Back to Blog

Artificial Intelligence

What the Data Use and Access Bill Means for UK Organisations

On 23 October 2024, the Data Use and Access (DUA) Bill was introduced into the House of Lords. It proposes pragmatic updates to key UK data protection regulations, specifically the UK GDPR, Data Protection Act (DPA) 2018, and Privacy and Electronic Communications Regulations (PECR). Aimed at easing the compliance load on businesses and the public sector, the changes have been positively received by the Information Commissioner, who sees them as balanced and unlikely to impact the UK’s adequacy status with the EU.

Simplifying compliance for organisations

The DUA Bill introduces several modifications to make data protection compliance more straightforward. Among the most notable changes:

  • Further processing guidance: The Bill offers clearer guidelines on further processing of personal data, removing uncertainties that organisations previously faced.
  • New legitimate interests: A new “recognised legitimate interest” provision will allow certain data processing activities without the need for consent, easing operations for businesses and research entities alike.
  • Scientific research: The DUA Bill aims to streamline the use of personal data for scientific research, reducing administrative hurdles. Researchers will face fewer requirements for re-obtaining consent when reusing data for compatible research purposes. The Bill also introduces clearer guidance around lawful processing, enabling easier access to datasets.

While the DUA Bill touches lightly on artificial intelligence (AI), it does not include detailed AI regulations, though the King’s Speech referenced upcoming legislation for high-powered AI models. Similarly, there’s no significant change to cybersecurity rules in the Bill itself, but the speech alluded to an upcoming Cyber Security and Resilience Bill to address this gap.

The DUA Bill proposes significant changes to the enforcement of the PECR, bringing penalty levels in line with the DPA. This means fines for breaches could increase dramatically, reaching up to £17.5 million or 4% of an organisation’s annual global turnover, whichever is higher. These enhanced penalties are expected to encourage stricter compliance with electronic marketing rules, such as those governing unsolicited emails, calls, and cookies.

The ICO has long advocated for these changes, as they will provide stronger deterrents against data misuse and bolster consumer privacy protections. The alignment of PECR fines with GDPR-level penalties reflects a tougher stance on privacy breaches in digital communications, aiming to significantly reduce intrusive marketing practices.

What this means for UK organisations

For UK businesses and public sector entities, the DUA Bill presents an opportunity to benefit from simpler compliance requirements. The new guidance on processing and the legitimate interests provision will be especially advantageous for organisations involved in research, innovation, and data-driven business models. The alignment of PECR penalties with the DPA 2018 signals a stronger regulatory stance on privacy breaches, underscoring the importance of robust compliance.

Companies will also need to ensure that their procedures for obtaining consent for electronic communications, such as marketing emails and texts, are fully compliant. The changes also signal a greater regulatory focus on consumer privacy, pushing organisations to adopt a more proactive approach in safeguarding personal data. For companies that already prioritise data protection, this shift may offer a competitive edge, as they can use their compliance track record to build trust with customers and differentiate themselves in the market.

Current status and legislative cycle

The DUA Bill is progressing through the UK parliamentary stages, with further scrutiny and potential amendments expected as it moves through both the House of Commons and the House of Lords. Having been introduced as part of the King’s Speech, it reflects a key legislative priority for the government. Organisations should accordingly monitor the DUA Bill’s development closely, as additional changes or clarifications may emerge before it is enacted into law. Final passage of the Bill would signal the start of a transition period, allowing organisations time to adapt to the updated compliance requirements.

Please contact Jose Saras and Xavier Prida for detailed advice on how your organisation can prepare to comply with these regulations.

The material in this article is only for general review of the topics covered and does not constitute legal advice. No legal or business decision should be based on its content.

This article is written in English language. Preiskel & Co LLP is not responsible for any translation of all or part of its content into any language.

A practical way forward

Tell us about the matter.

Speak to us