Data (Use and Access) Act 2025 modifies UK GDPR provisions on data access and sharing
Original title: Data (Use and Access) Act 2025 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 amends the UK GDPR to introduce new requirements for data access, portability, and controlled sharing mechanisms. These amendments establish procedural requirements for how controllers must facilitate data subject access and introduce requirements for sharing personal data in specific formats and through designated intermediaries. The changes affect data controllers' obligations to provide data in machine-readable formats and may require implementation of new systems for secure data access and transfer.
What changed
- Data (Use and Access) Act 2025 amends UK GDPR Regulation (EU) 2016/679 as it applies in the United Kingdom, introducing changes effective from the legislation's commencement date
- New provisions establish requirements for data controllers to facilitate data subject access rights with specified procedures and timeframes
- Amendments introduce or modify requirements for data portability, including specifications on data format, completeness, and transmission methods
- Act introduces provisions relating to data sharing mechanisms, potentially including requirements for controllers to share data through designated intermediaries or under specific conditions
Who is affected
Organisations processing personal data under UK GDPR (data controllers and processors); natural persons exercising data subject rights; potentially data intermediaries or organisations designated to facilitate data sharing</who_is_affected>
Summary generated by a language model; the official text prevails. Not legal advice.