On 19 June 2025, the UK’s Data (Use and Access) Act 2025 (DUAA) officially received Royal Assent, marking a significant shift in the UK’s post-Brexit data protection regulatory landscape. It reflects the government’s ambition to create a more agile and business-friendly data regime, while still maintaining high standards of privacy and accountability.
As we explored in our earlier post, Unlocking Growth and Trust: The Data (Use and Access) Bill Nears Enactment in the UK, the DUAA seeks to deliver a more flexible and innovation driven approach to data use while maintaining robust safeguards for individuals. The Act also marks a notable divergence from the EU GDPR, particularly in its governance reforms and enforcement priorities. A crucial change is the restructuring of the ICO into a multi-member Commission, which despite retaining operational independence, has raised concerns about its autonomy under EU data protection standards. The EU’s adequacy decision for the UK may therefore depend on whether the restructured authority is seen as sufficiently independent and impartial under EU data protection standards.
The DUAA is far more than a technical update; it is a strategic pivot. By easing certain compliance burdens and clarifying rules around the use of technologies such as cookies and automated decision-making, the Act aims to unlock the value of data for UK organisations, particularly in sectors like digital media, AI, and cross-border services.
Key Changes Introduced by the DUAA
- Eased Rules Around Cookies:
Organisations can now use certain cookies for analytics and site optimisation without obtaining prior consent though the need to offer compliant opt-out mechanisms remains.
- Automatic Decision- Making (ADM)
The DUAA broadens the lawful bases for ADM involving non-sensitive data. However, businesses must maintain safeguards, including offering individuals the right to contest AI-driven decisions.
- Stronger ICO Enforcement Powers:
The maximum fines under the Privacy and Electronic Communications Regulations (PECR) have increased from £500,000 to £17.5 million (or 4% of global turnover), signalling stricter scrutiny, particularly around direct marketing and spam.
- International Data Transfers
The legal threshold for transfers outside the UK has shifted from “essentially equivalent” to “not materially lower” protection, a subtle but business- friendly change.
- Children’s Privacy
A reinforced duty applies to online services accessed by children, complementing the existing Age-Appropriate Design Code.
- Complaints Handling
New procedural requirements oblige organisations to acknowledge complaints within 30 days and resolve them without undue delay.
Practical Steps for Businesses
While the DUAA introduces some welcome simplifications, the enhanced enforcement landscape, particularly for PECR breaches, means that businesses cannot afford complacency.
Recommended Actions to Include
- Review marketing practices, including cookie banners and direct marketing consent.
- Updating privacy notice to reflect new ADM provisions and complaints procedures.
- Reviewing mechanisms for international data transfers.
- Assessing risk in services accessed by children and updating safeguards accordingly.
Some provisions of the DUAA have already come into effect, while others will be implemented via secondary legislation over the next year. Businesses should therefore monitor forthcoming guidance from the ICO to ensure continued compliance.
Conclusion
The DUAA reflects the UK’s ongoing effort to balance innovation with strong data protection standards. As the regulatory landscape evolves, organisations will need to adapt their data governance framework accordingly. The Act provides an opportunity to augment and streamline compliance policies and procedures as well as to re-evaluate how data is used to drive value. However, it also demands a proactive approach to governance, particularly in light of the enhanced enforcement powers granted to the ICO.
Now is accordingly the time for organisations to align their data strategies with the new legal framework. In practice, this entails engaging with legal and compliance teams to ensure that data-driven initiatives are accountable. As further guidance emerges and secondary legislation fills in the details, staying up-to-date will be crucial to turning compliance into competitive advantage.
Please contact Jose Saras and Xavier Prida for detailed advice on the above.
The material contained in this article is only for general review of the topics covered and does not constitute any legal advice. No legal or business decision should be based on its content.
This article is written in English language. Preiskel & Co LLP is not responsible for any translation of all or part of its content into any language.