The main data protection changes made by the Data (Use and Access) Act 2025 commence today.
What changes now
- Recognised legitimate interests: processing for purposes such as network and information security and crime prevention no longer requires a balancing test.
- Automated decision-making: relaxed rules, with safeguards, except where special category data is involved.
- Subject access requests: controllers need only carry out “reasonable and proportionate” searches, and can pause the clock while seeking clarification.
- International transfers: a new “not materially lower” test for adequacy and transfer risk assessments.
- Cookies: consent exemptions for certain analytics and functionality cookies, subject to an opt-out; PECR fines raised to UK GDPR levels.
Controllers must also have a data protection complaints procedure in place from June 2026. Review your privacy notices, DSAR procedure, cookie banner and transfer risk assessments.
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.