The Data (Use and Access) Act 2025: What Actually Changed for UK GDPR Compliance
The first thing worth clearing up about the Data (Use and Access) Act 2025 (DUAA) is what it is not. It is not a UK replacement for GDPR, and it does not tear up the Data Protection Act 2018. Earlier drafts of this reform, back when it was the Data Protection and Digital Information Bill, were more ambitious about departing from the EU model. What actually reached Royal Assent on 19 June 2025 is narrower: a set of amendments bolted onto the existing UK GDPR, the DPA 2018 and PECR. If you already have a working compliance programme, you are patching it, not rebuilding it.
The second thing worth clearing up is that "Royal Assent" and "in force" are different dates, and DUAA has spread the gap between them unusually wide. Large parts of the Act commence only when the government makes a commencement regulation naming that section. The bulk of the Part 5 data protection changes, including the new international transfer rules and the cookie exemptions, came into force on 5 February 2026. The mandatory complaints-handling duty does not bite until 19 June 2026. Other provisions are still waiting on secondary legislation and ICO guidance as of this year. So "is this clause live yet" is a real question you have to check per-provision, not something you can answer once for the whole Act.
A lawful basis that skips the balancing test
DUAA adds a new lawful basis to Article 6: recognised legitimate interests. Parliament has pre-approved a specific list of purposes, including safeguarding national security, responding to emergencies, preventing or detecting crime, and safeguarding vulnerable individuals, and processing for those purposes no longer requires the usual legitimate interests balancing test against the data subject's rights and freedoms.
That is a genuine change in mechanics, not just a labelling exercise. Ordinary legitimate interests under Article 6(1)(f) still require you to weigh your interest against the individual's, document it, and be ready to defend that judgement call. Recognised legitimate interests skip straight past that step for the listed purposes. The other principles in Article 5 (purpose limitation, data minimisation, storage limitation) still apply in full; DUAA narrows the assessment you have to do, not your other obligations.
Automated decisions get easier to justify, not easier to make
The other structural change is to Article 22, on solely automated decision-making. Previously, an individual had a general right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to narrow exceptions. DUAA flips the framing for anything that is not special category data: solely automated decisions become generally permitted, including on the basis of ordinary legitimate interests, provided the controller puts specific safeguards in place. Those safeguards are not optional extras: the individual must be told a decision was automated, given a way to contest it, and given a route to meaningful human review.
Special category data (health, biometric identifiers used for identification, and so on) keeps the tighter regime. So an automated credit-scoring or CV-shortlisting system that never touches special category data has an easier compliance path than it did before, but only if the human-review and contestation machinery is actually built and actually works, not bolted on as a rubber stamp.
International transfers: a new test, and a caveat attached to it
DUAA replaces the old "essentially equivalent" standard for third-country data protection with a "data protection test": whether the standard of protection in the destination country is not materially lower than the UK's. This applies twice over. The Secretary of State applies it when deciding whether to grant a country adequacy status, and controllers and processors apply their own version of it when carrying out a transfer risk assessment before relying on standard contractual clauses or the International Data Transfer Agreement.
"Not materially lower" is deliberately a lower bar than "essentially equivalent", and that gap did not go unnoticed. When the European Data Protection Board reviewed the UK's continuing EU adequacy status against this new framework, its opinion flagged that the data protection test, as drafted, does not explicitly require consideration of government access to data, availability of redress for individuals, or the existence of an independent supervisory authority in the destination country. It also specifically asked the European Commission to keep monitoring the UK's use of powers like technical capability notices under the Investigatory Powers Act, given their bearing on exactly the "government access" question the new test is quieter about. The Commission renewed UK adequacy anyway, through to December 2031, but the EDPB's opinion is a fairly clear signal about how that test will be read if it is ever tested through litigation or a future adequacy review.
Cookies get cheaper to run, and PECR gets teeth
If you have already read the earlier post on PECR and reject-all cookie banners, the mechanics of consent there are unchanged; DUAA does not touch what a valid "reject all" has to do. What it does add, from 5 February 2026, is a short list of new consent exemptions: cookies used solely for first-party analytics aimed at improving a service, and cookies that just remember a user's display or accessibility preferences, no longer need opt-in consent, though the subscriber still has to be told about them and given a way to object. The other change is enforcement, not exemptions: PECR penalties are raised to UK GDPR levels, up to £17.5 million or 4% of global annual turnover. A cookie compliance failure used to sit under a much lower statutory ceiling than a GDPR one; that gap is now closed.
A complaints process you have to build, not just write down
From 19 June 2026, controllers must operate a specific process for handling data protection complaints made directly to them, separate from an individual's right to complain to the regulator. The requirements are concrete enough to be a systems problem rather than a policy-document problem: an accessible channel for submitting a complaint regardless of format, acknowledgement within 30 days, investigation and response without undue delay, and a retained record of when the complaint arrived, what was done, and what the outcome was, available for the regulator to inspect. If your current "privacy complaints" handling is an inbox someone checks occasionally, this is the provision that turns it into something with a required audit trail.
The regulator gets a new name and a new shape
Less consequential day-to-day, but worth knowing: DUAA restructures the Information Commissioner's Office into the Information Commission, moving from a single Commissioner model to a board with non-executive directors and a chief executive, on the pattern used by other UK regulators like Ofcom. John Edwards, the sitting Information Commissioner, chairs the new board; Paul Arnold was announced as the first chief executive. The change is institutional rather than doctrinal: it does not itself alter what conduct is lawful, though a board-run regulator with an appointed CEO is a different animal to lobby, consult and litigate against than a single statutory office-holder.
Taken together, none of this is a rewrite of the compliance obligations most engineering teams actually deal with day to day: you still need a lawful basis, you still need to honour subject rights, you still need a valid transfer mechanism. What DUAA mostly does is move the goalposts on specific mechanics, on a schedule spread across most of 2026, in a direction the UK's own regulator and the EU's regulators are watching rather differently.