News & Insight
DUAA data protection provisions in force, ICO guidance in transit: what to check now
On 19 June 2026 the last of the data protection provisions of the Data (Use and Access) Act 2025 (the ‘DUAA’) came into force, twelve months to the day after Royal Assent.
The statute book has settled but the regulator’s guidance has not. The ICO has been rewriting the latter in tranches since mid-2025. The guidance on storage and access technologies (formerly the cookies guidance) was updated in draft for the DUAA in July 2025 and finalised in April 2026. The detailed right of access guidance was rewritten over the winter to reflect the DUAA’s codification of ‘reasonable and proportionate’ searches and the new ‘stop the clock’ mechanic on subject access requests (‘SARs’). The international transfers guidance followed in January 2026, tracking the move to the ‘not materially lower’ standard. New guidance on the recognised legitimate interests basis has been published in both in-brief and detailed form, and complaints-handling guidance arrived ahead of the June commencement.
On 19 June 2026 the ICO’s DUAA overview page was updated to confirm that all of the Act’s data protection provisions are now in force, dropping the preparation checklist and adding a section on the regulator’s new powers. On 16 July 2026 the in-brief ‘A guide to subject access’ was brought into line with the rewritten detailed guidance. And on 23 July 2026 the ICO updated its public-facing guidance on the right to object.
One right, inconsistently updated guidance
The right to object is the most instructive example, because the ICO’s guidance on it has been updated unevenly. The page written for individuals – renamed ‘The right to object to the use of your information’ – was refreshed on 23 July 2026 in line with the DUAA. It now tells people they can object to processing carried out on the new recognised legitimate interests basis, sets out the purpose, necessity and balancing tests an organisation must satisfy to rely on ordinary legitimate interests, and points them to the new statutory right to complain to the controller – recommended as the first step, though the ICO can be approached at any point. It even supplies a template objection letter.
The general right-to-object guidance for organisations, by contrast, still sits under a review banner with content that pre-dates the Act: its account of the non-absolute right under Article 21(1) still mentions only public task and ordinary legitimate interests, and says nothing about the new recognised legitimate interests basis. The law itself has moved – section 70(5) DUAA added recognised legitimate interests to Article 21(1) UK GDPR. The ICO explains the expanded right in its separate guidance on recognised legitimate interests, but has not yet incorporated that explanation into its general right-to-object guidance for organisations. The automated decision-making guidance is also still in draft: the consultation on the new Articles 22A to 22D regime closed on 29 May 2026 and, at the time of writing, the final version has not been published – the ICO’s guidance plans currently give winter 2026 for it.
Six checks to run now
The practical consequence is that compliance documents drafted against pre-DUAA ICO boilerplate are liable to be out of date in specific, identifiable ways. Six checks are worth running this quarter.
One, privacy notices. Since 19 June 2026 privacy information has been required by law to tell individuals about their statutory right to complain to the controller under the new section 164A of the Data Protection Act 2018 – the DUAA wrote the point into Articles 13 and 14 UK GDPR. Where recognised legitimate interests is relied on, people must also be told both the basis and the relevant Annex 1 condition, unless an exemption applies. Notices should also be checked for any solely automated decision-making producing legal or similarly significant effects.
Two, SAR procedures. Searches need only be reasonable and proportionate, and the clock can be paused where clarification is reasonably required – both now on a statutory footing. Subject to any applicable exemption, SAR responses must tell requesters about their right to complain to the controller. Where the controller refuses to act, the response must also give the reasons and explain the rights to complain to the controller and to the ICO and to seek a judicial remedy. Templates drafted before this year are unlikely to contain all of that.
Three, objection-handling procedures. Templates drafted before this year may not recognise objections to processing based on recognised legitimate interests, and should now be updated to do so. Subject to any applicable exemption and the rules on manifestly unfounded or excessive requests, a controller may continue processing following an Article 21(1) objection only if it demonstrates compelling legitimate grounds that override the individual’s interests, rights and freedoms, or that the processing is for the establishment, exercise or defence of legal claims. Direct marketing objections remain absolute, and objections to research processing are subject to the separate Article 21(6) rule. Any refusal response must also signpost the complaints routes.
Four, a complaints procedure. Section 164A applies to all controllers. It requires them to facilitate data protection complaints, to acknowledge receipt within 30 days and, without undue delay, to take appropriate steps in response – including making appropriate enquiries – to keep complainants informed of progress and to tell them the outcome. In practice that means an accessible route in (a form, an address, a named inbox), an internal owner, staff able to recognise and escalate complaints arriving through other channels and records that demonstrate compliance. An existing customer-complaints process can be adapted, provided data protection complaints are triaged to someone who knows the difference.
Five, legitimate interests assessments. The new Article 6(11) confirms that direct marketing, intra-group transmission for internal administrative purposes and ensuring the security of network and information systems are the kinds of processing capable of resting on legitimate interests. It does not remove the balancing test. Review existing assessments against the current processing and record the outcome.
Six, the new basis itself. Recognised legitimate interests is narrow: Annex 1 to the UK GDPR currently contains five exhaustive conditions – disclosures requested for another controller’s public task or official function; national security, public security or defence; responding to emergencies; detecting, investigating or preventing crime, or apprehending or prosecuting offenders; and safeguarding vulnerable individuals. No balancing test is required, but necessity still is, and the right to object still applies – the ICO’s new public page says so in terms. Most commercial processing will not qualify for the new basis, and what stays on ordinary legitimate interests still needs the purpose, necessity and balancing tests, with a dated record of the assessment.
Guidance lag is not a grace period
As the DUAA commenced, the ICO published a statement on how it would regulate through the transition. It said it would apply the law as it stood at the time of the infringement, and that where an existing provision was being removed, amended or replaced it would judge whether to act under the old provision or, for continuing non-compliance, the new one – taking into account the guidance available to organisations at the time. That is worth something: keep dated records of the guidance you relied on and when. But it was a statement about the transition, not a standing grace period for the new duties. The statutory obligations – the complaints route, the notice content, the amended right to object – have applied since commencement, whether or not the relevant guidance has been updated. The general right-to-object guidance for organisations still needs updating; Article 21 as amended applies now – and, since late July, anyone minded to object can read about it.
We covered the substance of the DUAA when it received Royal Assent, here. The homework we set then – documentation, cookies and marketing, enforcement exposure, automated decision-making, international transfers – has not changed. What has changed is that the deadline has passed.
If you would like the state of your data protection paperwork checked against the DUAA and the current guidance, please contact Robert Humphreys or a member of the HLaw team.
All the thoughts and commentary that HLaw publishes on this website, including those set out above, are subject to the terms and conditions of use of this website. None of the above constitutes legal advice and is not to be relied upon. Much of the above will no doubt fall out of date and conflict with future law and practice one day. None of the above should be relied upon. Always seek your own independent professional advice.
Humphreys Law
If you would like to contact a member of our team, please get in touch by filling in the form below.
"*" indicates required fields
Humphreys Law