Is Emotion Recognition Legal in the UK?
Yes — nothing in UK law prohibits it. There is no UK equivalent of EU AI Act Article 5(1)(f), so emotion recognition is banned in no setting, including workplaces, recruitment and education, and as of September 2026 no AI bill is before Parliament. But the absence of a prohibition is not a safe harbour. UK GDPR, the new automated decision-making rules in Articles 22A–22D, the Equality Act 2010 and an openly sceptical regulator carry the weight instead. The practical consequence for enterprise buyers is the mirror image of the EU position: the EU gives you a bright line with a large lawful space beyond it, while the UK gives you no line at all and a burden of proof that follows you into every use case.
This is not legal advice. It is a buyer's orientation to a fast-moving area, written by a vendor in the category. UK positions on biometric classification and on the new automated decision-making articles vary between practitioners and are not settled. Take specific advice before deployment, and treat any vendor claim — including ours — as something to verify rather than accept.
There is no UK AI Act — so what actually governs?
The UK did not adopt the EU AI Act and has not enacted an AI statute of its own. The 2023 pro-innovation white paper put regulation in the hands of existing regulators rather than a new instrument, and although the government has repeatedly signalled legislation for the most capable models, no AI bill is before Parliament as of September 2026. Emotion recognition is therefore governed by general law, and four regimes do the work.
UK GDPR and the Data Protection Act 2018 supply the core duties: a lawful basis, an Article 9 condition where special category data is engaged, transparency, data minimisation, and a DPIA for high-risk processing. Articles 22A to 22D, introduced by section 80 of the Data (Use and Access) Act 2025 and in force since 5 February 2026, govern decisions made about people without meaningful human involvement. The Equality Act 2010 supplies a route to liability that has nothing to do with data protection and is routinely overlooked in procurement. And sector regulation — the FCA Consumer Duty most obviously — imposes its own expectations on regulated firms.
Notice what this means in practice. In the EU, a buyer's first question is whether the use case falls inside a prohibition, and if it does not, a substantial lawful space opens up. In the UK there is no prohibition to fall inside, so the first question is instead whether the deployment is defensible — and that question has to be answered for every use case, including the ones an EU buyer could clear in a sentence.
What the ICO has actually said
This is the part UK buyers should read before anything else, because it is the closest thing to a UK position on the technology itself.
The Information Commissioner's Office warned in 2022 against the use of biometric technologies for emotion analysis, describing the field as immature and, in the regulator's own framing, not yet backed by science. It has since maintained that posture: its AI and biometrics work sets a deliberately high bar for systems that infer subjective traits, intentions or emotions from physical or behavioural characteristics, and the substance of its stated position is that it has not yet seen an emotion AI system developed in a way that satisfies data protection requirements.
Nothing in that is a prohibition, and it should not be read as one. But it establishes the starting posture of any investigation, and it means a UK deployment carries an evidential burden that an equivalent EU deployment outside Article 5(1)(f) does not. The ICO also acted on recruitment specifically. Its audit of AI sourcing, screening and selection tools found considerable areas for improvement and produced 296 recommendations, covering inferred characteristics, excessive data collection, indefinite retention and inadequate human review. If you are scoping a recruitment deployment in the UK, assume the regulator has already looked at tools like the one you are buying.
Use case by use case
The table below maps common enterprise applications against the UK position. Not one of them is prohibited — that is the whole point of the UK regime — so the second column grades how hard each deployment is to defend rather than whether it is allowed, and the third column is where the actual decision gets made. This is a scoping aid for the conversation with your own counsel, not a substitute for it.
| Use case | How hard to defend | What carries the risk |
|---|---|---|
| Contact centre — customer emotion | Low friction | The subject is the customer, so no worker-monitoring question arises. Standard UK GDPR duties: lawful basis, transparency, DPIA where the processing is high risk. |
| Investor and earnings communication | Low friction | Your own executives, analysing their own delivery for their own preparation. Consent is meaningful here because the subject is also the beneficiary. |
| Market research and message testing | Low friction | Consenting participants, no employment relationship, and no decision with legal or similarly significant effect on the individual. |
| Vulnerability detection (FCA Consumer Duty) | High scrutiny | Consumer Duty makes identifying vulnerability an expectation. But inferring it can reveal health data, engaging Article 9, and it drives a decision affecting a consumer — so Articles 22A–22D and fairness testing apply. |
| Security and public space screening | Case by case | No AI Act-style prohibition applies in the UK, but the ICO's facial recognition guidance and the necessity and proportionality test are demanding. Specific legal advice required. |
| Recruitment and interview assessment | Hard to defend | The ICO audited AI recruitment tools and issued 296 recommendations. Candidate consent is rarely freely given, the Equality Act exposure is real, and EU-bound roles hit Article 5(1)(f) anyway. |
| Employee monitoring or engagement scoring | Hard to defend | Lawful in principle, but worker consent is not freely given, the ICO expects a necessity and proportionality case, and the employment-law exposure sits outside data protection entirely. |
| Education — student attention or engagement | Hard to defend | No prohibition as there is in the EU, but children's data attracts the Children's code and the highest level of ICO scrutiny of any category on this list. |
Compare this against the same table under the EU AI Act and the divergence is stark. The bottom three rows are outright prohibited in the EU and merely difficult in the UK. The top three are straightforward in both. Any organisation operating on both sides of the Channel should scope to the stricter of the two rather than maintain two postures, because the alternative is a system that is lawful in Manchester and prohibited in Munich, running on the same contract.
Biometric data, and the classification gap
Article 4(14) UK GDPR defines biometric data as personal data resulting from specific technical processing relating to physical, physiological or behavioural characteristics. Facial analysis and vocal analysis both meet that definition. But biometric data becomes special category data under Article 9 only where it is processed for the purpose of uniquely identifying a natural person — and emotion classification generally does not identify anyone. On that route alone, much emotion analysis is not special category data.
The trap is the second route in. If the system infers or reveals a health condition, a disability, or racial or ethnic origin, the output is special category data on that basis regardless of the identification question. Emotion inferred from physiological measures such as heart rate can be health data directly. A recruitment system whose scores diverge systematically by ethnicity is, in effect, processing data revealing racial origin. Neither of those requires anyone to be identified for Article 9 to apply.
Compounding this, the ICO's published biometric guidance addresses biometric recognition — identifying or verifying who someone is — rather than biometric classification, which is what emotion systems do. Classification is flagged but not comprehensively covered, and the guidance is itself under review following the Data (Use and Access) Act. That gap is the single largest source of genuine UK uncertainty in this area, and it will not be closed by a vendor assurance. Establish where your deployment sits, document it in a DPIA, and do that before procurement rather than after.
Articles 22A–22D: the change most buyers have missed
Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 UK GDPR with new Articles 22A to 22D, in force since 5 February 2026. The change is significant and widely misread in both directions.
Under the old Article 22, solely automated decisions with legal or similarly significant effects were prohibited by default, subject to narrow exceptions. The new articles reverse that default: such decisions are now permitted more broadly. That is a real liberalisation, and it is the reason some UK vendors have become noticeably more relaxed in their marketing since February. But three things limit it.
First, Article 22C requires safeguards to be in place and documented — telling the individual a decision was taken, enabling them to make representations and obtain human intervention, and enabling them to contest the decision. These are conditions of lawfulness, not best practice. Second, Article 22B retains the tighter rule where special category data is involved: a significant decision based wholly or partly on special category data may only be taken with the individual's explicit consent, or where required or authorised by law. If your emotion system engages Article 9 by either route described above, you are back inside the restrictive regime. Third, a decision is only solely automated where there is no meaningful human involvement — and a reviewer who approves a score without the information or the authority to overturn it does not supply it.
For emotion analysis specifically, the practical test is whether the output contributes to a decision about the person. A contact centre system that routes a frustrated caller to a supervisor is not making a significant decision about that caller. A screening system that ranks candidates is.
The Equality Act 2010 route nobody budgets for
UK procurement treats this as a data protection question and stops there. It is also a discrimination question, and that route does not require a regulator to act — an individual brings it.
Emotion inference degrades unevenly across populations. Autistic candidates, stroke survivors, people with Bell's palsy or Parkinson's, and people whose expressive norms differ by culture are all liable to be read as disengaged, evasive or low-affect by systems trained on a narrower baseline. That produces exposure under section 19 for indirect discrimination, section 15 for unfavourable treatment arising from disability, and sections 20 and 21 for failure to make reasonable adjustments.
The procedural point matters more than the substantive one. Under section 136, once a claimant establishes facts from which a tribunal could conclude that discrimination occurred, the burden shifts to the employer to show it did not. In practice that means being able to explain, in a tribunal, how the system reached its output about this individual and why the output is not tainted by a protected characteristic. A vendor who will not disclose enough for you to do that has handed you a liability, not a tool. Our separate guide to interview bias and the Equality Act covers this ground in detail.
The EU AI Act still reaches UK organisations
The most expensive mistake available to a UK buyer is to conclude that leaving the EU removed the Article 5(1)(f) problem. It did not. Article 2(1)(c) brings providers and deployers established in a third country within scope where the output produced by the system is used in the Union, and the UK has been a third country since Brexit. Scope follows the output, not the registered office.
A UK employer running emotion analysis on candidates for a Dublin role, a UK contact centre handling calls from EU customers with agent-side scoring enabled, a UK group deploying an engagement tool across European subsidiaries — each is inside the EU prohibition. Article 5 is an absolute market prohibition with no consent, contract or legitimate-interest gateway, so nothing in your UK governance stack lifts it. For most organisations with any EU footprint, the EU position is the binding constraint and the UK analysis is academic.
Five questions to put to any UK vendor in writing
Ask these before the technical evaluation, not after it. The answers are more diagnostic than the demo.
- Does your system infer emotional state or report observable signals — and how would you evidence that distinction to the ICO?
- What is your written position on whether your outputs constitute special category data under Article 9, by either the identification route or the health and ethnicity route?
- If our deployment produces a significant decision, what do you provide so we can meet the Article 22C safeguards and demonstrate meaningful human involvement?
- What adverse impact testing have you done across disability and ethnicity, and will you disclose enough for us to defend a section 136 burden shift at tribunal?
- Which of our intended deployments would you decline to support — in the UK, and separately in the EU?
The fifth question remains the most revealing, as it is under the EU regime. A vendor whose answer is “none” has either not looked at the problem or is willing to sell you one.
Where EchoDepth sits
EchoDepth reports observable delivery signals using the Facial Action Coding System — 44 Action Units calibrated across 14 cultural cohorts in 6 countries — together with vocal and language measures. It reports what the signals did and leaves interpretation to context-aware human review, rather than returning an emotion label. That design decision is the direct answer to the first vendor question above, and the calibration work is the answer to the fourth. Cavefish is ICO registered (ZB915633) and provides DPIA support documentation for every enterprise deployment.
We scope UK deployments on the same lines as our EU ones, deliberately. Contact centre, investor and executive communication, market research and message testing are supported. We do not scope candidate-facing recruitment assessment or employee monitoring deployments, in the UK or the EU, and we will say so at the first conversation rather than the last — the absence of a UK prohibition does not make those deployments defensible, and interviewer consistency measurement achieves more of what HR teams actually want. Where a security or public-space application is proposed, we expect the client to take specific advice before we proceed.
Primary sources
Read the instruments rather than summaries of them. UK GDPR and the Data Protection Act 2018, and section 80 of the Data (Use and Access) Act 2025 for Articles 22A–22D, are on legislation.gov.uk. The ICO publishes its biometric data guidance, its AI and biometrics strategy, its outcomes report on AI tools in recruitment, and its guidance on monitoring workers. The Equality Act 2010 sections 15, 19, 20, 21 and 136 are the relevant provisions for the discrimination analysis. Where this page and a primary source disagree, the primary source is right.
Frequently Asked Questions
Is emotion recognition legal in the UK?
Yes, in the narrow sense that no UK statute prohibits it. There is no UK equivalent of EU AI Act Article 5(1)(f), so emotion recognition is not banned in workplaces, in education, or anywhere else, and as of September 2026 no AI bill is before Parliament. What governs instead is general law: UK GDPR and the Data Protection Act 2018, the automated decision-making rules in Articles 22A to 22D introduced by the Data (Use and Access) Act 2025, the Equality Act 2010, and sector regulation such as the FCA Consumer Duty. The practical position is therefore the opposite of the EU one. The EU gives you a bright line and a large lawful space on the other side of it. The UK gives you no line at all and a burden of proof that applies everywhere.
Is there a UK equivalent of EU AI Act Article 5(1)(f)?
No. Article 5(1)(f) prohibits emotion recognition in workplaces and educational institutions across the EU. The UK did not copy that prohibition across, and the UK has not enacted an AI statute at all. The nearest thing to a UK position is regulatory rather than legislative: the Information Commissioner's Office has publicly described emotion analysis technologies as immature, has warned organisations against using them to make significant decisions about people, and has said it has not yet seen an emotion AI system developed in a way that satisfies data protection requirements. That is a statement of regulatory posture, not a prohibition — but it tells you what an ICO investigation would start from.
Can UK employers use emotion recognition in job interviews?
There is no UK prohibition, but it is difficult to defend and we do not recommend it. Four things bite at once. Candidate consent is rarely freely given under UK GDPR because of the imbalance of power, so consent is a weak lawful basis. If the analysis contributes to a rejection without meaningful human involvement, Article 22A applies, and Article 22B requires explicit consent or legal authorisation where special category data is involved. The Equality Act 2010 exposes you to indirect discrimination and disability claims, because emotion inference systematically misreads autistic candidates, stroke survivors, people with facial palsy and people across cultural groups — and once a candidate makes out a prima facie case, section 136 puts the burden on the employer to explain the system. Finally, if any output is used in the EU, EU AI Act Article 5(1)(f) applies regardless of where your company sits. The defensible alternative is to measure interviewer consistency and process fairness rather than infer candidate emotional state.
Is emotion data biometric data under UK GDPR?
Usually it is biometric data, but not usually special category data — and the distinction is where UK buyers get caught out. Article 4(14) UK GDPR defines biometric data as personal data resulting from specific technical processing relating to physical, physiological or behavioural characteristics. Facial and vocal analysis meets that. But biometric data only becomes special category data under Article 9 where it is processed for the purpose of uniquely identifying a person, and emotion classification generally does not identify anyone. The trap is the second route in: if the system infers or reveals a health condition, a disability, or racial or ethnic origin, it is special category data on that basis alone, whatever the identification position. The ICO's published biometric guidance covers biometric recognition rather than classification, and is itself under review following the Data (Use and Access) Act, so this gap is the single largest source of genuine UK uncertainty. Establish your position in a DPIA before procurement.
Does the EU AI Act apply to UK companies?
Yes, where the output is used in the EU. Article 2(1)(c) brings providers and deployers established in a third country within scope where the output produced by the AI system is used in the Union, and the UK has been a third country since Brexit. Scope follows the output, not the registered office. A London-headquartered employer running emotion analysis on candidates for a Dublin or Frankfurt role is inside the Article 5(1)(f) prohibition, and Article 5 is an absolute prohibition with no consent, contract or legitimate-interest gateway. Any UK organisation with EU staff, EU customers or EU operations should scope against both regimes, and in practice the EU position becomes the binding constraint.
What changed for automated decisions under the Data (Use and Access) Act 2025?
Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 UK GDPR with new Articles 22A to 22D, in force from 5 February 2026. The default flipped: solely automated decisions with legal or similarly significant effects are now permitted more broadly, rather than prohibited by default. That is a genuine loosening, but it is conditional. The safeguards in Article 22C — telling people a decision was made, allowing human intervention, and allowing them to contest it — must be in place and documented. Article 22B keeps the tighter rule where special category data is involved: such a decision may only be taken with explicit consent, or where required or authorised by law. And a decision is only solely automated where there is no meaningful human involvement, so a rubber-stamp review does not take you outside the regime.
Scope your use case before you procure
Tell us the deployment you have in mind. We will tell you what it has to survive under UK GDPR and the Equality Act — including if the answer is that we cannot support it.
Talk to us about scoping →