Insights

Six months of the Data (Use and Access) Act: where things stand

A plain-English round-up of the Data (Use and Access) Act so far: what has already taken effect, what is still coming, and the short list of things a UK business should do now.

TheDutyDesk Editorial5 June 20263 min readReviewed 7 June 2026

The Data (Use and Access) Act has been arriving in stages rather than all at once, which has made it hard to know what actually applies today. Here is the plain-English picture as of June 2026, and a short list of what to do next.

What has already taken effect

Most of the main data protection changes came into force on 5 February 2026.[6] Since then:

the rules on subject access requests are clearer, with the ability to pause the clock and to make only a reasonable and proportionate search;

some low-risk cookies no longer need a consent pop-up, while the fines for getting cookies and marketing wrong have risen sharply, with the final cookie guidance published in April 2026;[20]

there is a new "recognised legitimate interests" reason for using data in certain cases, with regulator guidance issued in March 2026;[21]

and the old near-ban on automated decisions has been replaced by a system of safeguards.[1]

What is still coming

The big date on the horizon is 19 June 2026, when the new duty to handle data protection complaints takes effect.[4] Every organisation must have a way to receive complaints, must acknowledge them within 30 days, and must investigate and respond.

The regulator itself is also changing, moving from the Information Commissioner's Office to the Information Commission during 2026.

Your short list before 19 June

If you do nothing else, do these.

Set up a clear way for people to raise a data protection complaint, name who owns it, and start logging the date each one arrives.

Check your cookie banner: stop any tracking that fires before consent, and tidy your marketing lists while the cost of getting it wrong is high.

Write down, in a page or two, what personal data you hold, why, and where it goes. Almost every change this year is easier to handle once that page exists.

None of this requires a lawyer on retainer. It requires a little structure and the habit of writing things down. The organisations that get the basics in place before the June deadline will find everything that follows much simpler.

Sources used in this article

  • [1]Data (Use and Access) Act 2025
  • [6]Commencement regulations (SI 2026/82)
  • [4]ICO guidance on complaint handling
  • [20]ICO guidance on storage and access technologies (final, April 2026)
  • [21]ICO guidance on recognised legitimate interests, March 2026

Source verification and SHA-256 hashes are maintained in our sources index.

Last reviewed: 7 June 2026. Next review: 5 December 2026, or sooner if relevant guidance changes.

TheDutyDesk helps you manage data protection complaints with a structured process and an audit trail.