Data (Use and Access) Act 2025 amends Data Protection Act 2018

Original title: Data (Use and Access) Act 2025 effect on Data Protection Act 2018

The Data (Use and Access) Act 2025 amends provisions of the Data Protection Act 2018, modifying the UK data protection regulatory framework. This change affects how data controllers and processors must handle personal data under UK GDPR, requiring compliance with updated obligations introduced by the new legislation. Organizations subject to UK data protection rules must review and update their data handling practices to align with the amended requirements.

What changed

  • Data (Use and Access) Act 2025 introduces modifications to Data Protection Act 2018 sections and schedules affecting data controller and processor obligations
  • Updates to UK GDPR implementation through DPA 2018 create new or modified compliance requirements for organizations processing personal data in the UK
  • Changes affect the regulatory framework governing personal data use and access rights, requiring organizations to reassess their data governance policies

Who is affected

All organizations processing personal data under UK GDPR in the United Kingdom, including data controllers and processors in both public and private sectors

Summary generated by a language model; the official text prevails. Not legal advice.