The Data (Use and Access) Act 2025 introduces consequential amendments to UK GDPR

Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 bring into effect amendments to the UK General Data Protection Regulation. These consequential amendments align UK GDPR with the new data use and access framework established by the 2025 Act. Organisations must review their data processing practices and governance frameworks to ensure compliance with the modified GDPR requirements as amended by the 2026 Regulations. The transitional provisions allow a period for organisations to implement the necessary changes to their data handling procedures.

What changed

  • The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 applies consequential amendments to UK GDPR effective from 23 June 2026
  • Transitional provisions are established to enable organisations to adapt their data processing operations to align with amended UK GDPR requirements

Who is affected

All organisations processing personal data in the UK under UK GDPR, including data controllers and data processors across all sectors and sizes operating in the United Kingdom

Summary generated by a language model; the official text prevails. Not legal advice.