The Data (Use and Access) Act 2025 is no longer something UK organisations need to prepare for.
It received Royal Assent on 19 June 2025, and the provisions affecting data protection law and the Privacy and Electronic Communications Regulations (PECR) are now in force. The Information Commissioner’s Office updated its organisational guidance on 19 June 2026 to reflect that position.
That changes the useful question for businesses.
It is no longer, “What might the DUAA mean for us?”
It is now, “Which parts of the way we already use personal information have actually changed?”
That distinction matters because the DUAA is not a replacement for the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 or PECR. It amends those laws. The existing data protection framework remains in place, but some of the rules within it have been clarified, widened or changed, and a small number of new organisational requirements have been introduced.
The Act itself is wider than privacy. It also supports areas including digital verification services, Smart Data schemes and the National Underground Asset Register. For most organisations reviewing their existing privacy and data-protection arrangements, however, the immediate questions are around personal information, automated decisions, individual rights, complaints, international transfers and changes to PECR.
Understanding those changes properly is more useful than trying to treat the DUAA as another general compliance framework.
What the DUAA actually changes
One of the easiest mistakes to make with a large piece of legislation is to turn it into a new set of broad principles.
That is not the most useful way to understand the DUAA.
The familiar data protection principles have not been replaced by a new set of “DUAA principles”. Instead, the Act makes targeted changes to the existing legal framework. Some give organisations more flexibility. Some clarify what was already permitted. Others create specific new obligations.
The ICO itself makes an important distinction here: most of the changes provide opportunities to do things differently rather than requiring every organisation to make changes simply to comply. But that does not mean the Act can be ignored. Where your organisation uses one of the affected processes, the detail matters.
A business using purely human decision-making may have little to change in relation to automated decisions. An organisation operating an online service likely to be used by children has a more specific issue to examine. A business already handling data protection complaints through a clear process may need relatively little adjustment, while one relying on an informal route through a general inbox now has a legal requirement it needs to operationalise.
The useful approach is therefore not to ask whether the whole organisation is “DUAA compliant” in the abstract.
It is to identify which decisions and processes the Act has changed, and whether the way those processes work still matches the law.
Automated decision-making has more room to operate
Automated decision-making is one of the more substantial changes.
Before the DUAA, significant decisions made solely through automated processing were restricted to a relatively narrow set of circumstances. The Act widens the situations in which organisations may be able to make those decisions, provided an appropriate lawful basis is available and the required safeguards are maintained.
The word significant matters.
Think about a recruitment system that automatically rejects an applicant, a financial system making a credit decision or another automated process that has a legal or similarly significant effect on somebody. The issue is not simply that software, an algorithm or AI has been involved. The question is whether the decision is made solely through automated processing, without meaningful human involvement, and whether its effect on the individual is legally or similarly significant.
For significant automated decisions involving information that is not special category data, the DUAA potentially allows organisations to use a wider range of lawful bases, including the standard legitimate interests basis. There is an important technical distinction here: the new recognised legitimate interests basis cannot be used for these significant automated decisions. Restrictions also remain around the use of special category personal information.
The increased flexibility does not remove the safeguards.
Organisations must provide information about the decision and enable the individual to make representations, obtain human intervention and contest the decision.
That makes the practical design of the process important.
A system can have a button labelled “request human review” without that review being particularly meaningful. If the person reviewing the decision has no authority to change it, lacks the information needed to challenge the automated output, or simply approves whatever the system recommends, the organisation has not solved the underlying issue simply by putting a human somewhere in the workflow.
The legal change gives organisations more room to use automation. It also makes it important to understand where automated decisions are being made, how significant they are and what happens when somebody challenges the result.
Subject access requests have been clarified
The DUAA also makes some useful changes around subject access requests (SARs).
It now makes explicit that organisations only need to carry out reasonable and proportionate searches for personal information when responding to a SAR. That puts into the legislation an important practical boundary around what an organisation is expected to do.
The Act also introduces a clearer “stop the clock” mechanism.
Where clarification is reasonably required to respond to a SAR, an organisation can ask for it and pause the response period while waiting for the information. The organisation must be able to demonstrate that the clarification was reasonably necessary; it is not simply an opportunity to delay difficult requests.
This does not reduce the importance of the right of access. It gives organisations a clearer framework for dealing with requests that are genuinely difficult to interpret or that could otherwise require disproportionately broad searches.
The operational question is whether the people receiving requests know how to recognise them, where they need to go and when clarification is genuinely necessary.
A well-written SAR procedure is useful. A procedure that only works when the request arrives through the expected channel is much less useful.
Data protection complaints are now a specific legal requirement
One of the most immediately relevant changes for many organisations is the new complaints requirement.
Imagine a customer emails a general support address:
“I want to complain about how you have used my personal information.”
To the person managing the inbox, it may look like another customer-service issue. They may respond themselves, forward it to a manager or leave it in the normal complaints queue.
Under the current law, the route that follows matters.
Organisations must give people a way to make a data protection complaint, acknowledge receipt within 30 days, take appropriate steps to investigate and keep the complainant informed without undue delay, and communicate the outcome without undue delay. These requirements came into force on 19 June 2026.
The legislation does not require every organisation to build an elaborate complaints department.
It does require the process to work.
That means somebody using an ordinary contact form, email address, telephone line or customer-service route should not have their data protection complaint disappear simply because they did not use the words the organisation expected.
This is a good example of where compliance becomes an operational question.
A privacy policy can describe a complaint route accurately, but if the people and systems receiving complaints do not know how to recognise and route them, the written process and the working process have separated.
Legitimate interests have changed, but not in one simple way
The DUAA introduces a new lawful basis called recognised legitimate interests.
It is different from the familiar standard legitimate interests basis.
Recognised legitimate interests applies to specific purposes set out in legislation. There is still a necessity test, but where the basis properly applies, the organisation does not carry out the additional balancing exercise between its interest and the individual’s rights and freedoms that forms part of the standard legitimate interests assessment.
That should not be read as a general new shortcut for processing personal information.
The recognised purposes are defined. An organisation cannot simply decide that something feels important enough to become a recognised legitimate interest.
The DUAA has also clarified the standard legitimate interests basis. The legislation now identifies direct marketing, intra-group administrative transfers and ensuring network and information-system security as examples of activities that may be necessary for a legitimate interest. The normal legitimate interests requirements still apply.
Direct marketing is a particularly useful example of why the legal layers still need to be kept separate.
The fact that direct marketing can be a legitimate interest under UK GDPR does not mean legitimate interests overrides PECR. Where PECR requires consent for a particular form of electronic marketing, legitimate interests cannot be used to bypass that requirement. Where PECR does not require consent, legitimate interests may potentially be appropriate, subject to the usual test.
The DUAA has clarified the lawful-basis landscape. It has not turned legitimate interests into general permission to use personal information however an organisation chooses.
Re-using personal information has clearer rules
Purpose limitation has also been revised.
Organisations sometimes collect personal information for one reason and later identify another legitimate use for it. The law has always required careful consideration of whether that further processing is compatible with the original purpose.
The DUAA restructures these rules and specifies circumstances where certain further uses can be treated as compatible without carrying out the usual compatibility test. The precise route differs depending on whether the information was originally collected on the basis of consent or another lawful basis. A lawful basis for the new processing is still required.
There are also specific changes around scientific research.
The Act clarifies the meaning of scientific research, including that it can encompass commercial scientific research, and allows broad consent to an area of scientific research where the statutory conditions are satisfied. It also provides some flexibility around privacy information where further processing for research would make individual notification impossible or involve disproportionate effort, provided people’s rights are protected through other measures.
These provisions will be highly relevant to some organisations and barely relevant to others.
That is another reason a blanket “DUAA compliance programme” can be less useful than identifying which provisions actually touch the organisation’s work.
International transfers use a new legal test
The DUAA also changes the language and assessment used when personal information is transferred outside the UK using appropriate safeguards.
The legislation now refers to a data protection test. The organisation must decide, acting reasonably and proportionately, that the standard of protection after the transfer will be “not materially lower” than the protection provided in the UK.
For transfers relying on appropriate safeguards, the requirement to perform what organisations have commonly called a transfer risk assessment is now formalised through that test.
This does not mean every existing international transfer arrangement needs to be discarded and recreated.
The ICO says that where an organisation completed a transfer risk assessment under its previous guidance and concluded that the protection was sufficient, that assessment meets the new data protection test.
The practical review is therefore about whether your transfer arrangements still reflect what you actually do, whether the appropriate mechanism is in place and whether new transfers are assessed against the current test.
Online services need to consider children’s needs explicitly
There is also a specific new requirement for organisations providing online services that are likely to be used by children.
When putting technical and organisational measures in place to comply with the data protection principles, providers must take children’s needs into account. That includes considering how best to protect and support children, recognising that children merit specific protection in relation to personal information, and recognising that their needs change with age and development.
For organisations already conforming to the ICO’s Age Appropriate Design Code, the regulator says those arrangements should already satisfy the new requirement.
Again, this is not simply a wording change for the privacy notice.
It affects decisions about how the service itself is designed and how personal information is used within it.
PECR has changed too
The DUAA does not only amend UK GDPR and the Data Protection Act.
It also changes PECR.
One significant area concerns technologies that store information on or access information from people’s devices — the rules historically associated most closely with cookies.
The basic prohibition remains, but the DUAA introduces additional exceptions. These include specified statistical uses and some uses connected with the appearance or functionality of a service, subject to the relevant conditions. The ICO finalised its updated guidance on storage and access technologies in April 2026.
This should not be translated into “cookie consent is no longer required”.
The purpose for which the technology is used still matters. A statistical exception, for example, does not become permission to use the same information for advertising or profiling simply because the technology also performs analytics.
The DUAA also introduces a new electronic-marketing soft opt-in for qualifying charities. Where the statutory conditions are met, charities can send marketing connected with their charitable purposes to people who have supported or expressed an interest in their work, while retaining the required opportunities to opt out.
PECR enforcement has become considerably stronger as well. The DUAA brings its enforcement framework much closer to the UK GDPR regime, and the ICO can now issue PECR fines of up to £17.5 million or 4% of global annual turnover, depending on the circumstances.
The ICO has stronger investigatory powers
The Act changes the regulator as well as the rules organisations follow.
Among the ICO’s new powers are the ability to compel witnesses to attend interviews and to require reports from approved persons. The ICO has said that the law is already in force and that it can use these powers where necessary in serious cases, while further procedural guidance continues to be developed.
The sensible takeaway is not that every organisation should suddenly expect aggressive enforcement.
It is that the DUAA should not be treated as a cosmetic tidying-up exercise. Some provisions make existing rules easier to use, some create more flexibility, and some strengthen the regulator’s ability to examine what happened when compliance fails.
What should UK organisations review now?
Not every DUAA provision will be relevant to every organisation. A useful review starts with the processes you actually use rather than attempting to redesign everything at once.
For most organisations, the practical checks are:
- Data protection complaints: Can people make a complaint easily, and can the organisation recognise, acknowledge, investigate and respond to it through the routes people actually use?
- Automated decision-making: Are any significant decisions being made solely through automated processing? If so, what lawful basis applies and are the required safeguards genuinely usable?
- Subject access requests: Do current procedures reflect reasonable and proportionate searches and the rules around asking for necessary clarification?
- Lawful bases and further use: Are teams relying on legitimate interests, recognised legitimate interests or compatibility assumptions correctly rather than treating the changes as blanket permission?
- International transfers: Do transfer arrangements and assessments reflect the current data protection test?
- Websites and digital services: Which cookies and other storage/access technologies are actually operating, for what purposes, and which PECR rule or exception applies to each?
- Specific activities: Does the organisation operate services likely to be used by children, conduct relevant scientific research or, if it is a charity, intend to use the new marketing soft opt-in?
The point of the review is not to produce another folder of DUAA documents.
It is to make sure the legal change reaches the places where somebody actually has to make a decision.
The law has to reach the way the work is done
This is where an apparently technical legislative amendment becomes much more ordinary.
A customer-service employee receives a complaint about personal information while dealing with dozens of other requests. A product team enables a new analytics feature because it helps them understand how a service is being used. HR introduces a recruitment tool that automatically filters applications. Somebody responding to a SAR has to decide whether they understand the request well enough to search for the information.
None of those moments necessarily feels like “implementing the DUAA”.
They are pieces of normal work.
The organisation’s responsibility is to make the correct route realistic inside that work.
If a data protection complaint can only be handled correctly when somebody happens to recognise an obscure legal phrase, the process is fragile. If automated decisions can supposedly be reviewed by a person who cannot change them, the safeguard is weak. If nobody knows which technologies a website plugin activates, a beautifully written cookie policy cannot repair the missing operational knowledge.
That does not mean every employee needs detailed knowledge of the Act.
Different roles need different things. Some people may need clear guidance or briefing because the decisions they make have changed. Others need a better process, clearer ownership, a technical control or a system that makes the right information visible at the point it is needed.
Training can support a genuine knowledge or judgement gap. It cannot substitute for a complaints route that does not work, an automated process with no meaningful human intervention, an unclear transfer decision or a technology deployment that nobody has properly assessed.
The better question is not whether everybody understands the DUAA.
It is whether the organisation has translated the parts that apply into workable decisions, responsibilities and controls.
What the DUAA means in practice
The Data (Use and Access) Act 2025 is an important change to the UK’s data landscape, but it is not GDPR 2.0 and it does not require organisations to start again.
The underlying framework remains familiar.
What has changed are specific rules inside it: more flexibility around some automated decisions and research uses; clearer treatment of legitimate interests, further processing, SARs and international transfers; new requirements around complaints and children’s online services; changes to PECR; and stronger regulatory powers.
For some organisations, several of those changes will require action. For others, only a handful will materially affect the way they operate.
That is why the strongest response is not a sweeping new policy labelled “DUAA”.
It is to map the legal changes against the way personal information is actually used, identify where an existing decision or process has changed, and update that part of the organisation properly.
The legislation has changed.
The practical job now is to make sure the relevant parts of the work have changed with it.
Director of Training and Development, Cyber Rebels.
Andy Longhurst is the founder of Cyber Rebels and a cybersecurity practitioner and educator focused on how risk actually shows up in real organisations. His work sits at the intersection of digital safety, education, and practical risk management — helping teams understand not just what policies say, but what happens in the moments where decisions are made under pressure.
With a background spanning adult education, web development, and technical consultancy, Andy specialises in translating complex security concepts into clear, usable understanding. Rather than focusing solely on tools or compliance frameworks, his approach centres on human behaviour, judgement, and the systems that shape everyday choices.
He delivers live, interactive cyber awareness training for organisations of all sizes, from small businesses and education providers to public-sector teams and larger organisations operating in complex risk environments.
Outside of delivery, Andy spends his time analysing emerging attack patterns, refining training design, and exploring how organisations can build resilience that holds up in the real world — usually with a strategically sized cup of tea close to hand.
