DUAA UK GDPR changes are now fully commenced, and the question most businesses are still asking is the simplest one: what is different today compared with 2025, and who in the building has to act on it? This article answers that as a comparison rather than a summary. Every section sets the old position beside the new one and then states the practical delta.

The Data (Use and Access) Act 2025 does not replace UK data protection law. It edits it. That distinction is the reason so much published commentary reads as either alarmist or complacent — an amending statute produces a patchwork, not a clean break, and a patchwork can only be understood by diffing it. So the DUAA UK GDPR changes below are presented as before-and-after pairs, followed by the document you edit and the team that owns the work.

We have already published a full obligation-by-obligation walkthrough of the Act, including its commencement timetable and a sequenced remediation plan. If you need the compliance checklist rather than the comparison, read the Data Use and Access Act 2025 risk checklist alongside this piece. This article assumes you know the Act exists and want to know precisely what moved.

One warning before the detail. The DUAA UK GDPR changes are frequently described as deregulation, and for most organisations that framing is wrong. Two provisions genuinely reduce work. One creates an entirely new universal duty, one raises a penalty ceiling thirty-five-fold, and one opens a divergence with the EU that multinational groups will spend money to close rather than exploit. Net, the majority of UK businesses will do more compliance work in 2026 than they did in 2025, not less. Data protection sits close enough to data management and analytics that most of the practical burden lands on the same teams either way.

The DUAA UK GDPR Changes in One Table: Old Text, New Text, Real Delta

duaa uk gdpr changes what changed for businesses b three solid filled hexagonal slabs

Before going provision by provision, it helps to see all of the DUAA UK GDPR changes at once. The table below is the article in miniature, and every row is expanded in a section further down.

The DUAA UK GDPR changes amend, they do not replace

The DUAA UK GDPR changes sit inside an Act of 142 sections and 16 schedules, and only Part 5 reaches into data protection law. Nothing in the DUAA UK GDPR changes repeals UK GDPR. Article numbers, the six principles, the accountability framework and the rights architecture all survive. What moved is the wording inside particular Articles, plus two new Annexes and one Article replaced by four. Existing citations in your policies remain valid; the text behind them has shifted in places.

The three instruments that actually moved

The DUAA UK GDPR changes touch three separate bodies of law, and confusing them is the most common error in internal briefings. UK GDPR gained Annex 1 and Annex 2 and lost Article 22. The Data Protection Act 2018 was amended around subject access and the regulator’s constitution. The Privacy and Electronic Communications Regulations gained new consent exemptions and a vastly higher penalty ceiling. A privacy notice edit fixes the first; only a tag audit fixes the third.

How to read the DUAA UK GDPR changes comparison

For each row, the “before” column states the position as it stood on 4 February 2026 and the “after” column the position from 5 February 2026, except the complaints duty, which commenced on 19 June 2026. Where the delta column says “no change to the obligation, change to the evidence”, it means your legal duty is identical but what a regulator expects to see in a file is not.

AreaPosition beforePosition afterPractical delta
Lawful basisEvery legitimate interest needs a balancing testAnnex 1 purposes need no balancing testSmall relief, narrow list, easy to over-claim
Automated decisionsArticle 22 prohibits, with three exceptionsArticles 22A to 22D permit, with safeguardsDefault flipped; build notification and contest routes
Subject accessReasonable search per ICO guidanceReasonable and proportionate search in statuteNo change to the obligation, change to the evidence
ComplaintsNo statutory internal procedure requiredEvery controller must run oneEntirely new duty, universal, easy to fail visibly
CookiesConsent unless strictly necessaryThree further narrow exemptionsBanner survives; notice and opt-out still required
PECR penalties£500,000 maximum£17.5m or 4% of worldwide turnoverCookie risk repriced by a factor of thirty-five
International transfersEssentially equivalent testNot materially lower testEasier future adequacy; nothing to do today
DPO, ROPA, DPIAMandatory where thresholds metUnchangedNo delta; ignore any 2024 briefing that says otherwise

DUAA UK GDPR Changes to Lawful Basis: Where the Balancing Test Went

duaa uk gdpr changes what changed for businesses c upright funnel

This is the change most often misreported, because the relief and the trap sit in adjacent sentences of the same statute.

The old position: one route, one test

Under Article 6(1)(f) as it stood, every legitimate interest required a three-part assessment — purpose, necessity, and a balance against the rights and freedoms of the individual. That applied identically to fraud screening, to intra-group administration and to a marketing list. Volume of paperwork, not difficulty, was the complaint.

The new position: a short list that skips the test

The DUAA UK GDPR changes insert Annex 1 to UK GDPR, listing recognised legitimate interests. Where processing genuinely falls inside it, the balancing test is not required at all. The list is deliberately public-interest flavoured: disclosures to public bodies performing statutory functions, national security, defence and public security, emergency response, crime detection and prevention, and safeguarding vulnerable individuals. Commercial purposes are conspicuously absent.

The trap that ships in most internal briefings

Direct marketing, intra-group transmission for administrative purposes, and network and information security are all named in the DUAA UK GDPR changes — but as illustrative examples of ordinary Article 6(1)(f) interests, not as recognised ones. A legitimate interests assessment remains mandatory for all three. Several widely circulated summaries of the DUAA UK GDPR changes state the opposite. If your marketing team retired an LIA on that basis, reinstate it, because an absent assessment is an accountability failure even where the processing itself was fair.

The DUAA UK GDPR changes you write into the file

Walk the record of processing and mark each legitimate-interests entry as either Annex 1 recognised or ordinary. For recognised entries, note that no balancing test applies and why the purpose fits. For everything else, the existing assessment stands unchanged. Then align the legitimate-interests wording in the privacy notice with the new statutory language. That is the entire practical effect of these particular DUAA UK GDPR changes: a column added to a register you already maintain.

PurposeBefore 5 Feb 2026After 5 Feb 2026Action on your LIA file
Disclosure to a public bodyBalancing test requiredRecognised, no testRetire the LIA, record the Annex 1 basis
Safeguarding a vulnerable personBalancing test requiredRecognised, no testRetire the LIA, record the Annex 1 basis
Crime detection and preventionBalancing test requiredRecognised, no testRetire the LIA, record the Annex 1 basis
Direct marketingBalancing test requiredBalancing test requiredKeep the LIA; reverse any retirement
Intra-group administrationBalancing test requiredBalancing test requiredKeep the LIA; cite the new example wording
Network and information securityBalancing test requiredBalancing test requiredKeep the LIA; cite the new example wording

Automated Decisions: The Largest of the DUAA UK GDPR Changes

duaa uk gdpr changes what changed for businesses d tall stack blank paper sheets

If one part of this reform generates litigation, it is this one. The default has flipped, and the safeguards that replace the old prohibition are engineering work rather than drafting work.

What the old Article 22 said

A decision based solely on automated processing that produced legal effects or similarly significant effects was prohibited, unless it was necessary for a contract, authorised by law, or based on explicit consent. The structure was a ban with narrow exits. In practice most organisations avoided the Article entirely by inserting a human somewhere in the workflow.

What Articles 22A to 22D say instead

Article 22 has been repealed outright and replaced by four provisions. Solely automated significant decisions are now permissible on any lawful basis, provided the specified safeguards are met. The prohibition survives only where the decision is based entirely or partly on special category data — health, biometrics, ethnicity, trade union membership, sexual orientation and the rest. That carve-out is broader than it looks: recruitment screening and insurance underwriting touch special category data routinely without the business classifying it that way.

Meaningful human intervention now has a definition

The DUAA UK GDPR changes put substance behind a phrase argued over for years. Meaningful human intervention requires review by a person competent to conduct it, holding the authority and the information needed to change the outcome. A workflow that routes an automated rejection past an administrator with no discretion never qualified; the difference is that this is now written down and therefore easy for a complainant to cite.

Three safeguards that are build tickets, not policy lines

Where you rely on the relaxed regime, the DUAA UK GDPR changes require you to inform the individual that a solely automated significant decision has been made, to let them make representations, and to let them obtain human intervention and contest the outcome. None of that is satisfied by a paragraph in a privacy notice. Your decisioning platform needs a notification event, a stored representation, an escalation route and an audit trail. Teams with mature model governance sometimes assume documented validation discharges the duty — it does not, because the obligations run to the individual, not to the model.

The statutory code is still coming, so design conservatively

Regulations made on 12 May 2026 require the ICO to produce a statutory code of practice on artificial intelligence and automated decision-making. The consultation closed on 29 May 2026 and the code is expected before the end of 2026. Anyone deploying machine learning in decisioning should treat today’s position as provisional and build to a stricter standard than the current text demands, because retrofitting a contest route after launch costs several times what including it does.

QuestionOld Article 22New Articles 22A to 22D
Is a solely automated significant decision allowed?No, unless one of three conditions appliesYes, on any lawful basis, with safeguards
Special category data involved?Prohibited save narrow exceptionsRestrictive regime largely retained
Must you tell the individual?Via Articles 13 to 15 transparencyExpress duty attached to the decision
Can they contest it?Only where an exception was relied onAlways, wherever the relaxed route is used
Is human review defined?No, guidance onlyYes, competence plus authority plus information
Where does the work land?Legal and policyEngineering and product

DUAA UK GDPR Changes to Rights, Requests and the New Complaints Duty

duaa uk gdpr changes what changed for businesses e three identical upright cylinders

Two of the DUAA UK GDPR changes on the rights side sit at opposite ends of the effort scale. One codifies what you already did. The other creates an obligation that did not exist in UK law at all.

Subject access: a statutory footing for existing practice

A controller must now carry out a reasonable and proportionate search in response to a request. This was already the ICO’s published position and had judicial support, so the duty has not moved. What has moved is the evidence: you can point at primary legislation when explaining why an unbounded search of every backup tape was not required. Where clarification is reasonably needed, the response period pauses until it arrives — again, prior practice given a statutory basis.

What the subject access change does not permit

It does not license a narrow search because a wide one is inconvenient, and it does not allow clarification to be requested tactically to buy time. Both are straightforward to challenge, and under the new complaints regime that challenge now has a formal internal route before it ever reaches the regulator. Reading these DUAA UK GDPR changes as permission to slow subject access handling is the fastest way to generate a complaint file against yourself.

The complaints duty is the only genuinely universal new obligation

Since 19 June 2026, every controller in the United Kingdom has needed a data protection complaints procedure, regardless of size, sector or processing volume. A sole trader with a spreadsheet of customer emails is in scope. Of all the DUAA UK GDPR changes this is the one most likely to catch a small business unprepared, because it does not depend on doing anything sophisticated with data — only on holding some.

What a compliant procedure actually contains

A complaint must be acknowledged within 30 days of receipt; an automated email acknowledgement suffices for an electronic complaint. You must facilitate complaints with an electronic form plus at least one alternative channel, and you must accept complaints however they arrive, including by social media. You must take appropriate steps to respond without undue delay, keep the complainant informed, tell them the outcome, and tell them they can escalate to the ICO. There is no fixed statutory deadline for the substantive response, which makes an internal service level worth setting yourself.

The record that proves it happened

Keep, for every complaint, the date received, how and when it was acknowledged, the steps taken, and the final outcome. The ICO can ask for these records. A controller who handled complaints well but logged nothing has an evidential problem rather than a compliance one, and the distinction will not help. Social channels are the usual point of failure here, because marketing owns them and the privacy function rarely sees what arrives there.

Cookies and PECR: The DUAA UK GDPR Changes With Financial Teeth

duaa uk gdpr changes what changed for businesses f two interlocking puzzle blocks

This is where the money is, and it is the part of the DUAA UK GDPR changes UK marketing teams have absorbed least.

From £500,000 to £17.5 million

The maximum PECR penalty was £500,000. It is now aligned with UK GDPR at £17.5 million or 4% of total annual worldwide turnover, whichever is higher. That is a thirty-five-fold increase in the fixed ceiling, applied to a body of rules — cookies, electronic marketing, unsolicited calls — that most organisations have historically treated as a lower tier of risk than data protection proper. Nothing about the underlying rules got harder. The consequence of ignoring them did.

The three new exemptions the DUAA UK GDPR changes created

The DUAA UK GDPR changes create exemptions from the consent requirement for three low-risk purposes: statistical analysis aimed solely at improving your own service, applying a user’s appearance or functionality preferences automatically, and establishing a user’s location to provide emergency assistance. These sit alongside the pre-existing strictly-necessary exemption. They are genuinely useful and they are genuinely small.

Why the analytics exemption is narrower than it reads

The statistical exemption is the one everyone wants and it is tightly drawn. The data must be used solely to improve your own service or website, and it must not be shared with anyone else except to assist with those improvements. An analytics deployment that also builds advertising audiences, or that shares data with a provider for the provider’s own purposes, falls outside the exemption entirely. On most commercial websites that describes the majority of the tag inventory.

Exempt does not mean silent

Where you rely on a new exemption you must still give clear information about the storage or access and provide a simple means of opting out. Deleting the banner is not an implementation of the DUAA UK GDPR changes; replacing it with a clear notice and a working opt-out is. Our own cookie policy follows that pattern, and it is worth comparing yours against any site that has actually done the audit.

A worked inventory of what the DUAA UK GDPR changes exempt

Take a representative commercial site carrying 40 tags. Suppose 6 are strictly necessary, 4 are first-party analytics that share nothing, 2 apply appearance preferences, and the remaining 28 are advertising, cross-site tracking or analytics that also feed ad audiences. That is 15%, 10% and 5% exempt against 70% still requiring consent. The exemptions remove a fifth of your banner problem and leave the rest exactly where it was — but now priced at £17.5 million rather than £500,000.

Worked 40-tag inventory: share of tags by consent treatment
Still require consent, 28 tags 70%
Strictly necessary, 6 tags 15%
First-party analytics, not shared, 4 tags 10%
Appearance preferences, 2 tags 5%

Which Documents the DUAA UK GDPR Changes Force You to Rewrite

Provision-by-provision analysis is how lawyers read the DUAA UK GDPR changes. Document-by-document is how a business absorbs one. Here is the register, with the edit stated rather than implied.

Privacy notice

Add the recognised legitimate interests language where Annex 1 applies, and add a description of any solely automated significant decision-making together with the route to obtain human review. Add the complaints procedure and the escalation path to the ICO. This is the single document that touches four of the DUAA UK GDPR changes at once, which makes it the right place to start.

Record of processing activities

Add a column distinguishing recognised legitimate interests from ordinary ones. Flag every processing activity that produces a significant automated decision, and flag whether it touches special category data. The ROPA obligation itself is unchanged, so this is an edit to a live document rather than a new artefact.

Legitimate interests assessments

Retire the assessments that are genuinely displaced by Annex 1 and keep the rest. Reinstate anything retired on the strength of a briefing that placed direct marketing in the recognised column. Keep the retired ones in the archive with a note explaining the statutory basis, because “we deleted it because the law changed” is a weaker answer than a dated file.

Cookie policy, banner configuration and tag register

The largest single piece of work for most organisations. Inventory every tag and answer one question per tag: does any data leave this site for a third party’s own purposes? If yes, it needs consent, an exemption or removal. Then implement notice plus opt-out for anything moved to an exemption. Given the new ceiling, this is no longer a low-stakes exercise.

Complaints policy, form and log

A new document, a new form, a new log and a briefing for whoever monitors social channels. Four fields in the log cover the statutory record: received, acknowledged, steps taken, outcome. This is days of work rather than weeks, and it is the largest unmanaged exposure in most organisations precisely because it is new.

Subject access procedure

Add the reasonable-and-proportionate search standard and the clarification clock-stop as documented steps, with a line requiring the searcher to record what was searched and why that scope was proportionate. The duty has not changed; the evidence you keep should.

Processor contracts and supplier schedules

Agreements written against the pre-2026 framework are not invalid, but they may reference the wrong standards for automated processing and transfers. Rather than reopening every contract, add the DUAA UK GDPR changes to the renewal checklist and address them as agreements come round. Where a provider delivers your managed IT services, confirm in writing which controls sit with them — the complaints duty in particular cannot be outsourced, only supported.

DocumentEdit requiredOwnerEffort (hours)
Complaints policy, form and logCreate from scratchPrivacy or operations24
Cookie policy and tag registerFull audit and re-consent designMarketing and web20
ROPA and LIA setReclassify legitimate interestsPrivacy16
Automated decision inventoryBuild list, flag special categoryEngineering and product12
Contracts and training materialRenewal checklist and briefingLegal and HR10
Privacy noticeFour targeted additionsPrivacy8

Taking the register’s own figures, the total is 90 hours, and the two newest of the DUAA UK GDPR changes — complaints and cookies — account for 44 of them, just under half.

Estimated effort by document, from the register above (90 hours total)
Complaints policy, form and log 24 hours
Cookie policy and tag register 20 hours
ROPA and LIA set 16 hours
Automated decision inventory 12 hours
Contracts and training material 10 hours
Privacy notice 8 hours

DUAA UK GDPR Changes Team by Team: Who Has to Do Something Different

Compliance programmes stall when the work is described by legal provision to people who own processes. Translating the DUAA UK GDPR changes into departmental language is usually worth more than another all-staff briefing.

Marketing

Two of the DUAA UK GDPR changes land here and both are unwelcome. The direct-marketing legitimate interests assessment survives, whatever the summaries said. And the tag audit is now a material financial exercise rather than a housekeeping one. There is a third, less obvious item: complaints arriving through social channels must reach the privacy function, which means the person running those accounts needs a route and a 30-day clock they know about. Teams running acquisition through marketing services should treat the tag inventory as the first deliverable.

HR and recruitment

Automated sifting of applications is where the DUAA UK GDPR changes bite hardest in a mid-sized business, and it is the single most common solely-automated significant decision there is, and it frequently touches special category data through diversity monitoring, health declarations or right-to-work checks. Where it does, the restrictive regime survives. Where it does not, you owe the applicant notification, representations and human review. Either way the current position is almost certainly undocumented.

Engineering and product

The three safeguards inside the DUAA UK GDPR changes are your tickets. A notification event on the decision, a representation the individual can submit and you can store, an escalation to a reviewer with authority, and an audit trail joining them. Add a flag in the data model for whether a decision path touched special category data, because that determines which regime applies and it cannot be reconstructed later. Design for the statutory code that is still to come.

Customer service and operations

The complaints procedure is operational, not legal. Somebody acknowledges within 30 days, somebody investigates, somebody records four fields, somebody communicates the outcome and the escalation right. Where these DUAA UK GDPR changes fail in practice, it is almost never because the policy was wrong; it is because no named person owned the inbox.

Legal and procurement

Add the DUAA UK GDPR changes to the contract renewal checklist rather than reopening the estate. Confirm which obligations sit with providers and which cannot be delegated. Where cybersecurity obligations already appear in supplier schedules, the automated-processing and transfer clauses usually sit in the same annex and can be updated in the same pass.

Finance and the board

One number matters at board level: the PECR ceiling moved from £500,000 to £17.5 million or 4% of worldwide turnover. That reprices a risk previously delegated to the web team. The second board-level item is the divergence question below, because it determines whether the group runs one privacy standard or two.

TeamWhat changed for themFirst action this month
MarketingTag risk repriced; marketing LIA survivesInventory every tag on the site
HR and recruitmentAutomated sifting now in scope explicitlyCheck whether sifting touches special category data
Engineering and productSafeguards became build requirementsRaise tickets for notify, represent, review
Customer serviceNew universal complaints dutyName an owner and start the log
Legal and procurementContract references now partly staleAdd clauses to the renewal checklist
Finance and boardPECR exposure up thirty-five-foldDecide one standard or two

Running One Programme Under Two Regimes After the DUAA UK GDPR Changes

For any business with EU customers or an EU entity, the interesting question is not what UK law now says. It is whether you run one policy or two.

Where UK and EU law now actually differ

The gap the DUAA UK GDPR changes opened is narrow but real, and it is widest on automated decision-making. Recognised legitimate interests have no EU equivalent. The reasonable-and-proportionate search standard is a codification the EU has not made. The internal complaints duty is a UK addition. Everything else — principles, breach reporting, DPO, ROPA, DPIA, transparency — remains materially aligned.

The single-standard option

Hold the EU standard everywhere and treat the DUAA UK GDPR changes as headroom you choose not to use. One policy set, one training package, one decisioning design, no branching logic. You forgo the Annex 1 relief and the automated-decision relaxation. Most multinational groups will land here, because the operational cost of running two regimes exceeds the value of a narrow relaxation that mainly benefits public-interest processing.

The dual-standard option

Run UK processing to UK law and EU processing to EU law. It is legitimate and it is more work: two lawful-basis registers, two decisioning configurations, two sets of privacy information and a data-residency question underneath all of it. It pays only where a large volume of UK-only automated decisioning exists and the relaxation genuinely removes a bottleneck.

Adequacy is the constraint underneath the choice

The European Commission renewed both UK adequacy decisions on 19 December 2025, running six years to 27 December 2031, with a mid-point review after four years conducted with the European Data Protection Board. The EDPB explicitly flagged automated decision-making as an area to monitor. Adequacy is therefore conditional in substance even though granted in form, which is a further argument for the single-standard approach: an organisation that never exploited the divergence has nothing to unwind if the assessment tightens. Keep a fallback transfer mechanism documented regardless.

One thing the divergence does not change

If you offer goods or services to people in the EU, or monitor their behaviour, EU GDPR applies to that processing under its own extraterritorial reach. No amount of UK reform reduces it. Treating the DUAA UK GDPR changes as a route out of EU compliance is a misreading that will not survive a single enquiry.

TopicUK after the ActEU GDPRDivergence
Solely automated significant decisionsPermitted with safeguardsProhibited save exceptionsWide
Recognised legitimate interestsAnnex 1 list, no balancing testNo equivalentModerate
Subject access search standardReasonable and proportionate, in statuteGuidance and case lawNarrow
Internal complaints procedureMandatory for all controllersNot mandatedUK addition
Cookie consent exemptionsStrictly necessary plus threeStrictly necessary onlyNarrow
Breach notification72 hours72 hoursNone
DPO, ROPA, DPIAUnchangedUnchangedNone

What the DUAA UK GDPR Changes Left Completely Alone

Knowing what did not move is as valuable as knowing what did, because reform of this size generates confident misinformation that costs real budget.

DPO, ROPA and DPIA all survive intact

The mandatory Data Protection Officer obligation under Article 37 remains. Records of processing under Article 30 remain. Data protection impact assessments under Article 35 remain. Every proposal from the abandoned Data Protection and Digital Information Bill that would have diluted these was dropped. If you deferred appointing a DPO on the strength of that draft, that decision needs revisiting now rather than at your next audit.

Breach reporting is untouched

The 72-hour notification obligation to the ICO stands, as does the duty to notify affected individuals where there is a high risk to their rights. Nothing in the DUAA UK GDPR changes alters the threshold, the timescale or the content of a report. Any incident runbook rewritten on the assumption that these DUAA UK GDPR changes touched breach reporting has been rewritten for no reason.

Principles and transparency obligations stand

Lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability all survive unamended. Articles 13 and 14 privacy information requirements survive. What changed is some of the detail you must disclose, not the obligation to disclose it.

Why this matters to your budget

Roughly two-thirds of a typical privacy programme is untouched by the DUAA UK GDPR changes. Scoping the work as “respond to the DUAA UK GDPR changes” rather than “refresh the privacy programme” is the difference between the 90 hours in the register above and a project that consumes a quarter. Resist the vendor pitch that treats the Act as a reason to rebuild everything, and route the saving into the two areas that genuinely moved.

A Ninety-Day Plan to Absorb the DUAA UK GDPR Changes

Assume a programme last updated in 2025 and 90 hours of available effort, distributed as the register implies. This sequence resolves the most exposure per hour spent on the DUAA UK GDPR changes.

Days 1 to 15 — close the complaints gap

Stand up an electronic complaints form, add one alternative channel, brief whoever monitors social accounts, write the 30-day acknowledgement into a template and create the four-field log. Roughly 30 hours, and it addresses the only obligation that is universal, already in force and trivially easy for a complainant to evidence a failure against.

Days 16 to 45 — audit tags and reclassify lawful bases

Run the tag inventory and answer the third-party question for each one, then reclassify legitimate interests against Annex 1 and reinstate any assessment retired in error. Around 28 hours across marketing and privacy, and it covers both the largest financial exposure and the most commonly misapplied of the DUAA UK GDPR changes.

Days 46 to 75 — inventory automated decisions and raise the build tickets

List every process producing a significant effect with no meaningful human involvement, flag the ones touching special category data, and raise engineering tickets for notification, representations and review. Around 20 hours. Design against a stricter future code, because one is expected before the year ends.

Days 76 to 90 — contracts, notices and training

Fold the DUAA UK GDPR changes into the renewal checklist, publish the amended privacy notice and deliver a short specific briefing to the teams that handle complaints and subject access. Around 12 hours. A targeted briefing on what actually changed beats a generic refresher, and it is the cheapest way to stop the misinformation about direct marketing spreading inside your own organisation.

The same 90 hours, distributed across the plan above
Days 1 to 15, complaints 30 hours
Days 16 to 45, tags and lawful basis 28 hours
Days 46 to 75, automated decisions 20 hours
Days 76 to 90, contracts and training 12 hours

Whoever owns the programme should also decide early whether privacy work is coordinated centrally or left with each function, since that choice shapes every deadline above. Organisations that already run a coherent digital strategy tend to close these gaps faster, because the ownership question is settled before the legal one arrives.

Frequently Asked Questions About the DUAA UK GDPR Changes

Do the DUAA UK GDPR changes replace UK GDPR?

No. The Act amends UK GDPR, the Data Protection Act 2018 and PECR. UK GDPR remains the operative instrument, with amended Articles, two new Annexes, and Article 22 replaced by Articles 22A to 22D. Your existing citations remain correct.

Which change affects the most businesses?

The complaints procedure, because it is the only new obligation that applies to every controller regardless of size or sector. It has been in force since 19 June 2026, and failure to acknowledge within 30 days is unusually easy for a complainant to evidence.

Can we stop doing legitimate interests assessments for marketing?

No, and this is the most commonly repeated error about the DUAA UK GDPR changes. Direct marketing is named in the DUAA UK GDPR changes as an illustrative example of an ordinary Article 6(1)(f) interest, not as a recognised legitimate interest under Annex 1. The balancing test remains mandatory.

Do we still need a Data Protection Officer?

If you needed one under Article 37 before, you still need one. The proposals to abolish the role came from the abandoned Data Protection and Digital Information Bill and were not carried into this Act.

Are cookie banners now optional?

Only for a narrow set of low-risk purposes, and even then a clear notice and a working opt-out are still required. Most commercial sites carry advertising or shared analytics tags that remain firmly inside the consent requirement.

Should a UK business with EU customers use the new automated decision-making freedom?

Usually not. The relaxation is the widest point of divergence from EU GDPR, and running two decisioning standards costs more than the relief is worth for most groups. The EDPB flagged this area for monitoring under the renewed adequacy decisions, which is a further reason to treat it as headroom rather than an opportunity.

When will the ICO start enforcing?

The regulator has signalled a phased, implementation-focused approach rather than immediate enforcement, with cookie compliance flagged as a renewed priority. A phased approach is not an amnesty, and the complaints duty in particular produces documentary evidence of failure without any investigation being needed.

References