Data (Use and Access) Act 2025 amends UK GDPR requirements for data holders and data intermediaries

Original title: Data (Use and Access) Act 2025 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 introduces amendments to the UK GDPR effective 23 March 2026. The Act establishes new obligations for data holders and data intermediaries, creates mechanisms for granting and refusing data access rights, and introduces provisions allowing the use of certain data for training AI models. Organizations processing personal data under UK GDPR must now comply with additional requirements introduced by this new legislation regarding data access, intermediary relationships, and AI training data sourcing.

What changed

  • The Act introduces the concept of 'data holders' and 'data intermediaries' with specific obligations regarding the provision and intermediation of data access
  • New procedures are established for granting or refusing data access requests, with specified timeframes and conditions
  • The legislation creates exemptions and limitations on data access rights, including provisions for trade secrets and confidentiality
  • Requirements are introduced for data holders regarding data sharing agreements and the terms under which intermediaries may act
  • New provisions enable the use of certain non-personal and personal data for AI model training, subject to specified conditions and safeguards

Who is affected

Data holders, data intermediaries, organizations processing personal data under UK GDPR, AI developers and organizations training AI models, entities using data for AI purposes across all sectors in the United Kingdom

Summary generated by a language model; the official text prevails. Not legal advice.