Journey

Prepare for the Data Use and Access Act 2025 changes

A step-by-step guide to understanding and adapting to the Data (Use and Access) Act 2025. Covers the 8 key reforms now in force, including recognised legitimate interests, SRI replacing DPO, cookie consent changes, and the 35x increase in PECR penalties.

Running a Business Updated 15 September 2026
6 milestones references 3 guides

What is the Data Use and Access Act 2025?

The Data (Use and Access) Act 2025 (DUAA) is the biggest reform to UK data protection law since the UK GDPR. It received Royal Assent on 19 June 2025, and the majority of its data protection provisions came into force on 5 February 2026.

The DUAA does not replace the UK GDPR or DPA 2018. It amends them, introducing 8 key changes that affect how businesses handle personal data, cookies, and electronic marketing.

  1. Understand the 8 key changes

    Start by understanding what has changed. The DUAA introduces reforms across lawful bases, governance, cookies, penalties, and automated decisions.

    Data Use and Access Act 2025: what changed for businesses

    A comprehensive explainer covering all 8 DUAA reforms, commencement timeline, and what each change means in practice.

  2. Review your lawful bases

    The DUAA introduces a new seventh lawful basis: recognised legitimate interests. This applies to specific purposes (national security, public safety, crime prevention, emergencies, safeguarding) without requiring a balancing test.

    Review whether any of your processing activities could use this new basis. For most commercial activities (marketing, customer analytics, business operations), the existing six lawful bases still apply unchanged.

  3. Assess your DPO or SRI requirement

    If your business currently has a Data Protection Officer (DPO) or was considering appointing one, the DUAA introduces the Senior Responsible Individual (SRI) as an alternative for some organisations. Public authorities must still appoint a DPO.

  4. Update your cookie consent

    One of the most practical changes: first-party analytics cookies can now be set without prior consent, provided you meet three conditions. Review your cookie banner and consent mechanism.

    Cookie consent and ePrivacy compliance

    How to comply with cookie consent rules, including the new DUAA analytics cookie exemptions.

  5. Review your marketing compliance

    The DUAA has dramatically increased the maximum penalty for PECR breaches (nuisance calls, spam emails, cookie violations). Businesses that rely on electronic marketing should review their practices urgently.

  6. Update your privacy notices and policies

    With new lawful bases, governance changes, and cookie exemptions, your privacy notice likely needs updating. Review it against the current requirements.

    Data protection for businesses

    The complete guide to UK GDPR compliance, including the seven principles, lawful bases, and ICO registration.

    DUAA compliance action checklist

Stay informed

The DUAA is being implemented in phases, with final provisions expected by June 2026. The ICO is publishing updated guidance as each phase commences.