Data (Use and Access) Act 2025 introduces new requirements affecting Data Protection Act 2018
Original title: Data (Use and Access) Act 2025 effect on Data Protection Act 2018
The Data (Use and Access) Act 2025 has come into effect and modifies the Data Protection Act 2018, introducing new requirements for data handling, access, and use. Organizations subject to UK GDPR must review the amended provisions to ensure compliance with both the Data Protection Act 2018 and the new Act's requirements. The changes establish additional obligations regarding data access rights and permissible use cases that apply alongside existing data protection frameworks.
What changed
- The Data (Use and Access) Act 2025 introduces new legislative requirements that modify the Data Protection Act 2018, effective from 2026-03-23
- Data controllers and processors must comply with new provisions governing data access and use introduced by the 2025 Act
- Organizations must assess how the new Act's data access requirements interact with existing UK GDPR and Data Protection Act 2018 obligations
Who is affected
All organizations processing personal data in the UK subject to UK GDPR and the Data Protection Act 2018, including data controllers, processors, and businesses handling personal data.
Summary generated by a language model; the official text prevails. Not legal advice.