The Data (Use and Access) Act 2025 amends UK GDPR through consequential amendments and transitional provisions

Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 brings consequential amendments and transitional provisions to UK GDPR through the 2026 Regulations, effective 23 June 2026. These amendments align GDPR obligations with the new Data (Use and Access) Act framework. Organizations processing personal data in the UK must review the amended provisions to ensure continued compliance with updated requirements.

What changed

  • The Data (Use and Access) Act 2025 introduces consequential amendments to UK GDPR, modifying how the regulation applies alongside the new Data (Use and Access) Act framework effective from 23 June 2026
  • Transitional provisions establish a transition period for organizations to adapt their processing activities and policies to align with both UK GDPR as amended and the Data (Use and Access) Act requirements
  • The amendments apply to data controllers and processors subject to UK GDPR, requiring review of their lawful basis for processing, privacy notices, and data subject rights procedures
  • Implementation requires organizations to assess impacts on existing data processing agreements, impact assessments, and compliance documentation under the updated regulatory framework

Who is affected

All organizations processing personal data of UK residents; data controllers and processors subject to UK GDPR; entities handling cross-border data flows with EEA relevance

Summary generated by a language model; the official text prevails. Not legal advice.