ICO’s Updated Guidance on Reusing Personal Data: What ‘Compatible Use’ Really Means
15th May 2026
For most SMEs, this question comes up almost every week: ‘We collected data for X. Can we now use it for Y?’ The honest answer used to be a long, hedged one. The Information Commissioner’s Office (ICO) updated its guidance on 23 March 2026 to reflect the Data (Use and Access) Act 2025 (DUAA), and we now have a much clearer framework. So when can you reuse data freely, when do you need to think harder, and what should you do either way?
What the law actually says
Article 5(1)(b) of the UK GDPR (the purpose limitation principle) requires personal data to be:
‘collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes’
Put simply: tell people why you are collecting their data, and stick to that. If you want a new use, it has to be ‘compatible’ with the original. The DUAA and the ICO now tell us what that means.
When reuse is automatically compatible
The DUAA introduced Annex 2 to the UK GDPR. This lists situations where the law treats a new use as compatible with the original, so long as the processing is necessary and proportionate. It covers disclosing data to a public body for a public task, archiving in the public interest, scientific or statistical research, safeguarding vulnerable individuals, and crime prevention or investigation.Some of these Annex 2 conditions align to the newly introduced category of recognised legitimate interests also introduced by the DUAA.
If your reuse falls cleanly within Annex 2, you do not need a separate ‘compatibility assessment’, although you still need a lawful basis for the new use. For example, a primary school sharing a pupil’s information with social services for a safeguarding concern is treated as a compatible purpose under Annex 2.
When you need to think harder
If your reuse is not in Annex 2, and you originally collected the data on a basis other than consent, you must actively assess compatibility. The ICO lists the factors to weigh: the link between the original and new purposes, the context of collection, the nature of the data (especially special category or criminal offence data), the possible consequences for the individual, and the safeguards in place.
Take a familiar SME scenario. Your HR team holds employee records for managing the employment relationship. Marketing wants to use those names and email addresses for a customer-facing case study. The context, the relationship of trust, and the potential consequences for the employee are all different. A compatibility assessment is essential, and in most cases you’ll need fresh consent or a different lawful basis.
A smaller but very common case: your receptionist keeps a paper visitor sign-in book for site security. Marketing wants to email everyone who came in last quarter to say ‘thanks for visiting’. Different context, different expectation, no compatibility shortcut. Either get consent, or don’t do it.
Three rules to remember
First, compatibility is not the same as compliance: you still need a lawful basis for the new processing. Second, if your original lawful basis was consent, the rules are tighter and the ICO usually expects you to obtain fresh consent. Third, if your purposes change, your privacy notice changes too. Transparency does not pause when you find a new use for old data.
What good looks like
The strongest position is one where you know what you hold, why you collected it, and how it might evolve. That’s what a Record of Processing Activities (RoPA) is for, and it’s the document the ICO will ask to see first if a complaint or audit comes your way. We’ve covered RoPAs in our recent practical guide, and our piece on data minimisation in practice covers the sister data minimisation principle of collecting only what you need in the first place. Beyond that, train staff to spot ‘scope creep’ early, refresh your privacy notice when purposes change, and write your compatibility assessments down. A short note on the factors you considered and the conclusion you reached is enough, and it’ll prove invaluable later if anyone asks.
How Griffin House Consultancy Can Help
Working out whether a new use of personal data is lawful, compatible and proportionate can feel like walking a tightrope. You don’t have to tackle it alone. We help organisations review their data flows, document compatibility assessments, refresh privacy notices and train staff on purpose limitation. Get in touch with us at Griffin House Consultancy, or call us on 01673 885533, and one of our team will be happy to talk it through.
Author: Mike Martin LLM
Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.
Sources
ICO, Principle (b): Purpose limitation (updated 23 March 2026)
ICO, Compatibility and the reuse of personal information