The Data (Use and Access) Act 2025 (DUA Act)
The Data (Use and Access) Act 2025 (DUA Act) received Royal Assent on the 19th of June 2025.
The Act updates the UK data protection law by amending the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA) and the Privacy and Electronic Communications Regulations (PECR).
Key changes
Research
The Act introduces clearer legal definitions for the processing for research purposes, such as 'scientific research' and 'historical research', to clarify how the UK GDPR applies to research. It also provides a clearer explanation of the permitted processing for statistical purposes.
It allows processing by way of consent for scientific research and for law enforcement purposes, subject to provisos.
Recognised legitimate interests
New ‘recognised legitimate interests’ are being introduced, which will require documentation of scope and safeguards, but not a full balancing test within Legitimate Interests Assessments (LIAs).
Automated decision-making (ADM)
The general restriction on solely automated decision-making for personal data has been removed. There is no longer a need to rely on explicit consent or a contractual relationship, provided appropriate safeguards and transparency of processing are in place. Stricter controls remain for special category data.
Government powers
The Secretary of State gains the power to designate new types of personal data as “special category data” if new privacy risks emerge.
International data transfers
The Act amends the legal test for international transfers. Instead of requiring “essentially equivalent” protection, the new test requires a standard “not materially lower than the UK’s.”
It also authorises the Secretary of State to make adequacy regulations with greater flexibility, and clarifies how appropriate safeguards, such as standard contractual clauses are to be used.
Privacy and Electronic Communications Regulations (PECR)
The PECR enforcement powers are brought in line with those under the UK GDPR and DPA. Specifically, it:
- Raises the maximum fines for PECR breaches to match UK GDPR levels.
- Aligns investigatory and enforcement powers of the Information Commissioner’s Office (soon to become the Information Commission) across all three regimes.
- Supports a more consistent regulatory approach to data protection and electronic communications.
- Allows charities to rely on the soft opt-in exemption to send direct email marketing without needing to obtain consent (subject to conditions).
Cookies
The Act also amends PECR to allow specific types of cookies and similar technologies to be used without prior consent, provided they are:
- Low risk;
- Non-intrusive; and
- Used for purposes such as functionality, or statistical purposes.
This change means organisations may no longer need to display cookie banners for these low-risk cookies, provided that users are still informed and given control where appropriate.
Data subject rights
Previous ICO guidance surrounding Data subject access requests is being incorporated, which includes extensions of time, searches and responses to data subjects.
Information Commissioner's Office (soon to become the Information Commission) guidance
The ICO has produced a checklist to help organisations be prepared for the changes, as follows:
- Familiarise yourselves with the changes that the DUA Act makes to data protection law using this guidance.
- If you provide an online service that children are likely to use, make sure you are doing enough to satisfy the new explicit requirement to consider their needs. You should be on track if you already conform to the ICO's Age Appropriate Design Code (AADC).
- Start thinking about how you can help people to make complaints.
- Review the changes that support innovation and make things easier and consider whether you want to take the opportunity to do anything differently or streamline your processes.
- Sign up to the ICO newsletter and e-shots, so you’ll know when they’ve updated guidance.
You can also find more information about these changes on the GOV.UK website.
See our previous Article: The Data (Use and Access) Bill (DUA Bill)
This article is for general information only. It does not constitute legal advice and should not be relied upon as such. If you require further information regarding its content, please contact us at info@kpdpconsultancy.co.uk. Law as of June 2025.
