After two failed attempts under the previous government (the Data Protection and Digital Information Bill died when the 2024 election was called), the UK finally passed its post-Brexit data reform as the Data (Use and Access) Act 2025, with royal assent on 19 June 2025. It is deliberately evolutionary: an amending act that keeps UK GDPR’s architecture while loosening specific obligations and adding new digital-economy frameworks. Provisions commence in phases via secondary legislation.
| Statute | Data (Use and Access) Act 2025 (c. 18) |
|---|---|
| Royal assent | 19 June 2025; phased commencement |
| Amends | UK GDPR, DPA 2018, PECR |
| Official text | legislation.gov.uk 2025 c. 18 |
What changed for day-to-day compliance
Lawful bases. A schedule of recognised legitimate interests lets controllers process for listed public-interest purposes (safeguarding, emergencies, crime, national security) without the Article 6(1)(f) balancing test. The Act also names examples of ordinary legitimate interests, including direct marketing, intra-group administration, and security, which still require the balancing test but with statutory acknowledgment they can qualify.
Automated decisions. The biggest divergence from the EU: outside special category data, solely automated decisions with significant effects move from near-prohibited to permitted-with-safeguards (transparency, human intervention on request, the ability to contest). Compare the EU position in our Article 22 guide.
DSARs. Reasonable and proportionate search is now the statutory standard, and stop-the-clock rules are codified, giving controllers firmer ground against fishing-expedition requests without changing the one-month deadline.
PECR and cookies. Narrow consent exemptions arrive for low-risk purposes such as first-party statistics and appearance settings, and PECR’s fine ceiling rises toward UK GDPR levels, a signal that marketing and cookie enforcement gets sharper teeth, not duller.
Institutions and infrastructure. The ICO becomes the Information Commission with a board structure; the Act builds statutory frameworks for smart data schemes (open-banking-style data portability by sector) and digital verification services, and provides for NHS data standards.
What it means in practice
For UK-only businesses, the Act mostly reduces friction at the margins; nothing requires urgent remediation, though marketing teams should watch the PECR fine increase. For businesses serving both the UK and EU, the practical answer is usually to keep running the stricter EU standard group-wide, because the EU GDPR has not moved and adequacy depends on the UK staying essentially equivalent. Verify your site’s consent behavior against the current rules with a free scan.