UK Data (Use and Access) Act 2025 introduces consequential amendments to UK GDPR
Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 introduces amendments to the UK GDPR (Regulation (EU) 2016/679 as retained in UK law) through consequential amendments and transitional provisions. These amendments align UK data protection rules with the new Data (Use and Access) Act 2025. The changes affect how organisations must comply with UK GDPR in relation to data use and access requirements introduced by the 2025 Act, with transitional provisions allowing a period for compliance.
What changed
- The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 amends UK GDPR by introducing consequential amendments to align the retained EU regulation with the new Data (Use and Access) Act 2025.
- Transitional provisions are introduced to allow organisations a period to comply with the new requirements arising from the amendments.
- The amendments are effective from 23 June 2026, giving organisations time to adjust their data processing and compliance practices.
Who is affected
UK organisations processing personal data, including data controllers and processors across all sectors subject to UK GDPR, particularly those engaged in data use and access practices.
Summary generated by a language model; the official text prevails. Not legal advice.