12/09/2025

The Data (Use and Access) Act 2025 (DUA Act) is a large and complex piece of law, containing 144 sections and 16 Schedules.

It amends, rather than replaces, UK GDPR and the Data Protection Act 2018, meaning businesses need to prepare for adjustments, not a wholesale rewrite of compliance.


The DUAA doesn’t replace GDPR or the Data Protection Act 2018, but it does add new rules and raise the stakes for compliance. Here are the essentials for small businesses:

  1. Cookies and website tracking
    Some lower-risk cookies (like basic analytics or site optimisation) may be allowed without consent, but you’ll still need to review your cookie banner to provide clear opt-outs.
  2. Complaints process
    From June 2026, every business must provide a way for customers to complain about data use. You’ll need to acknowledge within 30 days and respond without undue delay, so think about adding a form or contact option on your website and keeping a log of complaints.
  3. Children’s services
    If children could use your products or services, you’ll need to show “data protection by design”, stronger protections in how you collect and use their data. Remembering to tailor privacy notices to children.
  4. Marketing and legitimate interests
    The Act confirms that direct marketing can be a legitimate interest, and charities can rely on the soft opt-in, but PECR rules still apply, so consents and opt-outs must be watertight.
  5. Automated decisions and AI
    Restrictions are loosened slightly for automated decisions that don’t use sensitive data, but safeguards (the right to know, challenge, and get human review) remain in place. The Secretary of State is expected to provide more guidance on AI in due course following the parliamentary debates on this.
  6. Bigger fines for PECR breaches
    The ICO can now issue UK GDPR-level fines (up to £17.5m or 4% of turnover whichever is the highest) for marketing and cookie law breaches, so email lists, unsubscribes, and banners all need to be compliant.

What’s Next?

Much of the detail will come through secondary legislation and ICO guidance over the next 12–24 months. Businesses should keep an eye on:

  • The Secretary of State’s consultations on AI and transparency
  • ICO guidance on cookies, complaints, and automated decision-making
  • The next EU adequacy decision (expected late 2025), which will assess whether UK law remains aligned enough with EU GDPR to allow free data flows. The EU has published a draft decision confirming that UK data protection remains essentially equivalent to EU standards, with a proposal to extend the current adequacy arrangements beyond their 27 December 2025 expiry for a further six years.

What to Do Now, 3 Practical Steps

  1. Review your website, update cookie banners and privacy notices to prepare for the new DUAA rules
  2. Plan a complaints process, set up a simple log, draft an acknowledgement template, and ensure you can meet the 30-day acknowledgement rule
  3. Audit marketing practices, check consents, unsubscribe links, and soft opt-in use, especially if you are a charity or use direct marketing heavily

Leave a comment

  • The New Data Protection Complaints Process

    How are you implementing the new data protection complaints process?

  • Big Cyber Stories, Everyday Habits

    Every week, the headlines are full of major cyber incidents: ransomware attacks, data leaks, and system outages that cost millions, and that also bring significant risks to the individuals whose data is compromised. But behind many of those headlines often lie the same small mistakes that happen in every organisation, every day. It’s not always…

  • Welcome to Paradise! Please Upload Your Passport…

    QR codes, passport uploads, and missing privacy notices. Turns out I can escape the British weather, but not data protection.

  • Phishing is evolving

    15/10/2025 I managed to catch some of the ICO’s Annual Conference this week, and one of the most striking takeaways was how phishing attacks have evolved. People who once felt confident spotting a scam are now more likely to click, and they do! Apparently, the numbers of employees clicking on the links or download buttons…