What the Data (Use and Access) Act 2025 means for SMEs

The Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025, known as the DUAA, has changed the UK's data protection rules. Not dramatically enough to replace UK GDPR, but meaningfully enough that small and medium-sized businesses should take notice.

What is the Data (Use and Access) Act 2025?

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. Many of the main data protection and privacy changes came into force on 5 February 2026, with further requirements, including new complaints handling duties, taking effect in June 2026.

What does it mean for organisations?

For many organisations, the changes may not feel visible day to day. But they affect common business activities, including marketing emails, cookie banners, data complaints, automated decision-making and the use of personal data.

The DUAA 2025 refines the UK GDPR framework, giving organisations greater flexibility to innovate and grow, without weakening the rights of individuals. Read the ICO's overview of the Data (Use and Access) Act 2025.

The DUAA timeline: what changes and when

The Data (Use and Access) Act 2025 is arriving in stages

19 Jun 2025

Royal Assent

The DUAA becomes law, with provisions phased in over the following year.

5 Feb 2026

Main provisions live

Key data protection and PECR changes take effect, including higher fines.

19 Jun 2026

Complaints duty

Organisations must have a compliant data protection complaints process.

27 Dec 2031

Adequacy secured

EU–UK data adequacy renewed, so EEA data can keep flowing to the UK.

What this means: the biggest near-term deadline for most organisations was 19th June 2026, the date a documented complaints process becomes a legal requirement.

Key changes

What the Data (Use and Access) Act 2025 changes

Areas where the rules have shifted for organisations

Recognised legitimate interests

Expands the list of processing activities that automatically qualify as legitimate interests, reducing the burden of case-by-case balancing tests.

Automated decision-making

Clearer rules on when human review is required, giving organisations more confidence to deploy AI and automated systems responsibly.

Research provisions

Broader permissions to use personal data for scientific, statistical and historical research, reducing friction for innovation and public interest work.

Cookies & tracking

Simplified consent rules for low-risk cookies such as analytics and functional tools, reducing compliance overhead without compromising user privacy.

Subject access requests

Updated framework for handling vexatious or excessive SARs, with clearer timelines and thresholds to reduce misuse while protecting genuine rights.

Data reuse

Easier reuse of personal data for compatible secondary purposes, supporting analytics, product development and operational insight.

Complaints handling

Streamlined processes for managing data protection complaints, reducing administrative burden and improving responsiveness.

What this means for your organisation

  • Simpler, leaner compliance processes, less time on paperwork, more on outcomes.
  • Greater flexibility in how you lawfully use and repurpose data.
  • A clearer path to adopt AI, analytics and automation within a compliant framework.
  • Reduced regulatory friction for research and innovation activities.
  • If you operate across the UK and EU, aligned and efficient compliance is now more achievable.

Not sure how these changes affect your current data protection framework? RightCue can help you assess the impact, identify opportunities to simplify your compliance posture, and ensure you're positioned to get the most from the DUAA 2025.

For more information: read the ICO's official overview of the Data (Use and Access) Act 2025.

RightCue Consulting Services 

The Square, Basing View, Basingstoke, Hampshire, RG21 4EB 

Telephone: +44 (0)1256 744 780 

Email: [email protected] 

Web: www.rightcue.com 

Related articles & guides