Data (Use and Access) Act 2025 introduces consequential amendments to UK GDPR
Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 bring consequential amendments to UK GDPR effective from the regulations' commencement date. These amendments align UK GDPR requirements with the new data access and use framework introduced by the 2025 Act. Organizations subject to UK GDPR must review and update their data handling processes and governance structures to comply with the modified provisions where applicable.
What changed
- The Data (Use and Access) Act 2025 brings consequential amendments to UK GDPR through transitional provisions and modifications effective from the regulations' commencement date (23 June 2026)
- New data access and use framework introduced, requiring alignment of UK GDPR compliance procedures with provisions of the Data (Use and Access) Act 2025
- Transitional provisions establish compliance pathways for organizations adjusting their data processing practices to meet both UK GDPR and the new Act's requirements
Who is affected
Organizations processing personal data in the UK subject to UK GDPR; data controllers and processors; entities handling data subject access requests and data portability; businesses operating under UK data protection framework
Summary generated by a language model; the official text prevails. Not legal advice.