A new era for UK data protection
The UK’s Data Use and Access Act 2025 (DUAA) marks one of the most significant shifts in the UK data protection landscape since the post‑Brexit adoption of the UK GDPR.
With key provisions now in force from 5 February 2026 and further changes due in June, organisations can no longer rely on pre‑DUAA frameworks or assumptions.
The increasing use of AI tools and these reforms require immediate, practical updates across internal documentation, including privacy notices, lawful‑basis assessments, DSAR workflows, DPIAs, governance records, training materials, international transfer tools and research‑related protocols.
Whether you operate in the UK alone or across EU/UK boundaries, the DUAA demands a top‑to‑bottom review of your data protection posture to ensure policies remain aligned, defensible and audit‑ready in a newly diverging regulatory environment.
For our earlier analysis and background on how the DUAA has evolved, including its strategic aims, read more here and here.
Key developments now in force
The DUAA aims to clarify and modernise research processing, providing organisations conducting scientific and statistical research with a more workable footing while strengthening safeguards and governance expectations.
Those operating in academic, health and AI‑driven contexts should accordingly revisit their internal frameworks and documentation to ensure alignment with the revised approach.
For an overview of the policy direction and the anticipated practical benefits identified when the DUAA was first introduced, see What the Data Use and Access Bill Means for UK Organisations. Read more.
Updates to lawful bases and purpose limitation
Updates to lawful bases and purpose limitation also aim to provide clearer criteria for processing in the public interest and for compatible secondary uses. These adjustments are expected to reduce unnecessary friction in complex operational settings and help organisations make more confident decisions about further processing.
Data Subject Requests
Rights management has also been recalibrated, with adjustments intended to modernise how organisations receive, prioritise, and respond to individual rights requests.
Timelines, communication standards and fee rules have similarly been refined to balance transparency for individuals with practical implementation for controllers. Organisations should therefore refresh procedures, templates and internal guidance for handling requests, especially subject access requests, and ensure that records of decision‑making remain robust.
Automated Decision‑Making
The framework for automated decision‑making has been overhauled to reflect contemporary technologies including artificial intelligence. While operational flexibility increases, the expectation of meaningful safeguards remains, including appropriate human involvement and documented assessments.
Children
Children’s data protection is given explicit prominence, recognising the heightened risks associated with younger users and the need for services to anticipate how children interact with digital environments. Providers of online services that are likely to be accessed by children should be embedding children’s interests into product and service design, and reviewing user journeys, default settings and privacy information accordingly.
International Data Transfers
International data transfers are being reshaped through a more streamlined, UK‑specific test intended to preserve high protection standards while simplifying compliance. These developments build on the trajectory we have tracked since Royal Assent and our earlier overview of how cookies, ADM, enforcement and transfers would change under the DUAA. Read our coverage.
Significant new ICO enforcement powers
Regulatory oversight will strengthen as the Information Commissioner’s Office gains additional investigative and enforcement tools. Organisations should therefore expect a more proactive supervisory posture and a continued emphasis on demonstrable accountability across records, Data Protection Impact Assessments and governance.
Charities
A practical change for charities has also taken effect, extending the soft opt‑in for email marketing where the individual has previously shown interest in the charity’s purposes or offered support, provided clear opt‑outs are available at collection and in each message.
Charities will need to review how they capture supporter engagement and ensure that consent pathways and therefore preference management systems reflect the updated regulatory position.
They should also revisit their marketing segmentation practices to confirm that any reliance on the soft opt-in remains appropriate and properly documented.
Impact on UK and EU organisations
For UK organisations, the reforms collectively provide additional flexibility, clearer processing criteria and firmer expectations regarding accountability, system design and oversight. Many will need to update privacy notices, training and operational records and should consider whether the new framework enables more efficient approaches to research, automated tools and international data transfers.
For EU‑based organisations processing UK personal data the changes signify measured divergence from the EU GDPR. Although the high‑level principles remain aligned, the operational rules around automated decision‑making, research, international transfers and lawful bases are beginning to differ. This may require separate UK‑specific compliance measures and careful monitoring of EU–UK adequacy reviews. We previously discussed adequacy timelines when the European Commission moved to extend the UK’s adequacy decisions to allow for reassessment in light of the evolving regulation. Read our adequacy update.
Conclusion
While the DUAA aims to create a more agile and innovation supportive regulatory environment, it also introduces certain structural uncertainties that organisations should monitor closely. The UK’s deliberate post Brexit divergence from the EU GDPR may improve domestic flexibility but could increase long term compliance fragmentation, particularly for multinational organisations. The cumulative effect is a regulatory environment that is simultaneously more permissive and more complex, predominantly for those operating across multiple jurisdictions.
Organisations should therefore treat the implementation period not merely as an administrative update but as an inflection point requiring close attention to the future of UK EU adequacy.
The European Commission’s adequacy decision remains in place for now, but continued divergence will inevitably form part of future reviews, and organisations should be prepared for the possibility of additional transfer assessments or safeguards if the UK’s trajectory is viewed as materially departing from EU standards. Forward planning and clear documentation of data transfer decisions will help mitigate any disruption should UK adequacy come under renewed scrutiny.
Please contact Jose Saras and Xavier Prida for detailed advice on the above.
The material contained in this article is only for general review of the topics covered and does not constitute any legal advice. No legal or business decision should be based on its content.
This article is written in the English language. Preiskel & Co LLP is not responsible for any translation of all or part of its content into any language.