
Data (Use and Access) Act 2025: 10 Changes Businesses Need to Know
UK Data (Use & Access) Act 2025: What Business Owners Need to Know
What the UK Data (Use & Access) Act 2025 means for your privacy policy
The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025 and introduced a number of important changes to UK data protection law and the Privacy and Electronic Communications Regulations (PECR). The changes were brought into force in stages and, as of 19 June 2026, all of the provisions affecting data protection law and PECR are now in force.
While the DUAA does not replace the UK GDPR or the Data Protection Act 2018, it makes several important changes to how organisations can use personal data, respond to individuals and demonstrate compliance.
This article examines some of the changes organisations should consider when reviewing their privacy notices, cookie information and wider data protection procedures.
1.Changes to cookie requirements
The DUAA introduces additional exceptions to the requirement to obtain consent before storing or accessing information on a user’s device.
In particular, certain technologies used solely to collect statistical information for the purpose of improving a website or service may now be used without consent where the statutory conditions are met. There is also an exception for certain technologies used to adapt the appearance or functionality of a service in accordance with a user’s preferences.
These exceptions are not blanket exemptions for all analytics or functional cookies. Organisations relying on the statistical or appearance exceptions must provide clear information about their use and provide users with a simple and free means of objecting.
Cookies and other technologies used for purposes such as advertising, profiling or cross-site tracking will generally continue to require consent.
2. Increased fines under PECR
The DUAA has significantly strengthened the Information Commissioner’s enforcement powers under PECR.
The maximum financial penalties for relevant PECR infringements have increased from £500,000 to levels broadly aligned with the UK GDPR, including a maximum of £17.5 million or, where applicable, 4% of an undertaking’s total annual worldwide turnover.
This makes compliance with the rules governing electronic marketing, cookies and similar technologies considerably more important from a regulatory risk perspective.
Organisations should review their electronic marketing practices, consent mechanisms, soft opt-in arrangements and cookie compliance to ensure their practices reflect the amended rules.
3. Automated Decision Making (ADM)
The DUAA changes the rules governing significant decisions made solely through automated processing.
Under the amended UK GDPR, organisations have greater scope to make significant automated decisions using personal data, provided they have an appropriate lawful basis and put the required safeguards in place.
Those safeguards include informing the individual about the decision and allowing them to make representations, obtain human intervention and contest the decision.
Additional restrictions continue to apply where special category personal data is involved.
Organisations using artificial intelligence, automated recruitment tools, credit-scoring systems or other technologies capable of making significant decisions about individuals should therefore review both the lawful basis for the processing and the safeguards available to affected individuals.
Where automated decision-making takes place, this should also be accurately reflected in the organisation’s privacy information.
Stay ahead with expert data protection tips
Get practical advice, legal updates, and exclusive insights.
4. The Information Commission
The DUAA creates a new corporate regulator known as the Information Commission, which will take over the functions currently exercised by the Information Commissioner’s Office.
The new structure replaces the existing corporation-sole model with a board structure including a Chair, Chief Executive and executive and non-executive members.
The regulatory transition is taking place during 2026. The changes are primarily concerned with the governance of the regulator rather than creating an entirely different regulatory function for organisations.
The DUAA also strengthens the regulator’s investigatory and enforcement powers. These include powers to require certain organisations to commission reports at their own cost and powers to compel relevant individuals, including current and former personnel, to attend interviews in specified circumstances.
5. A new statutory data protection complaints process
The DUAA creates a statutory right for individuals to complain directly to a controller where they consider that their data protection rights have been infringed.
Controllers must facilitate the making of complaints, for example by providing an appropriate electronic method for submitting them.
An organisation must acknowledge receipt of a data protection complaint within 30 days. It must then take appropriate steps to investigate and respond to the complaint without undue delay, keep the complainant appropriately informed of progress and notify them of the outcome.
This means organisations should have a documented process for recognising, escalating, investigating and responding to data protection complaints.
Privacy notices and other information provided to individuals should also make it easy for people to understand how they can raise concerns about the use of their personal data.
6. Recognised legitimate interests
The DUAA introduces a new category of lawful basis known as recognised legitimate interests.
For certain specified types of processing, an organisation can rely on a recognised legitimate interest without carrying out the balancing exercise normally required when relying on the standard legitimate interests lawful basis.
The specified circumstances include certain processing relating to national security, public security and defence, emergencies, crime, safeguarding vulnerable individuals and certain disclosures to public bodies carrying out public tasks.
The DUAA also clarifies that activities such as direct marketing, intra-group transfers for internal administrative purposes and network and information security may constitute legitimate interests. These examples do not remove the usual requirement to consider necessity and balance the organisation’s interests against individuals’ rights where the standard legitimate interests basis is used.
Organisations should review their lawful-basis assessments and privacy information where these changes affect their processing.
7. International data transfers
The DUAA changes the terminology and legal test applying to international transfers of personal data.
The relevant standard is now whether the protection provided following the transfer is “not materially lower” than the standard of protection available under UK data protection law.
For organisations relying on appropriate safeguards, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, the assessment traditionally referred to as a Transfer Risk Assessment remains relevant. The legislation now expresses this assessment through the “data protection test”, which must be applied reasonably and proportionately.
This should not be confused with UK adequacy regulations. Where a destination or transfer is covered by applicable UK adequacy arrangements, a separate appropriate safeguard and transfer risk assessment may not be required.
Organisations transferring personal data outside the UK should therefore identify the transfer mechanism they rely upon, check whether the data protection test applies and ensure their privacy notices correctly describe relevant international transfers and safeguards.
8. Data Protection Officers remain under UK law
The DUAA has not replaced the UK GDPR Data Protection Officer regime.
Organisations must still appoint a DPO where required by the UK GDPR, including where they are a public authority or body, where their core activities involve large-scale regular and systematic monitoring of individuals, or where their core activities involve large-scale processing of special category or criminal-offence data.
Organisations that are not legally required to appoint a DPO may also choose to appoint one voluntarily.
Where an organisation has appointed a DPO, the relevant contact details must continue to be provided as required under the UK GDPR, including within appropriate privacy information.
9. Data subject access requests
The DUAA expressly confirms that organisations responding to a subject access request are required to conduct searches that are reasonable and proportionate.
Although this reflects an approach already recognised in case law and regulatory guidance, putting the principle expressly into legislation provides greater certainty when organisations are dealing with very broad or complex requests.
The standard UK GDPR response period remains one month, with the existing ability to extend the period by up to two further months where permitted by the UK GDPR.
A significant DUAA change is that an organisation may pause the response period where it reasonably requires clarification from the requester in order to respond to a subject access request. The clock resumes once the necessary clarification is received.
Organisations should therefore ensure that their DSAR procedures explain when clarification may legitimately be sought, how any pause in the response period is calculated and how they demonstrate that their searches were reasonable and proportionate.
10. Children’s data and online services
The DUAA strengthens the requirements applying to providers of online services that are likely to be used by children.
When implementing data protection by design measures, providers must specifically consider how best to protect and support children, recognise that children merit particular protection because they may be less aware of data protection risks and consequences, and take account of the different needs of children at different ages and stages of development.
Organisations providing online services likely to be accessed by children should therefore review their data protection by design processes alongside the ICO’s Children’s Code and consider whether existing risk assessments, DPIAs, privacy information and technical safeguards adequately address the needs of younger users.
Conclusion
The Data (Use and Access) Act 2025 represents an evolution of the UK’s existing data protection framework rather than a replacement for the UK GDPR.
For many organisations, the most immediate practical issues will be reviewing cookie practices, establishing an effective data protection complaints procedure, updating DSAR processes, assessing automated decision-making and ensuring that international-transfer assessments use the amended legal framework.
Privacy notices should be reviewed where an organisation’s actual processing or procedures have changed, but compliance with the DUAA extends well beyond the wording of the privacy notice itself.
If you’re unsure whether your privacy notice and wider data protection framework reflect the changes introduced by the Data (Use and Access) Act 2025, WDPS can review your existing documentation and identify the changes your organisation needs to make.
Explore more data protection & privacy services
Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]



