PECR

duaa compliance checklist uk smes a upright grooved slab

DUAA Compliance: Essential SME Checklist to Avoid Costly Fines

The Data (Use and Access) Act 2025 is fully commenced and there is no small-business exemption from the parts that matter. This checklist is written for the firm with no data protection officer and one person watching the shared inbox: a three-question scoping test, the five-item baseline every UK controller must meet, the conditional duties that only fire for some businesses, the new universal complaints procedure and its 30-day clock, the cookie audit behind a PECR ceiling that rose from £500,000 to £17.5 million, automated decisions hiding inside off-the-shelf SaaS, an honest hour-and-cost budget, the nine-artefact evidence pack, seven small-business failure patterns, and a ninety-day plan with owners.

Read more
duaa uk gdpr changes what changed for businesses a three ascending rounded pillars

DUAA UK GDPR Changes: Essential Guide to Avoid Costly Risk

The Data (Use and Access) Act 2025 edits UK data protection law rather than replacing it, which is why a summary is less useful than a diff. This guide sets the pre-2026 position beside the current one across lawful basis and the new Annex 1 recognised legitimate interests, the repeal of Article 22 and the safeguards in Articles 22A to 22D, the reasonable-and-proportionate subject access standard, the universal complaints duty and its 30-day clock, and the three narrow cookie exemptions behind a PECR ceiling that rose from £500,000 to £17.5 million. It then translates every change into the document you edit, the team that owns it, a 90-hour effort register, a UK-versus-EU divergence table, and a ninety-day plan.

Read more
data use and access act 2025 a three ascending rounded pillars

Data Use and Access Act 2025: Essential UK Risk Checklist

The main data protection provisions commenced on 5 February 2026, the mandatory complaints procedure followed on 19 June 2026, and the maximum PECR penalty rose thirty-five-fold to £17.5 million. This guide sets out exactly what is in force, what is still pending, and what each change obliges a UK business to do differently: the commencement timetable tied to its statutory instruments, recognised legitimate interests and the direct-marketing trap underneath them, the repeal of Article 22 and the new Articles 22A to 22D on automated decision-making, the reasonable-and-proportionate subject access standard, the universal complaints duty and its 30-day acknowledgement clock, the three narrow cookie exemptions and why the analytics one is narrower than it looks, renewed EU adequacy to December 2031, what the Act pointedly did not change, and a sequenced six-step remediation plan for the rest of 2026.

Read more
CHAT