Data (Use and Access) Act 2025 amends UK GDPR requirements for data controllers and processors
Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 Consequential Amendments Regulations 2026 introduce amendments to UK GDPR affecting data controllers and processors. These amendments align GDPR requirements with the new Data (Use and Access) Act framework, modifying how organizations manage personal data, fulfill transparency obligations, and handle data subject rights requests. Organizations subject to UK GDPR must review their data processing practices and documentation to ensure compliance with the updated provisions.
Who is affected
All organizations processing personal data in the UK subject to UK GDPR, including data controllers and data processors in all sectors and of all sizes
Summary generated by a language model; the official text prevails. Not legal advice.