The Data (Use and Access) Act 2025 introduces consequential amendments to Data Protection Act 2018

Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Data Protection Act 2018

The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 make amendments to the Data Protection Act 2018 to align it with new data access and use framework requirements. Organisations must review how their data protection practices comply with both the updated DPA 2018 and UK GDPR, particularly regarding data subject rights, controller obligations, and data processing frameworks. Transitional provisions establish specific timelines for implementation of these changes.

What changed

  • The Data (Use and Access) Act 2025 introduces consequential amendments to the Data Protection Act 2018 through SI 2026/386, effective from 23 June 2026
  • Amended provisions align DPA 2018 requirements with the new data access and use framework established under the Data (Use and Access) Act 2025
  • Transitional arrangements are established for organisations to adapt their data protection compliance processes
  • Updates affect how controllers and processors must handle data subject rights and access requests under the modified legislative framework

Who is affected

UK organisations subject to Data Protection Act 2018 and UK GDPR, including controllers and processors handling personal data, across all sectors and organisation sizes operating in or affecting UK residents.

Summary generated by a language model; the official text prevails. Not legal advice.