Don’t do SECURITY. Do business SECURELY.

Data (Use and Access) Act: main data protection changes commence

The main UK GDPR, DPA 2018 and PECR changes made by the Data (Use and Access) Act 2025 take effect today.

The main data protection changes made by the Data (Use and Access) Act 2025 commence today.

What changes now

  • Recognised legitimate interests: processing for purposes such as network and information security and crime prevention no longer requires a balancing test.
  • Automated decision-making: relaxed rules, with safeguards, except where special category data is involved.
  • Subject access requests: controllers need only carry out “reasonable and proportionate” searches, and can pause the clock while seeking clarification.
  • International transfers: a new “not materially lower” test for adequacy and transfer risk assessments.
  • Cookies: consent exemptions for certain analytics and functionality cookies, subject to an opt-out; PECR fines raised to UK GDPR levels.

Controllers must also have a data protection complaints procedure in place from June 2026. Review your privacy notices, DSAR procedure, cookie banner and transfer risk assessments.

Source: Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (legislation.gov.uk)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights