DUAA compliance is now a live obligation for every business in the United Kingdom, and the smallest organisations are the ones least equipped to work out what it means. The Data (Use and Access) Act 2025 is fully commenced. There is no grace period, no small-business exemption from the parts that matter, and no version of the checklist below that a twelve-person company can safely ignore.
This article is written for the firm with no data protection officer, no in-house lawyer, and one person who handles the info@ inbox alongside three other jobs. It answers a narrower question than the general commentary does: of everything in the Act, what does an SME actually have to do, how many hours does each item take, what evidence has to exist on file afterwards, and who in a small team should own it.
We have already published two longer pieces on this legislation. If you want the obligation-by-obligation walkthrough of the statute, read the Data Use and Access Act 2025 risk checklist. If you want the before-and-after comparison against the old law, read what the DUAA changed against UK GDPR. This one assumes you have neither the time nor the appetite for either, and want the shortest defensible path to being compliant.
One framing point before the detail, because it changes how you should read every section. DUAA compliance is not a project with an end date bolted onto your existing data protection posture — it is a set of small edits to documents and processes you already have, plus exactly one genuinely new duty.
Treated that way, DUAA compliance is roughly two working weeks of effort for a typical SME. Treated as a transformation programme it will cost you five times that and finish no more compliant. The same principle applies to cybersecurity generally: the organisations that stay out of trouble are usually the ones doing a small number of unglamorous things consistently, not the ones buying a platform.
Table of contents
- Does DUAA Compliance Apply to Your SME? Start With Scope, Not With the Act
- The DUAA Compliance Baseline Every UK SME Must Meet
- DUAA Compliance Duties That Only Apply to Some SMEs
- The Complaints Procedure: DUAA Compliance Without a Legal Department
- DUAA Compliance and Subject Access Requests in a One-Inbox Business
- Cookies, Consent and the DUAA Compliance Risk Behind a £17.5 Million Ceiling
- DUAA Compliance for Automated Decisions Hiding Inside Off-the-Shelf SaaS
- What DUAA Compliance Costs an SME: Hours, Money and Who Does the Work
- The DUAA Compliance Evidence Pack: What to Have on File
- DUAA Compliance for Processors and Suppliers: What an SME Can Demand
- Seven DUAA Compliance Failures Specific to Small Businesses
- A Ninety-Day DUAA Compliance Plan for a Small Team
- Frequently Asked Questions About DUAA Compliance
- References
Does DUAA Compliance Apply to Your SME? Start With Scope, Not With the Act
The first mistake small businesses make is reading the legislation before establishing which parts of it can possibly reach them. Scope first, statute second — DUAA compliance is decided by what you actually do. Almost every SME lands in the same place, but knowing why saves you from over-engineering the response.
You are almost certainly a controller, and that settles most of DUAA compliance
If your business decides why and how personal data gets processed — customer records, employee files, a mailing list, a CCTV camera at the entrance — you are a controller, and the full weight of DUAA compliance applies. There is no turnover floor and no headcount floor. A sole trader with a customer database is a controller in exactly the same sense that a bank is. What differs is the volume of work, not the existence of the duty.
Headcount changes DUAA compliance far less than people expect
The most persistent myth in SME data protection is that organisations under 250 employees are broadly exempt. They are not. The under-250 exemption in Article 30 relates only to maintaining a record of processing activities, and it evaporates the moment your processing is not occasional, risks the rights of individuals, or involves special category data — which describes essentially every business with employees and a payroll. Treat the exemption as unavailable and maintain a simple register anyway. Nothing else in DUAA compliance scales with headcount at all.
What actually scales the DUAA compliance workload
Three variables drive the effort: how many distinct systems hold personal data, whether any decision about a person is made automatically, and whether you process special category data. A ten-person consultancy running email, an accounting package and a CRM has perhaps eleven hours of work. A ten-person recruitment firm running automated CV screening against candidate health disclosures has considerably more, because two of the three variables are switched on.
The three-question DUAA compliance scoping test
Answer these before you read anything else. Do you make any decision about a person — hiring, pricing, credit, eligibility — where no human meaningfully reviews the outcome? Do you hold health, biometric, ethnicity, trade union, religious, sexual orientation or criminal offence data about anyone, including staff? Do you use cookies or similar technologies on a website for anything beyond making the site function? Each yes adds a defined block of work to your DUAA compliance plan, and each no removes it entirely.
| Scoping question | If the answer is no | If the answer is yes |
|---|---|---|
| Do you hold personal data at all? | Nothing applies (vanishingly rare) | Full baseline applies |
| Solely automated significant decisions? | Skip the safeguards build entirely | Notification, representation and contest routes |
| Special category data? | Standard lawful basis analysis only | Condition under Article 9 plus tighter ADM limits |
| Non-essential cookies or trackers? | No banner needed | Consent, notice and opt-out under PECR |
| Under 250 employees? | Register mandatory | Register still effectively mandatory |
| Any customer-facing channel? | Complaints duty still applies | Complaints duty applies on every channel |
The DUAA Compliance Baseline Every UK SME Must Meet
This is the irreducible DUAA compliance list. Whatever else your business does or does not do, these five items are the floor for DUAA compliance, and four of the five are edits rather than builds.
A written complaints procedure, the only genuinely new DUAA compliance duty
Since 19 June 2026 every controller in the United Kingdom must operate a data protection complaints procedure. Not a policy about complaints — an actual working route by which a person can complain, be acknowledged within 30 days, and be told the outcome. It applies regardless of size or sector. This is the single item most likely to be missing in an SME, because nothing in the previous law required it and no software vendor sells it to you.
Privacy notice edits to match the new statutory language
Your privacy notice almost certainly describes legitimate interests in language that predates Annex 1, and describes automated decision-making in language that predates the repeal of Article 22. Both need updating. This is a drafting job of perhaps two hours, and it is the most visible artefact you have, which is why regulators and complainants look at it first.
A column added to your legitimate interests register
The Act inserts Annex 1 to UK GDPR listing recognised legitimate interests where no balancing test is required — disclosures to public bodies performing statutory functions, national security, defence and public security, emergency response, crime detection and prevention, and safeguarding vulnerable individuals. Walk your existing register and mark each entry as recognised or ordinary. Most SME entries will be ordinary and change not at all.
A subject access procedure written down rather than improvised
The Act puts the “reasonable and proportionate” search standard into statute. Your obligation has not changed, but the evidence a regulator expects has. A one-page procedure naming who receives requests, what gets searched, and what gets recorded converts an improvised scramble into a defensible process. DUAA compliance frequently turns on whether the file shows what you did, not on whether you did it.
A cookie and tag audit against the new exemptions
Three narrow new exemptions to the consent requirement exist, and none of them covers advertising or analytics as most SMEs deploy it. The reason to audit anyway is that the maximum PECR penalty rose from £500,000 to £17.5 million or 4% of worldwide turnover — the same ceiling as UK GDPR. The obligation barely moved; the price of getting it wrong moved by a factor of thirty-five.
| Baseline item | Type of work | Evidence to file | Typical SME hours |
|---|---|---|---|
| Complaints procedure | New build | Procedure doc plus complaint log | 6 |
| Privacy notice update | Edit | Dated version history | 2 |
| Legitimate interests register | Edit | Register with Annex 1 column | 3 |
| Subject access procedure | Write down existing practice | One-page procedure plus search log | 3 |
| Cookie and tag audit | Review | Tag inventory plus banner screenshot | 4 |
| Processing register refresh | Edit | Register dated within 12 months | 4 |
DUAA Compliance Duties That Only Apply to Some SMEs
Everything in this section is conditional. If none of these triggers fires in your business, your DUAA compliance work is finished at the baseline above, and you should stop reading and go and do it.
Solely automated significant decisions change the DUAA compliance picture
Article 22 has been repealed outright and replaced by Articles 22A to 22D. Solely automated decisions with legal or similarly significant effects are now permissible on any lawful basis, provided specified safeguards are met — a reversal of the old default, which prohibited them subject to three narrow exceptions. If you make such decisions, three safeguards apply: tell the individual a solely automated significant decision was made, let them make representations, and let them obtain human intervention and contest the outcome.
Special category data narrows the automation route sharply
Where a decision is based entirely or partly on special category data — health, biometrics, ethnicity, trade union membership, religious belief, sexual orientation — the restrictive prohibition largely survives. This carve-out is broader than it looks. Recruitment screening that touches a declared disability, or insurance-adjacent pricing that touches health, sits inside it without the business ever classifying the data that way.
Meaningful human intervention now has a statutory definition
The Act defines what has been argued about for years. Meaningful human intervention requires review by a person competent to conduct it, holding both the authority and the information needed to change the outcome. A workflow that routes an automated rejection past an administrator with no discretion has never qualified; the difference is that it is now written down and easy for a complainant to cite. For an SME, the practical consequence is that naming a reviewer is not enough — that person needs the seniority to overturn the result.
Children’s data and online services
If your service is likely to be accessed by children, the age-appropriate design expectations continue to apply on top of everything here, and the DUAA compliance position is stricter rather than looser. Nothing in the Act relaxed it.
When a data protection officer becomes mandatory
The DPO triggers did not change. You need one if you are a public authority, if your core activities require regular and systematic monitoring of individuals on a large scale, or if your core activities involve large-scale processing of special category or criminal offence data. Most SMEs meet none of these. Appointing a named responsible person anyway is sensible practice, but do not confuse a sensible internal owner with a statutory DPO — the roles carry different protections and different independence requirements.
| Trigger | Typical SME example | What it adds to your plan | Added hours |
|---|---|---|---|
| Solely automated decisions | CV shortlisting, credit scoring | Notification, representation, contest route | 20 to 40 |
| Special category data | Occupational health records | Article 9 condition plus policy document | 6 |
| Large-scale monitoring | Fleet tracking, call recording | DPIA and possibly a DPO | 12 |
| Children likely to access | Consumer app or community site | Age-appropriate design assessment | 10 |
| International transfers | US-hosted SaaS | Transfer record; no new test to run | 2 |
| None of the above | Professional services firm | Baseline only | 0 |
The Complaints Procedure: DUAA Compliance Without a Legal Department
This deserves its own section because it is new, universal, and easy to fail visibly. A complaint that goes unacknowledged is the kind of failure a member of the public can escalate to the regulator with a single screenshot.
The 30-day acknowledgement clock at the centre of DUAA compliance
A complaint must be acknowledged within 30 days of receipt. An automated email acknowledgement suffices where the complaint arrived electronically, and a verbal acknowledgement is acceptable for a verbal complaint. The requirement is that the acknowledgement is prompt, recorded and traceable — three properties a shared inbox does not provide on its own.
Two channels minimum, but every channel must be accepted
You must facilitate complaints by providing an electronic form and at least one alternative route such as email or post. Separately, you must accept complaints however they actually arrive, including through social media. That second point breaks most SME implementations, because social accounts are run by whoever does marketing, and a data protection complaint arriving as an Instagram reply looks like a customer service message until someone recognises it.
Build it on the tools you already own
DUAA compliance here does not require new software. A form on your website that emails a dedicated address, an auto-responder on that address, and a spreadsheet with six columns is a complete and defensible implementation for a business of under fifty people. The failure mode is never the tooling; it is that nobody told the person watching the social accounts what a complaint looks like.
The complaint log schema that survives a regulator’s question
Record: date received, channel, complainant, summary, date acknowledged, steps taken, outcome, date outcome communicated. Eight columns. The ICO can request these records, and a controller who cannot produce them has an evidential problem irrespective of how well the complaints were actually handled. Record-keeping is the part of DUAA compliance organisations most often skip, because it produces no visible output until someone asks for it.
Tell people how to escalate
You must inform complainants of their right to escalate to the ICO and provide the ICO’s contact details. The design intent is that complaints route through the controller first, which reduces the regulator’s inbound volume — but only if people know the internal route exists, which means saying so in the privacy notice and in the acknowledgement itself.
DUAA Compliance and Subject Access Requests in a One-Inbox Business
Subject access is where small teams lose the most DUAA compliance time, and where the Act’s changes are most helpful to them if they understand what actually moved.
Reasonable and proportionate: the DUAA compliance standard now in statute
The obligation is to conduct a reasonable and proportionate search. That standard existed in regulatory guidance already; the Act puts it on a statutory footing. Your duty has not increased. What has changed is that “proportionate” is now a word you can point at in legislation when explaining why you did not image every backup tape in the building.
What proportionate means for a twenty-person firm
It means searching the systems where the data would reasonably be, using the identifiers the requester gave you, and documenting the boundary you drew and why. It does not mean forensic recovery of deleted material, and it does not mean reading a decade of archived email on the off-chance. Proportionality is judged against your size and resources, which is one of the few places where being small genuinely reduces the burden.
The stop-the-clock provisions worth knowing
The response deadline can be paused where you reasonably require further information to identify the requester or to locate the data. The pause is only valid if you actually ask promptly and record that you asked. Small teams routinely lose two weeks of a one-month deadline before starting, then discover the clarification they needed could have been requested on day one.
The search log that turns a scramble into evidence
Record what you searched, the terms used, the date range, what you found, what you withheld and under which exemption. This log is the whole of your defence if the requester complains, and it takes ten minutes to keep while you work versus half a day to reconstruct afterwards. Good data management and analytics practice makes this dramatically cheaper, because knowing where personal data lives is most of the work.
The request that does not say “subject access request”
There is no magic wording. “Can you send me everything you have about me” is a valid request, and so is a comment made in a phone call. Train whoever answers the phone and the inbox to recognise the substance, because the clock starts on receipt by the organisation, not on recognition by the right person.
Cookies, Consent and the DUAA Compliance Risk Behind a £17.5 Million Ceiling
The cookie rules changed slightly and the penalty for breaking them changed enormously, which makes this the highest-leverage hour of DUAA compliance work on the list. That asymmetry is the single most important commercial fact in this article.
Three new exemptions that change less DUAA compliance work than the headlines suggest
The Act adds narrow exemptions to the consent requirement, covering things like statistical measurement to improve a service, adapting the appearance or function of a site to a user’s preferences, and certain emergency and security purposes. Each carries conditions, including that the user is given clear information and a means to object. None of them exempts advertising cookies, none exempts third-party marketing pixels, and none exempts the analytics configuration most SME websites actually run.
Your banner stays, and it still has to work properly
Because the exemptions are conditional rather than blanket, the practical outcome for a typical SME site is that the consent banner remains necessary. What changes is that you can no longer treat the banner as a solved problem installed in 2019. The relevant question for DUAA compliance is whether tags actually hold fire until consent is given — and on a large share of small business sites they do not, because a plugin was added later and never wired into the consent layer.
The tag audit an SME can genuinely run in an afternoon
Open your site in a private browsing window with developer tools recording network requests. Load a page, refuse consent, and list every third-party request that fired anyway. Anything advertising or analytics-related in that list is a live problem. Repeat after accepting consent to confirm the tags then work. That is the whole audit, and it needs no budget.
A thirty-five-fold repricing of the same mistake
The maximum PECR penalty moved from £500,000 to £17.5 million or 4% of worldwide turnover, whichever is higher. For most SMEs the turnover-based figure is the binding one, and it converts a cookie misconfiguration from a nuisance into a genuine balance-sheet risk. Nothing about your website got more illegal; the consequence of it being illegal multiplied.
DUAA Compliance for Automated Decisions Hiding Inside Off-the-Shelf SaaS
Most SMEs answer “no” to the automated decision question and roughly a third of them are wrong. The reason is that the automation arrived inside a product they bought for another purpose.
Where the SME automated decisions that need DUAA compliance actually live
Applicant tracking systems that rank or filter candidates. Payment gateways that decline transactions on a fraud score. Credit checking built into an accounting package. Insurance and finance portals that price automatically. Tenant referencing. None of these were bought as artificial intelligence, and none of them appear on a list of AI systems, which is exactly why they are missed when scoping DUAA compliance.
The test is the effect on the person, not the sophistication of the model
A hand-written rule that automatically rejects every applicant without a specific qualification is a solely automated decision with a significant effect. A large machine learning model that produces a recommendation a manager genuinely weighs is not. Sophistication is irrelevant; what matters is whether a human meaningfully intervenes and whether the outcome significantly affects the individual.
Three safeguards that are build tickets rather than policy lines
Where you rely on the relaxed regime, you must inform the individual that a solely automated significant decision has been made, allow representations, and provide human intervention and a route to contest. A paragraph in a privacy notice satisfies none of that. Your system needs a notification event, somewhere to store the representation, an escalation route, and an audit trail. For an SME using a third-party platform, the honest first step is asking the vendor whether their product supports these — several do not.
The statutory code is still coming, so build conservatively
Regulations made on 12 May 2026 require the ICO to produce a statutory code of practice on artificial intelligence and automated decision-making. The consultation closed on 29 May 2026 and the code is expected before the end of 2026. Treat today’s position as provisional. Retrofitting a contest route into a live product costs several times what including it at the start does, and that ratio is worse for small teams, not better.
What DUAA Compliance Costs an SME: Hours, Money and Who Does the Work
Cost is the DUAA compliance question every owner asks first and most articles answer last or not at all. Here are defensible numbers for a business with no existing programme.
The realistic DUAA compliance hour budget
A professional services SME with no automated decisions, no special category processing beyond ordinary HR, and a standard marketing website should budget 22 to 26 hours to reach the baseline from a standing start. Add roughly 20 to 40 hours of DUAA compliance work if solely automated decisions are in play, because that work is engineering rather than drafting. Add six hours for a special category condition and policy document. Beyond that, the numbers stop being generic.
Who should own DUAA compliance internally
The DUAA compliance work splits cleanly. Document edits go to whoever owns your policies — usually operations or the finance director in a small firm. The complaints procedure and the SAR procedure go to whoever already handles customer correspondence. The tag audit goes to whoever manages the website, which in a small business is frequently an external agency, and that is fine provided someone internal reads the output. Only the automated decisions work needs technical ownership.
Buying it in: three options and their real prices
An hourly consultant will do the baseline in the same 22 to 26 hours at a blended rate that typically runs £90 to £150 in the UK regions and higher in London. A fractional or outsourced DPO service runs monthly and is worth it only if you have an ongoing volume of requests and complaints. A law firm is the right answer for a genuinely contested question of interpretation and the wrong answer for writing a complaints procedure. Most SMEs need a few hours of advice, not a retainer.
Where the money is genuinely well spent
Two places. First, an external tag audit if nobody internal can read a network waterfall — the penalty asymmetry makes this cheap insurance. Second, a single external review of your finished evidence pack, because the failure mode for self-serve DUAA compliance is not doing the wrong thing, it is doing the right things and never writing them down. A half-day review catches that. Firms that already outsource technology to a managed IT services provider should ask whether the system inventory they need already exists in the provider’s documentation.
| Delivery option | Best for | Indicative cost | Main risk |
|---|---|---|---|
| Fully internal | Under 30 staff, simple processing | 25 hours of internal time | Work done but never documented |
| Internal plus review | Most SMEs | 25 hours plus a half-day review | Review booked too late to change anything |
| Consultant delivered | No internal capacity at all | £90 to £150 per hour | Generic templates nobody adopts |
| Outsourced DPO service | Steady request and complaint volume | Monthly retainer | Paying for capacity you never use |
| Law firm | Contested interpretation, disputes | Highest hourly rate | Expensive way to write a procedure |
The DUAA Compliance Evidence Pack: What to Have on File
Regulators do not inspect intentions. The measurable output of your DUAA compliance work is a folder of dated documents that a third party can read without you in the room.
The nine DUAA compliance artefacts
Privacy notice with a version date. Record of processing activities. Legitimate interests assessments with the Annex 1 column. Data protection complaints procedure. Complaint log. Subject access procedure and search logs. Cookie and tag inventory with a banner screenshot. Processor list with contract references. If applicable, the automated decision-making register naming each decision, its safeguards and its human reviewer.
Where the DUAA compliance pack should live
One folder, one owner, access for at least two people, and a location that survives the departure of whoever built it. The most common evidential failure in a small business is not absence of documents but absence of documents anybody else can find. A shared drive folder beats a personal inbox and a wiki page beats both, provided it is backed up.
Version control and dates matter more than polish
A dated, slightly rough document beats an undated, beautifully formatted one, because the regulator’s question is when you did the work, not how it looks. Put a revision date and an owner name in the header of every artefact. That single habit resolves most of the “can you evidence this” conversations that follow a complaint.
A DUAA compliance review cadence realistic for a small team
Annual for the register, the privacy notice and the legitimate interests assessments. On change for the processor list and the tag inventory — meaning when you add a supplier or a plugin, not on a schedule. Continuous for the complaint and SAR logs, because they are records rather than documents. Anything more frequent will not survive contact with a busy quarter.
| Artefact | Typical SME owner | Review cadence | Fails if |
|---|---|---|---|
| Privacy notice | Operations or marketing | Annual | Undated or pre-2026 language |
| Processing register | Operations | Annual | Systems added but never recorded |
| Complaints procedure and log | Customer service lead | Continuous | Log does not exist |
| Subject access logs | Whoever handles requests | Per request | Search boundary undocumented |
| Tag inventory | Web owner or agency | On change | Plugin added outside the consent layer |
| Automated decision register | Technical lead | On change | Reviewer named but powerless |
DUAA Compliance for Processors and Suppliers: What an SME Can Demand
Small businesses have little negotiating leverage over large software vendors, and DUAA compliance does not pretend otherwise. The workable strategy is to ask a small number of precise questions and to record the answers.
Your existing Article 28 terms probably satisfy DUAA compliance already
The processor contract requirements did not change. If you have a data processing agreement in place with each supplier that touches personal data, that part of your file is already in order and needs no renegotiation. Check that the list of suppliers is current, which for most SMEs is where the gap actually is — the agreement exists, the inventory of who holds it does not.
The three DUAA compliance questions worth sending every processor
Does your product make or support any solely automated decision about our customers or staff? If so, does it support notifying the individual, storing a representation, and routing a contest to a human reviewer? And where is our data hosted and processed? Three questions, one email, and the replies go straight into your DUAA compliance evidence pack.
When the vendor will not answer
Record that you asked and what you received. An unanswered question that is documented is a materially better position than an unasked one, and for a small buyer facing a large vendor it is often the only realistic outcome. Where a product genuinely cannot support the safeguards and you rely on it for significant decisions, the honest conclusion is that a human has to stay in that loop.
International transfers after the not-materially-lower test
The transfer test changed from “essentially equivalent” to “not materially lower”, and EU adequacy for the UK has been extended to 27 December 2031. Both facts point the same way for SME DUAA compliance: there is nothing to do today beyond recording where data goes. Do not let a vendor sell you a transfer remediation project on the strength of this change.
Seven DUAA Compliance Failures Specific to Small Businesses
These are the DUAA compliance patterns that actually catch SMEs, as distinct from the enterprise failure modes that dominate published guidance.
The legitimate interests assessment that was retired on bad advice
Direct marketing, intra-group transmission for administrative purposes, and network and information security appear in the Act as illustrative examples of ordinary legitimate interests, not as Annex 1 recognised ones. Several widely circulated summaries say the opposite. If your marketing team retired an assessment on that basis, reinstate it — an absent assessment is an accountability failure even where the underlying processing was fair.
The DUAA compliance complaint that arrived on Instagram
Covered above, and worth repeating because it is the most likely single point of failure in the whole of SME DUAA compliance. Brief whoever runs the social accounts, in writing, on what a data protection complaint looks like and where to forward it.
The free cookie banner that fires tags before consent
A consent banner that displays correctly while the analytics tag has already fired is worse than no banner, because it demonstrates awareness of the obligation alongside failure to meet it. Run the private-window test described earlier before assuming yours works.
The trade show list nobody can source
Marketing lists acquired at events, bought from brokers, or scraped years ago are a recurring SME DUAA compliance problem, and the DUAA compliance answer is unchanged by the Act: if you cannot evidence the lawful basis, you should not be mailing the list. The penalty ceiling that just rose applies to electronic marketing.
Employee monitoring switched on by default
Productivity, location and communication monitoring features ship enabled in several popular platforms. Switching one on is a DUAA compliance decision requiring a lawful basis, transparency and frequently a DPIA, and in a small business it is typically switched on by someone who does not know that.
The privacy notice last edited in 2018, and the DUAA compliance gap it leaves
If your notice still describes the old automated decision-making position or the pre-Annex 1 legitimate interests wording, it is now inaccurate on its face. This is the cheapest DUAA compliance fix on the list and the most visible omission.
The subject access request nobody recognised
Recognition failures dominate the SAR side of SME DUAA compliance. The request rarely uses the legal phrase, it often arrives during an employment dispute, and the deadline runs from receipt by the business rather than by the right person.
A Ninety-Day DUAA Compliance Plan for a Small Team
Sequenced so that the highest-risk, lowest-effort DUAA compliance items land first. Each block assumes a few hours a week rather than dedicated time, because that is how the work will really happen.
Days 1 to 30: close the new DUAA compliance duty and find the data
Stand up the complaints procedure — form, mailbox, auto-acknowledgement, log. Brief the social and phone owners. In parallel, list every system holding personal data and refresh the processing register against it. This block alone removes the two failure modes most likely to produce a visible incident.
Days 31 to 60: DUAA compliance documents, cookies and suppliers
Update the privacy notice. Add the Annex 1 column to the legitimate interests register and reinstate anything wrongly retired. Run the tag audit and fix what fires early. Send the three questions to every processor and file the replies. Write the one-page subject access procedure.
Days 61 to 90: the conditional DUAA compliance work and the evidence pack
Complete the automated decision register if any exist, and raise the build tickets for notification, representation and contest. Assemble the evidence pack into one folder with dates and owners. Book the half-day external review if you are buying one, and book it while there is still time to act on it.
Day 91 and afterwards
Put an annual review in the calendar with a named owner, and add a single line to your supplier onboarding checklist asking whether the new tool touches personal data. Those two habits are what keep DUAA compliance from decaying back to where it started, and they cost minutes rather than hours. If the review keeps slipping, treat that as a signal to move it into whatever business process automation or recurring task system your team already uses rather than relying on memory.
| Window | Task | Owner in a small firm | Hours |
|---|---|---|---|
| Days 1 to 30 | Complaints procedure and log | Customer service lead | 6 |
| Days 1 to 30 | System inventory and register refresh | Operations | 4 |
| Days 31 to 60 | Privacy notice and register column | Operations | 5 |
| Days 31 to 60 | Tag audit and consent fix | Web owner or agency | 4 |
| Days 31 to 60 | Processor questions and replies | Operations | 2 |
| Days 61 to 90 | Automated decision register | Technical lead | Conditional |
| Days 61 to 90 | Evidence pack assembly and review | Named owner | 3 |
Frequently Asked Questions About DUAA Compliance
Is there a small business exemption from the Data (Use and Access) Act 2025?
No. The complaints duty in particular applies to every controller regardless of size, sector or processing volume. The only size-linked relief in the wider framework is the Article 30 record-keeping exemption for organisations under 250 employees, and its conditions exclude most businesses with staff, so DUAA compliance should be planned as though it does not exist.
What is the deadline for DUAA compliance?
The DUAA compliance deadlines have passed. The main data protection provisions commenced on 5 February 2026 and the complaints duty on 19 June 2026. There is no transitional period still running for the items in this checklist, which means the correct posture is remediation rather than preparation.
Do we need to appoint a data protection officer?
Only if you are a public authority, if your core activities require regular and systematic monitoring of individuals on a large scale, or if your core activities involve large-scale processing of special category or criminal offence data. Most SMEs meet none of these tests. Naming an internal owner for DUAA compliance is still worth doing, but that person is not a statutory DPO.
Can we still use a cookie banner from a free plugin?
Yes, provided it genuinely blocks non-essential tags until consent is given and offers a real reject option. The plugin is not the DUAA compliance problem; the wiring usually is. Test it in a private window with developer tools open before assuming it works, because the PECR maximum penalty is now £17.5 million or 4% of worldwide turnover.
Does the Act make automated decision-making easier or harder?
Both, depending on where you sit. It is easier to deploy solely automated significant decisions because Articles 22A to 22D replaced a prohibition with a permission plus safeguards. It is harder to run them casually under DUAA compliance, because the notification, representation and contest safeguards are concrete engineering obligations rather than policy statements.
How long should DUAA compliance take an SME with nothing in place?
Around 22 to 26 hours of work spread over 90 days for a business with no automated decisions and ordinary processing. Add 20 to 40 hours if solely automated significant decisions are in scope. The elapsed time matters less than the sequence: close the complaints duty first, because it is the only universal new obligation.
What happens if we do nothing?
Most likely nothing at all, until a complaint or a subject access request arrives. At that point the absence of a procedure, a log and a dated privacy notice converts a routine interaction into an evidential problem, and the escalation route to the ICO now sits in the legislation. The realistic DUAA compliance risk for an SME is not a headline fine; it is an avoidable regulatory correspondence that consumes far more than 25 hours.
References
Data (Use and Access) Act 2025
Data (Use and Access) Act 2025 Explanatory Notes
ICO Statement on the commencement of the Data (Use and Access) Act
ICO Advice for Small Organisations
ICO Guide to Privacy and Electronic Communications Regulations
ICO Guidance on the Right of Access
The Privacy and Electronic Communications (EC Directive) Regulations 2003