The Data (Use and Access) Act 2025 amends UK GDPR definitions and processing rules
Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 brings consequential amendments to the UK GDPR through regulations that took effect on 23 June 2026. These amendments update definitions, processing requirements, and operational rules under UK data protection law. Organisations processing personal data must review and adjust their compliance frameworks to align with the amended provisions, particularly regarding data use, access rights, and controller responsibilities.
What changed
- The regulations introduce consequential amendments to UK GDPR definitions, processing principles, and requirements stemming from the Data (Use and Access) Act 2025
- Transitional provisions are established to govern the implementation period and ensure organisations have sufficient time to comply with amended requirements
- Specific amendments modify how personal data use and access are regulated under UK GDPR, affecting controller and processor obligations
Who is affected
All organisations processing personal data in the UK, including data controllers and processors across all sectors and sizes that fall under UK GDPR scope
Summary generated by a language model; the official text prevails. Not legal advice.