The Data (Use and Access) Act 2025
The Data (Use and Access) Act 2025, known as the DUAA, has changed the UK's data protection rules. Not dramatically enough to replace UK GDPR, but meaningfully enough that small and medium-sized businesses should take notice.
What is the Data (Use and Access) Act 2025?
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. Many of the main data protection and privacy changes came into force on 5 February 2026, with further requirements, including new complaints handling duties, taking effect in June 2026.
What does it mean for organisations?
For many organisations, the changes may not feel visible day to day. But they affect common business activities, including marketing emails, cookie banners, data complaints, automated decision-making and the use of personal data.
The DUAA 2025 refines the UK GDPR framework, giving organisations greater flexibility to innovate and grow, without weakening the rights of individuals. Read the ICO's overview of the Data (Use and Access) Act 2025.
The DUAA timeline: what changes and when
The Data (Use and Access) Act 2025 is arriving in stages
19 Jun 2025
Royal Assent
The DUAA becomes law, with provisions phased in over the following year.
5 Feb 2026
Main provisions live
Key data protection and PECR changes take effect, including higher fines.
19 Jun 2026
Complaints duty
Organisations must have a compliant data protection complaints process.
27 Dec 2031
Adequacy secured
EU–UK data adequacy renewed, so EEA data can keep flowing to the UK.
Key changes
What the Data (Use and Access) Act 2025 changes
Areas where the rules have shifted for organisations
Expands the list of processing activities that automatically qualify as legitimate interests, reducing the burden of case-by-case balancing tests.
Clearer rules on when human review is required, giving organisations more confidence to deploy AI and automated systems responsibly.
Broader permissions to use personal data for scientific, statistical and historical research, reducing friction for innovation and public interest work.
Simplified consent rules for low-risk cookies such as analytics and functional tools, reducing compliance overhead without compromising user privacy.
Updated framework for handling vexatious or excessive SARs, with clearer timelines and thresholds to reduce misuse while protecting genuine rights.
Easier reuse of personal data for compatible secondary purposes, supporting analytics, product development and operational insight.
Streamlined processes for managing data protection complaints, reducing administrative burden and improving responsiveness.
What this means for your organisation
- Simpler, leaner compliance processes, less time on paperwork, more on outcomes.
- Greater flexibility in how you lawfully use and repurpose data.
- A clearer path to adopt AI, analytics and automation within a compliant framework.
- Reduced regulatory friction for research and innovation activities.
- If you operate across the UK and EU, aligned and efficient compliance is now more achievable.
RightCue Consulting Services
The Square, Basing View, Basingstoke, Hampshire, RG21 4EB
Telephone: +44 (0)1256 744 780
Email: [email protected]
Web: www.rightcue.com



