Data (Use and Access) Act 2025 modifies UK GDPR requirements for data access and portability
Original title: Data (Use and Access) Act 2025 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 amends the UK General Data Protection Regulation by introducing new requirements for data access and portability. Organizations handling personal data must now comply with expanded obligations regarding how data subjects can access and port their data. These changes affect data controllers and processors managing personal information under UK GDPR, requiring updates to data handling practices and policies.
What changed
- Data (Use and Access) Act 2025 amends UK GDPR framework with effective date of 23 March 2026, introducing modifications to data access and portability rights for data subjects
- New or modified requirements for data controllers regarding facilitation of data subject access requests and data portability in compliance with the amended regulation
Who is affected
Organizations subject to UK GDPR, including data controllers and processors handling personal data of UK residents. Applies across all sectors and sizes of organizations processing personal data under UK GDPR jurisdiction.
Summary generated by a language model; the official text prevails. Not legal advice.