UK Data Act Marks One Year: What's Changed for Businesses?
Exactly one year ago today, on August 19, 2025, the Data (Use and Access) Act 2025 (DUAA) officially took effect, fundamentally reshaping the landscape of data protection and usage across the United Kingdom. This pivotal legislation, now firmly embedded in the UK's regulatory framework, has spent its first year driving significant shifts for organisations handling personal data, balancing innovation with robust individual safeguards.
What's changing
The DUAA 2025 was introduced to update and refine existing data protection rules, making targeted changes to the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). Its core aim was to foster innovation and secure data sharing while maintaining strong protections for individuals. Since its phased commencement began a year ago, organisations across the UK have been navigating these new obligations.
One of the most significant introductions was a new "recognised legitimate interests" ground for processing data. This provision has simplified the legal basis for specific public interest activities, such as crime prevention, safeguarding vulnerable individuals, or managing emergencies, allowing for more streamlined data use in these critical areas without compromising individual rights.
The Act also brought about relaxed rules for automated decision-making, particularly concerning non-sensitive data. While this change aimed to facilitate the adoption of AI and automated processes, it came with stringent requirements for safeguards. Organisations are now strictly mandated to provide clear notice to individuals, offer a right to make representations against automated decisions, and ensure human review is available. These safeguards are crucial for maintaining transparency and accountability in automated systems that impact individuals.
Clarifications for Subject Access Requests (SARs) have also been a notable development. The DUAA introduced a practical "stop-the-clock" rule, allowing organisations to pause the SAR response timeline when they need more information from the requester. It also set clearer standards for proportional searches, helping organisations manage the burden of responding to complex or extensive SARs while still ensuring individuals can access their data effectively.
Furthermore, the Act established a new duty for services likely to be accessed by children to design with their protection in mind. This proactive approach ensures that digital services are inherently safer for younger users, requiring organisations to consider the best interests of children from the outset of product and service development.
While the Act received Royal Assent on June 19, 2025, and began its phased rollout on August 19, 2025, many provisions have continued to come into full effect over the past year. The Information Commissioner's Office (ICO) remains the primary regulator, and its investigatory powers have been expanded under the DUAA. Organisations must also be aware of the increased penalties for serious breaches of electronic communications rules, which can now reach up to £17.5 million or 4% of global annual turnover.
Who is affected
The Data (Use and Access) Act 2025 applies broadly across the United Kingdom, impacting any organisation or individual handling personal data within the nation's borders. As a national-level Act, its provisions are binding across England, Scotland, Wales, and Northern Ireland, ensuring a consistent approach to data protection throughout the UK.
Its reach extends to a diverse array of entities. Businesses developing cutting-edge digital verification services, for instance, must now align their data processing practices with the DUAA's updated framework. Similarly, organisations involved in "Smart Data" schemes, which aim to empower consumers by giving them more control over their data, are directly impacted by the Act's provisions on data sharing and access.
Beyond the private sector, public bodies play a significant role in the Act's scope. This includes law enforcement agencies, public service providers, and research institutions that routinely process vast amounts of personal data. The new "recognised legitimate interests" ground, in particular, has provided a clearer legal basis for these public sector entities to conduct essential activities while adhering to robust data protection standards.
Essentially, if an organisation processes personal data in the UK, whether it's a multinational corporation, a small startup, a government department, or a charity, it has been subject to the DUAA's requirements since its effective date. The ICO has been actively providing guidance to help these diverse entities understand and comply with their evolving obligations.
Three things to do this week
With the DUAA having been in full effect for a year, organisations should use this anniversary as an opportunity to review and reinforce their compliance efforts. Here are three critical areas to focus on:
-
Ensure Robust Safeguards for Automated Decisions: Review all processes involving automated decision-making on non-sensitive data. Confirm that the mandated safeguards – clear notice to individuals, the right to make representations, and the availability of human review – are fully implemented, documented, and operational. Test these processes to ensure they are effective and transparent, aligning with the Act's requirements for accountability.
-
Verify Child-Centric Design and Assessments: For any service or product likely to be accessed by children, conduct an immediate audit of your design and assessment duties. Confirm that child protection principles were integrated from the design phase, and that ongoing assessments ensure the service remains safe and appropriate for younger users. This is an ongoing duty, not a one-off task.
-
Confirm Organisational Complaint-Handling Process: The deadline for establishing an organisational data protection complaint-handling process was June 2026. This means your organisation should already have a robust system in place. This week, review your existing process to ensure it is fully compliant, accessible, and effectively handles data protection complaints from individuals. Verify that staff are trained, procedures are clear, and complaints are resolved promptly and fairly, reflecting the Act's emphasis on individual rights and redress.
Related context
The Data (Use and Access) Act 2025 does not operate in a vacuum; it is part of a broader UK regulatory landscape for data and digital information. Its provisions were developed alongside, and in some cases informed by, the ongoing discussions around the Data Protection and Digital Information Bill (/regulations/RAI-GB-NA-DPDIXXX-2023), which aimed to further reform the UK's data protection regime. While the DUAA made targeted amendments, the wider legislative efforts underscore the UK's commitment to adapting its data laws for the digital age.
Organisations should also be mindful of specific implementing regulations and guidance. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 (/regulations/RAI-GB-NA-SI20264-2026), for example, provides crucial detail and practical advice on navigating the automated decision-making provisions introduced by the DUAA. This code is essential reading for any entity deploying AI or automated systems.
Furthermore, the Information Commissioner's Office (ICO) has been actively shaping its strategic approach to AI (/regulations/RAI-GB-NA-ICOSAXX-2024), which complements the DUAA's framework. The ICO's strategy outlines its regulatory priorities and expectations for responsible AI development and deployment, offering valuable insights into how the regulator will interpret and enforce the new provisions. Staying abreast of these interconnected developments is vital for comprehensive compliance.
Note: this article was drafted by AI - Google Gemini