Data (Use and Access) Act 2025 amends UK GDPR provisions on data rights and access mechanisms

Original title: Data (Use and Access) Act 2025 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 brings modifications to the UK GDPR framework, effective from the act's implementation date. These changes affect how organisations must handle data subject rights, particularly regarding data access, portability, and the provision of data in reusable formats. Controllers will need to review and update their data handling processes, consent mechanisms, and technical systems to comply with the new requirements for facilitating data portability and interoperability.

What changed

  • {UNAVAILABLE: The source document URL points to a legislative changes record, but the specific amendments are not detailed in the provided information. To accurately list what changed in the GDPR text itself, the full amendment schedule or the modified GDPR provisions would be needed.}

Who is affected

All UK organisations processing personal data (controllers), particularly those providing digital services, online platforms, and data intermediaries. Data subjects exercising rights to access, port, and reuse their personal data. Applies across all sectors in the UK jurisdiction.

Summary generated by a language model; the official text prevails. Not legal advice.