
A significant piece of UK data protection reform has now moved from theory into practice. The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025.
Its provisions have been introduced in phases, with implementation completed in June 2026.
For any business that collects, stores or processes personal data, whether that is customer records, HR files or marketing lists, this is not a piece of legislation that can be left on the shelf.
It amends the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations, with several of the changes requiring action. If you haven’t amended your policies and approaches yet, now is the time.
A new lawful basis for processing
The DUAA introduces a seventh lawful basis for processing personal data, known as “recognised legitimate interests”.
Unlike the existing legitimate interests basis, this new category removes the need to carry out a balancing test against an individual’s rights for a defined list of purposes, including matters such as crime prevention and safeguarding.
This has been welcomed as a simplification for organisations relying on these grounds, but privacy notices and records of processing will need to be reviewed to reflect the change accurately.
Automated decision-making and AI tools
Businesses using automated or AI-driven tools for recruitment, credit assessments, fraud detection or customer service should take particular note of new clauses in the Act.
The rules on automated decision-making have been relaxed in circumstances that do not involve special category data.
This widens the scope for organisations to rely on these tools while still requiring appropriate safeguards to be in place.
Cookies, DSARs and complaints
The Act also eases the consent requirements for certain low-risk cookies and similar technologies, such as those used for analytics or to remember a user’s preferences.
On subject access requests, the DUAA formally confirms that organisations need only carry out searches that are reasonable and proportionate when responding to a request, bringing the law into line with existing regulatory guidance.
Organisations are also now required to have a clear and accessible process in place for individuals to complain directly about how their data is being handled, before escalating a concern to the Information Commissioner’s Office
Higher stakes for non-compliance
Alongside these relaxation of the rules, the DUAA aligns penalties under the Privacy and Electronic Communications Regulations with those under the UK GDPR, raising the maximum fine for breaches of marketing and cookie rules to £17.5 million or four per cent of global turnover, whichever is higher.
This means that organisations need to be extra careful and have their existing data policies and procedures checked for legal compliance to avoid costly regulatory action.
What businesses need to do
With enforcement powers already in place, businesses should, if they haven’t already, be reviewing and, where necessary, updating:
- Privacy notices and cookie policies to reflect the new lawful basis and consent rules.
- Data subject access request procedures to align with the reasonable and proportionate standard.
- Automated decision-making policies where AI or automated tools are used in recruitment, lending or customer decisions.
- Complaints handling processes to ensure individuals have a clear route to raise concerns directly.
- International transfer arrangements in light of the new data protection test for third-country transfers.
If you would like help reviewing your data protection policies in light of the Data (Use and Access) Act coming into force, our team can carry out a practical compliance check and update your documentation. Please get in touch to arrange a confidential discussion.





