The Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025
In: Legal Regulation

The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025, marking a significant update to the UK’s data protection framework. Although it doesn’t overhaul existing laws, it introduces targeted amendments to the UK GDPR, Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR), aims to balance data-driven innovation with individual privacy rights.

Recognised Legitimate Interests

The DUAA introduces a list of “recognised legitimate interests,” simplifying the process for organisations to process personal data without conducting a Legitimate Interests Assessment (LIA) in certain contexts. These contexts include activities like fraud prevention, network security, and safeguarding children. This change provides clearer guidance for businesses on when they can rely on legitimate interests as a lawful basis for data processing.

Data Subject Access Requests (DSARs)

The Act clarifies the obligations of data controllers when responding to DSARs. Organisations are required to conduct “reasonable and proportionate” searches for personal data, aligning with existing ICO guidance. Additionally, the DUAA allows for extensions to the standard one-month response timeframe in cases of complex or multiple requests and permits organisations to “stop the clock” while awaiting further information from the requester.

Automated Decision-Making (ADM)

The DUAA relaxes certain restrictions on ADM, allowing its use without explicit consent in specific scenarios, provided appropriate safeguards are in place. This change facilitates the use of ADM in areas such as credit scoring and employment decisions, as long as there is meaningful human oversight and the decisions do not involve special category data.

Cookies and Direct Marketing

Under the DUAA, certain cookies used for website functionality, security, and service improvement no longer require user consent, provided users are informed and given the option to opt out. This adjustment aims to reduce the burden of cookie consent banners for low-risk cookies.

For direct marketing, the Act extends the “soft opt-in” to charities, allowing them to send electronic marketing communications to individuals who have previously engaged with them, unless the individual opts out. This aligns the rules for charities with those previously applicable to commercial organisations.

Enforcement and Regulatory Changes

The DUAA enhances the enforcement powers of the Information Commissioner’s Office (ICO). The ICO can now issue fines of up to £17.5 million or 4% of global turnover for breaches of PECR, bringing penalties in line with those under the UK GDPR. Additionally, the ICO gains new powers, including the ability to compel witnesses to attend interviews and request technical reports.

The Act also restructures the ICO into the Information Commission, introducing a board and executive team to oversee its operations.

International Data Transfers

The DUAA introduces a “data protection test” for assessing the adequacy of third countries’ data protection standards. This test evaluates whether a country’s data protection laws are “not materially lower” than those of the UK. The Secretary of State gains the authority to approve countries based on this assessment, potentially impacting international data transfers and the UK’s data adequacy status with the EU.

Implementation Timeline

While the DUAA has received Royal Assent, most of its provisions will come into force through secondary legislation over the coming months. Organisations should monitor updates from the ICO and the government to ensure timely compliance with the new requirements.

Preparing for Compliance

Businesses should review their data processing activities, focusing on areas affected by the DUAA, such as legitimate interests, DSAR procedures, ADM practices, cookie policies, and direct marketing strategies. Updating privacy notices, conducting staff training, and consulting with legal professionals can aid in aligning with the new regulations.

For tailored advice on navigating the changes introduced by the Data (Use and Access) Act 2025, contact Cartwright King’s Regulatory team.

Legal Disclaimer

All advice is correct at time of publication.