Data (Use and Access) Act 2025 amends UK GDPR requirements for data sharing and business operations
Original title: Data (Use and Access) Act 2025 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 introduces amendments affecting the application of UK GDPR. The Act modifies data sharing requirements and access mechanisms for businesses handling personal data in the United Kingdom. Organizations must review their data processing policies and consent frameworks to ensure compliance with the revised UK GDPR provisions introduced by this legislation.
What changed
- Data (Use and Access) Act 2025 amendments to UK GDPR came into effect on 23 March 2026, modifying the legal framework for personal data processing and access rights in the United Kingdom.
- The legislation affects how data controllers must handle data sharing requests and establishes new access mechanisms for data subjects and authorized third parties.
- Changes impact data processing lawfulness assessments, as organizations must align their processing with the new requirements introduced under the Data (Use and Access) Act 2025.
Who is affected
All organizations processing personal data in the United Kingdom subject to UK GDPR, including controllers and processors of any size. Data subjects and third parties seeking access to personal data under new statutory rights are also affected.
Summary generated by a language model; the official text prevails. Not legal advice.