The UK Data (Use and Access) Act Changes Privacy Operations Without Replacing UK GDPR

The Data (Use and Access) Act 2025 did not sweep away the UK’s privacy framework. It changed how parts of that framework operate—and added complaint, research, digital-verification and smart-data provisions around it.

The Act received Royal Assent on 19 June 2025. Its provisions were commenced in stages, and by 19 June 2026 all of its data-protection provisions were in force. Organisations therefore need a controlled set of updates, not a wholesale replacement of every UK GDPR document.

The Act amends the UK GDPR, Data Protection Act 2018 and Privacy and Electronic Communications Regulations. It also reaches beyond conventional privacy law into digital verification services, smart data and information standards.

Lawful bases changed at the edges

The Act introduces “recognised legitimate interests” for specified processing. Where the conditions apply, an organisation still needs to show necessity but does not conduct the usual balancing test associated with ordinary legitimate interests.

That is not a general shortcut. Teams should record the exact recognised purpose and the processing that is necessary for it. If the activity does not fit the statutory list, the ordinary lawful-basis analysis remains.

The Act also clarifies examples that may fall within standard legitimate interests, including direct marketing, intra-group administrative transfers and network and information-system security. An example is not an automatic legal basis. Necessity, balancing, transparency and the right to object still require attention under the ordinary route.

Complaints become a defined operational process

One of the clearest new duties is a direct right for people to complain to an organisation about its use of their personal information. Organisations and competent authorities must facilitate complaints—for example through an electronic complaint form—acknowledge them within 30 days and respond without undue delay after taking appropriate steps to investigate.

This is a workflow requirement. A privacy email address that feeds an unmanaged inbox may fail when volume rises or a complaint spans customer service, security and a processor. The system needs acknowledgement, ownership, investigation notes, updates, outcome and escalation to the data protection officer where appropriate.

Complaints should remain distinct from subject-access requests even when one message contains both. Each part has its own legal analysis and deadline. A triage process should identify mixed requests without forcing the individual to use legal terminology.

Automated decisions require a new reading

The Act changes the restrictions on significant decisions based solely on automated processing. The strictest rules remain for special-category data, while other automated decisions operate under a revised framework with safeguards.

Organisations should not treat this as permission to remove human review. They need to determine whether a decision is solely automated, whether it has legal or similarly significant effects, what data it uses and which safeguards apply. People must have routes to make representations, obtain human intervention where required and contest decisions.

Model governance should connect those rights to the deployed system. If staff simply approve every recommendation, the nominal human step may not be meaningful.

Cookies and tracking need a targeted update

Changes to PECR expand circumstances in which some storage and access technologies can operate without consent, including specified statistical and service-improvement uses subject to conditions. The core rule has not disappeared.

Product teams should review each technology against the precise exemption rather than relabelling an analytics category as “essential.” Transparency, opt-out and purpose restrictions can remain relevant. The technical consent state should match the legal classification.

Build a change register, not a replacement programme

An efficient implementation plan should map each Act provision to an existing process:

  • lawful-basis records and privacy notices;
  • complaint intake and investigation;
  • automated-decision inventories and safeguards;
  • research and further-processing assessments;
  • cookie and tracking controls;
  • subject-access searches and time calculations; and
  • processor contracts and staff guidance.

For each item, record whether the law creates a duty, an option or a clarification. Some changes allow organisations to do something differently; they do not require every organisation to use that flexibility.

The DUAA rewards precision. The UK GDPR and Data Protection Act remain the framework, while selected definitions, procedures and permissions have changed. The safest response is a traceable amendment programme tied to real operations—not a new privacy policy pasted over systems that still behave the old way.

Official sources

Continue the series

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *