Duty

The Data (Use and Access) Act is live: seven changes every UK business should know

The main data protection changes in the Data (Use and Access) Act took effect on 5 February 2026. Here are the seven that matter most for an ordinary UK business, in plain language, with what each one means in practice.

TheDutyDesk Editorial9 February 20263 min readReviewed 7 June 2026

The biggest update to UK data protection rules since 2018 took effect on 5 February 2026.[6] The Data (Use and Access) Act does not tear up the rulebook. It adjusts it in several specific places, and a few of those changes touch jobs that ordinary businesses do every week.

Here is the short version of the seven that matter most.

The seven changes in plain terms

1. A new duty to handle complaints. From 19 June 2026, every organisation must have a proper process for data protection complaints and must acknowledge them within 30 days.[2] There are no exemptions for being small.

2. Easier subject access requests. You can now pause the response clock while you confirm someone's identity or ask what they actually want, and you only have to make a "reasonable and proportionate" search rather than turn over every stone.[1]

3. Looser cookie rules. A handful of low-risk cookies, including basic analytics, no longer need a consent pop-up.[1]

4. Bigger cookie fines. The trade-off for looser rules: penalties for breaking the cookie and marketing rules now match GDPR levels, up to £17.5m.[1]

5. A new "recognised legitimate interests" reason for using data. For a short list of public-interest purposes, you can use data without the usual balancing exercise.[1]

6. New rules for automated decisions. The old near-ban on fully automated decisions about people is replaced by a system of safeguards.[1] [3]

7. A new-look regulator. The Information Commissioner's Office is being reshaped into the Information Commission, with a board structure like other major UK regulators.[1]

What this means for you

Most businesses do not need to panic, but two of these have hard deadlines and real teeth.

The complaints duty is the one to plan for now, because it applies to everyone and starts on a fixed date. The cookie fines are the one to check this week, because the rules changed and the penalty for getting them wrong jumped sharply.

The rest reward a bit of housekeeping rather than a project. Knowing what data you hold, why you hold it, and how someone can complain about it covers the ground that nearly all of these changes touch.

Sources used in this article

  • [1]Data (Use and Access) Act 2025
  • [2]Data Protection Act 2018 (post-DUAA consolidated)
  • [3]UK GDPR (retained EU regulation)
  • [6]Commencement regulations (SI 2026/82)

Source verification and SHA-256 hashes are maintained in our sources index.

Last reviewed: 7 June 2026. Next review: 9 August 2026, or sooner if relevant guidance changes.

TheDutyDesk helps you manage data protection complaints with a structured process and an audit trail.