Sigilbase

UK automated decisions, and the record a contested one needs.

From 5 February 2026 the Data (Use and Access) Act 2025 lets UK organisations make more decisions by automated means, with safeguards attached. Each safeguard assumes a record of the decision exists and can be relied on.

Checked October 2026. This page describes the rules in plain words and is not legal advice. Dates have moved before and may move again.

What changed

The Act replaced the old near-prohibition on solely automated decisions with significant effects. Such decisions are now permitted more widely, provided safeguards are in place: the person is told a decision was automated, can make representations, can obtain human intervention, and can contest the decision. Decisions based on special category data remain restricted.

Why the record matters

Every safeguard is exercised after the decision. A person who contests a decision in March is contesting what the system did in January. The organisation must produce the record, and the person has no way to know whether the record they are shown is the record that existed at the time.

What Sigilbase does: keeps the decision record, and the record of the human review that followed, as sealed events that neither the organisation nor Sigilbase can rewrite without detection. The person, or their representative, can verify the bundle themselves.

Regulated firms

The FCA expects firms using automated decisioning to be able to explain and evidence individual decisions, and the Consumer Duty raises the bar on showing that outcomes were good. A verifiable decision record is evidence a firm can hand over. Whether it is sufficient is the firm's judgement and the regulator's.

Recording a human review

Log the review as its own event: the reviewer as the actor, review.upheld or review.overturned as the action, the original decision as the resource. Sent to the same stream, the two events sit in the same chain, in order, and an export shows both.

What this proves, and what it does not

Sigilbase proves that a record has not been modified, deleted or reordered since we received it, when we received it, and which identity sent it. Any lawful redaction is declared, never silent.

It does not prove that a model produced the output in the record, or ran at all. It does not prove a decision was accurate, fair or lawful. It does not prove that everything which happened was recorded; coverage is the sender's control. It does not prove the sender's claimed time, only ours. And it says nothing about the period before the sender started.

Sigilbase is the evidence layer. The conclusion belongs to the person examining the evidence.

Questions about UK automated decisions

  • Does this replace a data protection impact assessment?

    No. It gives the assessment something to point at.

  • Can the person verify the record themselves?

    Yes. The verifier is open source and runs offline. The organisation exports the bundle; the person, or anyone acting for them, checks it.

  • Does the record contain personal data?

    It contains what you send. Most customers send hashes of inputs and an identifier for the subject, so the ledger proves what the model saw without storing it.

Start recording provable history

Chained, sealed, independently verifiable audit logs, from the first event. Free while Sigilbase is in beta.

Start free Read the auditor guide

Questions first? Write to hello@sigilbase.io.

More in this section

Privacy

This site runs no analytics and no trackers.

The site itself collects nothing. If you create a Sigilbase account, the data that involves is described in the privacy policy.

To have your email removed, contact hello@sigilbase.io.

Read the full privacy policy.

Last updated July 2026.