12/09/2025

The Data (Use and Access) Act 2025 (DUA Act) is a large and complex piece of law, containing 144 sections and 16 Schedules.

It amends, rather than replaces, UK GDPR and the Data Protection Act 2018, meaning businesses need to prepare for adjustments, not a wholesale rewrite of compliance.


The DUAA doesn’t replace GDPR or the Data Protection Act 2018, but it does add new rules and raise the stakes for compliance. Here are the essentials for small businesses:

  1. Cookies and website tracking
    Some lower-risk cookies (like basic analytics or site optimisation) may be allowed without consent, but you’ll still need to review your cookie banner to provide clear opt-outs.
  2. Complaints process
    From June 2026, every business must provide a way for customers to complain about data use. You’ll need to acknowledge within 30 days and respond without undue delay, so think about adding a form or contact option on your website and keeping a log of complaints.
  3. Children’s services
    If children could use your products or services, you’ll need to show “data protection by design”, stronger protections in how you collect and use their data. Remembering to tailor privacy notices to children.
  4. Marketing and legitimate interests
    The Act confirms that direct marketing can be a legitimate interest, and charities can rely on the soft opt-in, but PECR rules still apply, so consents and opt-outs must be watertight.
  5. Automated decisions and AI
    Restrictions are loosened slightly for automated decisions that don’t use sensitive data, but safeguards (the right to know, challenge, and get human review) remain in place. The Secretary of State is expected to provide more guidance on AI in due course following the parliamentary debates on this.
  6. Bigger fines for PECR breaches
    The ICO can now issue UK GDPR-level fines (up to £17.5m or 4% of turnover whichever is the highest) for marketing and cookie law breaches, so email lists, unsubscribes, and banners all need to be compliant.

What’s Next?

Much of the detail will come through secondary legislation and ICO guidance over the next 12–24 months. Businesses should keep an eye on:

  • The Secretary of State’s consultations on AI and transparency
  • ICO guidance on cookies, complaints, and automated decision-making
  • The next EU adequacy decision (expected late 2025), which will assess whether UK law remains aligned enough with EU GDPR to allow free data flows. The EU has published a draft decision confirming that UK data protection remains essentially equivalent to EU standards, with a proposal to extend the current adequacy arrangements beyond their 27 December 2025 expiry for a further six years.

What to Do Now, 3 Practical Steps

  1. Review your website, update cookie banners and privacy notices to prepare for the new DUAA rules
  2. Plan a complaints process, set up a simple log, draft an acknowledgement template, and ensure you can meet the 30-day acknowledgement rule
  3. Audit marketing practices, check consents, unsubscribe links, and soft opt-in use, especially if you are a charity or use direct marketing heavily

Leave a comment

  • 19 June 2026: Is Your Data Protection Complaints Procedure Ready?

    Need a Data Protection Complaints Procedure in place before 19 June 2026? The deadline under the Data (Use and Access) Act 2025 is approaching fast, and many organisations still do not have a compliant process published. Email dpo@jhdataprotection.com to find out more about reviewing or implementing your data protection complaints procedure.

  • When curiosity becomes misconduct: lessons from the Nottingham NHS records scandal

    Data protection can often be dismissed as bureaucracy, policies and “tick-box exercises”. This week’s Nottingham NHS records scandal is a stark reminder that it is something far more important than that. When staff access sensitive personal data without lawful reason, the consequences are not merely regulatory, they are deeply human. Trust, dignity and confidentiality sit…

  • ARE YOU AI READY?

    AI is already regulated. Organisations just haven’t caught up 3 May 2026 There is still a perception that artificial intelligence sits ahead of regulation. From a UK GDPR perspective, it doesn’t. The legal framework is already in place. The issue for most organisations is not a lack of regulation, it is a lack of structured…

  • When data protection doesn’t protect you.

    17/04/2026 Recently, the Information Commissioner’s Office published the outcome of a criminal prosecution. The title? Just two names:Christopher Munro and William Chipoma. No explanation. No softening. No anonymity. And that, in itself, is a powerful lesson in how data protection law really works. Data protection isn’t about secrecy There’s a persistent myth that data protection…