Data (Use and Access) Act 2025 amendments modify UK GDPR obligations for data controllers
Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 introduce amendments affecting the UK GDPR framework. These changes align UK data protection law with the new data use and access regime while maintaining compliance obligations for organisations processing personal data. Organisations must review their data handling practices to ensure alignment with updated GDPR requirements under the new regulatory framework.
What changed
- The Data (Use and Access) Act 2025 introduces consequential amendments to UK GDPR provisions affecting how data controllers must handle personal data and respond to data subject rights requests
- Transitional provisions establish implementation timelines and compliance deadlines for organisations to adapt their data processing activities to amended GDPR requirements
- Updates clarify the relationship between UK GDPR obligations and new data use and access rights introduced under the 2025 Act
Who is affected
Organisations processing personal data in the UK under UK GDPR, including data controllers and processors across all sectors and sizes
Summary generated by a language model; the official text prevails. Not legal advice.