Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Data (Use and Access) Act 2025 — Data (Use and Access) Act 2025: Every Data Protection Change, Dated

Data (Use and Access) Act 2025: Every Data Protection Change, Dated

The Data (Use and Access) Act 2025 is the most significant change to UK data protection law since the Data Protection Act 2018. It received Royal Assent on 19 June 2025 and, rather than replacing the UK GDPR, amends it in place, along with the 2018 Act and the Privacy and Electronic Communications Regulations. The changes commenced in stages over a year, and each one lands in a specific procedure, register or notice. This summary lists every data protection change in the Act, the date it took effect, who it affects, and what a controller has to do about it.

What this guide covers

Data (Use and Access) Act 2025 explained
Data (Use and Access) Act 2025: Every Data Protection Change, Dated

What the Data (Use and Access) Act 2025 is

The Data (Use and Access) Act 2025 is wider than data protection. Part 1 creates a framework for smart data schemes; Part 2 establishes digital verification services; Part 3 deals with the national underground asset register; other parts cover births and deaths registration and online safety research. Part 5 is the part that amends the UK GDPR, the Data Protection Act 2018 and PECR, and it is the part this guide is about. The government’s stated aim was to reduce compliance friction while keeping the UK’s EU adequacy decision, which the European Commission renewed in December 2025 through to December 2031.

Commencement of the Data (Use and Access) Act 2025 was by regulation. The first commencement regulations, SI 2025/904, brought section 111 on PECR breach notification into force on 20 August 2025. The sixth, SI 2026/82, brought the main data protection provisions into force on 5 February 2026 and the statutory complaints duty on 19 June 2026. One provision, the reasonable and proportionate search in subject access requests, took effect at Royal Assent itself.

Date What commenced
19 June 2025 Royal Assent. Article 15(1A): access limited to a reasonable and proportionate search (s.78)
20 August 2025 PECR regulation 5A: service-provider breach notification aligned to the 72-hour standard (s.111)
5 February 2026 Recognised legitimate interests, purpose limitation, Article 12A time limits, Articles 22A to 22D, children’s higher protection matters, international transfers, cookie exceptions, charity soft opt-in, PECR penalties (ss.70, 71, 76, 80, 81, 85, 112, 114, 115)
19 June 2026 Statutory complaints to the controller: DPA 2018 sections 164A and 164B; Article 77 omitted (s.103)

Lawful bases: recognised legitimate interests and Article 6(11)

Section 70 inserted Article 6(1)(ea) and a new Annex 1. Processing that is necessary for one of the Annex 1 purposes is lawful without the balancing test that Article 6(1)(f) requires. The purposes are: disclosure to a person who needs the data for a public task and has asked for it; national security, public security and defence; responding to an emergency; detecting, investigating or preventing crime, or apprehending or prosecuting offenders; and safeguarding vulnerable individuals.

The same section inserted Article 6(11), which names direct marketing, intra-group transmission and network and information security as examples of purposes capable of being legitimate interests under 6(1)(f). Those still need the balancing test. Our guide to recognised legitimate interests covers the five conditions and their limits.

What to do: add a column to the lawful basis register for the Annex 1 paragraph relied on; write a short procedure for deciding when (ea) applies; and check that no solely automated significant decision relies on it, because Article 22B(4) forbids that combination.

Purpose limitation: Article 8A and Annex 2

Section 71 of the Data (Use and Access) Act 2025 restated the purpose limitation principle. Article 8A sets out the factors for deciding whether further processing is compatible with the original purpose, and now weighs the nature of the processing rather than the nature of the data. Annex 2 lists purposes treated as compatible without a test, mirroring the Annex 1 list: disclosures for another body’s public task, archiving and research, public security, emergencies, crime, vital interests and safeguarding. Section 77 added a duty to give individuals information about further processing. What to do: adopt a compatibility assessment template and use it before any reuse of data; update the privacy notice’s further-processing paragraph.

Rights requests: Article 12A and the reasonable search

Two changes to how the Data (Use and Access) Act 2025 handles rights requests. Section 78, in force from Royal Assent, inserted Article 15(1A): the controller is only required to provide what a reasonable and proportionate search yields.

Section 76, in force from 5 February 2026, inserted Article 12A, which defines the “applicable time period” for all requests: one month from the relevant time, which is the latest of receipt of the request, receipt of identity information asked for under Article 12(6), and payment of any fee; extendable by two months on notice within the first month where the request is complex or the person has made a number of requests; and paused while the controller awaits clarification it reasonably requires.

What to do: rebase the DSAR log on the relevant time, add a days-paused column, and record the search scope on every request. The UK subject access request time limit guide walks through the timeline.

Automated decision-making: Articles 22A to 22D

Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 with four new articles. Article 22A defines a solely automated decision as one with no meaningful human involvement, and a significant decision as one with a legal or similarly significant effect. Article 22B restricts solely automated significant decisions based on special category data to explicit consent, or contract or law together with a substantial public interest condition, and prohibits them entirely where the processing relies on the recognised legitimate interests basis.

Article 22C requires four safeguards for every solely automated significant decision: information about the decision, a route to make representations, human intervention, and a right to contest. Article 22D gives the Secretary of State regulation-making powers. What to do: assess every automated decision process against the two definitions, and design the four safeguards in before it goes live. The UK GDPR automated decision-making guide covers each.

Children, research and design under the Data (Use and Access) Act 2025

Section 81 inserted Article 25(1A) and (1B): a controller providing an information society service likely to be accessed by children must take account of the “children’s higher protection matters” when deciding its design and default measures. Sections 67, 68 and 86 gave scientific research a statutory definition, allowed consent to an area of research where the specific purpose cannot yet be identified, and set out research safeguards in new Articles 84A to 84D. What to do: add the children’s matters to the DPIA template and the design gate; update the research consent procedure if research is a purpose.

International transfers: Articles 44A to 49A

Section 85 and Schedule 7 of the Data (Use and Access) Act 2025 rewrote Chapter V. Article 44A states the principle: a transfer needs adequacy regulations, an appropriate safeguard, or a derogation. Article 45A gives the Secretary of State the power to make adequacy regulations, and Article 45B sets the test: whether the standard of protection is “not materially lower” than the UK’s. Article 46(1A) requires the transferring controller or processor, acting reasonably and proportionately, to consider that the same test is met before relying on a safeguard; that is the statutory basis of the transfer risk assessment.

Article 47A lets the Secretary of State issue standard data protection clauses; Article 49A lets the Secretary of State restrict transfers for important public interest reasons. What to do: re-check every transfer against the current adequacy list, refresh transfer risk assessments to the new test, and confirm no transfer relies on EU standard contractual clauses without the UK Addendum.

Cookies, marketing and PECR enforcement

Section 112 and Schedule 12 of the Data (Use and Access) Act 2025 replaced PECR regulation 6 and added Schedule A1. Consent is still the default for storing or accessing information on a device, but the exceptions are now listed: strictly necessary for a service the user requested; the appearance or function of the service as the user chose it; and statistical purposes for improving the service, provided the information is not shared beyond those helping, the user is given clear information, and the user has a simple, free means to object.

Section 114 extended the soft opt-in for email marketing to charities. Section 115 and Schedule 13 applied the Data Protection Act 2018 enforcement regime to PECR, including the section 157 penalty maxima and personal liability for officers for contraventions of regulations 19 to 24. What to do: reclassify every cookie and tag under Schedule A1, add the statistical objection route, and brief the board on the new liability. Our existing guide to cookie consent gives the general rules.

Complaints: the Data (Use and Access) Act 2025 change in force from June 2026

Section 103 and Schedule 10 inserted sections 164A and 164B into the 2018 Act and omitted Article 77 of the UK GDPR. From 19 June 2026, a data subject has a statutory right to complain to the controller about an infringement of the UK GDPR; the controller must facilitate complaints, for example through an electronic complaint form, acknowledge each one within 30 days, and without undue delay take appropriate steps to respond and inform the complainant of the outcome.

Section 164B lets the Secretary of State require controllers to report complaint numbers to the Commissioner. The right to complain to the Commissioner continues under section 165. What to do: stand up a complaints procedure, form, log and acknowledgement template, and replace every reference to Article 77 in the privacy notices. The data protection complaints procedure guide sets out the build.

The Commissioner and enforcement

The Data (Use and Access) Act 2025 restructures the Information Commissioner’s Office into an Information Commission with a board, gives it new statutory objectives, and strengthens its powers, including interview notices and higher information notice penalties. For a controller outside the public sector the practical consequence is the PECR alignment already described: marketing contraventions now carry the same maxima as data protection contraventions, 17.5 million pounds or 4 per cent of worldwide turnover at the higher tier.

A change register for the Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 has provisions still to commence, and the Commissioner’s guidance is being updated in stages, so a one-off reading is not enough. The organisation needs a register of each change, its date, the documents it touches and whether it has been applied, reviewed at least annually. The UK GDPR Toolkit ships that register with fifteen dated changes already entered, and every one of its 90 templates is written to the amended text rather than carrying the changes as a supplement. For the differences the Act has opened up between the two regimes, see UK GDPR vs EU GDPR; for the overall framework, our guide to the UK GDPR.

Frequently asked questions about the Data (Use and Access) Act 2025

Does the Act replace the UK GDPR?

No. The Data (Use and Access) Act 2025 amends the UK GDPR, the Data Protection Act 2018 and PECR. The UK GDPR remains the primary instrument; the Act’s changes are read into it.

When did the Act come into force?

Royal Assent was 19 June 2025, when the reasonable search provision took effect. The PECR breach change followed on 20 August 2025, the main data protection provisions on 5 February 2026, and the statutory complaints duty on 19 June 2026. Some provisions are still awaiting commencement regulations.

Did the Act affect the UK’s EU adequacy status?

The European Commission renewed the UK’s adequacy decisions in December 2025, with effect to 27 December 2031. Transfers from the EU to the UK continue without additional safeguards for as long as those decisions stand.

What is the single biggest operational change?

For most organisations, the statutory complaints duty: a 30-day acknowledgement clock that did not exist before, an electronic complaint form to build, and privacy notices to rewrite. Article 12A’s new time limits for rights requests are a close second.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.