United Kingdom - Data Access Reform (2025)

Data (Use and Access) Act 2025

United Kingdom

RAI-GB-NA-DUA2XXX-2025
Effective: August 19, 2025
In Force(In Force)
ActData Protection and PrivacyGovernance and OversightEnforcement and Penalties
Export PDF

The Data (Use and Access) Act 2025 (DUAA) is a wide-ranging UK Act that amends the UK GDPR, Data Protection Act 2018 and PECR to enable safer data sharing, encourage innovation (including digital verification services and smart data schemes), and streamline law enforcement and national security data processing while retaining protections for individuals. It introduces a new lawful basis ('recognised legitimate interests'), clarifies automated decision-making rules and subject access procedures, and phases commencement of provisions over months following Royal Assent.

Summary

The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025 and implements a series of targeted changes to the UK data protection and privacy framework. Rather than replacing the UK GDPR or the Data Protection Act 2018, the DUAA amends them and the Privacy and Electronic Communications Regulations 2003 (PECR) to simplify certain legal requirements, enable innovation in areas such as digital verification services and smart-data initiatives, and improve operational efficiency for public authorities and private organisations. Key themes include: (1) creation of a new lawful basis for processing personal data — 'recognised legitimate interests' — for specified public-interest and similar purposes without the necessity of running the standard legitimate-interests balancing test (though necessity and other data protection principles still apply); (2) relaxation and recalibration of rules on automated decision-making (ADM) for non-sensitive data while preserving safeguards such as information to data subjects, opportunities to make representations, and meaningful human review where necessary; (3) procedural clarifications including a 'stop-the-clock' rule for subject access requests to allow organisations to request further information where necessary and clear standards on reasonable and proportionate searches; (4) explicit duties for online services likely accessed by children to consider protection-by-design measures; (5) clarification that scientific and commercial research may be processed under research-friendly safeguards and consent arrangements, including scope for broad consent in certain research contexts; (6) updated rules and guidance on cookies and storage/access technologies to allow low-risk use without explicit consent in specified scenarios; and (7) provisions to simplify and align law enforcement and intelligence-related processing with the amended UK GDPR where appropriate.

The DUAA also establishes or underpins new and evolving digital infrastructure mechanisms (for example, enabling digital verification services and contributing to the development of Smart Data programmes and a National Data Library/National Underground Asset Register). The Act grants regulators — principally the Information Commissioner’s Office (ICO) — additional powers and duties, including strengthened investigatory powers, the ability to compel witness attendance and technical reporting, and a regulatory programme to publish guidance on phased commencement and practical compliance. The ICO has signalled staged commencement (two to twelve months after Royal Assent for most measures) and launched consultations on draft guidance such as on 'recognised legitimate interest' and the required organisational complaints-handling processes. The DUAA includes transitional and commencement provisions; organisations are expected to follow existing law until the new or amended provisions come into force. The DUAA is consequentially connected to other legislation (Data Protection Act 2018, UK GDPR, PECR) and government programmes (digital identity, smart data), and will be accompanied by statutory and non-statutory guidance from the ICO and policy materials from the Department for Science, Innovation & Technology (DSIT).

Full article

Read full text ↗

Overview

The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025 and introduces targeted amendments to the UK data protection framework to promote innovation, support secure data sharing, and streamline law enforcement and public service data access. The Act does not repeal the UK GDPR or the Data Protection Act 2018 but inserts new provisions and clarifications and amends PECR. The DUAA enables new digital verification services and Smart Data approaches, clarifies lawful bases for processing (notably the new 'recognised legitimate interests'), relaxes certain restrictions on automated decision-making for non-sensitive data while mandating safeguards, and creates tailored duties (for example in relation to children’s online protection and research). Commencement is phased and accompanied by guidance from regulators and departments; see the government's summary on GOV.UK and the ICO pages for guidance. For the enacted text and schedules consult Data (Use and Access) Act 2025 (as enacted) — legislation.gov.uk and government guidance at GOV.UK: Data (Use and Access) Act 2025 - data protection and privacy changes. The ICO has published a coordinated set of pages explaining how it will regulate during commencement phases: ICO: Data (Use and Access) Act 2025.

Definitions

The DUAA adds and clarifies definitional material in the UK GDPR and related statutes. Important defined concepts include: 'recognised legitimate interests' (an annexed list/categories of processing purposes treated as legitimate for the lawfulness of processing without a balancing test), 'digital verification services' (state-enabled or accredited services for verifying credentials), 'storage and access technologies' (cookies and similar), and refined definitions for 'automated decision-making' and 'meaningful human involvement'. The Act also clarifies the scope of 'research' to include commercial scientific research in specified contexts and sets out thresholds for 'services likely to be accessed by children'. These definitions are implemented by inserting new schedules and amendments into the UK GDPR and the Data Protection Act 2018; see the enacted text at legislation.gov.uk.

Governance and Institutional Framework

The ICO remains the primary regulator for data protection, with additional statutory duties flowing from the DUAA: the requirement to produce regulatory guidance for new powers, consult on guidance drafts, and publish commencement timetables. The Department for Science, Innovation & Technology (DSIT) is the sponsoring department for policy areas such as digital verification and Smart Data, and has published factsheets and commencement planning information on GOV.UK (DSIT factsheet). The Act also creates or authorises functions for new delivery bodies (for example, elements connected to digital identity and a National Data Library) and establishes interfaces between central government, sectoral regulators and the ICO for standards, accreditation and oversight. The ICO has been given additional investigatory powers, and the DUAA provides for formal guidance-making duties and consultation obligations for the ICO when new enforcement powers commence; for details see ICO: How we will regulate as the DUAA commences.

Key Focus Areas

The DUAA’s policy focus covers multiple areas: (1) Lawful bases and lawful processing — introducing 'recognised legitimate interests' for specified public interest purposes (crime prevention, safeguarding, emergencies, intra-group administrative transfers etc.) while maintaining necessity and proportionality tests; (2) Automated decision-making — widening permitted automated decisions for non-sensitive data with mandated safeguards such as notice, representation, and human review pathways; (3) Subject access and individual rights — clarifying timeframes, introducing a 'stop-the-clock' rule for requests where further information is required, and setting standards for proportional searches; (4) Children’s online protection — a design-and-assessment duty for services likely used by children; (5) Research and innovation — clearer rules for commercial and academic research, allowing calibrated broad consent and research safeguards; (6) Storage and access technologies — calibrated changes to consent for cookies and similar low-risk technologies; and (7) International transfers and regulatory alignment — legislative clarifications to support transfers while preserving safeguards. These principal areas are documented in government factsheets and ICO summaries; see GOV.UK and ICO.

Implementation Framework

Commencement is phased: most measures are scheduled to commence between two and twelve months after Royal Assent; exact commencement dates are set out in commencement regulations to be published on GOV.UK. The ICO has committed to publishing statutory and non-statutory guidance in tandem with commencement and to consulting publicly on key guidance such as recognised legitimate interests and organisational complaint-handling procedures. Organisations should maintain existing compliance arrangements until particular provisions commence; where the law will change, the ICO will indicate whether transitional arrangements apply or whether action is required by a specified deadline (for example, the requirement to have a data protection complaints process in place by June 2026). Departments and sectoral bodies (notably DSIT and health sector advisers) will issue complementary guidance for specialised areas such as health information standards and Smart Data schemes; see DSIT materials on GOV.UK at DSIT guidance.

Monitoring and Evaluation

The DUAA anticipates active monitoring by the ICO, which will use its expanded investigatory powers and published guidance to assess compliance. The ICO has said it will apply the law that existed at the time an alleged infringement occurred and exercise regulatory discretion in cases transitioning between old and new provisions. The Act also enables sector-specific reporting and evaluation mechanisms (for Smart Data pilots, digital verification services, and the National Data Library) to ensure evidence-based rollout and public accountability. The ICO and DSIT will publish monitoring frameworks and will consult stakeholders on metrics including complaint volumes, data-sharing outcomes, safeguarding incidents and take-up of new digital services; see ICO DUAA pages for planned consultations.

Penalties, Liability, and Appeals

The DUAA reinforces the ICO’s enforcement toolkit and introduces targeted penalties and investigatory powers. Under amendments to PECR, the ICO may issue fines of up to £17.5 million or 4% of global turnover for the most serious breaches of certain electronic communications rules. The Act also clarifies civil liabilities and administrative sanctions under the UK GDPR/DPA 2018 framework; individuals retain rights to bring complaints to the ICO and to seek redress in court in appropriate cases. The DUAA grants the ICO powers to compel witnesses, require technical reports, and make regulations governing the exercise of new powers. Standard appeal routes to the First-tier Tribunal (Information Rights) and onward appeal to the Upper Tribunal remain available for decisions of the ICO, and the Act provides for procedural protections for regulated entities when new powers are exercised; see ICO guidance on enforcement and powers at ICO regulatory powers.

Relationship to Other Instruments

The DUAA amends and sits alongside existing UK data protection instruments: the UK GDPR (as retained EU law), the Data Protection Act 2018 (Parts 3 and 4 for law enforcement and intelligence processing are also amended), and the Privacy and Electronic Communications Regulations 2003 (PECR). It also interacts with sectoral rules (health information standards, children’s services legislation), the Government Digital Service’s Technology Code of Practice, and evolving digital identity legislation and architectures. The Act contains schedules and consequential amendments to ensure alignment with these instruments; consult the enacted text at legislation.gov.uk and the parliamentary bill pages at bills.parliament.uk: Data (Use and Access) Bill for full cross-references.

International Alignment

The DUAA includes provisions designed to facilitate international transfers and practical alignment with foreign frameworks while maintaining UK sovereignty over data protection policy. It clarifies transfer mechanisms and cooperative arrangements for law enforcement and intelligence sharing. The government intends the Act to support economic opportunities for trade in data services, including interoperability with key partners, while preserving safeguards. The ICO will publish guidance addressing transfers and adequacy considerations and how the 'recognised legitimate interests' ground interacts with cross-border contexts; see GOV.UK and ICO materials for transfer-specific updates: GOV.UK, ICO.

Implementation Timeline

EventDate
Royal Assent2025-06-19
Government factsheet (DSIT) published2025-06-27
ICO initial guidance publication2025-06-19
Phased commencement window (many provisions)Two to twelve months after Royal Assent (commencements in 2025-08 through 2026-06)
First provisions came into effect (initial commencement dates published by DSIT/ICO)2025-08-19 to 2025-08-20 (initial stages)
Deadline to implement organisational complaint-handling process2026-06 (as indicated by ICO guidance timeline)

Sources and References

SourceType
Data (Use and Access) Act 2025 — as enacted (legislation.gov.uk)Primary Source
GOV.UK: Data (Use and Access) Act 2025 — data protection and privacy changes (DSIT)Primary Source
Information Commissioner’s Office: Data (Use and Access) Act 2025Primary Source
Parliamentary Bill: Data (Use and Access) Bill (bills.parliament.uk)Primary Source

Requirements for a company

What an organisation has to do under United Kingdom - Data Access Reform (2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

8
  • Implement mandated safeguards for automated decisions on non-sensitive data.Organisations using automated decision-making systems.
  • Conduct design and assessment duties for services likely accessed by children.Providers of online services likely accessed by children.
  • Establish an organisational data protection complaint-handling process.All organisations processing personal data.
  • Update subject access request processes to include new rules and timeframes.Organisations handling subject access requests.
  • Review data processing activities for reliance on 'recognised legitimate interests'.Organisations processing personal data.
  • Review research practices to align with clearer rules and safeguards.Organisations conducting commercial or academic research.
  • +2 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Monitor ICO and government guidance for new provisions and deadlines.All organisations processing personal data.

Should not do

0

Nothing in this category.

Who must do what

The obligations under United Kingdom - Data Access Reform (2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Organisations using automated decision-making systems.Implement mandated safeguards for automated decisions on non-sensitive data.
mandated safeguards such as notice, representation, and human review pathways
Critical
2Providers of online services likely accessed by children.Conduct design and assessment duties for services likely accessed by children.
a design-and-assessment duty for services likely to be accessed by children
Critical
3All organisations processing personal data.Establish an organisational data protection complaint-handling process.
the requirement to have a data protection complaints process in place by June 2026
2026-06Critical
4Organisations handling subject access requests.Update subject access request processes to include new rules and timeframes.
introducing a 'stop-the-clock' rule for requests where further information is required
Important
5Organisations processing personal data.Review data processing activities for reliance on 'recognised legitimate interests'.
introducing 'recognised legitimate interests' for specified public interest purposes
Important
6Organisations conducting commercial or academic research.Review research practices to align with clearer rules and safeguards.
clearer rules for commercial and academic research, allowing calibrated broad consent
Important
7Operators of websites and online services using cookies.Update consent mechanisms for cookies and similar low-risk technologies.
calibrated changes to consent for cookies and similar low-risk technologies
Important
8Organisations transferring personal data internationally.Review international data transfer mechanisms and preserve safeguards.
legislative clarifications to support transfers while preserving safeguards
Important
9All organisations processing personal data.Monitor ICO and government guidance for new provisions and deadlines.
Commencement is phased and accompanied by guidance from regulators and departments
Recommended

© Regulations.AI · updated on 13-Jun-2026