Data (Use and Access) Act 2025 amends UK GDPR requirements for data access and portability
Original title: Data (Use and Access) Act 2025 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 modifies the application and requirements of the UK General Data Protection Regulation, specifically in areas relating to data subject rights of access and data portability. These amendments introduce new procedures and standards for how organizations must respond to data access requests and facilitate data portability for individuals. The changes affect data controllers' obligations to provide timely and structured responses to individuals exercising their rights under the GDPR.
What changed
- The Data (Use and Access) Act 2025 modifies provisions of the UK GDPR relating to data subject rights, particularly those concerning access to personal data and data portability
- New requirements are introduced regarding how data controllers must process and respond to data access requests from individuals
- The amendment establishes procedures for facilitating data portability, allowing individuals to obtain and reuse their personal data across different services
- Changes affect the technical standards and formats in which organizations must provide data to individuals exercising their rights
Who is affected
All organizations processing personal data in the UK that handle data subject access requests and data portability obligations under the UK GDPR, including private companies, public authorities, and service providers across all sectors
Summary generated by a language model; the official text prevails. Not legal advice.