Understanding the Data (Use and Access) Act 2025: What UK Organisations Need to Know
You probably haven't heard much about the Data (Use and Access) Act 2025, but it's quietly reshaping the UK's approach to data across multiple sectors. While it brings the first changes to UK GDPR since it came into effect, this comprehensive new law goes much further – introducing smart data schemes, digital identity frameworks, and new requirements spanning everything from healthcare to underground infrastructure. 
For those managing data protection, compliance, or governance responsibilities, these changes offer both opportunities to innovate and new requirements to navigate. The Act received Royal Assent on 19 June 2025, and while the changes are being phased in gradually, some have already taking effect. 
 
So, let me walk you through what this could mean for your organisation and what you need to do to stay compliant. 

What Exactly Is the Data (Use and Access) Act 2025? 

The Data (Use and Access) Act 2025 – or DUAA as it's becoming known – represents the government's attempt to modernise data protection laws while promoting innovation and economic growth. Rather than replacing existing legislation, it amends the UK GDPR, Data Protection Act 2018, and Privacy and Electronic Communications Regulations. 
 
The Act is fundamentally about enabling better use of data across the economy. From energy and telecoms to healthcare and financial services, the government wants organisations to harness data more effectively while still protecting individual rights. It's a balancing act between innovation and protection, and one that affects virtually every sector. 
 
What makes this particularly significant is that these are the first changes to UK GDPR since it came into effect. The government has essentially decided that the original framework, while robust, was perhaps too restrictive for modern business needs. 

Which Organisations Will Be Affected by These Changes? 

Most of the provisions affect businesses across all sectors, particularly those relating to automated decision-making, legitimate interests processing, and cookie consent requirements. 
 
However, some changes target specific sectors more directly. For instance, social media companies and online service providers face new obligations around providing information to safety researchers. Energy, utilities, and infrastructure companies will also need to navigate changes involving the National Underground Asset Register. Healthcare providers and their IT suppliers must adapt to new standards for information sharing across the NHS. 
 
If you provide online services that children are likely to use, you'll face explicit new requirements to consider their needs in your data processing decisions. Charities get some welcome relief with new "soft opt-in" provisions for electronic marketing. 
 
The reality is that unless you're operating a very small, purely offline business with minimal data processing, these changes will touch your organisation in some way. 

Key Changes That Will Impact Your Data Processing 

Relaxed Rules Around Automated Decision-Making 
One of the most significant changes involves automated decision-making systems. The current restrictions are being softened, with the prohibition now applying only to special category data and situations where there's "no meaningful human involvement." 
 
This opens up broader scope for using artificial intelligence systems in decision-making processes. However, don't assume this means a free-for-all. Several conditions and restrictions still apply, and you'll need to carefully consider whether and how you can expand your use of these systems. 
 
Expanded Research Provisions 
The definition of "scientific research" has been broadened to include any research that "can reasonably be described as scientific," regardless of funding source or commercial nature. This change, combined with new provisions allowing "broad consent" for research areas, should make it easier for organisations to conduct and use research. 
 
You can also now re-use personal information for scientific research without providing a privacy notice if doing so would involve "disproportionate effort," provided you protect rights in other ways and publish the notice on your website. 
 
New "Recognised Legitimate Interests" Lawful Basis 
The Act introduces a new category of "recognised legitimate interests" that removes the need for balancing tests in certain circumstances. These include processing for public security, responding to public body requests, and various security and emergency purposes. 
 
The Act also makes it clearer that certain types of processing are more likely to count as legitimate interests, including direct marketing, intra-group transfers for internal administration, and network security measures. 
 
Simplified Cookie and Tracking Rules 
You'll no longer need user consent for cookies used solely to collect statistical data for service improvements, enhance website appearance or performance, or adapting sites to user preferences. This is subject to various conditions around transparency and the right to object, but it should reduce some of the compliance burden for website operators. 
 
Clearer Subject Access Request Requirements 
The Act clarifies that when someone requests access to their personal data, you only need to conduct "reasonable and proportionate" searches. While this largely codifies existing guidance, having it explicitly in law provides helpful clarity for organisations dealing with complex or extensive data requests
 
New Complaints Handling Requirements 
If you don't already have them, you'll need to implement processes to help people make data protection complaints, such as providing electronic complaint forms. You must acknowledge complaints within 30 days and respond "without undue delay." 
 
Enhanced Protections for Children's Data 
If you provide online services likely to be used by children, the Act explicitly requires you to consider their needs when deciding how to use their personal data. If you already comply with the ICO's Age Appropriate Design Code, you should be well-positioned for this requirement. 

When Do These Changes Actually Take Effect? 

The implementation is being phased in stages, which gives you time to prepare but also means you need to stay alert to different timelines. 
 
Some provisions took effect immediately when the Act received Royal Assent on 19 June 2025, including changes relating to counter-terrorism data retention. The subject access request clarification is backdated to 1 January 2024. Additional provisions havecome into effect two months after Royal Assent, including some law enforcement processing changes and new ICO powers. 
 
Most other provisions, including the main GDPR changes, will come into effect on future dates to be decided by the government, likely within the next 12 months. The ICO has committed to updating guidance as these changes take effect

What Your Organisation Needs to Do Right Now 

The ICO has provided a helpful preparation checklist, and it's worth working through this systematically: 
 
Start by familiarising yourself with the changes using the ICO's guidance and detailed summaries. If you provide online services that children might use, review whether you're doing enough to satisfy the new explicit requirements around considering their needs. 
Begin thinking about how you'll help people make complaints about your data processing. This might involve updating your website, creating electronic forms, or reviewing your current complaints procedures. 
Review the changes that support innovation and consider whether you want to take advantage of new opportunities or streamline existing processes. This could include reviewing your automated decision-making systems, research activities, or cookie implementation. 
Sign up for ICO newsletters and updates so you'll know when guidance is updated and new provisions come into effect. 
 
Most importantly, don't treat this as a one-off compliance exercise. The phased implementation means you'll need to stay engaged with the changes as they roll out over the coming months. 

Preparing Your Organisation for the New Data Landscape 

The Data (Use and Access) Act 2025 represents a significant shift in how the UK approaches data protection and usage. While the changes offer new opportunities for innovation and may simplify some compliance requirements, they also introduce new obligations that require careful planning and implementation. 
 
The key to successful compliance is starting your preparation now, even though many provisions haven't yet taken effect. Understanding what's coming allows you to plan updates to policies, procedures, and systems in a measured way rather than scrambling to comply when deadlines arrive. 
 
At Corporate Assist, we help organisations navigate complex compliance requirements and implement robust governance frameworks. Whether you need support understanding these new provisions, updating your data protection policies, or ensuring your board and committees are properly informed about regulatory changes, I'm here to help. 
 
If you'd like to discuss how the Data (Use and Access) Act might affect your organisation or need support preparing for these changes, you can reach me on 07576 829 591 or email amy@corporateassist.co.uk. I look forward to helping you turn these regulatory changes into operational advantages. 
Share this post: