UK's Data (Use and Access) Act 2025 Rewrites UK GDPR Rules: What Changed and When

By Recording Law Editorial Team7 min read
UK's Data (Use and Access) Act 2025 Rewrites UK GDPR Rules: What Changed and When

Frequently Asked Questions

Did the Data (Use and Access) Act 2025 replace the UK GDPR?

No. The Act amends the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations rather than replacing them. The core framework remains in force, with targeted changes to lawful bases, automated decisions, cookies, complaints, and the regulator. The Act received Royal Assent on 19 June 2025.

When did the new data protection rules take effect?

The reforms are phased. Technical provisions and new regulator objectives commenced on 20 August 2025, digital identity measures on 1 December 2025, and most data protection and privacy provisions in Part 5 on 5 February 2026. The duty on organizations to run a complaints process is on a longer lead-in and is expected around June 2026.

What is the Information Commission?

DUAA abolishes the corporation-sole structure of the Information Commissioner and creates a new body corporate called the Information Commission, governed by a board of executive and non-executive members. The transition depends on board appointments expected in early 2026.

Did the Act change the fines for spam and cookie violations?

Yes. The Act aligns the enforcement powers and fines under the Privacy and Electronic Communications Regulations with the Data Protection Act 2018. PECR penalties were previously capped well below the data protection regime, so this is a significant increase in the maximum exposure for unlawful marketing and tracking.

What changed for automated decision-making under DUAA?

The Act lets organizations make solely automated decisions with legal or similarly significant effects in more situations, provided they apply safeguards. Those safeguards include informing people about significant automated decisions and giving them a way to make representations and to challenge the decision.

Does this affect companies outside the UK?

It can. The amended UK regime continues to apply where organizations process the personal data of people in the UK or offer goods and services to them, subject to the legislation's territorial scope. Non-UK organizations handling UK personal data should review the new rules and watch for the complaints-handling duty expected around June 2026.

Sources and References

  1. Data (Use and Access) Act 2025, 2025 c. 18, introduction (enacted) showing Royal Assent date of 19 June 2025 and the full long title(legislation.gov.uk).gov
  2. Data (Use and Access) Act 2025, full table of contents (as enacted), showing the eight parts and the scope of the data protection amendments(legislation.gov.uk).gov
  3. GOV.UK guidance: Data (Use and Access) Act 2025 data protection and privacy changes (recognised legitimate interests, automated decision-making, cookies, subject access requests, complaints handling)(gov.uk).gov
  4. GOV.UK guidance: Data (Use and Access) Act 2025 plans for commencement, listing the staged commencement dates including 20 August 2025, 1 December 2025, and 5 February 2026(gov.uk).gov
  5. GOV.UK factsheet: the Data (Use and Access) Act 2025 and the ICO, confirming the new Information Commission body corporate, PECR alignment with the DPA 2018, and new enforcement powers(gov.uk).gov
  6. Information Commissioner's Office overview of the Data (Use and Access) Act 2025 and how the regulator will implement it(ico.org.uk).gov
Share: