The Data Use and Access Act 2025 (DUAA) is the UK’s most significant update to its data protection framework since the introduction of UK GDPR. It amends the UK GDPR and the Data Protection Act 2018, introduces new mechanisms for data sharing, and changes several areas that directly affect how organisations manage personal data.
This factsheet summarises the key changes and what they mean for your organisation.
Background
The Data Use and Access Act 2025 was developed following the consultation on the previous Data Protection and Digital Information Bill (DPDI). It reflects the UK government’s stated aim of enabling a more flexible, innovation-friendly approach to data use while maintaining the core principles of the UK GDPR framework.
Key changes affecting most organisations
Legitimate interests assessment
The DUAA introduces a list of recognised legitimate interests that can be relied upon without conducting a full Legitimate Interests Assessment (LIA). This is a practical change that will reduce the administrative burden for common, low-risk processing activities.
However, organisations should not assume that all legitimate interests processing is now straightforward. The recognised list covers specific activities; anything outside it still requires a proper three-part LIA. And the principle of data minimisation and purpose limitation still applies regardless of which lawful basis is relied upon.
Action: Review your Record of Processing Activities (RoPA) and the lawful bases you rely on. Assess whether any current legitimate interests processing falls within the recognised list and update your documentation accordingly.
Automated decision-making
The DUAA amends the automated decision-making provisions in Article 22 of UK GDPR. The previous strict prohibition on solely automated decisions with significant effects is now framed differently: providing a more workable framework for AI-assisted decision-making while maintaining safeguards.
For organisations using AI or automated systems to make or assist in making decisions about individuals (credit decisions, HR screening, insurance pricing, and so on), the DUAA provides greater legal clarity but does not remove the need for appropriate safeguards.
Action: Review any automated decision-making processes. Ensure your privacy notices accurately reflect how automated decision-making is used and what rights individuals have.
Senior Responsible Individual (SRI)
The DUAA replaces the mandatory Data Protection Officer (DPO) requirement (for most non-public sector organisations) with a Senior Responsible Individual (SRI). The SRI is a member of senior management who takes accountability for data protection compliance.
This is a significant change. Previously, organisations required to appoint a DPO needed to appoint a suitably qualified and independent person in that specific role. The SRI requirement is a senior management accountability rather than a specialist technical role.
Note: Many organisations that have an outsourced DPO arrangement may need to review how this maps to the SRI requirements. An outsourced DPO can still provide the technical expertise and support, but the formal SRI accountability may need to sit internally at senior management level.
Action: Identify who your SRI will be. Ensure they have appropriate seniority and accountability for data protection decisions. Brief them on their responsibilities.
International data transfers
The DUAA introduces reforms to the international data transfer mechanisms, providing additional flexibility alongside the existing adequacy decisions and standard contractual clauses. This includes a new framework for bulk personal data transfers for recognised purposes.
Action: Review your international data transfer arrangements. If you transfer personal data outside the UK, confirm which mechanism you rely on and whether it remains appropriate under the DUAA framework.
Data sharing and Smart Data schemes
The DUAA creates a framework for Smart Data schemes: sector-specific data sharing initiatives (similar to the existing Open Banking model) that allow individuals to share their data with third-party service providers. The energy, telecoms, and financial services sectors are among those expected to develop Smart Data schemes.
For organisations in these sectors, Smart Data schemes will create both new compliance obligations and new opportunities to access customer data (with appropriate consent) from third parties.
Changes to Subject Access Requests
The DUAA introduces some modifications to the Subject Access Request (SAR) framework, including provisions for refusing vexatious or excessive SARs and changes to certain exemptions. The one-month response deadline is unchanged.
Action: Review your SAR process to ensure it reflects the updated provisions. This is particularly relevant for organisations that receive high volumes of SARs.
What has not changed
The core principles of UK GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability: are unchanged. The DUAA does not reduce your obligations around these fundamental principles.
The ICO remains the supervisory authority. Fines and enforcement powers are broadly unchanged.
Practical steps for all organisations
-
Update your privacy notices to reflect any changes to lawful bases, automated decision-making, or the SRI contact.
-
Review your Record of Processing Activities (RoPA) for accuracy against the updated framework.
-
Appoint your Senior Responsible Individual if you have not already done so, and brief them on their responsibilities.
-
Review your data processor agreements: the DUAA makes some changes to the requirements for processor contracts.
-
Consider staff training: staff who handle personal data should be updated on the practical implications of the key changes.
How Elmar can help
The DUAA represents a significant update to the UK data protection framework, and keeping your compliance programme current requires specialist knowledge. Elmar Risk Management provides outsourced DPO services and data protection consultancy to help organisations navigate these changes.
Contact us to discuss how the DUAA affects your organisation and what steps you need to take.
Share:
LinkedIn
