On 19 June 2025, the Data (Use and Access) Bill received Royal Assent, becoming law and marking the biggest shake-up to UK data protection in years. While it doesn’t replace UK GDPR, the Data Protection Act 2018, or PECR, it does amend and layer on top of them, and the changes are wide-ranging.
The aim? To give organisations more flexibility when using data, while maintaining appropriate protections for this data and in doing so supporting the UK’s EU adequacy status. But this isn’t just a tidy-up of existing rules – the Data (Use and Access) Act (or DUA Act) introduces a new lawful basis, changes to consent, complaints handling, cookies, and much more.
Below, we’ve summarised the most practical and impactful changes you need to know.
A New Lawful Basis: Recognised Legitimate Interests
The Act introduces a new lawful basis: recognised legitimate interests. This removes the need to carry out a “balancing test” when processing personal data in certain predefined scenarios – such as safeguarding, crime prevention, national security, or public emergencies.
This won’t apply to just any commercial purpose, but it does provide more certainty when operating in areas of public interest or internal security.
Compatibility, Clarified
The DUA Act outlines when you can reuse data for a new purpose. If the original basis was consent, re-use is tightly limited, often requiring new consent. If it wasn’t, there’s more scope to justify reuse if it’s for research, statistical analysis, or listed public interest reasons.
This should help organisations avoid over-relying on repeat consent requests, especially where re-use is proportionate and ethical.
Subject Access Requests: Timeframes and Reasonableness
For anyone dealing with data subject rights organisations only need to conduct reasonable and proportionate searches when responding to requests in line with ICO guidance in this area.
The clock starts ticking when you receive the request or the additional info you need to process it, or a fee when required whichever is later.
Automated Decisions: More Scope, Same Safeguards
Previously, making significant decisions using solely automated processing was tightly limited. Now, the Act broadens that ability, provided key safeguards are in place: transparency, human review, and the ability to contest decisions.
If you use AI or algorithmic tools in decision-making, this is one to dig into.
Children’s Data: Stronger Expectations for Online Services
The Act reinforces the need for specific protections for children. Online service providers must consider how best to safeguard young users, taking into account age, maturity, and awareness of data risks.
This builds on the Children’s Code and signals regulators will continue to expect strong measures by design.
PECR Changes: Cookies, Charities, and New Powers
Changes to PECR (Privacy and Electronic Communications Regulations) are more than cosmetic:
- Soft opt-in extended to charities, allowing them to send marketing emails without consent under defined conditions.
- Cookie rules clarified and broadened to allow use of cookies for statistical purposes without consent.
- Notification Aligning timescales for reporting PECR breaches with the UK GDPR (within 72 hours).
- Enforcement powers strengthened, with PECR penalties brought in line with UK GDPR (£17.5M max).
Complaints Handling: Obligations for Organisations
A new right allows individuals to raise complaints about how their data is handled and organisations must:
- Provide an electronic complaints form
- Acknowledge the complaint within 30 days
- Keep the individual informed of progress and resolution
If this isn’t already built into your process, now’s the time.
International Transfers: “Not Materially Lower” Standard
The DUA Act updates the standard for international data transfers – organisations must now ensure the recipient country offers protection that is not materially lower than UK GDPR standards.
The requirement for transfer risk assessments has also been formalised.
What You Should Do Next
The Data (Use and Access) Act is significant and it’s only just getting started. DSIT and the ICO are due to publish further guidance and implementation dates, but smart organisations won’t wait.
Start by reviewing:
- Your lawful basis records
- SAR handling and response templates
- Cookie consent and PECR compliance
- Your complaints and privacy notice processes
Whether your systems can support greater transparency, automation review, and children’s data safeguards
Need support aligning with the new Data Use and Access Act?
Evolve North can help you assess your current practices and identify areas for improvement. Our consultancy team supports organisations across sectors with UK GDPR, PECR, DSPT and more including breach management, audits, and training.
Contact us on 01748 905 002, email info@evolvenorth.com or visit our page Data Use and Access Act – Evolve North.
