The Data (Use and Access) Act 2025 introduces consequential amendments to UK GDPR

Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 has prompted consequential amendments to the UK General Data Protection Regulation, formalised through the 2026 Regulations and effective from 23 June 2026. This reflects the UK Government's broader data governance reforms to support data-driven innovation while maintaining personal data protection standards. Organisations processing personal data in the UK must review and ensure compliance with any modified GDPR provisions that result from these amendments.

What changed

  • The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 came into force on 23 June 2026, introducing consequential amendments to UK GDPR (Regulation (EU) 2016/679 as retained and modified in UK law)
  • Transitional provisions have been established to manage the implementation of changes arising from the Data (Use and Access) Act 2025

Who is affected

All organisations processing personal data in the UK, including those with international data flows. The amendments affect controllers, processors, and data protection officers responsible for GDPR compliance in UK operations.

Summary generated by a language model; the official text prevails. Not legal advice.