The Data (Use and Access) Act 2025 amends UK GDPR requirements for data controllers and processors
Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 brings consequential amendments and transitional provisions to UK GDPR (Regulation (EU) 2016/679 as applied in the UK). This amendment impacts how data controllers and processors comply with their obligations under UK GDPR, particularly in relation to data subject rights and processing requirements. Organizations subject to UK GDPR must review the specific amendments to ensure continued compliance with their data protection obligations.
What changed
- The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 introduces consequential amendments to UK GDPR, effective from 23 June 2026. The amendments reflect changes to UK data protection legislation arising from the Data (Use and Access) Act 2025.
- Transitional provisions are established to facilitate the transition from previous requirements to new obligations under the amended UK GDPR framework.
Who is affected
All organizations processing personal data of UK residents (data controllers and processors subject to UK GDPR); applies specifically to entities operating in or affecting the UK jurisdiction.
Summary generated by a language model; the official text prevails. Not legal advice.