Data (Use and Access) Act 2025 amends GDPR requirements for data subject rights and processing obligations
Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 introduces amendments affecting the UK General Data Protection Regulation. The amendments modify requirements for organisations processing personal data, including adjustments to data subject rights and processing obligations. Controllers and processors must review their compliance frameworks to ensure adherence to the revised rules. The transitional provisions establish timelines for organisations to implement the necessary changes.
What changed
- The Data (Use and Access) Act 2025 introduces consequential amendments to UK GDPR effective from the date specified in the Regulations 2026
- Amendments modify the framework for exercising data subject rights under UK GDPR
- Changes affect organisations' processing obligations and requirements for handling personal data
- Transitional provisions establish implementation timelines for affected organisations to comply with revised requirements
Who is affected
All organisations processing personal data in the UK under UK GDPR, including data controllers and processors across all sectors and sizes subject to UK data protection regulation
Summary generated by a language model; the official text prevails. Not legal advice.