The Data Use and Access Act: What You Need to Know

On 19 June 2025, the Data (Use and Access) Bill received Royal Assent, becoming law and marking the biggest shake-up to UK data protection in years. While it doesn’t replace UK GDPR, the Data Protection Act 2018, or PECR, it does amend and layer on top of them, and the changes are wide-ranging.

The aim? To give organisations more flexibility when using data, while maintaining appropriate protections for this data and in doing so supporting the UK’s EU adequacy status. But this isn’t just a tidy-up of existing rules – the Data (Use and Access) Act (or DUA Act) introduces a new lawful basis, changes to consent, complaints handling, cookies, and much more.

Below, we’ve summarised the most practical and impactful changes you need to know.

A New Lawful Basis: Recognised Legitimate Interests

The Act introduces a new lawful basis: recognised legitimate interests. This removes the need to carry out a “balancing test” when processing personal data in certain predefined scenarios – such as safeguarding, crime prevention, national security, or public emergencies.

This won’t apply to just any commercial purpose, but it does provide more certainty when operating in areas of public interest or internal security.

Compatibility, Clarified

The DUA Act outlines when you can reuse data for a new purpose. If the original basis was consent, re-use is tightly limited, often requiring new consent. If it wasn’t, there’s more scope to justify reuse if it’s for research, statistical analysis, or listed public interest reasons.

This should help organisations avoid over-relying on repeat consent requests, especially where re-use is proportionate and ethical.

Subject Access Requests: Timeframes and Reasonableness

For anyone dealing with data subject rights organisations only need to conduct reasonable and proportionate searches when responding to requests in line with ICO guidance in this area.

The clock starts ticking when you receive the request or the additional info you need to process it, or a fee when required whichever is later.

Automated Decisions: More Scope, Same Safeguards

Previously, making significant decisions using solely automated processing was tightly limited. Now, the Act broadens that ability, provided key safeguards are in place: transparency, human review, and the ability to contest decisions.

If you use AI or algorithmic tools in decision-making, this is one to dig into.

Children’s Data: Stronger Expectations for Online Services

The Act reinforces the need for specific protections for children. Online service providers must consider how best to safeguard young users, taking into account age, maturity, and awareness of data risks.

This builds on the Children’s Code and signals regulators will continue to expect strong measures by design.

PECR Changes: Cookies, Charities, and New Powers

Changes to PECR (Privacy and Electronic Communications Regulations) are more than cosmetic:

  • Soft opt-in extended to charities, allowing them to send marketing emails without consent under defined conditions.
  • Cookie rules clarified and broadened to allow use of cookies for statistical purposes without consent.
  • Notification Aligning timescales for reporting PECR breaches with the UK GDPR (within 72 hours).
  • Enforcement powers strengthened, with PECR penalties brought in line with UK GDPR (£17.5M max).

Complaints Handling: Obligations for Organisations

A new right allows individuals to raise complaints about how their data is handled and organisations must:

  • Provide an electronic complaints form
  • Acknowledge the complaint within 30 days
  • Keep the individual informed of progress and resolution

If this isn’t already built into your process, now’s the time.

International Transfers: “Not Materially Lower” Standard

The DUA Act updates the standard for international data transfers – organisations must now ensure the recipient country offers protection that is not materially lower than UK GDPR standards.

The requirement for transfer risk assessments has also been formalised.

What You Should Do Next

The Data (Use and Access) Act is significant and it’s only just getting started. DSIT and the ICO are due to publish further guidance and implementation dates, but smart organisations won’t wait.

Start by reviewing:

  • Your lawful basis records
  • SAR handling and response templates
  • Cookie consent and PECR compliance
  • Your complaints and privacy notice processes
    Whether your systems can support greater transparency, automation review, and children’s data safeguards

Need support aligning with the new Data Use and Access Act?

Evolve North can help you assess your current practices and identify areas for improvement. Our consultancy team supports organisations across sectors with UK GDPR, PECR, DSPT and more including breach management, audits, and training.

Contact us on 01748 905 002, email info@evolvenorth.com or visit our page Data Use and Access Act – Evolve North.

Arrange a FREE Consultation

Want to learn more about improving your organisation's security? Our team is here to answer your questions and explain the options available. In a free consultation, we'll help you understand the services we offer and how they can support your goals. It's a simple, no-obligation way to start exploring the right approach for your business.