The Data (Use and Access) Act 2025 amends UK GDPR definitions and requirements

Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 amend the UK GDPR to align with the new Data (Use and Access) Act 2025. The regulations modify definitions and obligations related to personal data processing, data use agreements, and controller-processor relationships. Organisations processing personal data in the UK must review their data protection agreements and internal processes to comply with the amended definitions and new requirements introduced by the transitional provisions.

What changed

  • UK GDPR definitions updated to align with the Data (Use and Access) Act 2025 framework
  • Data use agreement requirements modified to reflect new obligations under the Data (Use and Access) Act 2025
  • Transitional provisions introduced to govern compliance during the implementation period
  • Controller and processor relationships redefined in accordance with the new legislation

Who is affected

All UK data controllers and processors handling personal data, particularly those entering into new data processing agreements or reviewing existing arrangements; affects organisations across all sectors and sizes operating in or transferring data within the UK

Summary generated by a language model; the official text prevails. Not legal advice.