DUAA UK GDPR changes are now fully commenced, and the question most businesses are still asking is the simplest one: what is different today compared with 2025, and who in the building has to act on it? This article answers that as a comparison rather than a summary. Every section sets the old position beside the new one and then states the practical delta.
The Data (Use and Access) Act 2025 does not replace UK data protection law. It edits it. That distinction is the reason so much published commentary reads as either alarmist or complacent — an amending statute produces a patchwork, not a clean break, and a patchwork can only be understood by diffing it. So the DUAA UK GDPR changes below are presented as before-and-after pairs, followed by the document you edit and the team that owns the work.
We have already published a full obligation-by-obligation walkthrough of the Act, including its commencement timetable and a sequenced remediation plan. If you need the compliance checklist rather than the comparison, read the Data Use and Access Act 2025 risk checklist alongside this piece. This article assumes you know the Act exists and want to know precisely what moved.
One warning before the detail. The DUAA UK GDPR changes are frequently described as deregulation, and for most organisations that framing is wrong. Two provisions genuinely reduce work. One creates an entirely new universal duty, one raises a penalty ceiling thirty-five-fold, and one opens a divergence with the EU that multinational groups will spend money to close rather than exploit. Net, the majority of UK businesses will do more compliance work in 2026 than they did in 2025, not less. Data protection sits close enough to data management and analytics that most of the practical burden lands on the same teams either way.
Table of contents
- The DUAA UK GDPR Changes in One Table: Old Text, New Text, Real Delta
- DUAA UK GDPR Changes to Lawful Basis: Where the Balancing Test Went
- Automated Decisions: The Largest of the DUAA UK GDPR Changes
- DUAA UK GDPR Changes to Rights, Requests and the New Complaints Duty
- Cookies and PECR: The DUAA UK GDPR Changes With Financial Teeth
- Which Documents the DUAA UK GDPR Changes Force You to Rewrite
- DUAA UK GDPR Changes Team by Team: Who Has to Do Something Different
- Running One Programme Under Two Regimes After the DUAA UK GDPR Changes
- What the DUAA UK GDPR Changes Left Completely Alone
- A Ninety-Day Plan to Absorb the DUAA UK GDPR Changes
- Frequently Asked Questions About the DUAA UK GDPR Changes
- References
The DUAA UK GDPR Changes in One Table: Old Text, New Text, Real Delta
Before going provision by provision, it helps to see all of the DUAA UK GDPR changes at once. The table below is the article in miniature, and every row is expanded in a section further down.
The DUAA UK GDPR changes amend, they do not replace
The DUAA UK GDPR changes sit inside an Act of 142 sections and 16 schedules, and only Part 5 reaches into data protection law. Nothing in the DUAA UK GDPR changes repeals UK GDPR. Article numbers, the six principles, the accountability framework and the rights architecture all survive. What moved is the wording inside particular Articles, plus two new Annexes and one Article replaced by four. Existing citations in your policies remain valid; the text behind them has shifted in places.
The three instruments that actually moved
The DUAA UK GDPR changes touch three separate bodies of law, and confusing them is the most common error in internal briefings. UK GDPR gained Annex 1 and Annex 2 and lost Article 22. The Data Protection Act 2018 was amended around subject access and the regulator’s constitution. The Privacy and Electronic Communications Regulations gained new consent exemptions and a vastly higher penalty ceiling. A privacy notice edit fixes the first; only a tag audit fixes the third.
How to read the DUAA UK GDPR changes comparison
For each row, the “before” column states the position as it stood on 4 February 2026 and the “after” column the position from 5 February 2026, except the complaints duty, which commenced on 19 June 2026. Where the delta column says “no change to the obligation, change to the evidence”, it means your legal duty is identical but what a regulator expects to see in a file is not.
| Area | Position before | Position after | Practical delta |
|---|---|---|---|
| Lawful basis | Every legitimate interest needs a balancing test | Annex 1 purposes need no balancing test | Small relief, narrow list, easy to over-claim |
| Automated decisions | Article 22 prohibits, with three exceptions | Articles 22A to 22D permit, with safeguards | Default flipped; build notification and contest routes |
| Subject access | Reasonable search per ICO guidance | Reasonable and proportionate search in statute | No change to the obligation, change to the evidence |
| Complaints | No statutory internal procedure required | Every controller must run one | Entirely new duty, universal, easy to fail visibly |
| Cookies | Consent unless strictly necessary | Three further narrow exemptions | Banner survives; notice and opt-out still required |
| PECR penalties | £500,000 maximum | £17.5m or 4% of worldwide turnover | Cookie risk repriced by a factor of thirty-five |
| International transfers | Essentially equivalent test | Not materially lower test | Easier future adequacy; nothing to do today |
| DPO, ROPA, DPIA | Mandatory where thresholds met | Unchanged | No delta; ignore any 2024 briefing that says otherwise |
DUAA UK GDPR Changes to Lawful Basis: Where the Balancing Test Went
This is the change most often misreported, because the relief and the trap sit in adjacent sentences of the same statute.
The old position: one route, one test
Under Article 6(1)(f) as it stood, every legitimate interest required a three-part assessment — purpose, necessity, and a balance against the rights and freedoms of the individual. That applied identically to fraud screening, to intra-group administration and to a marketing list. Volume of paperwork, not difficulty, was the complaint.
The new position: a short list that skips the test
The DUAA UK GDPR changes insert Annex 1 to UK GDPR, listing recognised legitimate interests. Where processing genuinely falls inside it, the balancing test is not required at all. The list is deliberately public-interest flavoured: disclosures to public bodies performing statutory functions, national security, defence and public security, emergency response, crime detection and prevention, and safeguarding vulnerable individuals. Commercial purposes are conspicuously absent.
The trap that ships in most internal briefings
Direct marketing, intra-group transmission for administrative purposes, and network and information security are all named in the DUAA UK GDPR changes — but as illustrative examples of ordinary Article 6(1)(f) interests, not as recognised ones. A legitimate interests assessment remains mandatory for all three. Several widely circulated summaries of the DUAA UK GDPR changes state the opposite. If your marketing team retired an LIA on that basis, reinstate it, because an absent assessment is an accountability failure even where the processing itself was fair.
The DUAA UK GDPR changes you write into the file
Walk the record of processing and mark each legitimate-interests entry as either Annex 1 recognised or ordinary. For recognised entries, note that no balancing test applies and why the purpose fits. For everything else, the existing assessment stands unchanged. Then align the legitimate-interests wording in the privacy notice with the new statutory language. That is the entire practical effect of these particular DUAA UK GDPR changes: a column added to a register you already maintain.
| Purpose | Before 5 Feb 2026 | After 5 Feb 2026 | Action on your LIA file |
|---|---|---|---|
| Disclosure to a public body | Balancing test required | Recognised, no test | Retire the LIA, record the Annex 1 basis |
| Safeguarding a vulnerable person | Balancing test required | Recognised, no test | Retire the LIA, record the Annex 1 basis |
| Crime detection and prevention | Balancing test required | Recognised, no test | Retire the LIA, record the Annex 1 basis |
| Direct marketing | Balancing test required | Balancing test required | Keep the LIA; reverse any retirement |
| Intra-group administration | Balancing test required | Balancing test required | Keep the LIA; cite the new example wording |
| Network and information security | Balancing test required | Balancing test required | Keep the LIA; cite the new example wording |
Automated Decisions: The Largest of the DUAA UK GDPR Changes
If one part of this reform generates litigation, it is this one. The default has flipped, and the safeguards that replace the old prohibition are engineering work rather than drafting work.
What the old Article 22 said
A decision based solely on automated processing that produced legal effects or similarly significant effects was prohibited, unless it was necessary for a contract, authorised by law, or based on explicit consent. The structure was a ban with narrow exits. In practice most organisations avoided the Article entirely by inserting a human somewhere in the workflow.
What Articles 22A to 22D say instead
Article 22 has been repealed outright and replaced by four provisions. Solely automated significant decisions are now permissible on any lawful basis, provided the specified safeguards are met. The prohibition survives only where the decision is based entirely or partly on special category data — health, biometrics, ethnicity, trade union membership, sexual orientation and the rest. That carve-out is broader than it looks: recruitment screening and insurance underwriting touch special category data routinely without the business classifying it that way.
Meaningful human intervention now has a definition
The DUAA UK GDPR changes put substance behind a phrase argued over for years. Meaningful human intervention requires review by a person competent to conduct it, holding the authority and the information needed to change the outcome. A workflow that routes an automated rejection past an administrator with no discretion never qualified; the difference is that this is now written down and therefore easy for a complainant to cite.
Three safeguards that are build tickets, not policy lines
Where you rely on the relaxed regime, the DUAA UK GDPR changes require you to inform the individual that a solely automated significant decision has been made, to let them make representations, and to let them obtain human intervention and contest the outcome. None of that is satisfied by a paragraph in a privacy notice. Your decisioning platform needs a notification event, a stored representation, an escalation route and an audit trail. Teams with mature model governance sometimes assume documented validation discharges the duty — it does not, because the obligations run to the individual, not to the model.
The statutory code is still coming, so design conservatively
Regulations made on 12 May 2026 require the ICO to produce a statutory code of practice on artificial intelligence and automated decision-making. The consultation closed on 29 May 2026 and the code is expected before the end of 2026. Anyone deploying machine learning in decisioning should treat today’s position as provisional and build to a stricter standard than the current text demands, because retrofitting a contest route after launch costs several times what including it does.
| Question | Old Article 22 | New Articles 22A to 22D |
|---|---|---|
| Is a solely automated significant decision allowed? | No, unless one of three conditions applies | Yes, on any lawful basis, with safeguards |
| Special category data involved? | Prohibited save narrow exceptions | Restrictive regime largely retained |
| Must you tell the individual? | Via Articles 13 to 15 transparency | Express duty attached to the decision |
| Can they contest it? | Only where an exception was relied on | Always, wherever the relaxed route is used |
| Is human review defined? | No, guidance only | Yes, competence plus authority plus information |
| Where does the work land? | Legal and policy | Engineering and product |
DUAA UK GDPR Changes to Rights, Requests and the New Complaints Duty
Two of the DUAA UK GDPR changes on the rights side sit at opposite ends of the effort scale. One codifies what you already did. The other creates an obligation that did not exist in UK law at all.
Subject access: a statutory footing for existing practice
A controller must now carry out a reasonable and proportionate search in response to a request. This was already the ICO’s published position and had judicial support, so the duty has not moved. What has moved is the evidence: you can point at primary legislation when explaining why an unbounded search of every backup tape was not required. Where clarification is reasonably needed, the response period pauses until it arrives — again, prior practice given a statutory basis.
What the subject access change does not permit
It does not license a narrow search because a wide one is inconvenient, and it does not allow clarification to be requested tactically to buy time. Both are straightforward to challenge, and under the new complaints regime that challenge now has a formal internal route before it ever reaches the regulator. Reading these DUAA UK GDPR changes as permission to slow subject access handling is the fastest way to generate a complaint file against yourself.
The complaints duty is the only genuinely universal new obligation
Since 19 June 2026, every controller in the United Kingdom has needed a data protection complaints procedure, regardless of size, sector or processing volume. A sole trader with a spreadsheet of customer emails is in scope. Of all the DUAA UK GDPR changes this is the one most likely to catch a small business unprepared, because it does not depend on doing anything sophisticated with data — only on holding some.
What a compliant procedure actually contains
A complaint must be acknowledged within 30 days of receipt; an automated email acknowledgement suffices for an electronic complaint. You must facilitate complaints with an electronic form plus at least one alternative channel, and you must accept complaints however they arrive, including by social media. You must take appropriate steps to respond without undue delay, keep the complainant informed, tell them the outcome, and tell them they can escalate to the ICO. There is no fixed statutory deadline for the substantive response, which makes an internal service level worth setting yourself.
The record that proves it happened
Keep, for every complaint, the date received, how and when it was acknowledged, the steps taken, and the final outcome. The ICO can ask for these records. A controller who handled complaints well but logged nothing has an evidential problem rather than a compliance one, and the distinction will not help. Social channels are the usual point of failure here, because marketing owns them and the privacy function rarely sees what arrives there.
Cookies and PECR: The DUAA UK GDPR Changes With Financial Teeth
This is where the money is, and it is the part of the DUAA UK GDPR changes UK marketing teams have absorbed least.
From £500,000 to £17.5 million
The maximum PECR penalty was £500,000. It is now aligned with UK GDPR at £17.5 million or 4% of total annual worldwide turnover, whichever is higher. That is a thirty-five-fold increase in the fixed ceiling, applied to a body of rules — cookies, electronic marketing, unsolicited calls — that most organisations have historically treated as a lower tier of risk than data protection proper. Nothing about the underlying rules got harder. The consequence of ignoring them did.
The three new exemptions the DUAA UK GDPR changes created
The DUAA UK GDPR changes create exemptions from the consent requirement for three low-risk purposes: statistical analysis aimed solely at improving your own service, applying a user’s appearance or functionality preferences automatically, and establishing a user’s location to provide emergency assistance. These sit alongside the pre-existing strictly-necessary exemption. They are genuinely useful and they are genuinely small.
Why the analytics exemption is narrower than it reads
The statistical exemption is the one everyone wants and it is tightly drawn. The data must be used solely to improve your own service or website, and it must not be shared with anyone else except to assist with those improvements. An analytics deployment that also builds advertising audiences, or that shares data with a provider for the provider’s own purposes, falls outside the exemption entirely. On most commercial websites that describes the majority of the tag inventory.
Exempt does not mean silent
Where you rely on a new exemption you must still give clear information about the storage or access and provide a simple means of opting out. Deleting the banner is not an implementation of the DUAA UK GDPR changes; replacing it with a clear notice and a working opt-out is. Our own cookie policy follows that pattern, and it is worth comparing yours against any site that has actually done the audit.
A worked inventory of what the DUAA UK GDPR changes exempt
Take a representative commercial site carrying 40 tags. Suppose 6 are strictly necessary, 4 are first-party analytics that share nothing, 2 apply appearance preferences, and the remaining 28 are advertising, cross-site tracking or analytics that also feed ad audiences. That is 15%, 10% and 5% exempt against 70% still requiring consent. The exemptions remove a fifth of your banner problem and leave the rest exactly where it was — but now priced at £17.5 million rather than £500,000.
Which Documents the DUAA UK GDPR Changes Force You to Rewrite
Provision-by-provision analysis is how lawyers read the DUAA UK GDPR changes. Document-by-document is how a business absorbs one. Here is the register, with the edit stated rather than implied.
Privacy notice
Add the recognised legitimate interests language where Annex 1 applies, and add a description of any solely automated significant decision-making together with the route to obtain human review. Add the complaints procedure and the escalation path to the ICO. This is the single document that touches four of the DUAA UK GDPR changes at once, which makes it the right place to start.
Record of processing activities
Add a column distinguishing recognised legitimate interests from ordinary ones. Flag every processing activity that produces a significant automated decision, and flag whether it touches special category data. The ROPA obligation itself is unchanged, so this is an edit to a live document rather than a new artefact.
Legitimate interests assessments
Retire the assessments that are genuinely displaced by Annex 1 and keep the rest. Reinstate anything retired on the strength of a briefing that placed direct marketing in the recognised column. Keep the retired ones in the archive with a note explaining the statutory basis, because “we deleted it because the law changed” is a weaker answer than a dated file.
Cookie policy, banner configuration and tag register
The largest single piece of work for most organisations. Inventory every tag and answer one question per tag: does any data leave this site for a third party’s own purposes? If yes, it needs consent, an exemption or removal. Then implement notice plus opt-out for anything moved to an exemption. Given the new ceiling, this is no longer a low-stakes exercise.
Complaints policy, form and log
A new document, a new form, a new log and a briefing for whoever monitors social channels. Four fields in the log cover the statutory record: received, acknowledged, steps taken, outcome. This is days of work rather than weeks, and it is the largest unmanaged exposure in most organisations precisely because it is new.
Subject access procedure
Add the reasonable-and-proportionate search standard and the clarification clock-stop as documented steps, with a line requiring the searcher to record what was searched and why that scope was proportionate. The duty has not changed; the evidence you keep should.
Processor contracts and supplier schedules
Agreements written against the pre-2026 framework are not invalid, but they may reference the wrong standards for automated processing and transfers. Rather than reopening every contract, add the DUAA UK GDPR changes to the renewal checklist and address them as agreements come round. Where a provider delivers your managed IT services, confirm in writing which controls sit with them — the complaints duty in particular cannot be outsourced, only supported.
| Document | Edit required | Owner | Effort (hours) |
|---|---|---|---|
| Complaints policy, form and log | Create from scratch | Privacy or operations | 24 |
| Cookie policy and tag register | Full audit and re-consent design | Marketing and web | 20 |
| ROPA and LIA set | Reclassify legitimate interests | Privacy | 16 |
| Automated decision inventory | Build list, flag special category | Engineering and product | 12 |
| Contracts and training material | Renewal checklist and briefing | Legal and HR | 10 |
| Privacy notice | Four targeted additions | Privacy | 8 |
Taking the register’s own figures, the total is 90 hours, and the two newest of the DUAA UK GDPR changes — complaints and cookies — account for 44 of them, just under half.
DUAA UK GDPR Changes Team by Team: Who Has to Do Something Different
Compliance programmes stall when the work is described by legal provision to people who own processes. Translating the DUAA UK GDPR changes into departmental language is usually worth more than another all-staff briefing.
Marketing
Two of the DUAA UK GDPR changes land here and both are unwelcome. The direct-marketing legitimate interests assessment survives, whatever the summaries said. And the tag audit is now a material financial exercise rather than a housekeeping one. There is a third, less obvious item: complaints arriving through social channels must reach the privacy function, which means the person running those accounts needs a route and a 30-day clock they know about. Teams running acquisition through marketing services should treat the tag inventory as the first deliverable.
HR and recruitment
Automated sifting of applications is where the DUAA UK GDPR changes bite hardest in a mid-sized business, and it is the single most common solely-automated significant decision there is, and it frequently touches special category data through diversity monitoring, health declarations or right-to-work checks. Where it does, the restrictive regime survives. Where it does not, you owe the applicant notification, representations and human review. Either way the current position is almost certainly undocumented.
Engineering and product
The three safeguards inside the DUAA UK GDPR changes are your tickets. A notification event on the decision, a representation the individual can submit and you can store, an escalation to a reviewer with authority, and an audit trail joining them. Add a flag in the data model for whether a decision path touched special category data, because that determines which regime applies and it cannot be reconstructed later. Design for the statutory code that is still to come.
Customer service and operations
The complaints procedure is operational, not legal. Somebody acknowledges within 30 days, somebody investigates, somebody records four fields, somebody communicates the outcome and the escalation right. Where these DUAA UK GDPR changes fail in practice, it is almost never because the policy was wrong; it is because no named person owned the inbox.
Legal and procurement
Add the DUAA UK GDPR changes to the contract renewal checklist rather than reopening the estate. Confirm which obligations sit with providers and which cannot be delegated. Where cybersecurity obligations already appear in supplier schedules, the automated-processing and transfer clauses usually sit in the same annex and can be updated in the same pass.
Finance and the board
One number matters at board level: the PECR ceiling moved from £500,000 to £17.5 million or 4% of worldwide turnover. That reprices a risk previously delegated to the web team. The second board-level item is the divergence question below, because it determines whether the group runs one privacy standard or two.
| Team | What changed for them | First action this month |
|---|---|---|
| Marketing | Tag risk repriced; marketing LIA survives | Inventory every tag on the site |
| HR and recruitment | Automated sifting now in scope explicitly | Check whether sifting touches special category data |
| Engineering and product | Safeguards became build requirements | Raise tickets for notify, represent, review |
| Customer service | New universal complaints duty | Name an owner and start the log |
| Legal and procurement | Contract references now partly stale | Add clauses to the renewal checklist |
| Finance and board | PECR exposure up thirty-five-fold | Decide one standard or two |
Running One Programme Under Two Regimes After the DUAA UK GDPR Changes
For any business with EU customers or an EU entity, the interesting question is not what UK law now says. It is whether you run one policy or two.
Where UK and EU law now actually differ
The gap the DUAA UK GDPR changes opened is narrow but real, and it is widest on automated decision-making. Recognised legitimate interests have no EU equivalent. The reasonable-and-proportionate search standard is a codification the EU has not made. The internal complaints duty is a UK addition. Everything else — principles, breach reporting, DPO, ROPA, DPIA, transparency — remains materially aligned.
The single-standard option
Hold the EU standard everywhere and treat the DUAA UK GDPR changes as headroom you choose not to use. One policy set, one training package, one decisioning design, no branching logic. You forgo the Annex 1 relief and the automated-decision relaxation. Most multinational groups will land here, because the operational cost of running two regimes exceeds the value of a narrow relaxation that mainly benefits public-interest processing.
The dual-standard option
Run UK processing to UK law and EU processing to EU law. It is legitimate and it is more work: two lawful-basis registers, two decisioning configurations, two sets of privacy information and a data-residency question underneath all of it. It pays only where a large volume of UK-only automated decisioning exists and the relaxation genuinely removes a bottleneck.
Adequacy is the constraint underneath the choice
The European Commission renewed both UK adequacy decisions on 19 December 2025, running six years to 27 December 2031, with a mid-point review after four years conducted with the European Data Protection Board. The EDPB explicitly flagged automated decision-making as an area to monitor. Adequacy is therefore conditional in substance even though granted in form, which is a further argument for the single-standard approach: an organisation that never exploited the divergence has nothing to unwind if the assessment tightens. Keep a fallback transfer mechanism documented regardless.
One thing the divergence does not change
If you offer goods or services to people in the EU, or monitor their behaviour, EU GDPR applies to that processing under its own extraterritorial reach. No amount of UK reform reduces it. Treating the DUAA UK GDPR changes as a route out of EU compliance is a misreading that will not survive a single enquiry.
| Topic | UK after the Act | EU GDPR | Divergence |
|---|---|---|---|
| Solely automated significant decisions | Permitted with safeguards | Prohibited save exceptions | Wide |
| Recognised legitimate interests | Annex 1 list, no balancing test | No equivalent | Moderate |
| Subject access search standard | Reasonable and proportionate, in statute | Guidance and case law | Narrow |
| Internal complaints procedure | Mandatory for all controllers | Not mandated | UK addition |
| Cookie consent exemptions | Strictly necessary plus three | Strictly necessary only | Narrow |
| Breach notification | 72 hours | 72 hours | None |
| DPO, ROPA, DPIA | Unchanged | Unchanged | None |
What the DUAA UK GDPR Changes Left Completely Alone
Knowing what did not move is as valuable as knowing what did, because reform of this size generates confident misinformation that costs real budget.
DPO, ROPA and DPIA all survive intact
The mandatory Data Protection Officer obligation under Article 37 remains. Records of processing under Article 30 remain. Data protection impact assessments under Article 35 remain. Every proposal from the abandoned Data Protection and Digital Information Bill that would have diluted these was dropped. If you deferred appointing a DPO on the strength of that draft, that decision needs revisiting now rather than at your next audit.
Breach reporting is untouched
The 72-hour notification obligation to the ICO stands, as does the duty to notify affected individuals where there is a high risk to their rights. Nothing in the DUAA UK GDPR changes alters the threshold, the timescale or the content of a report. Any incident runbook rewritten on the assumption that these DUAA UK GDPR changes touched breach reporting has been rewritten for no reason.
Principles and transparency obligations stand
Lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability all survive unamended. Articles 13 and 14 privacy information requirements survive. What changed is some of the detail you must disclose, not the obligation to disclose it.
Why this matters to your budget
Roughly two-thirds of a typical privacy programme is untouched by the DUAA UK GDPR changes. Scoping the work as “respond to the DUAA UK GDPR changes” rather than “refresh the privacy programme” is the difference between the 90 hours in the register above and a project that consumes a quarter. Resist the vendor pitch that treats the Act as a reason to rebuild everything, and route the saving into the two areas that genuinely moved.
A Ninety-Day Plan to Absorb the DUAA UK GDPR Changes
Assume a programme last updated in 2025 and 90 hours of available effort, distributed as the register implies. This sequence resolves the most exposure per hour spent on the DUAA UK GDPR changes.
Days 1 to 15 — close the complaints gap
Stand up an electronic complaints form, add one alternative channel, brief whoever monitors social accounts, write the 30-day acknowledgement into a template and create the four-field log. Roughly 30 hours, and it addresses the only obligation that is universal, already in force and trivially easy for a complainant to evidence a failure against.
Days 16 to 45 — audit tags and reclassify lawful bases
Run the tag inventory and answer the third-party question for each one, then reclassify legitimate interests against Annex 1 and reinstate any assessment retired in error. Around 28 hours across marketing and privacy, and it covers both the largest financial exposure and the most commonly misapplied of the DUAA UK GDPR changes.
Days 46 to 75 — inventory automated decisions and raise the build tickets
List every process producing a significant effect with no meaningful human involvement, flag the ones touching special category data, and raise engineering tickets for notification, representations and review. Around 20 hours. Design against a stricter future code, because one is expected before the year ends.
Days 76 to 90 — contracts, notices and training
Fold the DUAA UK GDPR changes into the renewal checklist, publish the amended privacy notice and deliver a short specific briefing to the teams that handle complaints and subject access. Around 12 hours. A targeted briefing on what actually changed beats a generic refresher, and it is the cheapest way to stop the misinformation about direct marketing spreading inside your own organisation.
Whoever owns the programme should also decide early whether privacy work is coordinated centrally or left with each function, since that choice shapes every deadline above. Organisations that already run a coherent digital strategy tend to close these gaps faster, because the ownership question is settled before the legal one arrives.
Frequently Asked Questions About the DUAA UK GDPR Changes
Do the DUAA UK GDPR changes replace UK GDPR?
No. The Act amends UK GDPR, the Data Protection Act 2018 and PECR. UK GDPR remains the operative instrument, with amended Articles, two new Annexes, and Article 22 replaced by Articles 22A to 22D. Your existing citations remain correct.
Which change affects the most businesses?
The complaints procedure, because it is the only new obligation that applies to every controller regardless of size or sector. It has been in force since 19 June 2026, and failure to acknowledge within 30 days is unusually easy for a complainant to evidence.
Can we stop doing legitimate interests assessments for marketing?
No, and this is the most commonly repeated error about the DUAA UK GDPR changes. Direct marketing is named in the DUAA UK GDPR changes as an illustrative example of an ordinary Article 6(1)(f) interest, not as a recognised legitimate interest under Annex 1. The balancing test remains mandatory.
Do we still need a Data Protection Officer?
If you needed one under Article 37 before, you still need one. The proposals to abolish the role came from the abandoned Data Protection and Digital Information Bill and were not carried into this Act.
Are cookie banners now optional?
Only for a narrow set of low-risk purposes, and even then a clear notice and a working opt-out are still required. Most commercial sites carry advertising or shared analytics tags that remain firmly inside the consent requirement.
Should a UK business with EU customers use the new automated decision-making freedom?
Usually not. The relaxation is the widest point of divergence from EU GDPR, and running two decisioning standards costs more than the relief is worth for most groups. The EDPB flagged this area for monitoring under the renewed adequacy decisions, which is a further reason to treat it as headroom rather than an opportunity.
When will the ICO start enforcing?
The regulator has signalled a phased, implementation-focused approach rather than immediate enforcement, with cookie compliance flagged as a renewed priority. A phased approach is not an amnesty, and the complaints duty in particular produces documentary evidence of failure without any investigation being needed.
References
Data (Use and Access) Act 2025
Data (Use and Access) Act 2025 Explanatory Notes
ICO Statement on the commencement of the Data (Use and Access) Act
ICO guidance on rights related to automated decision-making and profiling
ICO Guide to Privacy and Electronic Communications Regulations
ICO guidance for controllers and processors
ICO guidance on data protection impact assessments
European Commission adequacy decisions
EDPB opinions on the draft UK adequacy decisions
The Privacy and Electronic Communications (EC Directive) Regulations 2003