Guide · Data & Privacy

Data (Use and Access) Act 2025

What the DUAA changed in UK data-protection law - and which changes matter when you exercise your rights or complain about how an organisation uses your information.

The DUAA updates the UK GDPR, Data Protection Act 2018 and privacy rules. It does not replace them.

The Data (Use and Access) Act 2025 - usually shortened to DUAA - is a wide-ranging Act that changes parts of the UK's data and digital-information framework. For most consumers, the important point is not to throw away everything you already know about the UK GDPR or Data Protection Act 2018. Those laws still matter. The DUAA amends them.

The changes came into force in stages. The ICO updated its public guidance on 19 June 2026 to reflect that all stages of the Act are now in force. That means current disputes should be checked against current ICO guidance rather than relying on old articles that describe the pre-DUAA position.

Key points

  • Subject access remains a legal right, but the law now expressly refers to reasonable and proportionate searches for relevant information.
  • Organisations now have statutory duties when handling data-protection complaints, including helping people complain and acknowledging complaints within 30 days.
  • The rules on significant automated decisions have changed, allowing automated decision-making in more circumstances while retaining safeguards.
  • The Act introduced recognised legitimate interests and made other changes to lawful processing and re-use of information.
  • Privacy and electronic-communications rules have changed too, including new exceptions to consent for some low-intrusion storage/access technologies.

What does “the DUAA changed data protection law” actually mean?

The UK GDPR and Data Protection Act 2018 remain the core framework for personal-data rights. The DUAA inserts, removes and rewrites parts of that framework. So if you are making a SAR, asking for rectification, challenging inaccurate credit-file data or complaining about profiling, you will still see references to the UK GDPR and DPA 2018 - but some of the wording and procedures now operate as amended by the DUAA.

This matters because a complaint can be misframed if it relies on an old version of a rule. ConsumerWise therefore treats the DUAA as part of the current framework rather than as a separate replacement law.

Subject access requests: “reasonable and proportionate searches”

One of the most practically important changes is the express rule that an organisation responding to a data-subject request only has to carry out searches that are reasonable and proportionate. This wording reflects a concept that had already appeared in regulatory practice, but it is now stated in the legislation.

That does not mean an organisation can refuse to look properly and simply say “a proportionate search was carried out”. The real question remains whether the search was reasonable and proportionate in the circumstances. If you can identify a missing call recording, known email chain, named case note, account system, complaint log or document that plainly ought to exist, that can be relevant when challenging the adequacy of the response.

For a disputed SAR, focus on the search itself: what systems were likely to hold the information, what date range was relevant, what identifiers were used, whether archived or complaint systems were considered, and why the returned material appears incomplete.

A missing document is evidence to investigate - not automatic proof that the SAR was unlawful.

  • Identify the specific material you expected and why you believe it exists.
  • Ask whether the relevant system, mailbox, recording platform or archive was searched.
  • Distinguish information that may have been lawfully withheld under an exemption from information that appears not to have been located at all.
  • If the organisation relies on proportionality, ask it to explain enough about the search to make its position intelligible without demanding information it is not required to provide.

Data-protection complaints: organisations now have express handling duties

From 19 June 2026, the DUAA's new data-subject complaint provisions are in force. The ICO says organisations must take steps to help people make a data-protection complaint, acknowledge the complaint within 30 days, investigate it appropriately and communicate the outcome without undue delay.

This creates a clearer distinction between exercising a data right and complaining about how that right - or another data-protection issue - has been handled. For example, you may make a rectification request first, then make a data-protection complaint if the organisation refuses to correct information without adequately addressing your evidence.

When escalating to the ICO, it is therefore useful to preserve the original rights request, the organisation's response, the later data-protection complaint and the complaint outcome as separate documents.

Automated decision-making and profiling

The DUAA changed the rules governing decisions made solely by automated means that have legal or similarly significant effects. The previous framework was often described as a broad prohibition subject to exceptions. The amended framework permits significant automated decisions in more circumstances, but safeguards still apply and the rules are more restrictive where special-category data is involved.

For consumers, the practical questions include, was the decision actually automated; was there meaningful human involvement; what personal information fed into it; what lawful basis was relied upon; and what safeguards or route to challenge the decision were provided?

The ICO is continuing to update its detailed automated-decision-making guidance in 2026, so this is an area where checking the current ICO material is particularly important.

Recognised legitimate interests and other processing changes

The Act introduced a category of recognised legitimate interests for specified purposes. Where that basis genuinely applies, the organisation does not carry out the ordinary legitimate-interests balancing exercise in the same way. The DUAA also changes some rules around compatible re-use of information, research and archiving, and disclosures connected with public tasks.

This does not create a general permission to process information for anything an organisation finds convenient. It must still identify an applicable lawful basis, comply with the data-protection principles and satisfy any additional conditions that apply to special-category or criminal-offence data.

Cookies and similar technologies

The DUAA also changed the Privacy and Electronic Communications Regulations (PECR). Some storage or access technologies can now be used without consent where a statutory exception applies and the intrusion on privacy is limited. The ICO's current guidance uses the broader term storage and access technologies, covering more than traditional cookies - for example tracking pixels, scripts, web storage and device-fingerprinting techniques.

This is why a modern cookie/privacy analysis should not stop at “does the website set cookies?”. The relevant question is what technology stores or accesses information on the user's device, whether an exception applies and, if not, whether valid consent was obtained.

A SAR is returned, but a known complaint call is missing.

You made a SAR asking for account notes, complaint correspondence and call recordings. The organisation supplies notes and emails but not a call recording that its own chronology refers to. After the DUAA, it is not enough to argue that every conceivable system must be searched regardless of effort. A stronger challenge identifies the particular call, approximate date, department and evidence that it existed, then asks whether the relevant telephony/recording system was included in the reasonable and proportionate search. If the organisation says the recording was deleted, the issue may then become retention, accuracy of its explanation, or whether other personal data about the call still exists.