GDPR vs UK GDPR: How the Data (Use and Access) Act 2025 Is Creating Real Divergence

By Recording Law Editorial TeamReviewed May 19, 202619 min read
GDPR vs UK GDPR: How the Data (Use and Access) Act 2025 Is Creating Real Divergence

Frequently Asked Questions

Is the UK still covered by the GDPR after Brexit?

The EU GDPR no longer applies directly in the UK. Instead, the UK has its own UK GDPR, retained in domestic law through the European Union (Withdrawal) Act 2018 and supplemented by the Data Protection Act 2018. The two laws started nearly word-for-word identical, but the Data (Use and Access) Act 2025, in force from February 2026, has introduced material differences in legitimate interests, automated decision-making, SAR handling, and cookie consent.

What is the Data (Use and Access) Act 2025 and when did it come into force?

The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025. Its main data protection provisions came into force on 5 February 2026. The Act amends the UK GDPR and DPA 2018 to introduce recognised legitimate interests (no LIA required for listed categories), reformed automated decision-making rules, a SAR stop-the-clock mechanism, new cookie exemptions under PECR, higher PECR fines, broadened scientific research provisions, and the ICO transition to become the Information Commission.

Can personal data still flow freely between the EU and UK?

Yes. The European Commission renewed both UK adequacy decisions on 19 December 2025, covering transfers under the EU GDPR and the Law Enforcement Directive. The renewed decisions are valid until 27 December 2031. EU-to-UK personal data transfers do not require Standard Contractual Clauses or other transfer mechanisms during that period, provided the underlying processing otherwise complies with the EU GDPR.

What are recognised legitimate interests under the UK GDPR?

Recognised legitimate interests are a new lawful processing category inserted by Schedule 4 of the DUAA into UK GDPR Article 6. They cover crime prevention and detection, safeguarding vulnerable people, responding to emergencies, national security and public security, assisting law-sanctioned public interest tasks, and intra-group data transfers. Unlike ordinary legitimate interest processing, these categories do not require a Legitimate Interests Assessment. The EU GDPR has no equivalent -- all legitimate interest reliance in the EU requires a full balancing test.

What changed for subject access requests under the DUAA?

The DUAA introduced a stop-the-clock mechanism: the one-month SAR response deadline pauses when a controller requests clarification or additional information from the data subject, and resumes when that clarification arrives. The Act also codifies that SAR searches need only be reasonable and proportionate. These changes apply only to UK GDPR SARs. EU GDPR SARs still run on a continuous one-month deadline regardless of clarification exchanges.

Do businesses need to comply with both the UK GDPR and EU GDPR?

Yes, if they process personal data of both UK and EU residents. A UK-based company selling to EU customers must comply with the EU GDPR for those customers and the UK GDPR for UK residents. This now requires separate management of recognised legitimate interest assessments (full LIA for EU, potentially no LIA for UK), SAR timelines, automated decision-making logic, and cookie consent approaches for UK versus EU audiences.

Does the DUAA threaten the EU adequacy decision?

Not immediately. The Commission renewed adequacy in December 2025 having assessed the DUAA, and found current divergence acceptable. However, the EDPB flagged areas for ongoing monitoring: the UK's new onward adequacy test, Secretary of State powers to further amend the framework through secondary legislation, and the ICO's duty to consider innovation. If those powers are exercised to weaken data subject protections, adequacy could be reviewed before the 2031 expiry.

Updates

Major refresh: article fully updated to cover the Data (Use and Access) Act 2025 (Royal Assent 19 June 2025, main provisions in force 5 February 2026). Covers recognised legitimate interests, new automated decision-making framework, SAR stop-the-clock, cookie/PECR exemptions, PECR penalty increase, ICO renaming to Information Commission, scientific research broadening, and smart data schemes. EU adequacy decision renewed December 2025 through December 2031.

Initial publish. Covered post-Brexit UK GDPR origin, DPDI Act 2024, and EU adequacy decision.

Sources and References

  1. Data (Use and Access) Act 2025, c.18(legislation.gov.uk).gov
  2. Data Protection Act 2018(legislation.gov.uk).gov
  3. Data (Use and Access) Act 2025: data protection and privacy changes — GOV.UK(gov.uk).gov
  4. Data (Use and Access) Act factsheet: UK GDPR and DPA — GOV.UK(gov.uk).gov
  5. Data (Use and Access) Act 2025 — ICO(ico.org.uk).gov
  6. Statement on the commencement of the DUAA — ICO, February 2026(ico.org.uk).gov
  7. Recognised legitimate interest — ICO(ico.org.uk).gov
  8. Commission renews decisions to allow for the free and safe flow of personal data with the UK — European Commission, December 2025(ec.europa.eu).gov
  9. Draft UK adequacy decisions: EDPB adopts opinions — EDPB, October 2025(edpb.europa.eu).gov
  10. EU adequacy decisions — European Commission(commission.europa.eu).gov
  11. Receiving personal information from the EEA — ICO(ico.org.uk).gov
  12. UK International Data Transfer Agreement — ICO(ico.org.uk).gov
Share: