12/09/2025

The Data (Use and Access) Act 2025 (DUA Act) is a large and complex piece of law, containing 144 sections and 16 Schedules.

It amends, rather than replaces, UK GDPR and the Data Protection Act 2018, meaning businesses need to prepare for adjustments, not a wholesale rewrite of compliance.


The DUAA doesn’t replace GDPR or the Data Protection Act 2018, but it does add new rules and raise the stakes for compliance. Here are the essentials for small businesses:

  1. Cookies and website tracking
    Some lower-risk cookies (like basic analytics or site optimisation) may be allowed without consent, but you’ll still need to review your cookie banner to provide clear opt-outs.
  2. Complaints process
    From June 2026, every business must provide a way for customers to complain about data use. You’ll need to acknowledge within 30 days and respond without undue delay, so think about adding a form or contact option on your website and keeping a log of complaints.
  3. Children’s services
    If children could use your products or services, you’ll need to show “data protection by design”, stronger protections in how you collect and use their data. Remembering to tailor privacy notices to children.
  4. Marketing and legitimate interests
    The Act confirms that direct marketing can be a legitimate interest, and charities can rely on the soft opt-in, but PECR rules still apply, so consents and opt-outs must be watertight.
  5. Automated decisions and AI
    Restrictions are loosened slightly for automated decisions that don’t use sensitive data, but safeguards (the right to know, challenge, and get human review) remain in place. The Secretary of State is expected to provide more guidance on AI in due course following the parliamentary debates on this.
  6. Bigger fines for PECR breaches
    The ICO can now issue UK GDPR-level fines (up to £17.5m or 4% of turnover whichever is the highest) for marketing and cookie law breaches, so email lists, unsubscribes, and banners all need to be compliant.

What’s Next?

Much of the detail will come through secondary legislation and ICO guidance over the next 12–24 months. Businesses should keep an eye on:

  • The Secretary of State’s consultations on AI and transparency
  • ICO guidance on cookies, complaints, and automated decision-making
  • The next EU adequacy decision (expected late 2025), which will assess whether UK law remains aligned enough with EU GDPR to allow free data flows. The EU has published a draft decision confirming that UK data protection remains essentially equivalent to EU standards, with a proposal to extend the current adequacy arrangements beyond their 27 December 2025 expiry for a further six years.

What to Do Now, 3 Practical Steps

  1. Review your website, update cookie banners and privacy notices to prepare for the new DUAA rules
  2. Plan a complaints process, set up a simple log, draft an acknowledgement template, and ensure you can meet the 30-day acknowledgement rule
  3. Audit marketing practices, check consents, unsubscribe links, and soft opt-in use, especially if you are a charity or use direct marketing heavily

Leave a comment

  • With Great Power Comes Great Responsibility:

    Why AI Makes Data Protection More Important Than Ever 26/08/2026 I have always been fascinated by emerging technology. Part of working in data protection is trying to keep ahead of the game: understanding not only what technology can do now, but what it might be capable of next, and what that means for the people…

  • Cyber security is a data protection issue: lessons from the ICO’s ACRO reprimand

    14/08/2026 The Information Commissioner’s Office (ICO) has reprimanded ACRO Criminal Records Office following cyber security failings which potentially exposed the personal information of up to 10,920 people. The case is a useful reminder for organisations that cyber security is not simply an IT issue. It is a fundamental part of data protection compliance, accountability and…

  • Council officer convicted for unlawfully accessing personal data

    24/07/2026 The Information Commissioner’s Office (ICO) has recently highlighted an important reminder for all organisations that handle personal information: having access to a system does not mean you are entitled to access every record within it. A former Herefordshire Council employee has received a suspended prison sentence after unlawfully accessing approximately 490 personal records and…

  • Why Smart Companies Keep Getting Data Protection Wrong

    12/07/2026 The biggest data protection risk? It’s certainty. The organisations most likely to get into difficulty with data protection are rarely the ones asking difficult questions. They’re the ones convinced they’re already compliant. Whether it’s a multinational or a start-up, the mistakes are remarkably similar: Collecting data because they can, not because they need to.…