The Data (Use and Access) Act 2025 amends UK GDPR definitions and processing rules

Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 make amendments to Regulation (EU) 2016/679 as it applies in the United Kingdom. These changes introduce consequential amendments required to align UK GDPR with the Data (Use and Access) Act 2025, including modifications to key definitions and processing rules. Organizations subject to UK GDPR must review how these amendments affect their data handling practices and compliance frameworks.

What changed

  • The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 introduce amendments to UK GDPR to reflect requirements of the Data (Use and Access) Act 2025
  • Consequential amendments modify how certain processing activities and data uses are defined and regulated under UK GDPR
  • Transitional provisions are introduced to manage the implementation period for affected organizations
  • Amendments affect the interaction between UK GDPR and the new Data (Use and Access) Act 2025 framework

Who is affected

Organizations processing personal data in the UK and subject to UK GDPR; data controllers and processors; data subjects in the UK

Summary generated by a language model; the official text prevails. Not legal advice.