Data (Use and Access) Act 2025 modifies UK GDPR requirements for data access and processing

Original title: Data (Use and Access) Act 2025 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 introduces amendments to the UK General Data Protection Regulation (UK GDPR), effective from the legislation's commencement date. These changes affect how data controllers and processors must manage data access requests, handle personal data processing, and comply with data subject rights. Organizations subject to UK GDPR must review and update their data handling procedures, privacy policies, and contractual arrangements to align with the new requirements introduced by this Act.

What changed

  • The Data (Use and Access) Act 2025 introduces statutory modifications to how UK GDPR applies to data access and processing operations
  • Changes affect the framework for data subject rights exercise, including access requests and data portability under UK GDPR
  • New provisions may impact how data controllers implement transparency obligations and accountability measures
  • Amendments address data processing rights and the relationship between controllers and processors under UK GDPR
  • The Act modifies compliance requirements for organizations handling personal data subject to UK GDPR jurisdiction

Who is affected

Organizations processing personal data in the United Kingdom subject to UK GDPR, including data controllers, data processors, and entities handling data subject rights requests. All sectors are potentially affected, with particular impact on entities managing data access processes and personal data transfers.

Summary generated by a language model; the official text prevails. Not legal advice.