UK GDPR amendments: Data (Use and Access) Act 2025 introduces new controller obligations and transparency requirements

Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 introduce amendments to UK GDPR effective 23 June 2026. These amendments establish new obligations for data controllers regarding data use documentation, access mechanisms, and enhanced transparency requirements. Controllers must implement new processes and documentation systems to comply with the revised regulatory framework, with transitional provisions allowing time for implementation.

What changed

  • New controller obligations regarding documentation of data use purposes and processing activities introduced under the Data (Use and Access) Act 2025
  • Enhanced transparency requirements for data controllers to disclose how personal data is accessed, used, and shared
  • New access mechanisms and procedures that controllers must establish for data subjects requesting information about data processing
  • Transitional provisions specifying implementation timelines and compliance deadlines for the new requirements

Who is affected

All organizations processing personal data of UK data subjects acting as data controllers. Particularly impacts large-scale data processors, technology platforms, and organizations handling sensitive personal data categories.

Summary generated by a language model; the official text prevails. Not legal advice.