The Data (Use and Access) Act 2025 has received Royal Assent. It amends the UK GDPR, the Data Protection Act 2018 and PECR, and will be commenced in stages.
Headline data protection changes
- Recognised legitimate interests, including network and information security and crime prevention, with no balancing test required.
- Relaxed rules on automated decision-making, with safeguards (except for special category data).
- Subject access requests: “reasonable and proportionate” searches and a “stop the clock” while clarification is sought.
- A new “not materially lower” test for international transfers.
- Consent exemptions for certain analytics and functionality cookies, and PECR fines raised to UK GDPR levels.
- A requirement for controllers to operate a data protection complaints procedure.
- The ICO will be restructured as the Information Commission.
We will publish updates as the provisions commence.
Source: Data (Use and Access) Act 2025 (legislation.gov.uk)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.