The UK’s Data (Use and Access) Act 2025 (DUAA) has now received Royal Assent, bringing with it the most substantial updates to domestic data protection law since the UK GDPR was introduced. The legislation is designed to modernise how organisations use personal information, supporting innovation and economic growth while maintaining strong protections for individual rights.
The Act introduces wide-ranging reforms across key areas, including lawful bases for data processing, scientific research, cookie consent, automated decision-making, and complaint handling. It also strengthens the powers of the Information Commissioner’s Office (ICO) to ensure more effective oversight and enforcement.
To support organisations and the wider public in adapting to the changes, the ICO has published a series of guidance materials. This includes a practical overview aimed at organisations, a detailed technical breakdown for data protection professionals, and other resources for law enforcement and individuals. Separate guidance will follow over time, as implementation is phased in.
Key Changes Introduced by the DUAA
The DUAA amends the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR). Among its most impactful changes:
-
Research and innovation: The Act clarifies when personal information can be used for scientific research, including commercial research, and confirms that individuals can provide ‘broad consent’ to entire areas of study. Organisations can also reuse data for research without issuing individual privacy notices, so long as the effort required would be disproportionate and other safeguards are in place.
-
Automated decision-making: The Act removes previous limitations on relying solely on a person’s consent or contract to make significant automated decisions. Organisations may now use any lawful basis, including legitimate interests (with safeguards), to support such processing—though special category data remains restricted.
-
Cookies: New exemptions allow certain types of cookies to be set without user consent, including those used for statistical analysis and to improve website functionality.
-
Recognised legitimate interests: A new lawful basis lets organisations use personal data for certain pre-approved purposes—like public security—without the need to weigh those interests against individual rights.
-
Charity marketing: Charities are now permitted to send email marketing without consent to individuals who’ve supported or shown interest in their work, unless those individuals opt out—similar to the ‘soft opt-in’ rule already used by commercial organisations.
-
Data sharing: The Act shifts responsibility for deciding if personal information is needed for a public task to the requesting body, such as the police—freeing up the disclosing organisation from making this judgement.
-
Subject Access Requests: The legislation clarifies that organisations are only required to carry out “reasonable and proportionate” searches when responding to data access requests.
-
Clarity and structure: Without changing the core principles of data protection, the Act restructures parts of the legislation to improve readability. It confirms, for instance, that direct marketing can be a legitimate interest, and refines how organisations approach international data transfers.
New Obligations for Organisations
The DUAA introduces several specific responsibilities that organisations must now meet:
-
Children’s data: Providers of online services likely to be used by children must explicitly factor children’s needs into their data use. The ICO notes that those already conforming to the Age Appropriate Design Code should be well-placed to meet this requirement.
-
Complaints handling: Organisations must now provide mechanisms to help individuals submit complaints about how their data is used. This includes offering electronic complaints forms, acknowledging complaints within 30 days, and responding “without undue delay”.
To prepare, organisations are advised to:
-
Familiarise themselves with the legislative changes.
-
Assess whether their existing practices for children’s data and complaints meet the new requirements.
-
Re-evaluate how they might benefit from the more innovation-friendly provisions, including those related to automation, research, and cookies.
-
Subscribe to ICO newsletters for updates on new and evolving guidance.
Technical Summary for Data Protection Professionals
In addition to general guidance, the ICO has issued a detailed breakdown of the DUAA’s impact for those with data protection responsibilities—such as Data Protection Officers and compliance leads.
This expert-focused summary walks through each relevant section of the legislation and outlines substantive changes. These include:
-
Removal of balancing tests for recognised legitimate interests.
-
Clarification that certain data re-uses—such as for archiving in the public interest—are automatically compatible with their original purpose.
-
Updates to the lawful bases available for automated decision-making.
-
Refined language around international transfers, without altering the underlying legal standard.
The summary also flags where the DUAA alters law enforcement data rules under Part 3 of the DPA or intelligence services rules under Part 4—though most changes are relevant to general data use by businesses, public bodies, and charities.
It does not replace existing ICO guidance, which will be updated over time, but offers an interim technical reference for compliance planning.
New Powers and Duties for the ICO
The Act enhances the ICO’s investigatory and enforcement capabilities. New powers include the ability to:
-
Compel witnesses to attend interviews.
-
Require organisations to produce technical reports.
-
Issue fines under PECR of up to £17.5 million or 4% of global turnover.
The legislation also reforms the ICO’s structure and introduces new transparency and accountability requirements, aimed at modernising how the regulator operates.
Recommended reading
- Glasgow and Edinburgh Councils Face ICO Reprimand
- ICO Apologises Over Data Protection Response Times
- ICO Publishes New AI and Biometric Tech Strategy
Information Commissioner John Edwards said the changes would allow the ICO to “continue to operate as a trusted, fair and independent regulator,” and to better “balance innovation and economic growth with strong protections for people’s rights.”
Most of the DUAA’s provisions will come into force within two to six months from Royal Assent, though a few may take up to a year. The government will use secondary legislation to manage this phased rollout.
In the meantime, organisations are encouraged to:
-
Consult the ICO’s newly published guidance tailored to their role.
-
Identify which provisions require immediate changes to policy or practice.
-
Begin reviewing opportunities to simplify operations or enhance services under the new legal framework.





