Navigating the Data (Use and Access) Act: A Comprehensive Guide and AI Blueprint for UK Businesses

Data (Use and Access) Act

Navigating the Data (Use and Access) Act: A Comprehensive Guide and AI Blueprint for UK Businesses

The UK data protection landscape has officially entered a new era. Following years of post-Brexit regulatory deliberation, the Data (Use and Access) Act (DUAA) received Royal Assent in mid-2025, and as we navigate through 2026, its staggered implementation dates are actively reshaping how commercial entities operate. Originally introduced in late 2024 as the successor to the stalled Data Protection and Digital Information (DPDI) Bill, the DUAA was designed with a dual mandate: to reduce regulatory red tape and foster technological innovation—particularly in Artificial Intelligence—while maintaining the vital “adequacy” status that allows frictionless data flows between the UK and the European Union.

For UK businesses, the DUAA represents a paradigm shift. It is not a wholesale replacement of the UK GDPR, but rather a surgical amendment of it. The Act introduces fundamental changes to Subject Access Requests (DSARs), mandates new internal complaint procedures, drastically increases fines for marketing violations, and entirely rewrites the rules of engagement for Automated Decision-Making (ADM).

This comprehensive briefing explores the operational, legal, and strategic implications of the Data (Use and Access) Act for UK businesses, detailing the exact steps organisations must take to remain compliant and competitive in a data-driven economy.

Part 1: The New Data Economy – Smart Data and Digital Identity

Before delving into the compliance adjustments, it is vital to understand how the DUAA actively attempts to stimulate economic growth through data liquidity. The Act lays the statutory groundwork for two major digital infrastructure initiatives that will impact customer onboarding, verification, and market competition.

1. The Expansion of “Smart Data” Schemes

Drawing on the immense success of Open Banking, the DUAA introduces a statutory framework for “Smart Data” across multiple sectors, including energy, telecommunications, and retail. Smart Data schemes mandate that utility and service providers must securely share a customer’s data with authorised third-party providers (TPPs) at the customer’s request.

For businesses in these sectors, this is a compliance mandate requiring the development of robust, secure APIs to facilitate this data transfer. However, for technology startups, aggregators, and fintech companies, it is a monumental opportunity. Businesses can now build applications that analyse a user’s telecom or energy usage in real-time to recommend cheaper tariffs, fundamentally lowering the barrier to entry for cross-sector market comparison tools.

2. Digital Verification Services (DVS)

Identity verification has historically been a fragmented, high-friction process for businesses, often requiring customers to upload scans of passports or utility bills. The DUAA formally establishes the Office for Digital Identities and Attributes (OfDIA), which oversees a new trust framework for digital identity providers.

While certification is voluntary, certified digital identity providers will receive a government-backed “trust mark”. For UK businesses, integrating these certified services will streamline Anti-Money Laundering (AML) and Know Your Customer (KYC) checks. Instead of processing raw, highly sensitive identity documents directly, businesses can rely on verified digital tokens, thereby reducing their own data storage risks and significantly accelerating the customer onboarding journey.

Part 2: Rebalancing the Compliance Burden

A core promise of the DUAA was to alleviate the administrative fatigue associated with UK GDPR compliance. The Act delivers on this by clarifying ambiguous legal thresholds, though it simultaneously introduces strict new procedural requirements.

Subject Access Requests (DSARs): The “Reasonable and Proportionate” Standard

Historically, responding to DSARs has been an operational nightmare for employers and consumer-facing brands. The previous interpretation often felt like a strict liability to “leave no stone unturned,” leading to exorbitant eDiscovery costs. The DUAA codifies a new, pragmatic standard: businesses are now only legally required to conduct a “reasonable and proportionate” search for personal data.

Organisations can now factor in the size of their business, the specific nature of the request, and the resources available when determining the scope of a search. Furthermore, the Act officially codifies the “stop the clock” mechanism. If a business needs to ask a data subject for clarification regarding the scope of their request, the statutory 30-day response window is legally paused until the individual replies.

Mandatory Internal Complaints Procedures

To reduce the burden on the regulatory authority (reconstituted under the Act from the ICO to a corporate Information Commission), the DUAA shifts the initial dispute resolution burden onto businesses. Individuals can no longer escalate a grievance directly to the regulator as a first step.

Instead, the Act mandates that individuals must submit their complaint directly to the business. Consequently, businesses are legally required to establish a formal data protection complaints procedure. You must acknowledge receipt of a complaint within 30 days and respond “without undue delay”. Only if the individual is dissatisfied with the internal resolution can they escalate the matter to the Information Commission. This requires immediate operational updates, including creating accessible digital complaint forms (like our own complaints form) and training front-line customer service and HR staff to identify data privacy grievances.

PECR Alignment: The £17.5 Million Threat

While the DUAA reduces burdens in some areas, it aggressively tightens the screws on direct marketing and tracking. Historically, breaches of the Privacy and Electronic Communications Regulations (PECR)—which govern email marketing, telemarketing, and cookies—carried a maximum fine of £500,000.

The DUAA aligns PECR fines with UK GDPR standards. This means that a poorly implemented cookie banner, or an email marketing campaign sent without proper consent, can now result in fines of up to £17.5 million or 4% of global annual turnover.

Conversely, the Act does introduce helpful exemptions for cookies. Businesses no longer need explicit user consent for non-intrusive cookies used strictly for web analytics, service improvements, or basic site functionality. This allows businesses to gather essential performance metrics without bombarding users with aggressive consent pop-ups.

Part 3: The AI & Automated Decision-Making Shift

Perhaps the most commercially significant aspect of the DUAA is its proactive stance on Artificial Intelligence. The UK government recognised that strict interpretations of data privacy laws were actively impeding the development and deployment of algorithmic systems.

The Act fundamentally reforms Article 22 of the UK GDPR, which previously heavily restricted Automated Decision-Making (ADM)—decisions made without meaningful human involvement that have a legal or significant effect on an individual (e.g., automated CV screening, algorithmic credit scoring). Under the old regime, this was generally prohibited unless strictly necessary for a contract or based on explicit consent.

The DUAA flips this default. It permits ADM under broader legal bases, including “Legitimate Interests,” provided no special category (sensitive) data is used. However, this deregulation is paired with strict mandatory safeguards.

DUAA Artificial Intelligence & ADM Impact Table

To understand how the DUAA reshapes AI deployment, review the comprehensive breakdown below:

AI Activity / ProvisionPrevious UK GDPR StandardDUAA 2025 Legislative ChangePractical Implications for UK Businesses
Automated Decision-Making (ADM) ThresholdStrictly prohibited for decisions with “legal or significant effects” without explicit consent or contractual necessity.General prohibition removed for standard data. ADM is permitted under standard legal bases like Legitimate Interests.Businesses can now aggressively deploy AI for CV screening, dynamic pricing, and loan approvals without obtaining explicit, opt-in consent for the algorithm.
Processing Special Category Data via AIProhibited for ADM without explicit consent or specific substantial public interest exceptions.Unchanged. The strict prohibition remains only if the AI system relies entirely or partly on special category data (e.g., health, race, biometrics).If an AI recruitment tool infers health data or ethnicity, the new relaxed rules do not apply. Strict consent is still required.
Mandatory Algorithmic SafeguardsVague requirements for human intervention, heavily reliant on evolving regulatory guidance.Codified statutory safeguards. Businesses must explicitly notify individuals of ADM, allow them to make representations, and provide a route to contest the AI’s decision.Businesses must build “human-in-the-loop” appeal mechanisms into all AI tools. You cannot deploy an autonomous system without a manual override or review process.
Defining “Meaningful Human Involvement”Ambiguous. Minor human administrative actions (e.g., simply clicking “approve” on an AI output) were legally grey.Clarifies that ADM rules only apply to decisions lacking “meaningful human involvement.” Routine rubber-stamping by humans does not bypass ADM safeguards.Staff using AI must actively evaluate the algorithmic output. If an employee just accepts the AI’s recommendation by default, the law treats it as fully automated.
Scientific Research & Model TrainingNarrow definitions of “scientific research” made it difficult for private tech companies to scrape/process data for AI training under research exemptions.Broadens the definition to explicitly include commercial research. Allows “broad consent” where future specific research purposes are not yet fully known.AI developers and tech firms can more easily rely on research exemptions to train Large Language Models (LLMs), allowing greater flexibility with purpose limitation.

Expanding Commercial Research

For businesses developing proprietary AI models, data acquisition has been a major legal hurdle. The DUAA clarifies that commercial, privately funded research explicitly qualifies for the “scientific research” exemption. Furthermore, it permits “broad consent,” meaning users can consent to their data being used for general areas of research, even if the exact nature of the future AI model being trained is not yet fully defined. This provides immense intellectual property and developmental flexibility for the UK tech sector.

Part 4: A Compliance Action Plan for Businesses

To capitalise on the DUAA’s commercial benefits while avoiding its steep new penalties, UK businesses must execute a targeted compliance overhaul:

  1. Audit All AI and Algorithmic Tools: Inventory every software system that makes automated decisions (from HR applicant tracking systems to automated credit scoring). Ensure these systems do not process special category data without explicit consent, and formally document the safeguards in place that allow users to contest the AI’s decision.
  2. Build a Data Privacy Complaints Funnel: You can no longer direct unhappy customers straight to the regulator. Implement a dedicated electronic complaints form. Draft internal SLAs ensuring an acknowledgement is sent within 30 days, and train customer-facing staff to escalate these appropriately.
  3. Revise DSAR Standard Operating Procedures (SOPs): Update your internal DSAR guidelines to reflect the new “reasonable and proportionate” standard. Train your legal and IT teams on how to lawfully implement the “stop the clock” mechanism when seeking clarification from data subjects.
  4. Elevate PECR to a Board-Level Risk: With marketing fines jumping to £17.5 million or 4% of global turnover, conduct an immediate audit of your CRM systems. Verify that all email marketing lists rely on robust consent or the “soft opt-in,” and ensure your website’s cookie architecture accurately categorises analytics trackers separately from advertising trackers.

Part 5: Five Key Questions & Answers (Q&A)

Q1: Does the Data (Use and Access) Act affect our compliance with the EU GDPR, and will the UK lose its EU adequacy decision?

Answer: The DUAA was meticulously drafted to diverge from EU law just enough to support UK economic growth without crossing the threshold that would jeopardise the UK’s adequacy status. Because the core principles of data protection (fairness, transparency, security) remain intact, the EU has indicated that these reforms are acceptable. However, if your business operates in Europe, you must maintain a dual-track compliance programme, as you can deploy AI more freely for UK citizens under the DUAA than you can for EU citizens under the strict rules of the EU AI Act and EU GDPR.

Q2: What exactly constitutes a “reasonable and proportionate” search when we receive a Subject Access Request (DSAR)?

Answer: The Act deliberately moves away from the expectation of a flawless, exhaustive search. A “reasonable and proportionate” search allows you to weigh the complexity of the request against the size of your organisation. For example, if searching through 10 years of unstructured backup tapes would cost thousands of pounds and disrupt business operations for a minor data inquiry, you are legally permitted to exclude those archives. You must, however, document your rationale for limiting the search based on available resources and the nature of the data requested.

Q3: Are annoying cookie consent banners completely gone under the new Act?

Answer: Not completely, but they are significantly reduced. You no longer need a user’s active consent to drop cookies that are strictly for statistical web analytics (e.g., measuring page views to improve site architecture) or for basic site functionality and security. However, if you use third-party tracking cookies for targeted advertising, cross-site profiling, or retargeting campaigns, the strict consent requirements—and the new massive fines for violating them—still firmly apply.

Q4: How does the DUAA change how our HR department uses AI for recruitment?

Answer: Previously, using an AI tool to automatically filter out CVs without human review was heavily restricted. Under the DUAA, HR can use fully automated screening algorithms based on Legitimate Interests, provided the system does not make decisions based on health data, race, or other special category data. The catch is that you must inform applicants that an AI is reviewing their application, and you must provide a clear mechanism for rejected candidates to contest the decision and request that a human reviews their CV instead.

Q5: When do we need to have our mandatory internal complaints procedure ready?

Answer: The DUAA received Royal Assent in June 2025, but its provisions are subject to staggered implementation dates. The requirement for mandatory internal complaints procedures is currently taking effect through 2026 as the Information Commission publishes its updated guidance. Businesses should not wait; the operational infrastructure—such as web forms, updated privacy notices, and staff training protocols—must be implemented immediately to avoid compliance gaps as the regulator shifts its enforcement focus.

Conclusion

The Data (Use and Access) Act is a distinctly pro-business piece of legislation, aiming to transform data from a compliance liability into an economic asset. By expanding smart data schemes and relaxing the suffocating restrictions on automated algorithmic decision-making, the UK government is actively encouraging businesses to innovate. However, this freedom comes with a clear warning: the penalties for abusing marketing data have never been higher, and the procedural obligations to handle user grievances internally are now strict statutory requirements. Businesses that proactively adapt their data architectures to align with the DUAA will find themselves operating with greater agility, lower administrative costs, and a significant competitive advantage in the AI-driven marketplace.

For the official text, see the Data (Use and Access) Act 2025 on legislation.gov.uk and the ICO’s guidance.

Is your business ready for the DUAA?

We help UK businesses put practical DUAA and UK GDPR compliance in place, from complaints procedures and DSAR processes to AI governance. See our data compliance service or book a free, no-obligation call.

Leave a Reply

Your email address will not be published. Required fields are marked *