Data Use and Access Act 2025 obligations are no longer a planning exercise for UK businesses. The main data protection provisions commenced on 5 February 2026, the mandatory complaints procedure followed on 19 June 2026, and the maximum penalty for a cookie breach is now thirty-five times what it was. If your privacy programme still reflects the pre-2026 position, it is out of date.

The formal title is the Data (Use and Access) Act 2025, and it is the reform that finally landed after the Data Protection and Digital Information Bill fell in 2024. It does not replace UK GDPR. It amends it, alongside the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations, through a phased commencement that ran across eighteen months. That phasing is the single biggest reason compliance teams have lost track of what is actually live.

This guide is written for the person who has to make the changes, not the person who has to summarise them. It sets out precisely which parts of the Data Use and Access Act 2025 are in force today, which are still pending, what each one obliges you to do differently, and where the drafting contains traps that a fast read will miss. Every date is tied to the commencement instrument that brought it into effect, and every figure in the charts comes from arithmetic stated on this page.

One framing worth carrying through: the Data Use and Access Act 2025 is not a deregulation package, whatever the pre-legislative commentary suggested. It removes friction in a handful of narrow places and adds a genuinely new, universally applicable obligation in another. Most organisations will end up doing more work, not less. The relief is targeted; the burden is general.

Data management and analytics teams tend to feel this first, because the changes bite hardest where personal data is aggregated, profiled and automated. But the complaints requirement applies to every controller in the country, including the ones with a single spreadsheet of customer emails.

What the Data Use and Access Act 2025 Actually Changed

data use and access act 2025 b three identical upright cylinders

Start with what the Act is, structurally, because a lot of published commentary describes it as a new data protection regime. It is not one. It is an amending statute of 142 sections and 16 schedules, and Part 5 is the portion that reaches into existing data protection law.

An amending statute, not a replacement regime

Nothing in the Data Use and Access Act 2025 repeals UK GDPR. Article numbers, principles, data subject rights and the accountability framework all survive intact. What changes is the content of specific Articles, the addition of two new Annexes, and the wholesale replacement of one Article with four. If your compliance documentation cites UK GDPR, those citations remain correct; the underlying text they point at has moved in places.

The parts that survived the abandoned DPDI Bill

The Act inherits much of the Data Protection and Digital Information Bill, but not the most controversial parts. Proposals to abolish the mandatory Data Protection Officer role and to replace records of processing activities with a lighter regime did not make it into the Data Use and Access Act 2025. Anyone who deferred appointing a DPO on the strength of that draft made a bad bet and needs to revisit it.

The five areas where the reach is broadest

Practically, the Data Use and Access Act 2025 changes five things that affect ordinary commercial processing: the lawful basis analysis, automated decision-making, subject access request handling, complaints, and the electronic marketing and cookies regime under PECR. There are further provisions on smart data schemes, digital verification services, the National Underground Asset Register and the ICO’s own constitution, but those affect specific sectors rather than every business.

Why “in force” has been such a moving target

The Act commenced in six tranches. Section 142 left almost everything to commencement regulations, so the operative dates live in statutory instruments rather than in the Act itself. That is why an organisation reading the Data Use and Access Act 2025 in isolation cannot tell what applies to it — the Act text and the live legal position have been different documents for most of the last year.

MilestoneDateInstrumentStatus today
Royal Assent19 June 2025Act itselfComplete
EU adequacy renewed19 December 2025EU Commission decisionsComplete
Main data protection provisions5 February 2026Commencement No. 6 RegsIn force
Purported intimate image offence6 February 2026Commencement No. 5 RegsIn force
Mandatory complaints procedure19 June 2026Commencement No. 6 RegsIn force
Statutory code on AI and ADMExpected late 2026Regulations of 12 May 2026Pending
ICO becomes the Information CommissionNot yet appointedFuture commencement regsPending

Data Use and Access Act 2025 Commencement Dates Every Controller Should Have Diarised

data use and access act 2025 c upright funnel

The dates matter more than usual here, because the transitional provisions mean some obligations attach to processing that began before commencement and some do not. Getting the date wrong changes the answer.

19 June 2025 — Royal Assent

Royal Assent brought a small number of provisions into effect immediately and started the clock on others. For most commercial controllers nothing operative happened on this date, which is precisely why so many programmes stalled: the Act was law, and nothing had changed yet.

5 February 2026 — the substantive reforms

The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 brought the bulk of Part 5 into force on 5 February 2026. Recognised legitimate interests, the new automated decision-making Articles, the subject access changes, the international transfer test and the PECR penalty uplift all took effect on that day. This is the date most of your policy documents should now reference.

19 June 2026 — the complaints procedure

Section 103 and Schedule 10 were held back and commenced on the first anniversary of Royal Assent. That deliberate four-month gap after the main tranche was the implementation window, and it has closed. Every controller should already have a compliant complaints procedure running.

Still pending as of today

Two things remain outstanding. The ICO’s transformation into the Information Commission, a body corporate with a chair and a board, awaits its own commencement regulations. And the statutory code of practice on artificial intelligence and automated decision-making — mandated by regulations made on 12 May 2026, with the ICO consultation having closed on 29 May 2026 — is expected before the end of the year.

Months elapsed from Royal Assent to each milestone
EU adequacy renewed 6 months
Main provisions in force 7.5 months
Complaints duty in force 12 months
ADM code expected 18 months

Lawful Basis Under the Data Use and Access Act 2025: Recognised Legitimate Interests

data use and access act 2025 d tall stack blank paper sheets

This is the change most likely to be misapplied, because the headline and the detail point in different directions. The Data Use and Access Act 2025 introduces a genuinely new route to lawfulness, and separately clarifies an old one, and the two are constantly conflated in summaries.

What Annex 1 actually covers

The Act inserts a new Annex 1 to UK GDPR listing recognised legitimate interests. Where a purpose is on that list, a controller can rely on legitimate interests without carrying out the balancing test at all. The list is short and public-interest flavoured: disclosures to public bodies performing statutory functions, national security, defence and public security, responding to emergencies, detecting and preventing crime, and safeguarding vulnerable individuals.

Direct marketing is not on that list

Here is the trap. Direct marketing, intra-group transmission of personal data for administrative purposes, and processing necessary for network and information security are named in the Data Use and Access Act 2025 — but as illustrative examples of ordinary Article 6(1)(f) legitimate interests, not as recognised legitimate interests. A legitimate interests assessment is still mandatory for all three.

Why the distinction has real consequences

Several published summaries of the Data Use and Access Act 2025 state that no balancing test is needed for direct marketing. Acting on that would leave a marketing programme with no documented lawful basis analysis, which is an accountability failure regardless of whether the underlying processing was fair. If you have already amended your LIA policy on that basis, reverse it.

What to change in your ROPA and privacy notice

The practical work is small but must be done. Where a purpose genuinely falls within Annex 1, record it as a recognised legitimate interest in your record of processing and note that no balancing test applies. Where it does not, leave the existing assessment in place. Privacy notices that describe your legitimate interests should be updated to reflect the new statutory language.

PurposeRouteBalancing test?Objection right?
Disclosure to a public body for a statutory functionRecognised (Annex 1)NoYes
Safeguarding a vulnerable individualRecognised (Annex 1)NoYes
Crime detection and preventionRecognised (Annex 1)NoYes
Direct marketingOrdinary 6(1)(f)YesYes, absolute
Intra-group administrative transferOrdinary 6(1)(f)YesYes
Network and information securityOrdinary 6(1)(f)YesYes

Automated Decision-Making Is Where the UK Now Diverges Most From the EU

data use and access act 2025 e three solid filled hexagonal slabs

If one part of the Data Use and Access Act 2025 will generate litigation, it is this one. The old Article 22 has been repealed outright and replaced with four new provisions, and the default has flipped.

Article 22 is gone, Articles 22A to 22D replace it

Under the previous regime, a solely automated decision producing legal or similarly significant effects was prohibited unless one of three narrow conditions applied. The Data Use and Access Act 2025 removes that structural prohibition for most processing. Solely automated significant decisions are now permissible on any lawful basis, provided the safeguards in the new Articles are met.

Special category data still triggers the old restrictions

The liberalisation is not universal. Where a significant decision is based entirely or partly on special category data — health, biometrics, ethnicity, trade union membership, sexual orientation and the rest — the restrictive regime survives largely intact. Recruitment screening and insurance underwriting frequently touch special category data without the business realising it, which makes this a mapping exercise rather than a policy decision.

What “meaningful human intervention” now means

The Act puts substance behind a phrase that had been argued over for years. Meaningful human intervention requires review by a person who is competent to conduct it and who has the authority and the information to change the outcome. A workflow that routes an automated rejection past an administrator with no discretion does not qualify, and never did — the difference is that this is now written down.

The three safeguards you must actually build

Where you rely on the relaxed regime, the Data Use and Access Act 2025 requires you through Articles 22A to 22D to inform the data subject that a solely automated significant decision has been made, to enable them to make representations, and to allow them to obtain human intervention and contest the outcome. These are engineering requirements, not policy requirements. If your decisioning platform has no route to log a contest and escalate it, that is a build ticket.

Note also that the safeguards apply to the decision, not to the model. Teams with mature cybersecurity and model governance practices sometimes assume that documented model validation discharges these duties. It does not — the Data Use and Access Act 2025 obligations run to the individual affected, and they are satisfied by notification, representation and review, not by internal assurance.

The statutory code of practice is still coming

Regulations made on 12 May 2026 require the ICO to produce a statutory code of practice covering artificial intelligence and automated decision-making. The consultation closed on 29 May 2026 and the code is expected later this year. Any organisation deploying machine learning in decisioning should treat the current position as provisional and design for a stricter code rather than a looser one.

Why the divergence from the EU matters commercially

This is now the widest gap between UK GDPR and EU GDPR. A group operating on both sides of the Channel cannot run one automated decisioning policy and satisfy both regimes. In practice most multinationals will hold to the EU standard everywhere and treat the Data Use and Access Act 2025 relaxation as headroom they choose not to use.

The Complaints Procedure the Data Use and Access Act 2025 Made Mandatory

data use and access act 2025 f single closed padlock

Everything above is conditional on what your organisation does. This is not. Since 19 June 2026 every controller in the United Kingdom has needed a data protection complaints procedure, regardless of size, sector or processing volume. It is the only part of the Data Use and Access Act 2025 that creates a new, universally applicable operational duty, and it is the part most likely to catch a small business unprepared.

The 30-day acknowledgement clock

A complaint must be acknowledged within 30 days of receipt. An automated email acknowledgement is sufficient where the complaint arrived electronically, and a verbal acknowledgement is acceptable for a verbal complaint. The obligation is simply that the acknowledgement is prompt, recorded and traceable.

The channels you must offer

Controllers must facilitate complaints by providing an electronic form and at least one alternative route, such as email or post. Complaints must also be accepted however they arrive — including by social media, which is where a meaningful proportion of them will land. That last point is what breaks most implementations, because social channels are usually run by marketing rather than by the privacy function.

What you must do after acknowledging

Beyond acknowledgement, the controller must without undue delay take appropriate steps to respond, which includes making enquiries into the subject matter where appropriate and keeping the complainant informed of progress. You must then inform the complainant of the outcome. There is no fixed statutory deadline for the substantive response, which makes internal service levels worth setting yourself.

Records the ICO can ask to see

Keep a record of when each complaint was received, how and when it was acknowledged, the steps taken during the investigation, and the final outcome. The ICO can request these records, and a controller who cannot produce them has an evidential problem irrespective of how well the complaints were actually handled. Record-keeping is the part of the Data Use and Access Act 2025 complaints duty that organisations most often skip, because it produces no visible output until a regulator asks.

Telling people about the escalation route

You must inform complainants of their right to escalate to the ICO and provide the ICO’s contact details. The wider design intent of the Data Use and Access Act 2025 is to route complaints through the controller first, which reduces the regulator’s inbound volume but only works if people are told the onward route exists.

Statutory response clocks a UK controller now runs in parallel
Personal data breach notification to ICO 72 hours
Complaint acknowledgement 30 days
Subject access request, standard 1 month
Subject access request, extended 3 months

Subject Access Requests Under the Data Use and Access Act 2025

The subject access changes are the most modest in the Act, and they are also the ones most likely to be over-read by an enthusiastic operations team. The Data Use and Access Act 2025 codified existing regulatory practice here; it did not create new latitude.

“Reasonable and proportionate” is now in the statute

A controller is required to carry out a reasonable and proportionate search in response to a request. This was already the ICO’s published position and had been endorsed judicially, so the effect is to move a guidance principle into primary legislation. The practical benefit is evidential: you can now point to statute when explaining why an unbounded search of every backup tape was not required.

Stopping the clock for clarification

Where a controller reasonably requires clarification to respond — typically because the requester holds a large volume of data and has not indicated what they want — the response period is paused until clarification is received. This too reflects prior practice, but the statutory footing removes the argument about whether the clock ever really stopped.

What this does not give you

It does not permit a narrow search because a wide one would be inconvenient, and it does not allow clarification to be requested tactically to buy time. Both would be straightforward for a complainant to challenge, and under the new complaints regime that challenge now has a formal internal route before it reaches the regulator. Treating the Data Use and Access Act 2025 as a licence to slow subject access handling would be a poor reading of it.

Cookies, PECR and a Thirty-Five-Fold Increase in Maximum Fines

Of all the changes the Data Use and Access Act 2025 brought in, this is the one with the sharpest financial edge, and it is the one most UK marketing teams have not yet absorbed.

The penalty ceiling moved from £500,000 to £17.5 million

Before the Data Use and Access Act 2025, the maximum penalty under PECR was £500,000. It is now aligned with UK GDPR: up to £17.5 million or 4% of total annual worldwide turnover, whichever is higher. That is a thirty-five-fold increase in the fixed ceiling, applied to a body of rules — cookies, electronic marketing, unsolicited calls — that many organisations have historically treated as a lower tier of risk.

The three new consent exemptions

The Data Use and Access Act 2025 creates narrow exemptions from the consent requirement for low-risk storage and access: statistical purposes aimed solely at improving your own service, applying a user’s appearance or functionality preferences automatically, and ascertaining a user’s location to provide emergency assistance. These sit alongside the pre-existing strictly-necessary exemption.

Why the analytics exemption is narrower than it looks

The statistical exemption is the one everyone wants, and it is tightly drawn. The data must be used solely to improve your service or website, and it must not be shared with anyone else except to assist with those improvements. An analytics deployment that also feeds advertising audiences, or that shares data with a provider for that provider’s own purposes, falls outside the exemption entirely and still requires consent.

Opt-out is still mandatory

Exempt does not mean invisible. Where you rely on one of the new exemptions you must still give clear information about the storage or access and provide a simple means of opting out. Replacing a consent banner with nothing is not a compliant implementation of the Data Use and Access Act 2025; replacing it with a clear notice and a working opt-out is.

Maximum PECR fixed penalty, before and after commencement
Before 5 February 2026 £500,000
After 5 February 2026 £17,500,000
Cookie purposeConsent needed?Notice needed?Opt-out needed?
Strictly necessaryNoYesNo
First-party analytics, not sharedNoYesYes
Appearance and accessibility preferencesNoYesYes
Emergency location assistanceNoYesYes
Analytics also feeding ad audiencesYesYesYes
Advertising and cross-site trackingYesYesYes

International Transfers and EU Adequacy After the Data Use and Access Act 2025

Divergence carries a standing risk for the United Kingdom: if the European Commission concludes that UK law has drifted too far, adequacy falls and every inbound EU data flow needs a transfer mechanism. That question has now been answered, at least for the medium term.

The renewed adequacy decisions

The Commission renewed both UK adequacy decisions on 19 December 2025, having extended the originals by six months specifically to assess the framework as amended by the Data Use and Access Act 2025. The renewed decisions run for six years, expiring on 27 December 2031, with a mid-point review after four years conducted with the European Data Protection Board.

Monitoring is a live condition, not a formality

The EDPB identified areas where it wanted further clarification and where Data Use and Access Act 2025 implementation should be monitored — automated decision-making prominent among them. Adequacy is therefore conditional in substance even though it is granted in form. An organisation with significant EU-to-UK flows should keep a fallback transfer mechanism documented rather than assume six years of certainty.

The new data protection test

The Act replaces the standard the Secretary of State applies when assessing a third country. The question is now whether the standard of protection is not materially lower than under UK law, rather than whether it is essentially equivalent. In practice this makes future UK adequacy regulations easier to grant, which is useful for outbound flows and irrelevant to inbound ones.

Processor-to-controller transfers clarified

A useful piece of housekeeping: the position on the three-step transfer test has been clarified so that a UK processor transferring personal data back to a controller outside the UK is not making a restricted transfer. That resolves a long-running argument in outsourcing arrangements and removes a category of unnecessary transfer paperwork.

What the Data Use and Access Act 2025 Did Not Change

Knowing what has not moved is as valuable as knowing what has, because a reform of this size generates a great deal of confident misinformation.

DPOs, ROPAs and DPIAs all survive

The mandatory DPO obligation under Article 37 remains. Records of processing activities under Article 30 remain. Data protection impact assessments under Article 35 remain. The Data Use and Access Act 2025 dropped every DPDI proposal that would have diluted these, so if your accountability documentation was compliant in 2024 its structure is still correct.

Breach reporting is untouched

The 72-hour notification obligation to the ICO and the requirement to notify affected individuals where there is a high risk to their rights are unchanged. Nothing in the Act alters the threshold, the timescale or the content of a breach report.

The principles and the transparency obligations remain

Lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability all stand. Articles 13 and 14 privacy information requirements stand. What changes is some of the detail you have to disclose, not the obligation to disclose.

The EU GDPR still applies to your EU-facing processing

If you offer goods or services to individuals in the EU or monitor their behaviour, EU GDPR applies to that processing under its own extraterritorial reach. The Data Use and Access Act 2025 does not and cannot reduce those obligations. UK reform is not a route out of EU compliance for a business with EU customers.

A Practical Remediation Plan for the Rest of 2026

Assume you are starting from a programme that has not been updated since 2025. This is the order that resolves the most exposure per unit of effort under the Data Use and Access Act 2025, and it is deliberately sequenced so the legally hardest deadline is addressed first.

First — close the complaints gap

The complaints duty is in force, universal and easy to evidence a failure against. Stand up an electronic complaints form, add one alternative channel, brief whoever monitors your social accounts, write the 30-day acknowledgement into a template, and create a complaints log with the four fields the ICO can ask for. This is days of work, not weeks, and it is the largest unmanaged risk for most organisations.

Second — re-do the lawful basis mapping

Walk your record of processing and mark each legitimate interests entry as either a recognised legitimate interest under Annex 1 or an ordinary one needing an assessment. Correct any LIA you retired on the strength of a summary that put direct marketing in the wrong column. Update the legitimate interests wording in your privacy notice at the same time.

Third — audit cookies and analytics honestly

Inventory every tag, and for each one answer a single question: does any data leave this site for a third party’s own purposes? If yes, it needs consent, exemption or removal. Where an exemption genuinely applies, replace the consent prompt with clear information and a working opt-out rather than deleting the banner. Given the new penalty ceiling, this is no longer a low-stakes exercise.

Fourth — inventory automated decision-making

List every process that produces a significant effect on a person with no meaningful human involvement, and flag any that touch special category data. For each, confirm you can deliver the three safeguards: notification, representations, and human review by someone empowered to change the outcome. Design against a stricter future code, because one is coming.

Fifth — refresh training and governance

The people handling complaints and subject access requests need to know what the Data Use and Access Act 2025 changed. A short, specific briefing beats a generic refresher. If your organisation relies on an external provider for managed IT services, confirm in writing which of these controls sit with them and which remain yours — the complaints obligation cannot be outsourced, only supported.

Sixth — revisit supplier contracts at renewal

Processor agreements written against the pre-2026 framework are not invalid, but they may reference the wrong standards for automated processing and transfers. Rather than reopening every contract, add the Data Use and Access Act 2025 changes to your renewal checklist and address them as agreements come round. Our notes on trust and security practice cover the controls most often missed at that point.

Frequently Asked Questions About the Data Use and Access Act 2025

Does the Data Use and Access Act 2025 replace UK GDPR?

No. It amends UK GDPR, the Data Protection Act 2018 and PECR. UK GDPR remains the operative instrument, with amended Articles, two new Annexes and Article 22 replaced by Articles 22A to 22D.

Do we still need a Data Protection Officer?

If you needed one under Article 37 before, you still need one. The proposals to abolish the role came from the abandoned DPDI Bill and were not carried into the Data Use and Access Act 2025.

Has the ICO started enforcing the Data Use and Access Act 2025 provisions?

The ICO has signalled a phased, implementation-focused approach rather than immediate enforcement, with cookie compliance flagged as a renewed priority and automated decision-making enforcement likely to target absent transparency or missing human intervention. A phased approach is not an amnesty.

Does this affect our EU customers?

Not directly. EU GDPR continues to apply to processing within its territorial scope, and the Data Use and Access Act 2025 cannot reduce it. The renewed adequacy decisions mean EU-to-UK transfers continue without additional safeguards until at least 27 December 2031, subject to the mid-point review.

What happens if we ignore the complaints requirement?

It is an enforceable obligation under the Data Use and Access Act 2025, and non-compliance is unusually visible: a complainant who receives no acknowledgement within 30 days can escalate straight to the regulator with a documented failure. That is a far easier case to make than most data protection complaints.

Does the Data Use and Access Act 2025 make cookie banners optional?

Only for a narrow set of low-risk purposes, and even then a notice and an opt-out are still required. Most commercial websites carry advertising or third-party analytics tags that remain firmly inside the consent requirement.

References