Logo

UK data protection law has entered a new phase. If your organisation processes personal data in the UK, 2026 is the year to reassess your compliance posture – not because the fundamentals have been torn up, but because important legislative changes demand updated policies, processes and documentation across your business.

Executive summary: recent UK data protection changes

UK data protection law now centres on three interlocking statutes: the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025 (DUAA). The DUAA was passed on 19 June 2025 and its provisions have been commenced in phases, with all data protection changes in force by 19 June 2026. Together, the UK GDPR and the Data Protection Act 2018 structure the core legislative framework for personal data handling in the UK.

Here are the headline changes organisations need to understand:

  • A new lawful basis called recognised legitimate interests, pre-approved for specific purposes such as crime prevention and safeguarding

  • Broader rules for automated decision making, with new safeguard requirements

  • Revised subject access request obligations, including reasonable and proportionate searches and a “stop the clock” mechanism

  • Simplified international transfer rules through “data bridges” and a clearer data protection test

  • Updates to cookie and storage technology rules under PECR, allowing some low-risk cookies without consent

In practice, this means UK-based organisations must update privacy notices, Data Protection Impact Assessments (DPIAs) and records of processing. Training needs refreshing across HR, marketing, IT and customer-facing teams. Vendor contracts, marketing consent mechanisms and international transfer arrangements all require review.

Data Privacy Services (DMPC Ltd) can provide a free GDPR / data protection audit and DPO as a Service to help your organisation review these changes and maintain compliance. More on that below.

The UK data protection framework: UK GDPR, DPA 2018 and DUAA 2025

UK data protection law is a layered regime. Understanding which statute does what is essential before diving into the recent reforms.

  • The Data Protection Act 2018 was enacted in the UK and came into force on 25 May 2018. It incorporates the European Union’s General Data Protection Regulation into UK law, tailoring GDPR-style obligations for UK-specific contexts – including dedicated rules for law enforcement processing under Part 3 and intelligence services under Part 4.

  • The UK GDPR was created after Brexit in 2019 through the EU Exit Regulations. It retains the same core data protection principles, data subject rights, fines and obligations as its EU predecessor but operates under UK jurisdiction. The UK GDPR applies to organisations processing data of UK residents, and the Act defines personal data as any identifiable information about individuals.

  • The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and amends both the UK GDPR and the Data Protection Act 2018, as well as PECR. It does not replace these laws – it updates them.

  • The Privacy and Electronic Communications Regulations govern electronic marketing and communications alongside the UK GDPR, covering areas such as electronic communications, cookies and direct marketing.

Throughout this article, “data protection law” refers to this combined framework. The Information Commissioner’s Office (ICO) remains the primary interpretive resource, and organisations should rely on ICO guidance rather than outdated EU GDPR commentary.

Key recent reforms under the Data (Use and Access) Act 2025

The DUAA’s policy aims are threefold: supporting innovation, reducing administrative burdens and clarifying data protection rules – without lowering protections for individuals.

The Act changes several major areas:

  • Recognised legitimate interests as a new lawful basis for specified processing purposes

  • Expanded permissions and safeguards for automated decision making and profiling

  • Clarified subject access request handling, including time-limit adjustments

  • Broadened definition of scientific research to include commercial research and statistical purposes

  • Simplified international data transfer mechanisms and “data bridge” decisions

  • Updates to cookies and storage/access technologies under PECR

  • Reinforced ICO investigation and enforcement powers

The DUA Act also underpins “Smart Data” schemes, digital identity verification and the National Underground Asset Register – initiatives that sit alongside but rely on the updated data protection rules.

Organisations must not treat the DUAA as optional or purely future-facing. The DUA Act introduces a new lawful ground for processing data, clarifies time limits for responding to subject access requests, allows certain cookies to be used without consent, and simplifies international data transfer rules. These changes alter how existing UK GDPR and Data Protection Act 2018 requirements are interpreted right now.

Core UK data protection principles and how DUAA affects them

The key principles of UK GDPR remain the foundation of every compliance programme. They have not been removed or weakened by the DUAA.

The six data protection principles (plus accountability) are:

Principle

What it requires

Lawfulness, fairness and transparency

Personal data must be lawfully processed and handled in a transparent manner

Purpose limitation

Data must be collected for specified, explicit and legitimate purposes only

Data minimisation

Only data that is necessary for the stated purpose should be collected

Accuracy

Personal data must be kept accurate and up to date

Storage limitation

Personal data should not be retained longer than necessary

Integrity and confidentiality

Appropriate security measures must protect data from unauthorised access or loss

Accountability

Controllers must demonstrate compliance with data protection principles

Lawfulness, fairness, and transparency are among the seven fundamental principles of UK GDPR. Data minimisation mandates collecting only what is necessary for the purpose. Purpose limitation requires data to be collected for specified purposes only. Storage limitation dictates that personal data should not be retained longer than necessary. Integrity and confidentiality require appropriate security measures to protect data.

The DUAA clarifies how these principles apply in newer contexts. For example, purpose limitation and compatibility rules have been adjusted to allow re-use of personal data for certain public interest or emergency purposes, provided specific criteria are met. For AI and analytics use cases, organisations should reassess whether their data minimisation practices genuinely limit collection to what is necessary – or whether legacy systems are harvesting more personal data relating to individuals than current processing requires.

Accountability remains central. Organisations must document how they apply the data protection principles under the new regime, including updated Records of Processing Activities (RoPA), DPIAs and internal policies. The Act requires organisations to demonstrate compliance with data protection principles, and controllers must demonstrate compliance through clear documentation.

Data subjects, lawful bases and recognised legitimate interests

A data subject is any identifiable living individual whose personal data is being processed. Personal data includes any information relating to an identifiable person – from names and email addresses to IP addresses and location data.

Businesses must establish a lawful basis before processing personal data. The six main lawful bases under Article 6 UK GDPR are:

  • Consent – the individual has given clear, informed agreement (e.g. opting in to a marketing newsletter)

  • Contract – processing is necessary to fulfil a contract with the data subject (e.g. delivering a purchased product)

  • Legal obligation – processing is required by UK law (e.g. payroll reporting to HMRC)

  • Vital interests – processing is necessary to protect someone’s life (e.g. sharing medical data in an emergency)

  • Public tasks – processing is necessary for a public authority to perform its official functions

  • Legitimate interests – processing is necessary for a legitimate purpose that doesn’t override the individual’s fundamental rights (e.g. fraud prevention, network security)

The DUAA introduces a seventh category: recognised legitimate interests. This legal basis is pre-approved for specific purposes including crime prevention, safeguarding of children and vulnerable adults, public security, and emergency response. Where processing falls under a recognised legitimate interest, the usual balancing test is not required – but necessity and proportionality assessments and compliance with data protection principles still apply.

Organisations should review existing Legitimate Interest Assessments to determine whether any current processing can now be reclassified under recognised legitimate interests, and update documentation, privacy notices and lawful basis justifications accordingly.

Special category data and criminal convictions data

Special categories of personal data – health records, biometric and genetic data, racial or ethnic origin, religious beliefs, sexual orientation and related sensitive information – carry elevated protections under Article 9 UK GDPR. Criminal convictions and offences data is subject to additional rules under data protection legislation, governed by Article 10 and Schedule 1 of the Data Protection Act 2018.

Processing such data requires both a lawful basis under Article 6 and a separate condition under Article 9 or Schedule 1, plus an “appropriate policy document” in many cases. The DUAA gives the Secretary of State powers to amend Schedule 1 conditions and clarify substantial public interest grounds – covering, for example, employment vetting, safeguarding and regulatory obligations for professional bodies.

A practical workplace example: an employer conducting enhanced DBS checks for roles involving children must hold both a valid Article 6 basis and a Schedule 1 condition for personal data relating to criminal convictions. Occupational health records used in fitness-to-work assessments similarly require dual justification and strict access controls.

Regulatory expectations are higher when handling special category data. Organisations must implement strong technical and organizational measures for security, access control and retention, and complete DPIAs before commencing high-risk processing.

Automated decision making and profiling: new rules and risks

UK GDPR Article 22 restricts significant automated decisions – those based solely on automated processing (including profiling) that produce legal effects or similarly significant impacts on a data subject. Previously, such decisions were only permitted with explicit consent, contractual necessity or statutory authorisation.

The DUAA broadens when automated decision making is permitted but introduces mandatory safeguards: meaningful human involvement in oversight, the ability for data subjects to obtain human intervention and challenge decisions, and clear information provided to the individual about how the decision was reached.

Concrete examples of high-impact automated decisions include credit scoring, automated job application screening, dynamic pricing algorithms and fraud-blocking systems. In each case, organisations must now ensure that a human can review and override automated outcomes when requested.

For law enforcement processing under Parts 3 and 4 of the Data Protection Act 2018, the DUAA aligns some requirements but adds exemptions for national security or legal privilege – subject to meaningful human review after the fact. Intelligence services benefit from similar carve-outs, though safeguards remain.

Practical steps for organisations: revise ADM/profiling DPIAs, update privacy notices to describe automated processing in clear and plain language, log all significant automated decisions, and train staff on when a decision is “solely” automated versus one with genuine human intervention.

Data subject rights: access, rectification, erasure, portability and objection

Data subject rights remain largely unchanged under UK GDPR and the Data Protection Act 2018, but the DUAA clarifies how some must be handled in practice.

Individuals have the right to know how their data is used under UK data protection law. The core rights are:

  • Access – data subjects can request access to their personal data

  • Rectification – data subjects may request correction of inaccurate personal data

  • Erasure – data subjects can request erasure of their personal data

  • Restriction – data subjects have the right to restrict processing of their data

  • Data portability – data subjects can request data portability in a machine readable format

  • Objection – individuals can object to processing, including for direct marketing

  • Automated decisions – rights to obtain human intervention in relation to significant automated decisions

The DUAA’s changes to subject access requests are particularly significant. Organisations perform reasonable and proportionate searches when responding, rather than exhaustive searches across every system. A new “stop the clock” mechanism allows response deadlines to pause when the organisation needs clarification from the requester – once the information is provided, the one-month time limit resumes.

Operationally, this means organisations should establish SAR triage processes, robust identity verification, defined search strategies across email and messaging systems, clear redaction protocols, and documented justifications when declining or narrowing requests. The DUAA does not remove obligations but gives more practical tools to handle vexatious or excessively broad requests when properly documented and justified.

International data transfers and UK adequacy decisions

UK GDPR Chapter V continues to govern transfers of personal data to countries outside the UK. The DUAA aims to simplify and accelerate “data bridge” decisions while maintaining appropriate safeguards.

The core transfer tools available to organisations are:

  • UK adequacy regulations (“data bridges”), including the EU’s renewed adequacy decision for the UK, extended to 27 December 2031

  • International Data Transfer Agreements (IDTAs)

  • Addendums to EU Standard Contractual Clauses (SCCs)

The DUAA allows the UK government to create flexible data bridges and to restrict transfers to destinations that impose serious limitations on data protection. Around 39% of UK businesses that transfer personal data outside the UK report using no recognised legal safeguard – a significant risk area.

UK organisations should act now: map all cross-border data flows, verify the transfer tool used with each processor and data controller, document transfer risk assessments, and align with the latest ICO guidance. Data Privacy Services can review your international transfer arrangements as part of a free data protection audit and ongoing DPO as a Service engagement.

Security, breach notification and enforcement under UK data protection law

Integrity and confidentiality under UK GDPR’s Article 32 require organisations to implement appropriate security measures proportionate to the risk. Organisations must implement strong technical and organizational security measures – covering encryption, access controls, pseudonymisation and regular testing. Compliance obligations vary for different sectors and types of organisations, but the baseline expectation applies universally.

UK GDPR mandates data breach notifications within 72 hours. Breaches must be reported to the ICO without undue delay and, where feasible, within that window. In high-risk cases, affected data subjects must also be notified. Record-keeping of all incidents – reportable or not – is mandatory.

The ICO’s enforcement powers include investigations, compulsory information notices, assessment notices (audits), stop-processing orders and financial penalties. The maximum fine under UK GDPR is £17.5 million or 4% of global annual turnover, whichever is higher. Fines for non-compliance can reach £4,350 for controllers who fail to pay the data protection fee, while the maximum fee for large organisations is £2,900.

Recent enforcement actions underline the ICO’s priorities:

  • South Staffordshire Waterfined £963,900 in May 2026 after a cyber attack went undetected for nearly two years, exposing personal data of over 633,000 customers and employees

  • Reddit, Inc. – fined £14,472,500 for breaches involving user data privacy in the online technology sector

  • Capita plc – fined a combined £14 million for security failures affecting approximately 6.6 million individuals, including special category data

By mid-2026, the ICO had issued six monetary penalty notices totalling approximately £16 million. ISO 27001-aligned controls, security audits and incident response planning are practical ways to evidence compliance and reduce breach risk.

Electronic marketing, cookies and storage/access technologies

While UK GDPR governs personal data, the Privacy and Electronic Communications Regulations and DUAA changes govern many aspects of electronic marketing and the use of cookies or similar technologies.

For direct marketing, the lawful bases under UK GDPR are usually consent or legitimate interests – but the absolute right to object to direct marketing remains in all cases, including profiling related to such marketing. Law enforcement agencies and other organisations using marketing channels must respect these rules equally.

The DUAA updates cookie rules: certain low-risk cookies and similar storage/access technologies (for example, some analytics or security-related technologies) may now be used without consent, provided users are fully informed and have an easy opt-out. Hidden or pre-ticked consent remains non-compliant.

In 2026, compliant cookie banners should:

  • Use clear and plain language to explain what technologies are in use

  • Offer genuine choice with equally prominent “accept” and “reject” options

  • Allow granular control through a preference centre

  • Not rely on consent for exempt low-risk cookies, but still inform users

Organisations should also review email and SMS marketing lists, suppression files and third-party advertising relationships under updated data protection and PECR rules. If you collect information for marketing, ensure your contact details records reflect current consent status and objection rights.

Children's data protection, online services and profiling

Children receive enhanced protection under UK data protection law. The Age Appropriate Design Code (Children’s Code) and DUAA changes are particularly relevant for online services and app-based products.

The Data Protection Act 2018 sets the digital consent age at 13 for “information society services” offered directly to children. Organisations must identify when their online services are likely to be accessed by children – and if so, apply higher standards.

The DUAA emphasises designing services with children’s data protection in mind from the outset. This includes restricting profiling and automated decision making safeguards for child users, and ensuring data processing meets the data protection principles with added rigour.

Practical measures include:

  • Age assurance mechanisms appropriate to the risk level

  • Default privacy settings set to maximum protection

  • Limits on geolocation tracking and behavioural profiling

  • Child-friendly transparency information written in plain language

Organisations with any significant child user base should undertake specialised DPIAs and periodic audits. Data Privacy Services can support this through consultancy and certified data protection officer training.

The role of the ICO and evolving regulation in the UK

The ICO is the supervisory authority for data protection in the UK, headquartered at Wycliffe House, Wilmslow. It is the supervisory authority for UK GDPR compliance, and its remit covers other laws including PECR and relevant provisions of the Data Protection Act 2018.

Under the DUAA, the ICO gains new or strengthened powers: the ability to compel witness attendance at interviews, request reports from approved persons during investigations, and take more targeted enforcement action. These tools make investigations more efficient and penalties harder to avoid.

ICO guidance on the DUAA, UK GDPR and the Data Protection Act 2018 is being updated in stages. Organisations should subscribe to ICO updates rather than rely on outdated commentary from the pre-Brexit era.

Organisations should voluntarily engage with the ICO in cases involving major breaches, complex high-risk processing (such as large scale profiling or AI deployment), or where prior consultation is legally required before commencing certain types of data processing.

Individuals can complain to the Information Commissioner’s Office and seek judicial remedies, increasing litigation and reputational risk for non-compliant organisations. It establishes rights for individuals regarding their personal data that are enforceable through both the regulator and the courts.

What UK organisations should do now to stay compliant

The 2025–2026 changes mean that even previously compliant organisations should treat 2026 as a “refresh year” for their data protection programme. Organisations are encouraged to build data protection into their operations as a proactive measure, not a reactive one.

Key practical steps:

  • Update RoPA and lawful basis assessments, including review of recognised legitimate interests

  • Revise privacy notices to reflect DUAA changes and ensure information is provided in clear and plain language

  • Refresh SAR procedures with defined search strategies and “stop the clock” processes

  • Reassess ADM/profiling DPIAs for all significant automated decisions

  • Map international transfers and verify each data bridge or transfer tool

  • Align marketing and cookie practices with DUAA and the latest ICO guidance

Governance actions matter equally: board-level briefings on regulatory change, revised data protection policies, updated processor contracts, and integration with information security management frameworks such as ISO 27001. Core activities across every function should reflect the new requirements.

Staff awareness and role-specific training – for HR, marketing, IT, customer service – is essential to make these legal reforms operational, not just theoretical.

Top 10 actions for 2026:

  1. Conduct a gap analysis against DUAA requirements

  2. Update all lawful basis documentation and LIAs

  3. Review and revise privacy notices

  4. Audit automated decision-making systems

  5. Map and verify international data transfers

  6. Refresh cookie banners and preference centres

  7. Assess children's data practices and age assurance

  8. Strengthen breach detection and incident response

  9. Update processor and vendor contracts

  10. Deliver role-specific data protection training

How Data Privacy Services can help: DPO as a Service and free data protection audits

Data Privacy Services (trading name of Data Privacy and Data Security Services Limited) is a UK and Cyprus-based specialist consultancy in GDPR, UK data protection law and information security for organisations of all sizes.

Our free GDPR / data protection audit provides a quick review of your current policies, records of processing, security posture, data subject rights handling and DUAA readiness. You receive a short risk report with prioritised recommendations – at no cost and with no obligation. For a deeper understanding of the audit process, see our guide on understanding the GDPR audit.

Our DPO as a Service provides an outsourced data protection officer function, delivering ongoing advice, DPIA review, breach support, training and liaison with the ICO. This is particularly valuable for organisations required to appoint a DPO under Article 37 UK GDPR – where a public authority or an organisation’s core activities involve large scale processing of personal data. DPOs must have expert knowledge of data protection law, must report directly to the highest management level, and cannot be dismissed for performing their tasks. Groups of organisations can appoint a single DPO for multiple entities, and smaller organisations benefit from outsourced expertise without the overhead of a full-time hire. Controllers must appoint a DPO if they process personal data at the scale or nature that triggers the statutory requirement.

We also provide ISO 27001-certified security audits, CISO-as-a-Service, DSAR management services, training and risk assessments – all designed to support wider data protection compliance for both private and public sector organisations.

UK data protection law has shifted significantly, and the window for passive compliance has closed. Whether you need a full compliance refresh or reassurance that your policies are current, acting now is the most cost-effective approach.

Contact Data Privacy Services today to book your free data protection audit or discuss DPO as a Service – and align your organisation with the latest UK data protection regulation.

Leave a Reply

Your email address will not be published. Required fields are marked *

Thank you for contacting us

We will respond shortly

Note – if you do not receive an email from us please check your spam folder as we normally respond within 2 hours.