Data (Use and Access) Act 2025 amends UK GDPR provisions on data subject rights and controller obligations
Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 amend the UK GDPR to align with the new data access and use framework. The amendments affect data subject rights, responsibilities of controllers and processors, and Information Commissioner's Office enforcement powers. Organizations processing personal data in the UK must review their policies and procedures to ensure compliance with the modified GDPR provisions under this new legislative framework.
What changed
- The regulations introduce consequential amendments to align UK GDPR with the Data (Use and Access) Act 2025, affecting multiple sections of Regulation (EU) 2016/679 as applied in UK law
- Data subject rights and related procedures have been modified to reflect the new data access and use framework
- Controller and processor obligations are amended to accommodate the new data governance requirements introduced by the 2025 Act
- Provisions regarding Information Commissioner's Office powers and enforcement mechanisms have been adjusted
- Transitional provisions establish timelines and procedures for organizations to implement the required changes
Who is affected
All UK-based data controllers and processors, data subjects in the UK, and any organizations processing personal data under UK GDPR
Summary generated by a language model; the official text prevails. Not legal advice.