The UK Data (Use and Access) Act (DUAA) is now in force and introduces important changes to the UK’s data protection laws. It doesn’t replace existing laws but amends them to make compliance easier for organisations. It supports responsible innovation and drives economic growth. The Act also seeks to improve how organisations use and access personal data, while continuing to protect the rights and freedoms of individuals. The Secretary of State will phase in implementation between June 2025 and June 2026

Key changes

The DUAA introduces a wide range of reforms.

Expanded legitimate interests and further processing

  • Legitimate interests: The DUAA confirms that certain processing activities can rely on legitimate interests. These include direct marketing, intra-group transfers of personal data for internal administrative purposes, and ensuring cybersecurity. This gives organisations more flexibility to process personal data without consent in these contexts. However, they should still document their decisions and take data subject rights and freedoms into account.
  • Recognised legitimate interests: Organisations may rely on recognised legitimate interests without conducting a balancing test if the interest appears on the approved list. The list includes public interest purposes such as national security and crime prevention. The Secretary of State may amend the list.
  • Further processing of personal data: The DUAA clarifies that further processing is not automatically lawful simply because it is compatible with the original purpose. Businesses must assess compatibility before processing personal data for a new purpose.

Consent

  • Consent clarification: The DUAA confirms that consent must be freely given, specific, informed and unambiguous. It also sets out specific conditions for when consent is considered valid. Businesses must consider whether they are making access to a service conditional on consent to process personal data that isn’t essential for delivering that service.
  • Scientific research: The Act expands the definition of scientific research to include any activity, commercial or non-commercial, that one can reasonably describe as scientific. Organisations may obtain broad consent for a defined area of research, as long as they meet recognised ethical standards. They may also omit privacy notices if providing them would be disproportionately burdensome. In those cases, they must make the required information publicly available and put appropriate safeguards in place.

Updates to the Privacy and Electronic Communications Regulations (PECR)

  • Cookie consent: If you or a third party places or accesses data through cookies, you’re both responsible for obtaining consent. The Act makes website publishers and ad tech vendors jointly accountable. You can no longer rely on the other party to handle it for you.
  • Soft opt-in for charities: Charities and non-profits may now rely on the soft opt-in rule when sending direct marketing by email, provided recipients have a clear opportunity to opt out.
  • Increased fines: The DUAA aligns the maximum penalties for PECR breaches, including cookie violations, with those under the UK GDPR, which allow fines of up to £17.5 million or 4% of global annual turnover.
  • Enforcement powers: The Information Commission (formerly ICO) may now issue assessment notices, information notices, and enforcement notices for breaches under the PECR.

Data subject access requests (DSARs) and automated decision-making

  • DSARs: Data controllers must conduct a “reasonable and proportionate” search when responding to a DSAR. If responding would involve a disproportionate effort, they may refuse the request or ask the requester to narrow its scope. They may also pause the response deadline if they reasonably need more information to identify the relevant data or processing activities.
  • Automated decision making: The DUAA relaxes restrictions on automated decision-making, except when the processing involves special category personal data. In those cases, organisations must implement appropriate safeguards. The Act defines terms like “meaningful human involvement” and “significant decisions” to guide when human oversight is required.

Other additions

  • International data transfers: The Secretary of State may approve data transfers based on a new “data protection test”. This test assesses whether the protection in the destination country is not materially lower than in the UK.
  • Digital verification services: The DUAA introduces a trust framework and register for providers of digital verification services.
  • ICO reforms: The Act establishes the Information Commission, which replaces the ICO. It also transfers all of the ICO’s powers and functions, including enforcement powers, to the new Commission.

Actions you can take

DUUA’s implementation phase runs from June 2025 to June 2026. During this time, organisations need to prepare for how they will use, share, and protect personal data under the new rules. Here are some actions you can take now:

  • Review and update your privacy notices to include new lawful grounds introduced by the DUUA, like recognised legitimate interests and clarify when notices can be omitted.
  • Update your records of processing activities (ROPAs) to reflect any new processing purposes or legal bases, especially further processing and legitimate interests.
  • Continue to conduct and update legitimate interests assessments (LIAs) where you’re relying on legitimate interests, including the Act’s “recognised” categories. Make sure your assessments are documented and kept up to date.
  • Review your DSAR process to account for the DUAA’s updated timelines, clarification requests, and the new “stop the clock” mechanism.
  • Audit your use of cookies and tracking technologies, especially if your business instigates their use.
  • Review and update your contracts with data processors, joint controllers or research partners to reflect the Act’s new responsibilities and safeguards.
  • Train your team so that staff processing, handling or using data know and understand what’s changed and what they need to do.
  • Stay up to date with developments by reading more about the DUAA and how it impacts your organisation.

How can we help you

  • We can help your organisation by getting up to speed with the changes effected by the Act. Book a consultation with our legal experts to discuss your compliance needs or ask us for a quote.
  • Sign up for our newsletter for more developments on the Act.