UK GDPR amended by Data (Use and Access) Act 2025 Consequential Amendments Regulations 2026

Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 have amended the United Kingdom General Data Protection Regulation (UK GDPR). These consequential amendments align UK GDPR with the new Data (Use and Access) Act 2025, which establishes new rights for data access and use in the UK. Organizations processing personal data in the UK must review the amended rules to ensure ongoing compliance with both the updated GDPR requirements and the new framework. The amendments may affect data subject rights, data processor obligations, and the overall governance of personal data processing in the UK.

What changed

  • The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 introduce amendments to UK GDPR through consequential modifications required by the new Data (Use and Access) Act 2025. The specific substantive changes to UK GDPR provisions are not detailed in the legislative reference provided.
  • Transitional provisions are included in the Regulations 2026 to manage the shift from existing UK GDPR obligations to the amended framework under the Data (Use and Access) Act 2025.
  • The amendments establish the legislative relationship between the new Data (Use and Access) Act 2025 and existing UK GDPR requirements, ensuring consistency across UK data protection law.

Who is affected

All organizations processing personal data in the UK, including data controllers and processors of any size and sector. UK entities, international entities processing UK residents' data, and data subjects in the UK are affected by the amended UK GDPR requirements.

Summary generated by a language model; the official text prevails. Not legal advice.