The Data (Use and Access) Act 2025 amends UK GDPR provisions on data subject rights and controller obligations

Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

The Data (Use and Access) Act 2025 introduces consequential amendments to the United Kingdom General Data Protection Regulation (UK GDPR) through the 2026 Regulations. These amendments modify how data controllers must handle data subject rights and implement new obligations regarding data use and access. Organizations processing personal data in the UK must review and update their data handling procedures and policies to comply with the new requirements under the amended UK GDPR framework.

What changed

  • The 2026 Regulations introduce consequential amendments to UK GDPR arising from the Data (Use and Access) Act 2025, effective from the date specified in the legislation
  • Data controllers' obligations regarding data subject rights and access requests are modified to align with the new data use and access framework
  • Transitional provisions are established to manage the transition between the previous and new regulatory requirements under UK GDPR

Who is affected

All UK-based organizations and entities processing personal data; data controllers subject to UK GDPR; multinational organizations with UK operations

Summary generated by a language model; the official text prevails. Not legal advice.