The Data (Use and Access) Act 2025 introduces consequential amendments to UK GDPR
Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 implements consequential amendments to UK GDPR effective from 23 June 2026. Organisations subject to UK GDPR must review how the new data use and access framework intersects with their existing personal data processing obligations. The regulations include transitional provisions to facilitate the phased implementation of changes affecting data access rights and processing requirements.
What changed
- The regulations introduce consequential amendments to UK GDPR resulting from the Data (Use and Access) Act 2025, affecting how certain data processing and access rights provisions operate
- Transitional provisions are established to govern the application of amended rules during the implementation phase, allowing organisations time to adjust compliance processes
- Changes affect the interaction between the new data use and access regime and existing GDPR requirements, particularly regarding data subject rights and controller obligations
Who is affected
Organisations processing personal data under UK GDPR in the United Kingdom, including data controllers and processors across all sectors handling personal data of UK residents
Summary generated by a language model; the official text prevails. Not legal advice.