News & Insight

Data privacy September 8, 2025
New UK data protection rules: top five things to now do

New UK data protection rules: top five things to now do

The Data (Use and Access) Act 2025 (the “DUAA”) represents the most substantial recalibration of the UK’s data protection regime since Brexit effective 1 February 2020. It received Royal Assent on 19 June 2025 and is being rolled out in stages through to June 2026. We have written extensively on the detail elsewhere.

Certain measures came into force on 19 and 20 August 2025 and others will come into effect gradually between now and mid-2026, but businesses should not wait. Taking steps early will enable businesses to stay ahead of regulatory change rather than reacting under pressure as the DUAA comes into effect.

From a practical perspective, five practical considerations emerge that businesses should now begin to address.

  1. Refresh internal documentation

Once in force, the introduction of “recognised legitimate interests” will change the compliance landscape, creating a new statutory basis for certain types of data processing activities. Privacy notices, records of processing activities and legitimate interests assessments should be reviewed and updated to reflect where this new statutory category applies, ensuring continued transparency with data subjects.

  1. Re-evaluate cookies and marketing practices

With consent requirements set to be relaxed for low-risk uses such as analytics and authentication, while enforcement powers are to be substantially increased, businesses ought prudently to undertake a thorough review. A comprehensive audit of cookie banners, tracking technologies and electronic marketing practices is advised, ensuring that users are provided with clear choices and accessible information. The relaxation of these requirements is also good news for businesses and users alike, as it should reduce the need for frequent pop-ups and make compliance simpler to manage.

  1. Prepare for tougher enforcement

The DUAA will align the penalty regime across UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), replacing PECR’s existing £500,000 cap with fines of up to £17.5 million or 4% of global turnover. With exposure and potential penalties now dramatically higher, key personnel will prudently be trained and made aware of the new requirements and obligations under the DUAA.

  1. Review AI and automated decision-making processes

The proposed loosening of restrictions around automated decision-making opens opportunities for wider adoption of AI-driven tools, but safeguards remain essential. Businesses should identify where such AI-driven tools and processes are used, ensure that procedures are put into place to monitor changes to the use of such tools and processes and ensure that individuals can request review and challenge outcomes.

  1. Monitor international transfers and EU adequacy

The proposed move under the DUAA from the EU’s ‘essentially equivalent’ test to the UK’s ‘not materially lower’ standard represents a policy shift. Businesses relying on cross-border transfers will need to check their transfer mechanisms and keep a close eye on adequacy discussions with the EU, given the risk of divergence later this year.

Looking ahead

While the reforms under the DUAA are incremental in nature, they introduce a number of practical and enforcement-related challenges that cannot be disregarded. Documentation, processes and governance all prudently require attention now, well before the DUAA is fully in force. With the stakes for non-compliance having risen considerably, taking these steps early will help businesses manage risk and avoid a compliance scramble as the DUAA comes into force.

Those businesses raising finance or involved in M&A transitions will also be concerned to see that they are compliant such that they are able to survive relatively unscathed in legal due diligence processes.

This piece was written by Sanya Bhambhani and Robert Humphreys.  As ever, If you would like advice on the new Data (Use and Access) Act 2025 or would like to further understand how it could impact your business, please don’t hesitate to contact a member of the HLaw team.

All the thoughts and commentary that HLaw publishes on this website, including those set out above, are subject to the terms and conditions of use of this website.  None of the above constitutes legal advice and is not to be relied upon.  Much of the above will no doubt fall out of date and conflict with future law and practice one day.  None of the above should be relied upon.  Always seek your own independent professional advice.

Humphreys Law

If you would like to contact a member of our team, please get in touch by filling in the form below.

"*" indicates required fields

Humphreys Law