Data (Use and Access) Act 2025 amends UK GDPR provisions on data access and processing rights

Original title: Data (Use and Access) Act 2025 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 came into effect on 23 March 2026, modifying specific provisions of UK GDPR. The Act strengthens data subjects' rights of access and controllers' obligations regarding the reuse of personal data. These changes require organisations to adapt their data handling practices, consent mechanisms, and documentation to comply with new requirements on data portability and secondary use of personal data.

What changed

  • Data (Use and Access) Act 2025 amends UK GDPR to introduce or strengthen requirements for data reuse and portability, requiring controllers to facilitate the transfer and secondary use of personal data by data subjects.
  • Amendments affect the scope and exercise of data subject rights under UK GDPR, particularly rights of access and data portability, with new conditions and procedures for their implementation.
  • Changes modify controller and processor obligations regarding documentation, records of processing activities, and transparency requirements when personal data is made available for reuse.

Who is affected

All organisations processing personal data in the UK, including data controllers and processors of all sizes across all sectors subject to UK GDPR. Particularly affected are those handling customer or employee data, digital service providers, and organisations facilitating data reuse.

Summary generated by a language model; the official text prevails. Not legal advice.