The Data (Use and Access) Act 2025 introduces consequential amendments to UK GDPR

Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 bring into effect amendments to the UK GDPR following the enactment of the 2025 Act. These amendments introduce transitional provisions and align UK GDPR with the new data governance framework established by the principal Act. Organizations must review how their data processing obligations and rights under UK GDPR interact with the new legislative framework.

What changed

  • The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 introduce amendments to UK GDPR effective from the date specified in the regulations, establishing how the new data access and use framework applies alongside existing GDPR requirements.
  • Transitional provisions are established to manage the implementation of changes and define how organizations must comply with both the new Act and existing UK GDPR obligations during the transition period.

Who is affected

All organizations processing personal data in the United Kingdom under UK GDPR, including data controllers and processors across all sectors and sizes.

Summary generated by a language model; the official text prevails. Not legal advice.