The Data (Use and Access) Act 2025 amends UK GDPR requirements for data controllers and processors
Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 and its 2026 Consequential Amendments Regulations amend the UK GDPR with effect from 23 June 2026. The amendments introduce transitional provisions and consequential changes to how data controllers and processors must comply with GDPR requirements. Organizations operating in the UK must review the specific amendments to understand how their data processing obligations, transparency requirements, and data subject rights are affected under the revised framework.
What changed
- The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 come into force on 23 June 2026, amending Regulation (EU) 2016/679 as it applies to the United Kingdom
Who is affected
Data controllers and processors subject to UK GDPR, organisations processing personal data in the United Kingdom, data protection officers and compliance professionals
Summary generated by a language model; the official text prevails. Not legal advice.