Data (Use and Access) Act 2025 amends UK GDPR requirements for data sharing and access

Original title: Data (Use and Access) Act 2025 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 has introduced amendments to the UK General Data Protection Regulation, affecting how personal data must be shared and accessed in digital markets. These changes modify processing obligations for data controllers and introduce new requirements for data sharing in specific contexts. Organisations handling personal data in the UK must review their data governance frameworks to ensure compliance with the amended GDPR provisions, particularly regarding data access and portability mechanisms.

What changed

  • The Data (Use and Access) Act 2025 introduces modifications to UK GDPR, effective from March 2026, establishing new requirements for data controllers regarding data sharing and access obligations in digital services
  • Amendments affect the scope and mechanisms for exercising data subject rights, particularly in relation to data portability and third-party access
  • New provisions establish requirements for interoperability and data access in specific digital market contexts covered by the Act

Who is affected

Organisations in the UK subject to UK GDPR, particularly those operating in digital markets, offering digital services, or acting as data holders. Data controllers and processors must assess impact on their data governance and consent mechanisms. The text does not specify whether these changes apply sector-specifically or by organisation size.

Summary generated by a language model; the official text prevails. Not legal advice.