Data (Use and Access) Act 2025 introduces consequential amendments to UK GDPR

Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 has triggered consequential amendments to the UK General Data Protection Regulation through the 2026 Regulations. These changes introduce new obligations and transitional provisions that entities processing personal data in the UK must comply with. Organisations should review their data processing activities and governance frameworks to ensure alignment with the amended requirements.

What changed

  • The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 modifies specified provisions of the UK GDPR to accommodate new data access and use requirements introduced by the primary legislation
  • Transitional provisions establish timeframes for entities to adapt their data processing practices and compliance mechanisms to align with amended UK GDPR requirements

Who is affected

UK-based and international organisations processing personal data of UK residents, including data controllers and processors in all sectors subject to UK GDPR

Summary generated by a language model; the official text prevails. Not legal advice.