The Data (Use and Access) Act 2025 (DUAA), which obtained Royal Assent on 19 June 2025, marks a transformative shift in the UK’s data protection landscape, particularly post-Brexit. Aimed at modernising data practises while safeguarding individual rights, it sets out a phased implementation timeline from 2025 to 2026. Notable changes include expanded allowances for automated decision-making, clarified response timelines for subject access requests, and enhanced protections for children’s data. The DUAA also introduces new requirements for organisations regarding complaint handling and international data transfers, necessitating swift adaptation to these evolving compliance standards as outlined by the Information Commissioner’s Office.

The Data (Use and Access) Act 2025, known as the DUAA, was enacted on 19 June 2025 and marks a substantial reform of the UK's data protection landscape, particularly after Brexit. Its primary objective is to safeguard personal data while fostering innovation and growth in data-driven sectors. As digital transformation continues to reshape industries, the DUAA addresses the complexities of evolving data use, ensuring that individuals retain control over their personal information. Organizations are required to comply with specific guidelines to ensure lawful data processing, thus promoting trust among citizens. The Act aligns with international standards, which is crucial for facilitating cooperation with global data protection laws, making it easier for businesses to navigate compliance in a broader context. The DUAA is expected to significantly impact various sectors, including healthcare, education, and technology, necessitating tailored compliance strategies to meet the unique challenges each sector faces. To ease the transition, the Act features a phased implementation schedule, allowing organisations time to adapt to the new requirements systematically. Public awareness campaigns will also be initiated to educate citizens about their rights under the DUAA, empowering them to make informed decisions regarding their data. Furthermore, the Act introduces penalties for non-compliance, underscoring the importance of robust data protection practises. Regular review periods will be established to evaluate the Act's effectiveness and implement necessary adjustments, ensuring that it remains relevant in a rapidly changing digital environment.
The Data (Use and Access) Act 2025 (DUAA) introduces several significant changes aimed at enhancing data protection and transparency. One of the key alterations is the increased clarity on data processing agreements between organisations and third parties, ensuring that all parties involved have a clear understanding of their responsibilities regarding data handling. Additionally, the Act mandates a stronger emphasis on transparency, requiring organisations to inform individuals about their data practises in a more comprehensive manner.
Another notable change is the reinforcement of the requirement for organisations to conduct data protection impact assessments. This ensures that potential risks to individuals' privacy are evaluated proactively. Individuals are also granted clearer rights to object to data processing in specific circumstances, empowering them to have greater control over their personal information.
The DUAA further introduces a framework for the ethical use of artificial intelligence in data processing, establishing guidelines that promote responsible practises. Organisations are now required to ensure that privacy notices are easily accessible and written in plain language, making it simpler for consumers to understand their rights and the implications of data usage.
New provisions for data portability allow individuals to transfer their data between different services effortlessly, facilitating a smoother transition if they choose to switch providers. The Act also specifies data retention periods, clarifying how long personal data can be retained before it must be deleted.
Moreover, the scope of data breaches has been expanded under the DUAA, demanding more rigorous reporting standards from organisations in the event of a breach. Finally, organisations are encouraged to adopt privacy-by-design principles, integrating data protection measures into their processes from the outset to ensure that privacy is considered at each stage of data handling.
| Change | Description | Implications |
|---|---|---|
| Automated Decision-Making (ADM) | Broader framework for ADM, enabling significant automated decisions with safeguards. | Organisations must inform individuals and allow challenges to decisions. |
| Subject Access Requests (SARs) | Clarifies SAR response time with a 'stop the clock' rule. | Enhances efficiency in processing requests. |
| Children’s Data Protection | Stricter rules for processing children's data, requiring explicit consent. | Protects children’s privacy. |
| Scientific Research | Broader consent arrangements for related research, with clear safeguards. | Facilitates ethical data use for research purposes. |
| Recognised Legitimate Interests | New lawful ground for data use without balancing individual rights. | Increases flexibility for data processing. |
| International Data Transfers | Clarifies conditions for transferring personal data outside the UK. | Simplifies compliance for organisations. |
| Complaints Handling | Mechanisms must be provided for individuals to lodge complaints. | Enhances accountability and responsiveness of organisations. |
| Storage and Access Technologies | Allows certain cookies to be used without explicit consent in low-risk areas. | Promotes user control while simplifying practices. |
| Amendments to the Data Protection Act 2018 | Modifies provisions for law enforcement to streamline processes. | Aims for more efficient data handling in security contexts. |

The Data (Use and Access) Act 2025 (DUAA) establishes a comprehensive Automated Decision-Making (ADM) framework that aims to enhance transparency and accountability in the use of automated processes. By providing a clear definition of ADM, the act ensures that organisations have a better understanding of their responsibilities when relying on such systems. In instances where significant decisions are made solely through automated processes, organisations are mandated to inform individuals accordingly, thus fostering a sense of trust and awareness.
One of the key provisions is the right to human intervention, allowing individuals to request a review of automated decisions that may affect them. This right empowers individuals to contest automated outcomes and seek explanations regarding the factors influencing those decisions. Transparency requirements further necessitate that organisations disclose the logic behind their automated processes, thereby enhancing public understanding of how decisions are made.
The DUAA also reinforces safeguards against discrimination in automated systems, particularly to protect vulnerable groups who may be disproportionately affected by biassed algorithms. Organisations are encouraged to conduct fairness assessments to evaluate the impact of their automated decision-making practises. Regular audits of these systems are required to ensure compliance with the act, promoting fairness and accountability.
Guidelines for developing and testing algorithms to minimise bias are included within the framework, thereby guiding organisations towards responsible innovation in their automated processes. Furthermore, the act encourages training and education on ethical AI use, ensuring that organisations not only comply with regulations but also adopt best practises in their data handling.

Subject Access Requests (SARs) are a crucial aspect of the Data (Use and Access) Act 2025 (DUAA), providing individuals with the right to access personal data held by organisations. The DUAA establishes a clear timeline for organisations to respond to these requests, enhancing efficiency in data management. Individuals can expect comprehensive information regarding their data, which promotes transparency and accountability. The Act also includes a 'stop the clock' provision, enabling organisations to pause the response time if they require further clarification from the requester. To ensure the integrity of the process, organisations must implement robust verification methods to confirm the identity of individuals making SARs.
To streamline compliance, a standardised format for responding to SARs is recommended, helping organisations maintain consistency in their handling of requests. The DUAA encourages the use of technology to make it easier for individuals to submit SARs, thereby improving accessibility. Furthermore, organisations are required to document their handling of these requests, which fosters accountability.
The Act outlines clear guidelines regarding exemptions to SARs, aiding organisations in navigating complex scenarios where full disclosure may not be possible. Staff training on SAR processes is mandated to ensure that requests are processed consistently and effectively. Failure to comply with SAR requests can lead to significant penalties and damage to an organisation's reputation, underscoring the importance of adhering to the regulations set forth by the DUAA.
The Data (Use and Access) Act 2025 (DUAA) introduces rigorous standards for the collection and handling of data pertaining to children under the age of 18. Organisations are now mandated to secure explicit consent from parents or guardians before they can process any data related to minors. This requirement aims to ensure that children's privacy is safeguarded effectively. To aid compliance, the Act encourages the implementation of age verification mechanisms, helping businesses ascertain the age of their users and apply appropriate data protection measures accordingly.
Moreover, the DUAA stipulates that children's data must be managed in a manner that is age-appropriate and easily comprehensible. This includes the necessity for privacy notices aimed at children to be clear, concise, and engaging, allowing young users to understand their rights and the implications of data processing. The Act also promotes the creation of educational resources to inform children about their data rights, empowering them with knowledge about how their information can be used.
In terms of data handling practises, organisations are required to adhere to data minimisation principles, ensuring they collect only the data that is essential for their operations concerning children. Regular assessments of data processing activities related to minors are also mandated to guarantee ongoing compliance with the new regulations. Additionally, the DUAA requires organisations to establish channels through which children can report any concerns regarding data misuse or breaches, thereby fostering a safer digital environment for young users.
The Data (Use and Access) Act 2025 (DUAA) introduces significant provisions aimed at enhancing the role of scientific research while ensuring ethical data handling. One of the key features is the facilitation of broader consent arrangements for research purposes. This flexibility allows researchers to utilise data across related areas, thereby promoting innovation in various fields. Research organisations are encouraged to collaborate closely with data controllers, fostering a culture of ethical data sharing practises that can lead to groundbreaking discoveries.
To protect individual identities, the Act outlines specific safeguards for anonymising data before it is used in research. This is crucial in maintaining the confidentiality of participants, allowing researchers to focus on their studies without compromising privacy. Furthermore, transparency is a core principle of the DUAA; researchers are required to clearly disclose the purpose and scope of their data usage, ensuring that participants are fully informed about how their data will be employed.
The Act mandates regular audits of research practises to ensure compliance with ethical standards, thereby reinforcing accountability within the research community. Researchers must provide participants with clear information about the use of their data, which not only builds trust but also empowers individuals to make informed choices about their involvement in research.
The provisions for data retention in research contexts are also clearly defined, establishing acceptable timeframes for how long data can be stored. Additionally, the DUAA supports the use of data for secondary research purposes under specific conditions, allowing for further exploration and analysis that can benefit society at large. Public consultations are encouraged to address any community concerns regarding data use in research, ensuring that the voices of the public are heard and considered.
Lastly, the relationship between research and data protection is emphasised, highlighting that both can coexist harmoniously. This balance is vital in fostering an environment where innovation can thrive while respecting individual rights.
The Data (Use and Access) Act 2025 (DUAA) provides a clearer framework for the concept of legitimate interests in data processing. This framework allows organisations to process personal data based on recognised legitimate interests, provided that they conduct balancing tests to evaluate the potential impact on individual rights. For instance, organisations may process data for purposes such as fraud prevention or network security, which are acknowledged as legitimate interests. However, they must ensure that these interests do not override the rights of individuals.
Individuals have the right to challenge the basis of legitimate interests, especially in circumstances where they feel their privacy may be compromised. To enhance transparency, the DUAA mandates that organisations inform individuals when they are relying on legitimate interests for data processing. This obligation fosters trust, as individuals are made aware of how their data is being used.
Organisations are also required to document their assessments of legitimate interests, demonstrating compliance with the Act. This documentation must include the results of the balancing tests and must be reviewed regularly to ensure that the interests remain relevant and appropriate. Furthermore, training staff on the principles of legitimate interests is recommended to ensure a consistent application of these regulations across the organisation. The Act establishes an accountability process for organisations relying on these interests, ensuring that they adhere to the standards set forth by the DUAA.
The Data (Use and Access) Act 2025 (DUAA) presents a streamlined approach to transferring personal data outside the UK, making it easier for organisations to navigate compliance. Under the Act, organisations must first evaluate the level of protection afforded by the recipient country before proceeding with any data transfer. This assessment is crucial, as it ensures that personal data remains protected in accordance with international standards. The DUAA provides clear guidelines for data transfer agreements, establishing a framework that organisations can follow to ensure compliance.
One of the significant features of the Act is the introduction of standard contractual clauses, which organisations can use to facilitate data transfers. These clauses help maintain a consistent level of protection for personal data, regardless of where it is sent. Furthermore, organisations are required to conduct impact assessments for international data transfers to identify potential risks associated with the transfer and mitigate them effectively.
The Act clarifies the role of adequacy decisions, which can ease the compliance burden by allowing data transfers to countries deemed to provide adequate protection. It encourages the use of frameworks such as the Privacy Shield where applicable, providing organisations with additional options for ensuring compliance. It is essential for organisations to stay informed about any changes in international data protection laws that could affect their data transfer practises.
To ensure ongoing compliance, the DUAA mandates regular reviews of data transfer practises and requires organisations to maintain comprehensive records of international data transfers. This accountability not only helps organisations demonstrate compliance but also enhances their ability to respond to any inquiries or audits related to data protection.
The Data (Use and Access) Act 2025 mandates that organisations must set up clear procedures for managing data protection complaints. This includes designating a specific contact point for individuals wishing to lodge complaints, ensuring that they have a straightforward method to voice their concerns. Once a complaint is received, organisations are required to acknowledge it promptly and provide updates on its progress in a timely manner. To maintain accountability, the Act outlines clear guidelines for escalating complaints if they remain unresolved, thereby ensuring that individuals have avenues for further action.
Furthermore, organisations must document their complaints handling processes and regularly review their effectiveness. This practise not only enhances transparency but also helps identify areas for improvement. Training staff on these procedures is essential to guarantee that complaints are handled consistently and fairly. Additionally, organisations are encouraged to implement feedback mechanisms, allowing them to learn from the complaints received and refine their data protection practises accordingly.
The Act promotes transparency by requiring organisations to report on statistics related to complaint handling. It is crucial for individuals to be informed of their rights, especially the option to escalate unresolved complaints to the Information Commission. By fostering an environment where organisations learn from complaints and actively work to enhance their data protection measures, the DUAA aims to build trust between individuals and organisations in the handling of personal data.
The Data (Use and Access) Act 2025 (DUAA) introduces significant changes regarding the use of storage and access technologies. One of the notable provisions allows organisations to use cookies and similar technologies in low-risk scenarios without requiring explicit consent from users. However, it is essential for these organisations to inform users about their use of such storage technologies through comprehensive privacy notices, ensuring transparency in their data handling practises.
To support compliance, the Act establishes clear guidelines regarding consent mechanisms for cookies, aiming to enhance user understanding and control. This includes the development of privacy-friendly technologies that empower users to manage their own data more effectively. Regular audits of storage practises are mandated to confirm adherence to the DUAA, promoting accountability within organisations.
Before implementing any new storage technologies, organisations must conduct thorough risk assessments to identify potential issues and safeguard user data. The use of encryption and other security measures is encouraged to protect stored data, which is crucial in maintaining user trust. Furthermore, the DUAA creates a framework for testing and evaluating new access technologies, ensuring they meet compliance standards. Organisations are also required to maintain detailed records of their storage practises, demonstrating accountability and allowing for oversight. Additionally, the Act provides clear guidelines on user rights concerning access to their data stored through these technologies, reinforcing the importance of individual privacy.
The Data (Use and Access) Act 2025 introduces significant amendments to the Data Protection Act 2018, particularly focusing on data processing for law enforcement and intelligence services. These modifications aim to streamline procedures, making it clearer how personal data can be processed for public safety and crime prevention. Key terms have been updated to align with the new framework, ensuring that definitions reflect contemporary practises.
One notable change is the introduction of a more flexible approach to data use for research and innovation, while still prioritising the protection of individual rights. For instance, the Act allows for the use of pseudonymised data in specific contexts without requiring explicit consent, enhancing data utility for various purposes. Additionally, there is a clearer framework for handling data breaches, including defined reporting obligations that organisations must follow.
Rules surrounding data retention have also been simplified, enabling organisations to manage their data storage more efficiently. Accountability measures for data controllers and processors have been strengthened, promoting greater transparency in data handling. Furthermore, guidelines on consent have been revised, simplifying the process for organisations to obtain and manage consent when processing personal data. Finally, the Act incorporates feedback mechanisms that allow the public to express concerns regarding data handling practises, thereby fostering trust between organisations and individuals.
Organizations must undertake a thorough review of their existing data protection policies to ensure they comply with the DUAA. This involves not only updating policies but also implementing new complaint-handling systems by June 2026, which will require timely and effective responses to complaints. Staff training on the new regulations will be essential, ensuring that employees at all levels understand their responsibilities under the Act.
Furthermore, organisations need to assess the impact of automated decision-making on their operations, incorporating necessary safeguards to protect individuals. A proactive approach to subject access requests will be vital, especially with the introduction of the new 'stop the clock' rule, which allows organisations to pause the response time if they require additional information from the requester.
Clarifying the legal grounds for processing personal data will be crucial to avoid compliance issues, as well as engaging with legal experts to navigate the complexities of international data transfers under the DUAA. Investment in technology and systems for data management may be required to meet the new compliance standards. Regular audits of data practises will help identify potential gaps before they become problematic, while collaboration with the Information Commission will be vital for staying informed on regulatory changes and guidance.
The Data (Use and Access) Act 2025 (DUAA) brings significant regulatory changes, marking a shift in how data protection is enforced in the UK. The Information Commissioner’s Office (ICO) will be transformed into the Information Commission, which will enhance its regulatory capabilities. This new structure is designed to facilitate more efficient investigations into data protection violations, thereby ensuring that compliance is taken seriously by organisations. As part of the DUAA, organisations will face stricter penalties for non-compliance, highlighting the necessity of adhering to the new regulations. The Information Commission will be empowered to impose fines and corrective actions, increasing accountability among data handlers. Moreover, the Commission will gain broader investigative rights, including the authority to conduct unannounced inspections when deemed necessary. An additional focus will be placed on engaging with the public and organisations regarding data protection, with the Commission expected to provide regular updates and guidance to help navigate the evolving landscape. This proactive approach aims to promote best practises in data protection. The Commission will also publish reports on compliance trends, which will serve as valuable resources for organisations striving to meet the new standards. Furthermore, the DUAA seeks to enhance international cooperation with data protection authorities, aligning UK practises with global standards and ensuring a more cohesive framework for data protection.
The Data (Use and Access) Act 2025 (DUAA) brings significant enhancements to consumer rights, particularly in the realm of data protection. Consumers now have the explicit right to lodge complaints directly with data controllers concerning breaches of their personal data. This change fosters a direct line of accountability, allowing individuals to address their concerns more effectively. Organisations are required to acknowledge these complaints promptly and must provide clear pathways for resolution, ensuring that consumers are not left in the dark regarding the status of their issues.
Furthermore, the DUAA enhances individuals' access to clearer information about how their data is used and processed. This includes expectations of increased transparency surrounding automated decision-making processes, enabling consumers to understand how such decisions impact them. Strengthening the right to object to certain data processing activities empowers individuals to exert greater control over their personal data.
Organisations are now obligated to clearly communicate the implications of their data processing decisions, enhancing consumer understanding and trust. The DUAA also aims to simplify the process for individuals seeking to exercise their rights under data protection law, making it more accessible and straightforward. Recognition of consumer feedback will play a pivotal role in shaping organisational data practises going forward, promoting a culture of responsiveness.
Additionally, organisations are encouraged to establish clear and accessible communication channels to address consumer inquiries effectively. This new framework supports consumer empowerment, positioning individuals as active participants in the data protection landscape. Overall, the enhancements introduced by the DUAA signify a meaningful shift towards prioritising consumer rights and fostering a more transparent data environment.
Organisations should promptly assess their current data protection practises against the new requirements set forth by the DUAA. This initial evaluation will help identify gaps and areas needing improvement. Following this, it is essential to develop a detailed compliance strategy that outlines specific actions to address each change introduced by the DUAA. Engaging with legal professionals can provide valuable insights into how the DUAA impacts specific business operations, ensuring that all legal obligations are clearly understood.
A significant focus should be placed on establishing a complaint-handling system that meets DUAA standards, with a compliance deadline set for June 2026. This system should facilitate easy access for individuals wishing to lodge complaints and ensure timely responses from the organisation. Additionally, implementing training programmes for employees is crucial to ensure they understand their roles in adhering to the new regulations, fostering a culture of data protection within the organisation.
Organisations should also establish a timeline for the phased implementation of changes, allowing for a structured approach that avoids last-minute compliance issues. Regular reviews and updates of data protection policies will be necessary to reflect ongoing changes in legislation and best practises. Considering investments in new technologies that enhance data management and security can further align operational practises with the DUAA.
Finally, staying informed about updates from the Information Commission will ensure ongoing compliance and adaptation to any emerging guidelines. By prioritising these steps, organisations can effectively navigate the complexities introduced by the DUAA.
The Data (Use and Access) Act 2025 aims to enhance the protection and accessibility of data for individuals and organisations, while ensuring that data is used responsibly and ethically.
The Act impacts not only businesses that handle data but also individuals whose data is being collected, processed, or shared.
Individuals have the right to access their personal data, request corrections, and be informed about how their data is being used.
The Act includes measures that require organisations to implement security protocols, ensuring that personal information is safeguarded against misuse and breaches.
Organisations are required to be transparent about their data practises, provide proper user consent mechanisms, and take steps to protect the data they manage.
TL;DR The Data (Use and Access) Act 2025 (DUAA) was enacted on 19 June 2025, modernising the UK’s data protection framework post-Brexit and introducing significant changes, including a more permissive automated decision-making framework, clarified subject access request procedures, and enhanced protections for children's data. The Act streamlines data processing for research, allows recognised legitimate interests in data use, and simplifies international data transfer rules. Organizations must update their compliance measures by mid-2026 and adapt to the new regulatory landscape, all whilst ensuring that consumer rights are enhanced and complaints handling mechanisms are established.