In focus

Data (Use and Access) Act 2025: what the UK GDPR reforms mean for your business

The Data (Use and Access) Act 2025 reforms UK GDPR, the Data Protection Act 2018 and PECR in stages. The first commencement regulations brought provisions into force on 20 August 2025, and the main changes for businesses took effect on 5 February 2026. Key changes include a new recognised legitimate interest basis, relaxed automated decision-making rules, extended soft opt-in marketing for charities, cookie consent exceptions, and mandatory complaint-handling procedures from 19 June 2026. On 30 September 2026 the Information Commission replaces the Information Commissioner as the data protection regulator. Businesses must review their privacy notices, DPIAs, marketing practices, and cookie mechanisms.

Data (Use and Access) Act 2025 reforms UK GDPR from early 2026 · effective 1 June 2026

Data ProtectionPrivacy Notices

Overview

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and amends UK GDPR and related data protection legislation in several phases. While the changes are broadly deregulatory — removing some compliance burdens — they require active updates to your existing data protection documentation and processes.

The Act is being commenced in stages. The Phase 1 changes described below took effect on 5 February 2026, and mandatory complaint-handling procedures took effect on 19 June 2026. On 30 September 2026 the office of Information Commissioner is abolished and its functions transfer to a new Information Commission, which is run by a board.

Royal Assent
19 June 2025
First commencement regulations (SI 2025/904)
20 August 2025
Phase 1 (early provisions)
5 February 2026
Phase 2 (complaint handling, Section 103)
19 June 2026
Complaint acknowledgement deadline
30 days
Information Commission replaces the Information Commissioner
30 September 2026
Enforcing regulator
Information Commissioner's Office (ICO); the Information Commission from 30 September 2026

Phase 1: recognised legitimate interest and automated decisions

The Act introduces a new recognised legitimate interest lawful basis for processing personal data. For specified purposes — including safeguarding, national security, and democratic engagement — organisations can process data without conducting the traditional three-part balancing test required under the standard legitimate interest basis.

This does not replace the existing legitimate interest basis. It creates an additional, simplified route for a defined set of purposes. You must still identify which lawful basis you rely on and document it in your records of processing activities.

The Act also relaxes restrictions on solely automated decision-making under Article 22 of UK GDPR. The previous near-blanket prohibition is replaced with a more flexible framework. If you use automated decision-making systems (including AI-based tools), review whether your current safeguards and transparency measures remain appropriate under the new rules.

Phase 1: marketing and cookie consent changes

The soft opt-in exemption for electronic marketing is extended to charities and non-commercial organisations. Previously, only commercial businesses could rely on soft opt-in to send marketing communications to existing customers without explicit consent. Charities can now market to supporters who have previously engaged, provided they offer an easy opt-out.

The Act also introduces new exceptions for cookies and similar tracking technologies. Certain categories of cookies — such as those used for security, fraud prevention, or audience measurement — may no longer require prior consent. Review your cookie consent mechanisms to determine which cookies now fall under the exemptions and update your cookie banners accordingly.

Phase 2: mandatory complaint-handling procedures (from 19 June 2026)

Section 103 of the Act requires organisations to establish formal complaint-handling procedures for data protection complaints. This provision took effect on 19 June 2026 and applies to complaints received on or after that date.

Under these requirements, you must:

  • make it easy for people to complain, for example by providing a complaint form that can be completed electronically and by other means
  • acknowledge receipt of a complaint within 30 days of receiving it
  • without undue delay, take appropriate steps to respond (including making enquiries into the complaint and keeping the complainant informed of progress) and tell the complainant the outcome

People can still complain directly to the ICO (the Information Commission from 30 September 2026). The law does not require them to complain to you first.

ICO governance changes (from 30 September 2026)

The Act replaces the Information Commissioner, a single office holder, with the Information Commission, a body corporate run by a board. The Commission was established in law on 20 August 2025. It has a chair and other non-executive members, and executive members including a chief executive.

On 30 September 2026 the office of Information Commissioner is abolished and all of its functions transfer to the Information Commission. From that date the Commission is the regulator for UK GDPR and PECR.

For businesses, the practical impact is limited in the short term. The change of regulator does not change your data protection obligations. References to the Information Commissioner in legislation and other documents are treated as references to the Information Commission. Anything done by or in relation to the Commissioner before 30 September 2026, or still under way on that date (such as a complaint, investigation or enforcement action), is treated as done by or in relation to the Commission and can continue. The new governance structure may lead to changes in enforcement strategy and priorities over time.

What you need to do

Review and update the following:

  • Privacy notices — ensure they reflect any new lawful bases you rely on, including recognised legitimate interest
  • Data protection impact assessments — revisit DPIAs for automated decision-making systems to check alignment with the relaxed Article 22 rules
  • Marketing practices — if you are a charity or non-commercial organisation, assess whether the soft opt-in exemption applies to your supporter communications
  • Cookie consent mechanisms — update cookie banners to remove consent prompts for newly exempt cookie categories
  • Complaint-handling procedures — if you have not already done so, set up a way for people to make data protection complaints (such as an electronic complaint form), acknowledge them within 30 days, respond without undue delay and tell complainants the outcome (required since 19 June 2026)
  • Records of processing activities — update to reflect any changes in lawful basis or processing purposes

UK-only changes

These reforms apply to UK GDPR only. If your business also processes personal data of individuals in the EU or EEA, you must continue to comply with EU GDPR separately. The recognised legitimate interest basis and cookie consent exceptions do not apply under EU GDPR. Ensure your compliance framework distinguishes between UK and EU data protection requirements where relevant.