The UK's data protection reform is no longer a bill working its way through Parliament. It is a law. The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on June 19, 2025, and most of its substantive provisions are now in force, with the last major pieces due to land by mid-2026.
If your organization has been tracking this reform through headlines about "the Data (Use and Access) Bill" or an even older "Data Protection and Digital Information Bill," this guide brings you current. It covers what the Act actually is, exactly which provisions are in force and when, what changed from UK GDPR and the Data Protection Act 2018, and what your compliance team needs to check off before the next enforcement cycle.
What Is the Data (Use and Access) Act 2025?
The Data (Use and Access) Act 2025, officially cited as 2025 c. 18, is the primary legislation that reforms UK data protection law, the UK's e-privacy rules under PECR (the Privacy and Electronic Communications Regulations), and several adjacent areas including smart data schemes and digital identity verification services. You can read the full statutory text at legislation.gov.uk.
The Act was introduced to Parliament on October 23, 2024, as the "Data (Use and Access) Bill." It passed through the House of Lords and then the House of Commons, and received Royal Assent on June 19, 2025. It amends the UK GDPR and the Data Protection Act 2018 rather than replacing them outright. If your organization is already UK GDPR compliant, the DUAA is a set of targeted amendments layered on that existing framework, not a wholesale rewrite.
Unlike its more sweeping predecessor, the DPDI Bill (covered below), the DUAA retains the core structure of UK GDPR. The government set aside several of the DPDI Bill's more ambitious proposals, largely to protect the UK's data adequacy relationship with the European Union.
Current Status: In Force, Rolling Out in Stages
This is the part earlier coverage of this reform got wrong: the DUAA is not "progressing through Parliament." It is enacted, and its provisions are commencing in a series of statutory stages rather than all at once. As of this writing, most of the substantive changes that affect day-to-day compliance are already active.
Stage 1, August 20, 2025: Smart Data provisions (Part 1), an amendment aligning PECR's personal data breach notification requirements with UK GDPR, and new statutory objectives for the then-still-named Information Commissioner's Office.
Stage 2, roughly three to four months after Royal Assent: Most of the digital verification services framework (Part 2), plus provisions on retaining information held by internet service providers connected to the death of a child (Part 7).
Stage 3, February 5, 2026: The bulk of Part 5, covering the core data protection and e-privacy reforms. This is the stage that matters most for compliance teams. It brought into force recognised legitimate interests, the reformed automated decision-making rules, the new international transfer standard, the "reasonable and proportionate search" standard for subject access requests, and the four new PECR cookie-consent exemption categories.
June 19, 2026 (one year after Royal Assent): The new statutory right for individuals to complain directly to organizations before escalating to the regulator.
Stage 4, still pending as of mid-2026: Provisions needing a longer lead-in, most notably the formal abolition of the Information Commissioner's office and the transfer of its functions to the new Information Commission board.
If your organization last reviewed its DUAA compliance position before February 2026, treat that review as out of date. The provisions that reshape your legal bases, automated decision-making processes, DSAR handling, and cookie consent all went live on or around February 5, 2026.
From the DPDI Bill to the DUAA: What Actually Happened
UK data protection reform did not arrive in one attempt. Two earlier bills came before the DUAA, and both died.
The first, the Data Protection and Digital Information Bill (introduced as "Bill 143" in July 2022, following a 2021 government consultation called "Data: A New Direction"), proposed a substantially more ambitious overhaul. It included a detailed legitimate-interests list, a plan to replace Data Protection Impact Assessments with a lighter "Assessment of High Risk Processing," a plan to replace Records of Processing Activities with simplified "appropriate records," a proposal to swap the Data Protection Officer role for a "senior responsible individual," and a restructuring of the ICO into a board-led Information Commission. Its Second Reading was postponed following a change in prime minister in 2022, and it was never rescheduled.
A revised "No. 2 Bill" followed in March 2023, with similar goals: reduced administrative burden, more flexible international transfers, and a new legitimate-interests basis. It reached the report stage in the Commons by late 2023 and was expected to pass in 2024. It did not. Both versions of the DPDI Bill expired when Parliament was dissolved for the 2024 general election.
The DUA Bill that eventually became the DUAA was introduced fresh in October 2024, not revived from the DPDI Bill's text. It is a narrower, more measured piece of legislation than the DPDI Bill was. Some DPDI Bill concepts survived into the DUAA in modified form. Others did not.
Carried forward, in updated form:
- A legitimate-interests list survived, but narrower. The DPDI Bill's list had seven categories, including broad ones like "democratic engagement" and general "processing necessary to the public interest." The DUAA's recognised legitimate interests basis has five: crime prevention and detection, safeguarding vulnerable individuals, national security, responding to emergencies, and public security and defense-related purposes.
- The DPDI Bill's plan to let controllers refuse "vexatious or excessive" DSARs evolved into the DUAA's "reasonable and proportionate search" standard, plus a right for controllers to ask requesters for clarification when an identification is difficult.
- The DPDI Bill's ICO governance overhaul (board and chief executive replacing a single Commissioner) survived largely intact as the DUAA's Information Commission, though full implementation is still pending.
- The DPDI Bill's PECR fine increase to UK GDPR levels (up to £17.5 million or 4% of global turnover) was enacted essentially unchanged.
Did not survive into current DUAA guidance:
- The DPIA-to-AHRP replacement. Data Protection Impact Assessments remain part of the UK GDPR framework; the lighter "Assessment of High Risk Processing" concept from the DPDI Bill does not appear in current DUAA coverage.
- The ROPA-to-"appropriate records" replacement. Records of Processing Activities obligations under UK GDPR Article 30 were not simplified in the way the DPDI Bill proposed.
- The DPO-to-"senior responsible individual" swap. The Data Protection Officer role remains the standard under the enacted law.
If your organization made compliance decisions based on the DPDI Bill's specific proposals (an AHRP process instead of DPIAs, for example, or a senior responsible individual instead of a DPO), those decisions should be revisited. The law that actually passed does not include them.
What Actually Changed: The Substantive Reforms
Recognised legitimate interests
The DUAA adds a new lawful basis to Article 6 of UK GDPR: recognised legitimate interests. For five specified public-interest purposes (crime prevention and detection, safeguarding vulnerable individuals, national security, emergency response, and public security and defense), organizations no longer need to run the usual legitimate-interests balancing test weighing their interests against the data subject's rights. This basis is narrow by design. It is not a general shortcut around consent or standard legitimate interests for routine commercial processing. The Information Commissioner's Office (now, functionally, still operating as the ICO pending the full Information Commission transition) published guidance on this basis on March 23, 2026.
Automated decision-making
This is one of the more significant departures from the old rules, and one where earlier coverage of the reform oversimplified what changed. Before the DUAA, UK GDPR Article 22 generally prohibited solely automated decisions with legal or similarly significant effects, subject to narrow exceptions. Section 80 of the DUAA, in force since February 5, 2026, replaces that default prohibition for decisions based on ordinary personal data. Solely automated decisions are now permitted by default for non-special-category data, provided organizations put safeguards in place: giving the individual information about the decision, enabling them to make representations, allowing them to request human intervention, and letting them contest the outcome.
Decisions based on special category data (health information, for example, or data revealing political opinions or religious beliefs) are treated differently. There, the stricter prior regime is preserved: solely automated decisions remain prohibited unless the individual gives explicit consent or the processing is necessary for a contract or is justified by substantial public interest grounds alongside appropriate safeguards.
If your organization uses any automated scoring, eligibility screening, or algorithmic triage process on UK personal data, this reform changes your starting legal position. Review which of your automated processes touch special category data and which do not, since the applicable rules now diverge sharply between the two.
Subject access requests and the new complaints procedure
Two related changes affect how individuals exercise their rights and raise concerns.
First, the DUAA codifies a "reasonable and proportionate search" standard for DSARs. Controllers are only required to search for personal data using efforts that are reasonable and proportionate to the request, and can ask a requester for clarification where identifying the relevant data would otherwise be difficult. This formalizes ICO guidance that already existed informally, giving organizations firmer legal ground.
Second, and separately, a new statutory right to complain came into force on June 19, 2026. Organizations acting as data controllers must now give individuals a mechanism for submitting data protection complaints, acknowledge each complaint within 30 days, investigate without undue delay, and inform the complainant of the outcome. Individuals are generally expected to raise a complaint with the organization first before escalating to the ICO. If your complaints inbox has been treated as a customer-service function, it now needs to operate as a documented, timed regulatory process.
International data transfers
The DUAA replaces the "essentially equivalent" standard for assessing third-country data protection with a "not materially lower" standard. This applies both when the UK government assesses a country for adequacy purposes and when your organization assesses transfer risk using safeguards like standard contractual clauses. "Not materially lower" is a looser test than "essentially equivalent." It permits more variation between a destination country's protections and the UK's own, as long as the gap is not material, with particular attention to whether a transfer is likely to cause real harm to the people whose data is involved. This does not remove the need for a transfer risk assessment. It changes the bar that assessment needs to clear.
Smart Data schemes and digital verification services
Two lower-profile parts of the Act matter mainly to specific sectors. Part 1 establishes a legal framework for "Smart Data" schemes, allowing customers to securely share their data with authorized third-party providers, an open-banking-style model extended to other sectors. Part 2 creates a formal trust framework and registration system for digital identity verification services. Both commenced earlier in the rollout (Stage 1 and Stage 2, respectively) and are most relevant if your organization operates in financial services, identity verification, or data-sharing platforms.
Cookie Consent and PECR: What Changed
The DUAA also amends PECR, the UK's e-privacy rules governing cookies and similar tracking technologies. In brief: as of February 5, 2026, four categories of cookies (analytics, functionality, security, and software update) can qualify for an exemption from the prior-consent requirement, each subject to strict conditions. Advertising, targeting, and cross-site tracking cookies are unaffected and still require prior consent. PECR fines rose to match UK GDPR's ceiling of £17.5 million or 4% of global turnover, whichever is greater.
That is intentionally the short version. The analytics exemption in particular has narrow conditions that most standard analytics tools, including default GA4 implementations, do not meet, and getting this wrong carries real fine exposure. For the full breakdown, including which cookie categories qualify, what the analytics exemption actually requires, and a UK-versus-EU comparison for organizations running combined consent flows, see the companion guide: UK Data (Use and Access) Act 2025: PECR Cookie Consent Changes and How to Comply.
ICO Becomes the Information Commission
The Act restructures the UK's data protection regulator from a "corporation sole," where authority sits with a single Information Commissioner, to a body corporate called the Information Commission, governed by a Chair, a Chief Executive, and up to seven non-executive directors. This mirrors the governance model used by regulators like the Financial Conduct Authority and the Competition and Markets Authority.
Some elements of this change are already active: the regulator's new statutory objectives came into force in Stage 1, in August 2025. The full transition, including the formal abolition of the Information Commissioner's office and the transfer of its powers to the new Information Commission board, was still pending as of mid-2026 and falls under the Act's later commencement stage. Until that transition completes, expect to see references to both "the ICO" and "the Information Commission" in official guidance.
Enforcement and Fines
The DUAA does not raise the maximum fine for UK GDPR violations, which remains £17.5 million or 4% of global annual turnover, whichever is greater. What it does is bring PECR violations, including cookie consent failures and unlawful direct marketing, up to that same ceiling. Before the DUAA, PECR fines were capped at £500,000. That cap is gone. If your organization's cookie compliance risk assessment still references the old £500,000 figure, it understates your actual exposure by a wide margin.
The new pre-complaint requirement also changes the practical enforcement pathway: individuals must raise concerns with your organization first, then escalate to the regulator only if unresolved. Expect complaint volumes reaching you directly to rise.
Compliance Checklist
Use this as a starting point, not a substitute for legal advice specific to your organization.
- Confirm your organization understands that the DUAA is in force, not pending, and update any internal documentation, training materials, or client-facing guidance that still describes it as a bill.
- Review whether any of your processing activities could rely on recognised legitimate interests, and confirm you meet the narrow conditions before skipping the standard balancing test.
- Map your automated decision-making processes. Separate those touching special category data (still subject to the stricter prior regime) from those that do not (now subject to the safeguards-based approach).
- Update your DSAR process to reflect the "reasonable and proportionate search" standard, and build in a clarification-request step for ambiguous requests.
- Stand up a formal data protection complaints procedure: a submission channel, a 30-day acknowledgment commitment, an investigation process, and a record-keeping system, ahead of the June 19, 2026 deadline if you have not already.
- Revisit your international transfer risk assessments against the "not materially lower" standard rather than the older "essentially equivalent" language.
- Review your cookie consent setup against the four new PECR exemption categories, and confirm whether any of your analytics, functionality, security, or update-related cookies genuinely qualify (most default analytics implementations do not). See the companion PECR guide for the full walkthrough.
- Update your PECR and cookie-related fine exposure assessments to reflect the £17.5 million/4% ceiling, not the old £500,000 cap.
- Watch for the completion of the Information Commissioner-to-Information Commission transition, since it affects who your organization formally reports to and how enforcement decisions are made.
Frequently Asked Questions
Is the Data (Use and Access) Bill now law?
Yes. It received Royal Assent on June 19, 2025 and is now the Data (Use and Access) Act 2025. Most of its substantive provisions are already in force, with the last stages commencing through mid-2026.
Is this the same as the Data Protection and Digital Information Bill (DPDI Bill)?
No. The DPDI Bill was an earlier, separate piece of legislation, introduced in 2022 and revised in 2023, that expired before the 2024 general election without ever passing. The Data (Use and Access) Bill was introduced as new legislation in October 2024 and is narrower in scope than the DPDI Bill had been, though it carries forward a few of that bill's ideas in modified form.
Does the DUAA replace UK GDPR?
No. It amends UK GDPR and the Data Protection Act 2018. Your existing UK GDPR compliance program remains the foundation; the DUAA changes specific rules within it, such as legal bases, automated decision-making, subject access requests, and international transfers.
Do we still need cookie consent banners under the DUAA?
Yes, for most cookies. Four categories (analytics, functionality, security, and software update) can qualify for a consent exemption if strict conditions are met. Advertising, targeting, and cross-site tracking cookies still require prior consent. See the companion PECR guide for the full detail.
When does the new complaints procedure take effect?
June 19, 2026, one year after Royal Assent. Organizations must provide a complaint mechanism, acknowledge complaints within 30 days, and respond without undue delay.
Has the ICO already become the Information Commission?
Partially. New statutory objectives for the regulator came into force in August 2025, but the full transition, including the formal abolition of the Information Commissioner's office, was still pending as of mid-2026.
Does this reform affect the UK's EU data adequacy status?
The DUAA was deliberately drafted to preserve the UK's EU adequacy status, and the government set aside several more aggressive proposals from the earlier DPDI Bill for that reason. Organizations operating across both the UK and EU should still monitor adequacy developments, since the UK and EU frameworks are diverging in specific areas, including cookie consent rules.
Sources
- Data (Use and Access) Act 2025, legislation.gov.uk: https://www.legislation.gov.uk/ukpga/2025/18
- Information Commissioner's Office, "Data (Use and Access) Act 2025": https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/
- Norton Rose Fulbright, "Data (Use and Access) Bill receives Royal Assent": https://www.nortonrosefulbright.com/en/knowledge/publications/6242a9c9/07-data-use-and-access-bill-receives-royal-assent
- Addleshaw Goddard, "The Data (Use and Access) Act 2025: Top 7 Changes": https://www.addleshawgoddard.com/en/insights/insights-briefings/2025/data-protection/data-use-and-access-act-2025-top-7-changes/
- Withers, "The Data Use and Access Act 2025: A New 'Right to Complain'": https://www.withersworldwide.com/en-gb/insight/read/new-right-to-complain-under-the-data-use-and-access-act-2025
- Debevoise Data Blog, "The UK's New Automated Decision-Making Rules": https://www.debevoisedatablog.com/2025/11/19/the-uks-new-automated-decision-making-rules-and-how-they-compare-to-the-eu-gdpr/
- Society for Computers and Law, "Data (Use and Access) Act 2025 (Commencement No. 1) Regulations 2025 made": https://www.scl.org/data-use-and-access-act-2025-commencement-no-1-regulations-2025-made/
- DLA Piper Privacy Matters, "UK: Commencement of the data protection provisions in the Data (Use and Access) Act": https://privacymatters.dlapiper.com/2026/02/uk-commencement-of-the-data-protection-provisions-in-the-data-use-and-access-act/
- Legislation.gov.uk, "The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026": https://www.legislation.gov.uk/uksi/2026/82/regulation/2/made
- CMS Law, "ICO Restructuring: Leadership and Compliance Updates": https://cms.law/en/gbr/legal-updates/ico-restructuring-and-leadership-update
- Secure Privacy, "UK Data (Use and Access) Act 2025: PECR Cookie Consent Changes and How to Comply" (companion article, internal)



