Data (Use and Access) Act 2025 Explained: What Every UK Business Must Do

Data (Use and Access) Act 2025 Explained: What Every UK Business Must Do

Data (Use and Access) Act 2025 Explained: What Every UK Business Must Do Before 19 June 2026

The Data (Use and Access) Act 2025, often shortened online to the Data Use Access Act 2025 or simply the DUA Act, is the biggest change to UK data protection since the Data Protection Act 2018, and its key business deadline has now arrived: since 19 June 2026, every organisation must operate a statutory data protection complaints process, acknowledging complaints within 30 days. This guide explains what the Act does, what had to be in place by the deadline (and what to do if you are not ready), and how the new regime differs from the UK GDPR you already know. 

If you run a business that handles personal data, which is every business, 2026 is the year the DUA Act stopped being a future concern. The reforms have been arriving in waves, and the wave that matters most to SMEs, the complaints-handling duty, is now live. Here is the practical picture, without the panic or the jargon.

 

What Is the Data (Use and Access) Act 2025?

The Act received Royal Assent on 19 June 2025. Two design decisions explain everything about it:

 

It amends rather than replaces. The UK GDPR, the Data Protection Act 2018 and the marketing rules (PECR) all remain in force; the Act rewires parts of them. If your business was already UK GDPR-compliant, you are adjusting, not starting again.

It is broader than data protection. The Act also creates frameworks for "smart data" schemes (think open banking extended to other sectors), digital verification services, and a register of underground pipes and cables, and it restructures the regulator: the Information Commissioner's Office is being reformed into an Information Commission. The smart data provisions matter long-term: they allow the government to mandate sector schemes under which customers can port their data to challenger providers, extending the open-banking model to markets such as energy.

 

The data protection changes have commenced in stages: the main amendments to the UK GDPR took effect on 5 February 2026, and the complaints-procedure duty followed on 19 June 2026.

 

Two quieter changes matter for ordinary businesses. The Act relaxes the cookie rules in PECR for certain low-risk purposes, such as statistics and website appearance, meaning consent banners can eventually slim down once the relevant provisions are in force. And it raises the maximum penalties for PECR marketing breaches from their old modest levels to UK GDPR levels, which turns sloppy email marketing from a nuisance risk into a boardroom one.

 

The 19 June 2026 Deadline: What Must Be in Place

The title of this piece says "before 19 June 2026", and that date has now passed, so treat this section as a compliance audit rather than a countdown. Since 19 June 2026, under the new section 164A of the Data Protection Act 2018, data subjects have a statutory right to complain directly to the organisation (the controller), and every controller must:

 

Facilitate complaints: provide a simple means of making a data protection complaint, such as an electronic complaint form.

Acknowledge within 30 days of receiving a complaint.

Respond substantively without undue delay: take appropriate steps to investigate and inform the complainant of the outcome.

 

Alongside the process itself, privacy notices need updating to tell people they can complain to you (as well as to the regulator), and staff need to recognise a data protection complaint when one arrives in an inbox. If none of that is in place, you are late, not doomed: implement now, document the date, and prioritise any complaints already waiting.

 

The changes already in force since 5 February 2026 also deserve a check. The Act created a list of "recognised legitimate interests" (including crime prevention, safeguarding and emergencies) where processing no longer requires a balancing test, codified the "reasonable and proportionate search" standard for subject access requests, and relaxed parts of the rules on automated decision-making except where special category data is involved. Each is an opportunity to simplify your processes, and each has conditions worth reading before you rely on it. For a data subject access request employer obligations remain deadline-driven, so the codified search standard helps, but it is not an excuse for slow responses.

 

Data Complaints Process: Step-by-Step Guide

A compliant process for an SME can be genuinely simple:

 

1. Publish the route. A short "data protection complaints" section in your privacy notice plus a web form or dedicated email address.

2. Log and acknowledge. Record the complaint and send an acknowledgment within 30 days (in practice, aim for days, not weeks).

3. Triage. Is it really a data protection complaint (about how you handled personal data), a subject access request, or ordinary customer dissatisfaction? Route each correctly, and remember one message can contain more than one.

4. Investigate proportionately. Establish what happened, whether anything went wrong under the UK GDPR, and what remediation is appropriate.

5. Respond with the outcome. Explain what you found and what you are doing, and tell the complainant they can escalate to the regulator if dissatisfied.

6. Record and learn. Keep a log: patterns in complaints are early warnings of process failures, and the log is your evidence of compliance.

 

For a micro-business the entire setup is an afternoon's work: a web form or mailbox rule, a one-page procedure, a named owner and a spreadsheet log. Align your wording with the regulator's published guidance on the complaints duty rather than inventing your own definitions.

 

How the DUA Act Differs from GDPR/UK GDPR

Think evolution, not divergence for its own sake:

 

Same foundations. Lawful bases, data subject rights, security duties, breach reporting and accountability all continue. Data protection act 2026 SME searches often expect a new rulebook; the truth is a modified one.

Targeted relaxations. Recognised legitimate interests, clearer research provisions, more workable automated decision-making rules, and codified proportionality in subject access searches.

A new duty the GDPR never had. The complaints-handling obligation is additive: EU businesses have no direct equivalent, and UK businesses must not miss it precisely because it is unfamiliar.

EU data flows. The EU has renewed the UK's adequacy status following the Act, so personal data can continue to flow from the EU without extra safeguards, a point worth confirming periodically if your business depends on it.

 

For GDPR small business England Wales compliance, the practical reading is: keep your existing framework, bolt on the complaints process, and review whether the new flexibilities let you simplify.

 

On enforcement, the regulator's toolkit is unchanged in scale: fines can still reach £17.5 million or 4% of worldwide turnover for the most serious infringements, alongside enforcement notices and audits. What the Act changes is the regulator itself, restructuring the ICO into an Information Commission with a board and chief executive, and nudging it towards a more structured, business-engaged approach. Do not mistake reorganisation for retreat: complaint volumes now flow through your own front door first, and unhandled complaints are exactly what escalates.

 

SME Compliance Checklist

Complaints route published, with a form or dedicated address.

30-day acknowledgment and outcome-response process assigned to a named person.

Privacy notice updated (right to complain to you; regulator escalation).

Complaint log created; staff briefed on spotting data protection complaints.

Subject access procedure updated for the "reasonable and proportionate" search standard.

Legitimate interests assessments reviewed against the new recognised list.

Automated decision-making uses mapped and checked against the revised rules.

If you trade with the EU: adequacy position noted and diarised for review.

 

Frequently Asked Questions

We missed the 19 June 2026 deadline. What now? Implement immediately and document when you did. A regulator confronted with a complaint will treat a functioning, if late, process very differently from an absent one.

 

Does the complaints duty apply to micro-businesses? Yes. The duty applies to controllers generally, whatever their size, so even a sole trader handling customer data needs a route for complaints and a habit of acknowledging them.

 

Is the UK GDPR gone? No. It remains the core of UK data protection law; the DUA Act amends it. Your existing policies are the starting point, not waste paper.

 

Do we still need consent for marketing emails? The PECR rules still govern electronic marketing, and the Act increased the penalties for breaking them to UK GDPR levels, so marketing compliance matters more, not less.

 

Where do complaints go if the customer is still unhappy? To the regulator (the ICO, transitioning to the Information Commission). Your response should say so explicitly.

 

Key Takeaways

The DUA Act 2025 amends the UK GDPR and DPA 2018 rather than replacing them; the main changes took effect on 5 February 2026.

Since 19 June 2026, every controller must run a statutory complaints process: facilitate, acknowledge within 30 days, respond with an outcome.

New flexibilities (recognised legitimate interests, proportionate SAR searches, revised automated decision-making rules) can simplify compliance if applied carefully.

EU adequacy has been maintained, so EU-UK data flows continue.

 

Sources

Data (Use and Access) Act 2025; Data Protection Act 2018 (new section 164A); UK GDPR

gov.uk "Data Use and Access Act 2025: plans for commencement"; commencement regulations (2026)

ICO guidance on the new complaints requirements and DUAA changes

 

Not sure which duty bites your business next? Research Data Law with Ask.Legal and get sourced answers on the DUA Act in plain English.

This article is general information about the law of England and Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.

Back to the blog