In mid-June, the Data (Use and Access) Act, 2025 finally received the royal assent after several rounds of revision since 2021. The amendment comes with clarifications to existing laws and updates, rather than significant changes.
Overview of the DUAA 2025 key provisions :
- When and how personal data may be used for scientific research
- Eases limits on certain automated decisions that rely on personal data
- Circumstances under which cookies can be set without explicit consent
- Permitted email-marketing practices for charities
- Expanded guidance on using “legitimate interests” as a lawful basis
- Requirement for organisations to have a clear complaints procedure
- Children’s data protection requirements
Here is a better and closer look at the Data (Use and Access) Act.
What is the Data (Use and Access) Act of 2025?
The DUAA amends the data protection laws of the United Kingdom, namely the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018 (DPA), and the Privacy and Electronic Communications Regulations (PECR).
- Scope: It applies to organisations that process personal data in the UK or offer goods or services to individuals located in the UK.
- Aim: DUAA aims to promote innovation and provide further clarification to some key concepts under UK GDPR and DPA.
It also establishes the Information Commission, replacing the ICO as the enforcement agency.
The changes will be implemented in stages within 12 months. Therefore, businesses should take charge and understand what the changes mean to them.
What are the key concepts of the UK Data (Use and Access) Act?
This section provides a snapshot of the key changes and updates that the amendments to UK privacy laws bring.
#1 Research and statistical purposes: Meaning and consent requirements
- Scientific research means any project you can fairly call science, whether it is academic, commercial, public, or privately funded.
- It covers tech development, prototypes, fundamental and applied research. Public-health studies qualify, too, provided they serve the public interest.
- Historical research is widened to include genealogy (the study of family history).
- Work done purely for statistical purposes is allowed when the output is aggregate, non-personal data and is never used to take actions about specific people.
- Researchers may obtain broad consent from participants for a specific area of scientific studies even when the precise purposes of data processing are not yet known.
In most cases, processing of personal data for research or statistical purposes is generally considered compatible with the original purpose of collection.
However, this new use must be carried out in a fair, lawful, and transparent manner, with appropriate safeguards in place to protect individuals’ rights.
Additionally, the business must identify a valid lawful basis for this new processing, which may differ from the original basis used for service delivery.
#2 Recognised legitimate interests
The amendment brings a new lawful ground named Recognised Legitimate Interests (RLIs). These are a finite list of high-public-interest purposes.
RLIs allow organisations to process personal data for certain purposes like crime prevention, national security, emergencies, etc, without a legitimate interest assessment (LIA).
When disclosing personal data that is strictly necessary for one of these RLIs, the controller:
- may rely on the RLI as a lawful basis without carrying out the usual Legitimate Interest Assessment (LIA); and
- need not perform the balancing test between its interests and the data subject’s rights.
The receiving party must, of course, have its own legal power to process the data for that RLI purpose.
Example: An online marketplace transferring seller-account details and IP addresses to Trading Standards after counterfeit goods are uncovered is an example of relying on RLI for crime prevention.
Previously, controllers needed to balance the legitimate interest with the rights and freedoms of data subjects(LIA). The DUA Act 2025 simplify this by explicitly indicating when such an assessment is no longer required.
Recognised legitimate interests under the UK DUAA, 2025


#3 Cookies and tracking technologies
The general rule is that you need consent for storing internet cookies on user devices. Interestingly, the Data (Access and Use) Act sets out situations where this won’t apply.
This means that you may not require consent for the following:
- Cookies that are necessary for providing the service
- First-party analytics cookies that are used for statistical purposes to measure website performance
- Cookies that adapt how the site looks or works for that person’s device or preferences
Do you need cookie consent under the updated UK data privacy amendments?
Yes. You still need to obtain cookie consent from users visiting your website under the DUAA 2025.
The Data (Use and Access) Act does not exempt businesses from cookie consent requirements. Instead, it clarifies which cookies do not require consent. Most of these already fall under the category of essential cookies, which can be used without user permission. This is because they are technically necessary for the basic and important functions.
Note: The amendment now allows websites to use first-party cookies for statistical and research purposes, such as analysing how users interact with the site or application, to drive improvements.
Forget cookie consent confusions
Sign up to CookieYes and stay compliant with UK cookie consent laws
Sign up for free14-day free trialCancel anytime
#4 Purpose limitation: Know when you can reuse personal data
When you want to use personal data for something new, Article 5(1)(b) of UK GDPR says you must check whether that fresh use sits comfortably with the reason you collected it in the first place.
Section 71 of the DUA Act inserts Article 8 (A), which clarifies the factors to check if further processing is compliant with UK GDPR:
- Link between purposes: Are the old and new aims closely related?
- Collection context: What was the relationship with the person when you took the data? Did they expect reuse?
- Nature of the processing: Is it sensitive data (health, race, etc.) and does it pose any privacy risks?
- Possible impact: Could the new use harm or disadvantage people?
- Safeguards: Are strong protections in place, such as encryption, pseudonymisation, and access limits?
If after looking at these, the new purpose seems too far removed or risky, you must find another legal basis (like fresh consent) or stop the processing.
What if the data were collected on the basis of consent?
In that case, you usually need to ask again, unless the new use falls into the compliance check or public-interest categories and getting fresh consent would be unrealistic.
#5 Response to data subject requests
Organisations must respond to data subject requests within one month from the relevant time.
The relevant time may be when the controller or organisation receives the request, when they obtain the information from the data subject, or when the fee is paid.
They can also extend the response period by 2 months by giving prompt notice in special scenarios.
Earlier, the window for a Subject Access Request began immediately. The new Act lets you “stop the clock” while you wait for the requester to clarify or supply missing information; once you have what you need, the timer resumes.
Furthermore, the Data (Use and Access) Act specifies that controllers are only expected to search with reasonable effort when responding to a data subject request. This means that businesses may not need to search every possible record or archive if doing so would be unreasonable, excessive, or disproportionate in effort or cost.
#6 Automated decision-making
Under the current UK GDPR, organisations can only make significant decisions based solely on automated processing (like profiling) in limited circumstances, such as when it’s necessary for a contract, required by law, or based on explicit consent.
The DUAA 2025 replaces this restriction with a more flexible approach. Most significant decisions based on automated processing will now be permitted on a lawful basis, including legitimate interests, as long as appropriate safeguards are in place.
These safeguards are:
- Clear information for individuals about the decision and how it was made
- A way for them to challenge or respond to the outcome
- The option to request human intervention
However, if the decision involves special category data (e.g., health, race, biometrics), stricter rules remain:
- You need explicit consent, or
- The processing must meet a substantial public interest condition and be necessary for a contract or required by law.
Also, if your lawful basis is a Recognised Legitimate Interest (RLI) under the Act, you may not be able to rely on ADM alone for significant decisions. In that case, manual involvement is required.
This expands the use of AI-driven systems in business processes, especially where only standard (non-sensitive) personal data is involved.
#7 Children’s online privacy
The update to Article 25 of the UK GDPR makes it explicit that any online service likely to be used by children must build in stronger privacy safeguards from the start.
For this, organisations must consider higher protection matters such as their limited awareness of data risks and evolving needs, when choosing technical and organisational measures.
The above rule applies only to services aimed at minors (excluding counselling or preventive services) and doesn’t change the requirements for other user groups.
#8 Soft opt-ins for charity
The UK DUAA, 2025, allows charities to email those who have previously expressed interest in their purposes, classifying this as direct marketing.
However, recipients must have the option to opt out at any time.
Want to comply with UK cookie laws?
Sign up to CookieYes and automate your consent management today
Sign up for free14-day free trialCancel anytime
FAQ on UK Data (Use and Access) Act, 2025
The Data (Use and Access) Act, 2025, amends and updates the current data protection regimes, including the UK GDPR. It aims to bring all the data protection laws on the same page and simplify the law for organisations while also tailoring it for innovations and economic growth.
The amendments are expected to come into effect within a year. Though it does not make significant changes, it clarifies the definition of scientific research, allows temporarily pausing the response period, and widens permission for automated decision-making.
In the United Kingdom, data protection is governed by both the UK GDPR and the Data Protection Act 2018, with recent amendments introduced by the UK Data Use and Access Act to update the existing framework.


