Data (Use and Access) Act 2025 Guidance For Businesses

The Data (Use and Access) Act 2025 updates UK data protection law and introduces new expectations for how organisations handle complaints, subject access requests, marketing and data use. For businesses, the key challenge is understanding what has changed and putting the right processes in place now to stay compliant and avoid regulatory risk.

Speak to an expert
01234 923643

Hippodrome Casino London Logo
Rocco Forte Hotels Logo
Bedfordshire Chamber of Commerce Logo
Hippodrome Casino London Logo
Hippodrome Casino London Logo
PMDSC Logo
SwiftComm Logo
iCabbi Logo
The Kemnal Academies Trust Logo

Book a free consultation to discuss the act in more detail.

About The Data Use and Access Act 2025

From 19th 2026 June, UK organisations are required to operate an internal data protection complaints process. Individuals must raise complaints directly with the organisation first, and these must be acknowledged within 30 days and handled without undue delay before escalation to the ICO. Businesses without a clear process in place risk complaints being escalated more quickly to regulatory review.

What the Act is and why it matters now

The Data (Use and Access) Act 2025 forms part of the UK Government’s wider data reform programme, designed to modernise how personal data is used across the economy while maintaining core privacy protections under UK GDPR, the Data Protection Act 2018 and PECR.

The Government has positioned the reforms as a way to reduce unnecessary administrative burden on organisations and improve the practical use of data across both the public and private sectors. This includes improving efficiency in areas such as public service delivery, healthcare administration and regulatory processes, where large volumes of personal data are routinely handled.

The aim is not to weaken data protection standards, but to make compliance more proportionate and operationally workable for organisations, particularly where existing rules have been considered overly complex or resource intensive.

Looking for a deeper dive? For the full parliamentary history, political context and the AI copyright debate, read our comprehensive guide: Data Use and Access Act 2025 Explained.

Key changes businesses need to know

One of the most important changes is the new complaints process. Individuals will generally need to raise a data protection complaint with the organisation first, rather than going straight to the ICO. That means businesses must be able to receive, log, acknowledge and respond to complaints properly.

The Act also introduces a more practical approach to subject access requests. Organisations will no longer be expected to carry out unnecessarily exhaustive searches where that would be unreasonable. Instead, the standard moves towards searches that are reasonable and proportionate.

There are also changes to automated decision-making, legitimate interests, privacy notices, children’s online services, cookies, and PECR enforcement. Some of these changes reduce administrative burden, but others increase the need for strong internal controls.

Alongside these operational changes, the wider regulatory structure is also expected to evolve, with the Information Commissioner’s Office (ICO) moving towards a more formalised commission-style model similar to other UK regulators. This reflects a broader shift towards more structured oversight and clearer enforcement expectations for organisations

What organisations need to do in practice

The Act introduces several operational changes that organisations will need to implement across complaints handling, DSARs marketing compliance and governance.

At a minimum, organisations should:

  • Implement a formal complaints handling process with clear escalation routes
  • Review DSAR procedures to ensure requests are handled proportionately
  • Update PECR and marketing compliance approaches
  • Ensure privacy notices and cookie practices reflect current requirements
  • Strengthen internal governance and record-keeping processes
  • Review use of automation or AI for additional safeguards

Who it applies to

The Act applies to any organisation that processes personal data in the UK. That includes private businesses, charities, public bodies, membership organisations, professional services firms, agencies and online businesses.

It is especially relevant if you:

  • Handle customer, client, employee or supplier data.

  • Use direct marketing by email, SMS or other electronic channels.

  • Operate a website that uses cookies or analytics.

  • Rely on legitimate interests as a lawful basis.

  • Use profiling or automated decision-making.

  • Process children’s data or operate online services likely to be used by children.

  • Receive complaints or requests relating to personal data.

Even if data protection is not central to your business model, the Act may still affect how you operate. If you collect personal information, you need to understand your obligations.

The complaints process and 30-day response expectation

The complaints requirement is one of the most commercially important parts of the Act. It means organisations must be ready to handle data protection complaints internally before they reach the ICO.

That creates a need for a proper process, not an informal inbox. Complaints should be recorded, reviewed and acknowledged quickly, with a clear route for investigation and response. The expectation is that complaints will be acknowledged within 30 days and dealt with without undue delay.

For businesses, the risk is that a poor or slow response can escalate a relatively straightforward issue into a regulatory problem. A clear process, supported by trained staff, is now essential.

Risks of non-compliance and enforcement

The main risk of non-compliance is not just a fine. It is the possibility of regulatory attention, reputational damage and avoidable escalation from a complainant who feels ignored.

If an organisation does not have a proper complaints process, or fails to respond in time, it may create the impression that it is not taking data protection seriously. That can make future complaints harder to manage and may increase the chance of ICO involvement.

There are also financial risks to consider. PECR penalties are significantly higher than they were previously, and failures involving email marketing, SMS, cookies or telemarketing can now lead to much more serious consequences. Businesses that rely on digital marketing should take this particularly seriously.

Recent enforcement activity highlights this regulatory focus. In 2026, the ICO issued a penalty to MediaLab.AI Inc, owner of Imgur, following concerns around the handling of children’s personal data. The case reinforces the importance of making sure that appropriate safeguards are in place where vulnerable data subjects are involved, particularly in online environments where profiling or behavioural data may be used.

How Privacy Helper supports implementation

Privacy Helper helps organisations translate the Act into practical compliance steps. That means more than simply explaining the law. It means reviewing how your business actually handles data, complaints, requests and marketing activity.

Support may include assessing current procedures, identifying gaps, updating policies and helping staff understand what needs to happen in practice. For many businesses, the biggest value is having a clear, business-friendly interpretation of what the law means day to day.

This is especially useful where compliance and commercial activity overlap, such as marketing, website tracking, customer service and internal data handling.

Relevant industries and use cases

This legislation affects a range of sectors, but it is particularly relevant to:

  • Professional services firms.

  • Marketing agencies.

  • Charities and membership organisations.

  • Recruitment businesses.

  • Healthcare and care providers.

  • Education providers.

  • E-commerce and online businesses.

  • Organisations using AI, automation or profiling tools.

If your organisation falls into one of these groups, the Act is likely to have a direct impact on how you collect, use and respond to personal data. That makes this a good time to review your compliance position and make sure your procedures are fit for purpose.

Next steps

The Data (Use and Access) Act 2025 is a reminder that privacy compliance is becoming more operational and more visible. Organisations that prepare now will be in a much stronger position than those that wait until a complaint or request forces the issue.

If you need help understanding what the Act means for your organisation, Privacy Helper can support you with practical compliance advice.

Our Contributors

Andy Chesterman

Andy Chesterman

As co-founder of Privacy Helper, I regularly contribute and provide comment in articles publications and journals on privacy matters. I am also a member of the Betting & Gaming Council’s Working Group on Live Facial Recognition.

Dan Brooks-Tonkin

Dan Brooks-Tonkin

I am a full-time Data Protection Consultant at Privacy Helper, supporting organisations to understand their data protection obligations and implement clear and effective compliance solutions.

Non-compliance Cases

Compliance Timescales

23 October 2024

The Data (Use and Access) Bill was introduced to Parliament. This marked the beginning of the Government’s latest programme of post-Brexit data protection reform and proposed amendments to UK GDPR, the Data Protection Act 2018 and PECR.

19 June 2025

The Bill received Royal Assent and became the Data (Use and Access) Act 2025. Certain provisions came into force immediately, while most changes were scheduled to be implemented in phases through commencement regulations.

21 July 2025

The Data (Use and Access) Act 2025 (Commencement No. 1) Regulations 2025 were made. These regulations confirmed the first staged implementation timetable for the legislation.

20 August 2025

The first commencement regulations took effect, bringing selected provisions of the Act into force, including certain operational, regulatory and technical measures.

2 September 2025

Further commencement activity followed as additional provisions under the phased implementation programme began to take effect. Organisations were expected to continue reviewing their governance and compliance arrangements during the transition period.

June 2026

By 2026, the majority of the Act’s data protection and privacy reforms are expected to be operational, including changes affecting complaints handling, marketing compliance, automated decision-making and regulatory enforcement. Organisations should ensure policies, procedures and staff training reflect the updated legal framework.

Speak to us About the Data Use and Access Act 2025 Today!

Phone Number
01234 923643