Data (Use and Access) Act 2025 receives Royal Assent

Share This Post

On 19th May 2025, the Data (Use and Access) Act received Royal Assent, meaning that the updates to UK GDPR and DPA2018 (collectively referred to in this message as “UK GDPR”) is now a new piece of UK data protection legislation for you to think about.

If anything, the new Act should make GDPR compliance a little easier in some areas, although it does introduce some new obligations, so here’s a quick summary of the changes:

Data Protection changes:

  • Subject access requests (DSAR): only have to make reasonable and proportionate searches for a data subject requests
  • Recognised legitimate interests: introduces a range of “approved” legit interests that can be used without requiring assessment, including clarifying when legit interest applies to marketing
  • NEW Complaint handling: need to have a data protection complaint handling process, acknowledge complaints within 30 days and respond “without undue delay”
  • Assumed purposes: introduces situations where you can assume some processing is compatible with the original processing purpose
  • Updated definitions: some amendments to the definitions for processing for scientific research, historical research and statistical purposes
  • Automated decision making: provides a range of automated decision making legal basis for processing personal data, although safeguards still need to apply and the new basis do not apply to special category data
  • Non-UK processing: some clarity about processing data outside the UK
  • NEW Online services used by children: requires online services used by children to take children’s needs into account when processing their data (anyone following the ICO’s Children’s Code will already be doing this)

PECR (electronic marketing) changes:

  • Change to cookie rules: consent will not be needed for certain types of cookies such as those used for analytics and website improvement
  • Soft opt-in for charities: charities will be able to rely on soft opt-in for their marketing activities

Also, the Information Commissioner’s Office (ICO) will become the Information Commission (IC) with a CEO and Board.

Whilst the Act has been passed, the government will phase implementation of the new law using secondary legislation. Most provisions are expected to come into force two to six months after Royal Assent (so August – December 2025), some may take up to a year – so watch this space!

More To Explore

Eat. Sleep. GDPR. Repeat.

We live and breathe GDPR and ePrivacy compliance, so you don’t have too. Our GDPR UNLIMITED helpline is all about offering you help and support, whenever you need it most. As well as the unlimited helpline, you get up to 4 hours “hands-on” help each month, which we can configure to help you in anyway you need such as a GDPR review, or acting as your DPO.

As well as the unlimited helpline and hands-on help you get GDPR and privacy updates, access to our GDPR knowledge centre and webinars.

Unlimited email & phone support

Unlimited email and phone support. Email or organise a voice call as often as you need each month.​

Up to 4 hours "hands-on" help per month

We use these "hands-on" hours to do the GDPR work for you, such as reviews, acting as your DPO, checking DPIA, dealing with breaches, training your staff, etc. (Additional hours: £100+VAT per hour)

Online resources

Our Knowledge Centre gives you access to information, guidance, topic related guides and other tools to support your GDPR and PECR compliance

Updates, alerts & briefings

We provide updates and alerts and a monthly compliance briefing. You can either sign into the Knowledge Centre or sign up via email to receive an email every time we add a new update or alert

DPO services

Whether mandated or not we can act as your Data Protection Officer (DPO) and manage your day to day compliance

Webinars, workshops & training

Whether updates on the latest issue, workshops or team training, it's all included in your monthly retainer.

LIKE WHAT YOU'RE READING? join our email list

Sign up for monthly briefings and the occasional emails about our webinars and services

Want to know more about how we use your data? Check out our privacy policy