UK Privacy Law United Kingdom

Data (Use and Access) Act 2025: How the UK Reformed Its GDPR

What the DUAA 2025 changed in UK data protection: recognised legitimate interests, relaxed automated decision rules, and DSAR search limits.

Regulation

Data (Use and Access) Act 2025 (amending UK GDPR, DPA 2018, PECR)

Max Penalty

GBP 17.5 million or 4% of global annual turnover (UK GDPR, unchanged)

Enforcing Authority

Information Commissioner's Office (ICO)

Official Source

www.legislation.gov.uk

Executive Summary

  • The Data (Use and Access) Act 2025 received royal assent on 19 June 2025, succeeding the abandoned Data Protection and Digital Information Bill and amending UK GDPR, the DPA 2018, and PECR rather than replacing them.
  • Headline changes: recognised legitimate interests that skip the balancing test, relaxed Article 22 automated decision-making rules outside special category data, and a reasonable-and-proportionate standard for DSAR searches.
  • PECR changes include narrow new cookie consent exemptions and raising PECR fines toward UK GDPR levels.
  • The Act creates smart data schemes and digital verification services frameworks, and restructures the ICO into an Information Commission.
  • EU adequacy survived: the European Commission extended the UK's adequacy decisions in 2025 after reviewing the reforms.

After two failed attempts under the previous government (the Data Protection and Digital Information Bill died when the 2024 election was called), the UK finally passed its post-Brexit data reform as the Data (Use and Access) Act 2025, with royal assent on 19 June 2025. It is deliberately evolutionary: an amending act that keeps UK GDPR’s architecture while loosening specific obligations and adding new digital-economy frameworks. Provisions commence in phases via secondary legislation.

StatuteData (Use and Access) Act 2025 (c. 18)
Royal assent19 June 2025; phased commencement
AmendsUK GDPR, DPA 2018, PECR
Official textlegislation.gov.uk 2025 c. 18

What changed for day-to-day compliance

Lawful bases. A schedule of recognised legitimate interests lets controllers process for listed public-interest purposes (safeguarding, emergencies, crime, national security) without the Article 6(1)(f) balancing test. The Act also names examples of ordinary legitimate interests, including direct marketing, intra-group administration, and security, which still require the balancing test but with statutory acknowledgment they can qualify.

Automated decisions. The biggest divergence from the EU: outside special category data, solely automated decisions with significant effects move from near-prohibited to permitted-with-safeguards (transparency, human intervention on request, the ability to contest). Compare the EU position in our Article 22 guide.

DSARs. Reasonable and proportionate search is now the statutory standard, and stop-the-clock rules are codified, giving controllers firmer ground against fishing-expedition requests without changing the one-month deadline.

PECR and cookies. Narrow consent exemptions arrive for low-risk purposes such as first-party statistics and appearance settings, and PECR’s fine ceiling rises toward UK GDPR levels, a signal that marketing and cookie enforcement gets sharper teeth, not duller.

Institutions and infrastructure. The ICO becomes the Information Commission with a board structure; the Act builds statutory frameworks for smart data schemes (open-banking-style data portability by sector) and digital verification services, and provides for NHS data standards.

What it means in practice

For UK-only businesses, the Act mostly reduces friction at the margins; nothing requires urgent remediation, though marketing teams should watch the PECR fine increase. For businesses serving both the UK and EU, the practical answer is usually to keep running the stricter EU standard group-wide, because the EU GDPR has not moved and adequacy depends on the UK staying essentially equivalent. Verify your site’s consent behavior against the current rules with a free scan.

Frequently Asked Questions

Is the DUAA a replacement for UK GDPR?

No. It amends UK GDPR, the DPA 2018, and PECR in targeted ways. The framework, principles, lawful bases, rights, and fine structure remain. Businesses compliant before the Act remain compliant on most points; the changes mostly loosen rather than tighten.

What are recognised legitimate interests?

A new lawful basis route: for listed purposes such as national security, emergencies, safeguarding, and crime prevention, controllers can rely on legitimate interests without conducting the usual balancing test. Ordinary commercial purposes still require the full assessment.

How did automated decision-making rules change?

The old Article 22 near-prohibition is replaced for most data: solely automated decisions with significant effects are broadly permitted with safeguards (information, human intervention on request, contestability). The restrictive regime survives for special category data. This diverges from the EU, where the stricter rule stands.

What changed for DSARs?

The Act codifies that controllers need only conduct reasonable and proportionate searches, and confirms the clock can pause while the controller awaits identity verification or clarification. Response deadlines themselves are unchanged.

Did the changes threaten EU adequacy?

It was the central worry during passage, but the European Commission reviewed the Act and extended the UK's adequacy decisions in 2025. Divergence remains bounded by that dependency: reforms that cut too deep would put EU-to-UK data flows back at risk.

Regulatory Crosswalk

EU GDPRUK PECRUK GDPR

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.