Picture this: your organisation receives a data subject access request that would require searching through decades of archived files. Under the old rules, you might have felt obligated to conduct an exhaustive search regardless of cost or practicality. But what if there was a more balanced approach that protected individual rights whilst acknowledging business realities?
The Data Use and Access Act 2025 (DUAA) represents the most significant overhaul of UK data protection law since Brexit. This comprehensive legislation doesn’t just tweak existing rules—it fundamentally reshapes how UK organisations handle personal data, automated decision-making, and regulatory compliance. Understanding what is the Data Use and Access Act 2025 has become essential for any organisation operating in the UK’s evolving data landscape.
Key Takeaways
- Comprehensive Reform: The DUAA comprises seven distinct parts covering everything from data protection amendments to smart data schemes and digital verification services
- Phased Implementation: The Act rolls out in four stages throughout 2025-2026, with major data protection changes taking effect in Stage 3 during 2026
- Practical Improvements: New “reasonable and proportionate” search requirements for data subject access requests provide much-needed clarity for organisations
- Enhanced Rights: Consumers gain direct complaint rights against data controllers, whilst automated decision-making rules become more nuanced
- Regulatory Transformation: The Information Commissioner’s Office (ICO) will be reorganised into the Information Commission with expanded powers and responsibilities
Understanding What is the Data Use and Access Act 2025: Structure and Scope
The Data Use and Access Act 2025 isn’t a single-focus piece of legislation. Instead, it’s a comprehensive framework that addresses multiple aspects of the UK’s digital infrastructure and data governance. The Act comprises seven distinct parts, each tackling different elements of the modern data ecosystem.[2]
Part 1 introduces smart data schemes designed to enhance data portability and innovation across sectors. Part 2 establishes digital verification services to streamline identity verification processes. Part 3 creates the National Underground Asset Register, whilst Part 4 modernises births and deaths registration systems.
However, for most UK organisations, Part 5 represents the most significant change. This section contains substantial amendments to data protection and privacy laws, fundamentally altering how businesses must approach GDPR compliance. Part 6 reorganises the ICO into the Information Commission, and Part 7 addresses sector-specific provisions.[2]
The Staged Implementation Approach
Rather than implementing everything at once, the government has adopted a phased approach. Five commencement regulations have already been made, with Commencement No. 1 taking effect on August 20, 2025, bringing smart data provisions into force. More recently, Commencement No. 5 introduced new offences relating to non-consensual deepfake intimate images on February 6, 2026.[2]
The most significant changes for data protection compliance are scheduled for Stage 3 in 2026, whilst complaints-handling duties and ICO governance changes will follow in later stages.[2]
Key Changes to Data Protection Under the DUAA
Automated Decision-Making: A More Nuanced Approach
One of the most significant changes concerns automated decision-making. Previously, UK GDPR contained broad restrictions on solely automated decision-making. The DUAA narrows this prohibition significantly.
Now, the general prohibition applies only to significant automated decisions based entirely or partly on “special category” data—such as health information, racial or ethnic origin, or political opinions. This change broadens the legal bases available for other significant automated decisions to include legitimate interests, providing organisations with greater flexibility.[3]
This shift acknowledges the reality of modern business operations whilst maintaining strong protections for the most sensitive personal data categories.
Recognised Legitimate Interests: Expanding Legal Bases
The Act introduces a new legal basis for processing that covers several important areas:
- National security, public security and defence
- Crime detection, investigation and prevention
- Responding to public interest body requests
- Safeguarding vulnerable individuals[3]
These recognised legitimate interests provide clearer legal foundations for processing activities that serve important public purposes, reducing uncertainty for organisations operating in these sectors.
Data Subject Access Requests: “Reasonable and Proportionate” Searches
Perhaps one of the most practical changes for day-to-day operations concerns data subject access requests (DSARs). The DUAA codifies the principle that data controllers must make only “reasonable and proportionate” searches in response to DSARs.[2]
This change provides welcome clarity by establishing that controllers have no obligation to conduct searches where doing so would be “unreasonable or disproportionate to the importance of providing access.” This codifies earlier regulatory guidance and should help organisations balance compliance obligations with practical considerations.
The ICO has already updated its Right of Access guidance to clarify this principle, providing organisations with clearer direction on implementation.[2]
Enhanced Consumer Rights and Complaint Mechanisms
Direct Complaint Rights to Data Controllers
The DUAA introduces a significant new right for consumers: the ability to complain directly to data controllers regarding data protection infringements. This complements existing ICO complaint mechanisms rather than replacing them.[3][5]
Under the new system, when consumers raise complaints with data controllers, organisations must:
- Acknowledge complaints within 30 days
- Take appropriate steps to resolve them without undue delay
- Inform data subjects of progress and outcomes[3]
This creates a more immediate avenue for resolving data protection concerns whilst potentially reducing the burden on the ICO by encouraging direct resolution.
Compliance Deadline for Complaints Procedures
Organisations must have compliant complaints handling procedures in place by June 2026.[2] This gives businesses several months to develop and implement appropriate systems, but the deadline is approaching faster than many realise.
The ICO plans to release updated guidance on complaints handling during Winter 2025/2026, which should help organisations understand exactly what’s required.[2]
Special Protections for Children’s Data
The Act introduces specific “children’s higher protection matters” within the UK GDPR framework. These provisions require organisations to update their data handling policies to provide enhanced protections for children’s personal data.[3][5]
This change reflects growing recognition of children’s particular vulnerability in digital environments and aligns with broader trends in data protection law towards stronger safeguards for young people. Organisations that regularly process children’s data—including schools, gaming companies, and social media platforms—will need to review and potentially overhaul their current approaches.
For guidance on implementing these changes effectively, organisations might benefit from reviewing GDPR training requirements to ensure staff understand the enhanced obligations.
Regulatory Changes and Enhanced Enforcement Powers
ICO Transformation into the Information Commission
Part 6 of the DUAA reorganises the ICO into the Information Commission, bringing significant changes to the UK’s data protection regulatory landscape. This isn’t merely a cosmetic change—it represents a fundamental restructuring of how data protection regulation operates in the UK.[2]
Increased Penalties and Investigative Powers
The Act significantly enhances the regulator’s enforcement capabilities. Maximum penalties under the Privacy and Electronic Communications Regulations (PECR) have been increased, bringing them more in line with GDPR fines and penalties.[3]
The Information Commission will also gain expanded investigative powers, including:
- The ability to compel witnesses
- Authority to require investigation reports at the controller or processor’s expense
- Enhanced information-gathering powers[3]
These changes signal a more robust enforcement approach and underscore the importance of maintaining strong compliance programmes.
Sector-Specific Implications and Smart Data Schemes
Smart Data Initiatives
Part 1 of the DUAA establishes frameworks for smart data schemes across various sectors. These schemes aim to enhance data portability and enable innovation by making it easier for consumers to share their data with authorised third parties.
Smart data schemes could transform sectors like banking, energy, and telecommunications by enabling more personalised services and promoting competition. However, they also create new compliance obligations for participating organisations.
Digital Verification Services
Part 2 introduces digital verification services designed to streamline identity verification processes across government and private sector services. This could significantly reduce bureaucratic friction whilst maintaining security standards.
For organisations that frequently need to verify customer identities, these services could provide more efficient and reliable alternatives to current methods.
Preparing for DUAA Compliance: Practical Steps
Immediate Actions for UK Organisations
With implementation already underway and major changes scheduled for 2026, organisations should begin preparing now:
- Review Current Data Protection Policies: Assess how automated decision-making rules, legitimate interests, and children’s data protections apply to your operations
- Develop Complaints Handling Procedures: Create systems to acknowledge, investigate, and respond to data subject complaints within the required timeframes
- Update DSAR Processes: Implement “reasonable and proportionate” search principles in data subject access request procedures
- Staff Training: Ensure teams understand the changes and their implications for daily operations
Understanding how much GDPR compliance costs can help organisations budget appropriately for these necessary updates.
Monitoring Upcoming Guidance
The ICO plans to release additional guidance during Winter 2025/2026 covering:
- Codes of conduct
- Certification schemes
- Complaints handling procedures
- Lawful basis and legitimate interests
- Purpose limitation principles[2]
Organisations should monitor these releases closely and adjust their compliance programmes accordingly.
International Considerations and Cross-Border Data Flows
UK GDPR vs EU GDPR Divergence
The DUAA represents a significant divergence between UK and EU data protection approaches. Organisations operating across both jurisdictions will need to navigate increasingly different regulatory requirements.
For detailed analysis of these differences, see our comprehensive guide to EU GDPR vs UK GDPR to understand how the DUAA affects cross-border compliance strategies.
Impact on International Organisations
Companies based outside the UK but processing UK residents’ data will need to understand how the DUAA affects their obligations. This is particularly relevant for US companies, who should review whether GDPR affects US companies under the new framework.
Looking Ahead: What is the Data Use and Access Act 2025’s Long-Term Impact?
The DUAA represents more than regulatory change—it signals the UK’s vision for data governance in the digital age. By balancing individual rights with business practicality, the Act aims to maintain high privacy standards whilst promoting innovation and economic growth.
Innovation and Competition
Smart data schemes and digital verification services could unlock significant innovation opportunities. By making data more portable and identity verification more efficient, the DUAA could enable new business models and services that weren’t previously feasible.
Regulatory Leadership
The UK is positioning itself as a leader in pragmatic data governance. The “reasonable and proportionate” approach to DSARs and the more nuanced treatment of automated decision-making demonstrate how regulation can evolve to meet real-world needs without compromising fundamental protections.
However, this approach also creates challenges. Organisations operating internationally must navigate multiple regulatory frameworks, potentially increasing compliance complexity and costs.
Addressing Remote Working and Security Considerations
The DUAA’s enhanced enforcement powers and expanded data protection obligations have particular relevance for organisations with remote workforces. The increased focus on data security and the ICO’s expanded investigative capabilities make it more important than ever to address security risks of remote working.
Remote working arrangements must be designed with DUAA compliance in mind, particularly regarding automated decision-making, data subject complaints, and children’s data protections.
Conclusion
Understanding what is the Data Use and Access Act 2025 is crucial for any UK organisation handling personal data. This landmark legislation represents a fundamental shift in how the UK approaches data governance, balancing individual rights with business practicality in ways that could influence global regulatory trends.
The Act’s phased implementation provides organisations with time to adapt, but the window for preparation is narrowing. With major data protection changes scheduled for 2026 and complaints handling procedures required by June 2026, the time for action is now.
Next Steps for Your Organisation
- Conduct a DUAA Impact Assessment: Review how the changes affect your specific operations and compliance obligations
- Update Policies and Procedures: Revise data protection policies to reflect new requirements around automated decision-making, legitimate interests, and complaints handling
- Implement Training Programmes: Ensure staff understand the changes and can implement them effectively
- Monitor Regulatory Guidance: Stay updated with ICO guidance releases throughout 2026
- Consider Professional Support: Given the complexity of the changes, many organisations will benefit from specialist advice
The Data Use and Access Act 2025 isn’t just about compliance—it’s about positioning your organisation for success in the UK’s evolving digital landscape. By understanding and embracing these changes, organisations can turn regulatory compliance into competitive advantage whilst maintaining the trust and confidence of their customers.
The future of UK data protection is here. The question isn’t whether your organisation will need to adapt, but how quickly and effectively you can implement the necessary changes to thrive under the new framework.
References
[1] Data (Use Access) Act Fact Sheet UK GDPR – DPA
[2] The Data Use And Access Act fact sheet ICO
[3] The Data Use And Access Act fact sheet PEC Regulations
[4] The Data Use and Access Act 2025 (DUAA) – what does it mean for organisations?
