Data Use and Access Act 2025 Passes Into Law

24th July 2025

The DUA Bill, now known as the Data Use and Access Act 2025 or the DUA Act, passed into UK law as of June 19th when it received Royal Assent. This Act mainly involves updates to the existing data protection laws to modernise them, and with the exception of raising PECR fines to match those in the GDPR, it does not place any additional burdens on Controllers in relation to the GDPR, PECR or any other UK laws. The Act was introduced by the current government on October 23rd, 2024, and is based heavily on the previous Conservative government’s Data Protection and Digital Information (DPDI) Bill.

Details of the DUA Act

The Act introduces some changes to the UK GDPR, PECR and the Data Protection Act 2018 and gives more powers to the ICO, which under the new law will be known as the Information Commission. The main changes to the law include:

Automated decision-making

The existing laws on automated decision making (ADM) will be relaxed slightly by the DUA Act. Providing that appropriate safeguards are put in place, the DUA Act will allow organisations to make solely automated decisions using standard category personal data. ADM using sensitive or special category data typically will require explicit consent. The ICO will release more guidance on ADM later this year.

Personal data for research purposes

The DUA Act clarifies when researchers can process personal data for commercial and scientific research, how to obtain ‘broad consent’ from individuals for an area of scientific research, and outlines the safeguards needed for the use of personal data in research. It also extends the concept of purpose limitation, so that historical or scientific research can be done with already collected data, provided that the new purpose is not incompatible with the original purpose for the data processing. 

Legitimate interests

The Act includes a whitelist of certain activities as legitimate interests, which eliminates the need for a legitimate interest assessment as long as certain criteria are fulfilled, such as direct marketing, intra-group transfers for admin purposes, network security and public interest.

Data Subject Access Requests

The DUA Act has clarified existing case law in the new legislation, stating that controllers need only to carry out ‘reasonable and proportionate’ subject access requests and can also wait for verification of an individual’s identity before the time period for responding to SARs begins. Additionally, organisations are not obligated to provide privacy information to individuals if it is “impossible or would involve disproportionate effort”, especially if they have gathered personal information indirectly, i.e. from the electoral roll.

Data Transfers

The DUA Act introduces a risk-based approach to assessing adequacy for international data transfers. If a data protection test by the Secretary of State reveals that the standard of protection applied to data transferred outside the UK to a ‘third country’ is “materially lower than the standard of protection provided”, then the transfer cannot take place. Note: this is not radically different to Section 18(2) of the Data Protection Act 2018.

Special category data

The DUA Act makes provision for the Secretary of State to define new categories of special category data via secondary legislation. This enables the government to respond swiftly to new technological advancements and societal developments and the risks they may pose to data protection and individuals’ rights.

Children and online services

Organisations that create online services or platforms that are likely to be used by children will be legally obliged to take into account how children can be protected and build in protections from the design phase.

Complaints

The DUA Act introduces a new ‘Right to Complain’ and allows individuals to complain directly to data controllers regarding the use of their personal data, and controllers must have a procedure in place to facilitate and respond to these complaints within 30 days. Privacy notices should also be amended to reflect this change.

Electronic marketing and charities

Charities will soon be able to utilise PECR’s soft opt-in clause historically only been available to commercial organisations. This will allow them to send electronic marketing communications, i.e. emails, to people who provide their personal information or express an interest in the charity, unless they object.

Cookies: Of great interest and benefit to most companies and organisations will be the reclassification of analytical cookies from ‘optional’ to ‘essential’, as this will allow website administrators to again utilise user and visitor activity data that has been unavailable over the past 5 years.

Digital verification services (DVS)

Provisions have been included in the Act to set up a new national framework for digital identities in the UK, and allow for greater sharing of data for official public interest purposes such as fraud prevention. 

Changes to the ICO

The ICO will become the Information Commission (IC), a body corporate with an appointed Chief Executive. The IC will have new powers to issue interview notices, require organisations to fund internal audits and reports, provide mandatory document production, and align the penalty regime of PECR with that of the GDPR, meaning it can impose fines up to £17.5 million or 4% of global turnover. This strengthens the ICO’s ability to act as a regulator and enforcer of the law. 

The Act passed into law as of June 19th, but these changes will be rolled out over the next 2 to 12 months – the dates for these changes will be published by the government in commencement regulations on gov.uk. Organisations should familiarise themselves with the changes introduced by the DUA Act and ensure that their practices comply with this and other data protection laws, for example, by updating public privacy notices.  

If you are concerned about the DUA Act, we are here to help – contact us using the form here or call us on 01673 885533.

Author: Mike Martin LLM

Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Sources

Brodies LLP

ICO

Data Protection Network

Gowling WLG

Legislation.gov.uk

Taylor Wessing

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details