
For personal data:
- how future developments in AI and other data‑intensive technologies may affect the application of the above regulatory obligations in practice;
- how lawful bases are selected and evidenced in practice, including approaches to the legitimate interest balancing test;
- how consent is used as a lawful basis for processing in AI systems, including agentic AI;
- how purpose specification and reuse of data are managed over time;
- how data minimisation is applied in large‑scale or complex datasets;
- identification and handling of special category data in real-world settings (i.e. sensitive data requiring extra protection under data protection law, such as data relating to an individual’s health, genetics, race or ethnic origin etc.);
- views on how straightforward or complex the above compliance obligations are in practice.
Theme 2 – Data quality, accuracy and downstream impacts
This theme examines how organisations assess and manage data quality, accuracy and fairness across their processing activities. In particular, it looks at how they consider and understand fairness and impacts of using technology such as AI on individuals from the outset, and how they monitor and address impacts arising from AI model outputs or downstream uses of technology.
Through our initial engagement, stakeholders have raised questions about how fairness and accuracy expectations within the data protection framework should be interpreted for modern data‑driven systems, including where impacts may arise from outputs and downstream uses.
Therefore, we are interested in how organisations approach these issues in practice, and how factors relating to data quality and accuracy (such as consistency, completeness, integrity, timeliness and relevance in changing environments) directly influence decisions and outcomes in different stages. We are also interested in how future developments in AI and other data-intensive technologies may affect the application of accuracy and fairness principles in practice.
Prompt question 1: What approaches do you take in practice to assess and ensure the quality and accuracy of data, including personal data, and what challenges do you encounter?
Prompt question 2: How do you assess and manage fairness and impacts on individuals when using AI or other data‑intensive technologies?
Prompt question 3: How appropriate are the data protection framework’s principles of fairness and accuracy when applied to data-intensive technologies, and are they likely to remain fit for purpose as these technologies continue to evolve?
We are particularly interested in evidence relating to:
- how future developments in AI and other data-intensive technologies may affect the interpretation and application of accuracy and fairness principles;
- how organisations assess the quality of data, including at different processing stages, and how they overcome any issues;
- individuals’ experiences of fairness and accuracy in AI and data-intensive technologies;
- methods and processes used to assess fairness and/or accuracy, to comply with legal requirements, and at what stages are these carried out (e.g. training, deployment, monitoring);
- the extent to which those methods and processes improve fairness and accuracy in practice, and when interventions are most meaningful or effective (for example, in relation to input data, outputs or downstream impacts);
- how organisations approach data protection impact assessments, equality impact assessments, human rights impact assessments and/or AI impact assessments;
- what internal or external guidance, standards or assurance mechanisms are used (e.g. ICO guidance, sector standards, internal policies, third-party audits);
- what risks to individuals are most commonly observed;
- how data access and data quality limitations affect fairness and accuracy, and how impacts of these limitations are addressed;
- The role and potential of synthetic data.
Theme 3 – Governing data use across organisations
This theme examines how organisations govern data across the entire AI/data lifecycle in complex supply chains, which are often global, opaque and across organisations.
Increasingly, when developing and applying data-intensive technologies - including AI - multiple organisations will contribute and process data at different stages for different purposes (e.g. data collection, development/training, deployment). Similarly, as technology evolves and more automated systems are adopted across organisations, the role of humans in decision making may change. This can raise practical and legal questions about roles and responsibilities, and how governance enables safe, effective and accountable data sharing and reuse.
Therefore, we are interested in how governance arrangements operate in practice, how these may have changed due to data-intensive technologies, and whether future technological developments may challenge the application of existing governance frameworks or require new approaches to data governance. This includes: how legal roles and responsibilities are allocated; how organisations choose to implement processes for solely automated decision-making, with associated safeguards; and what enables or constrains effective data sharing arrangements across organisations, including through data sharing infrastructure or data intermediaries.
Prompt question 1: How do you collect and then govern data across supply chains or between organisations in practice, including allocating responsibility and enabling data sharing or access?
Prompt question 2: How do you approach automated decision-making, and will this approach remain fit-for-purpose as technology advances?
Prompt question 3: How effective and appropriate are the data protection framework’s definitions in assigning responsibilities (e.g. controller/processor), and are they likely to remain fit-for-purpose over time as technology advances?
We are particularly interested in evidence relating to:
On data governance:
- where future technological developments may create new governance challenges or test the effectiveness of existing approaches;
- how roles and responsibilities are determined across organisations and throughout the data lifecycle;
- when data protection law applies, how do organisations determine whether they are acting as controllers, processors or joint controllers;
- how accountability is maintained in practice, including governance or oversight mechanisms such as trust frameworks, contracts, audits, or technical controls and other data sharing infrastructure;
- what records or controls are maintained to support auditability;
- arrangements that enable or constrain data sharing and reuse;
- interoperability, data portability or system integration challenges;
- the effectiveness of anonymisation and pseudonymisation, and how clearly organisations can distinguish between personal and anonymous data;
- where autonomous AI systems or agents act with delegated authority, how that authority is defined, permissioned, controlled and evidenced;
- whether there are any specific regulatory barriers that present challenges in a data governance context.
On automated decision-making:
- how future technological developments may affect approaches to governing automated decision‑making and profiling in practice, including whether emerging capabilities create new compliance considerations or challenges;
- approaches to governing automated decision‑making and profiling in practice, including how risk is managed;
- how organisations assess what constitutes a ‘significant decision’ and whether it falls under Article 22A-C UK GDPR (or Section 50A-C DPA);
- how meaningful human involvement is applied to automated decision-making processes (i.e. when there is a ‘human in the loop’ for decisions to be outside the scope of Article 22 UK GDPR (or Section 50 DPA), and the impact of the human on an outcome);
- what safeguards organisations implement, if any, when carrying out automated decision-making, and how effective these are;
- individuals’ understanding of automated decision-making systems, and how organisations use their personal data for such decision-making;
- individual experiences of contesting automated decision-making outcomes.
Theme 4 - Transparency and rights in complex data environments
This theme examines how organisations provide transparency and enable individuals to exercise their data protection rights in complex, opaque or large‑scale data processing environments.
Transparency is essential to build public trust by making data use understandable, supports fairness by enabling scrutiny of decisions, and empowers individuals to exercise their rights. We want to understand what approaches work well in practice in modern systems, including where data is collected indirectly, processed at scale, or shared across supply chains.
We are also interested in how future developments in AI and other data-intensive technologies may affect the practical application of transparency and data rights requirements, including where emerging capabilities may create new compliance considerations, opportunities or challenges for organisations and individuals.
Therefore, we are seeking evidence of what organisations do in real settings, including worked examples and operational steps.
Prompt question: What approaches have you found effective for providing transparency and for enabling individuals to exercise their data protection rights in complex data processing environments?
Prompt question 2: How effective are the data protection framework’s transparency requirements and data subject rights in the context of data-intensive technologies and will these remain fit for purpose over time as technology advances?
We are particularly interested in evidence relating to:
- how future developments in AI and other data‑intensive technologies may influence transparency and the exercise of data rights in practice;
- individual experiences of transparency in AI and data-intensive technologies;
- individual experiences of exercising data subject rights (access, erasure, rectification) in AI and data-intensive technologies;
- approaches to providing transparency where personal data is used at scale or collected indirectly;
- approaches to providing transparency in different settings, for example AI training, or operating embodied AI systems in real-world environments;
- approaches to transparency where the complexity of AI and data-intensive technologies may limit the ability to provide a full explanation of processing activities or outputs;
- operational steps used to handle data rights (e.g. access, erasure);
- practical examples of handling data rights requests at different processing stages;
- how, when personal data flows across organisations, this affects transparency or data rights;
- whether there are any specific regulatory barriers that impact transparency and data rights.
Theme 5 - Effectiveness of data frameworks in regulating AI
We welcome any additional evidence on how data regulation operates in practice for AI and other data‑intensive technologies. We are also interested in how future technological developments may shape the application of data regulation, creating new compliance challenges, opportunities to improve privacy, or implications for the effectiveness of existing protections. This will help ensure the UK’s data framework remains fit for the future.
Prompt question 1: Overall, what is working well, where have you observed disproportionate or unintended barriers in practice, and where have risks to data protection arisen?
Prompt question 2: Are the existing data frameworks sufficiently adaptable to future developments in AI, and where might rapid technological advances give rise to future difficulties? Or are there any alternative approaches that may be more effective, both now and in the future?
We are particularly interested in evidence relating to:
On existing AI technologies:
- whether protections, including data protection principles and data rights, offer meaningful protection in practice – that is, how rules are complied with, if they operate effectively, and if any specific regulatory barriers exist;
- The role and effectiveness of data regulation in building public trust in AI and other data-intensive technologies;
- whether data legislation clashes with or conflicts with other legislation in a way that prevents data use;
- whether alternative approaches or regulatory frameworks may be better suited to address certain risks, to provide greater trust and confidence in the use of personal data;
- whether there are examples where organisations chose not to pursue certain approaches, innovations or uses of data or technology, and the factors influencing those decisions.
On future AI technologies:
- whether existing data protection obligations and definitions are likely to remain fit-for-purpose over time, including given the potential future trajectory of AI development and deployment;
- whether alternative approaches or regulatory frameworks may be better suited to regulate novel technologies such as highly advanced (including agentic) AI and the relevant supply chains;
- the potential of AI technologies to improve privacy and data protection compliance, such as by reducing data loss or facilitating individuals to exercise their data rights.