The Data (Use and Access) Act 2025 brings consequential amendments to UK GDPR

Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 introduced a new legal framework for data access and use in the UK, and consequential amendments are being made to UK GDPR through the 2026 Regulations to ensure alignment and consistency. Organizations processing personal data in the UK must review how these amendments affect their data governance practices, rights of data subjects, and obligations under the updated regulatory regime. The transitional provisions allow time for compliance before full implementation.

What changed

  • The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 make amendments to UK GDPR (Regulation (EU) 2016/679 as retained in UK law) effective from 23 June 2026, creating alignment between the new data access and use framework and existing data protection requirements.
  • The source document indicates consequential amendments are being applied, suggesting modifications to how certain GDPR provisions interact with the new Data (Use and Access) Act 2025 framework, though specific amendments require review of the full regulatory text.

Who is affected

All organizations processing personal data in the UK subject to UK GDPR, particularly those handling data access requests and data usage rights under the new Data (Use and Access) Act 2025 framework.

Summary generated by a language model; the official text prevails. Not legal advice.