The Data (Use and Access) Act 2025 made significant changes to the UK’s data protection framework. With its data protection provisions now in force, organisations need to consider whether those changes have been reflected in their policies, procedures, systems and working practices.
When I first wrote about the Data (Use and Access) Act 2025, several important provisions had not come into force. Organisations were asked to prepare for the changes and to wait for further commencement dates and regulatory guidance.
The position has changed. Most of the remaining data protection provisions took effect on 5 February 2026. The requirement for organisations to have a data protection complaints procedure took effect on 19 June 2026, and all the Act’s data protection provisions are now in force.
This article explains the principal changes under the Data (Use and Access) Act 2025 and the practical implementation challenges organisations should now consider.
Understanding the Data (Use and Access) Act 2025
The Data (Use and Access) Act 2025 (DUAA) introduced the first significant changes to the UK GDPR since it came into force.
Rather than replacing the existing data protection framework, it amended the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations.
It introduces regulation for smart data schemes, digital verification services, healthcare information and the National Underground Asset Register.
The overall intention was to enable organisations to use data more effectively while continuing to protect individual rights. For organisations, this created both opportunities and new responsibilities.
Now that the relevant provisions are in force, the question is whether the changes have been reflected in your organisation’s policies, procedures, systems and day-to-day working practices.
Which organisations are affected?
Many of the data protection changes apply across different sectors. These include provisions on automated decision-making, recognised legitimate interests, scientific research, subject access requests, data protection complaints, cookie practices, children's personal information and electronic marketing by charities.
Other provisions apply more directly to specific sectors. These include healthcare information standards, access to information for online safety research, and the National Underground Asset Register.
The effect on an individual organisation depends on what it does, what information it processes, and whether it intends to use any of the opportunities introduced by the Act.
Changes to automated decision-making
One of the most significant changes concerns solely automated decisions that produce legal or similarly significant effects on individuals.
The amended framework allows a wider range of lawful bases to support these decisions when they do not involve special category personal information. However, this does not mean that organisations have unrestricted authority to automate decisions.
Appropriate safeguards continue to apply. Individuals need to be able to receive information about the decision, make representations, obtain human intervention and contest the outcome.
The broader data protection principles also remain relevant, including lawfulness, fairness, transparency, accuracy and accountability.
Before introducing or expanding an automated process, an organisation now needs to establish:
What decision is being made
How the decision affects the individual
What personal information is used
Whether special category information is involved
Which lawful basis applies
Whether meaningful human involvement exists
What safeguards are in place
How compliance will be demonstrated
The fact that a system contains an automated or AI-enabled function does not explain how it is used or what reliance is placed on its output. Both need to be understood.
The connection With AI governance
Automated decision-making changes are connected to the wider governance of artificial intelligence.
An organisation cannot assess the requirements applicable to an AI system unless it first understands where AI is used, what information it processes and how its outputs affect employees, customers or other individuals. This includes:
Where AI is being used
What the system is intended to do
What information it processes
How its output is used
Whether a person reviews that output
Whether the output influences or determines a decision
How the decision affects employees, customers or other individuals
The DUAA and the EU AI Act are separate legal frameworks, but both may apply to the same activity. Compliance with one does not automatically ensure compliance with the other.
A starting point is to maintain an accurate record of the organisation's AI systems and their uses. The relevant Legal, Data Protection, Compliance, Risk and technical specialists can then determine which requirements apply.
Our article, “AI Inventory: Do You Know Where AI Is Being Used Across Your Organisation?”, explains how organisations can identify, gather and organise this information.
Other important data protection changes
The DUAA introduced and clarified several other areas.
The scientific research provisions clarify the meaning of scientific research, broad consent, and the circumstances in which providing privacy information directly might require disproportionate effort. Conditions and safeguards continue to apply.
The recognised legitimate interests provisions remove the usual balancing test for specified activities involving matters such as national security, public security, emergencies and safeguarding. Organisations still need to identify and document the appropriate lawful basis.
Certain cookies and similar technologies can be used without consent, including specified uses for statistical information and service functionality. Transparency requirements and an opportunity to object may still apply, so organisations need to assess each type of cookie or tracking technology against the relevant sections of the legislation.
The Act also confirms that searches carried out in response to subject access requests should be reasonable and proportionate. Organisations should still be able to explain how they determined the scope of the search and the steps they took.
Data protection complaints
Organisations must provide an appropriate way for individuals to make data protection complaints, including electronically.
Complaints must be acknowledged within 30 days, investigated without undue delay, and followed by a clear outcome. Individuals must also be informed of their right to complain to the Information Commissioner.
This means checking that your organisation's complaints process does more than satisfy the wording of a policy. Responsibilities need to be clear, deadlines need to be monitored, and an appropriate record of the complaint, investigation, and outcome needs to be retained.
The ICO has confirmed that organisations are not necessarily required to establish a separate data protection complaints system. An existing complaints process can be adapted, provided that it enables the organisation to meet the new requirements.
Children's information and charity marketing
The Act reinforces the importance of protecting children when processing their personal information. Organisations providing online services likely to be used by children should continue to consider the ICO's Age Appropriate Design Code and the broader requirements on fairness and transparency.
The electronic marketing soft opt-in was also extended to eligible charities and non-commercial organisations. Conditions apply, including providing an opportunity to opt out when collecting contact information and in subsequent communications.
Charities wishing to rely on the change need to review their supporter journeys, privacy information, preference records and marketing systems.
What should organisations do now?
Now that the relevant provisions are in force, organisations should confirm which changes apply and whether they have been implemented.
The review might cover automated decision-making, AI use, data protection complaints, subject access requests, privacy notices, cookie practices, electronic marketing, and management reporting.
Responsibility for any outstanding work should be clear, with actions and evidence properly recorded. Earlier implementation plans should also be reviewed, as they may still describe provisions as awaiting commencement.
The ICO's Data (Use and Access) Act guidance provides further information.
Support With Data Act implementation
Your organisation may already have the necessary Data Protection, Legal and Compliance expertise. The difficulty may be finding sufficient time to review the position across functions, consolidate the information and ensure that the resulting actions are completed.
Corporate Assist could provide Corporate Project Support by coordinating information, maintaining a clear record of actions and evidence, and preparing progress reports.
I work alongside the specialists responsible for determining the organisation's legal and regulatory position, helping to keep the wider implementation project organised and on track.
If you need additional capacity to support a defined governance or compliance project, please get in touch to discuss your requirements.
Share this post: