Navigating the UK’s evolving data protection landscape requires constant vigilance. We translate complex legislation into practical, secure IT policies that protect your business from regulatory fines and reputational damage.
The Data (Use and Access) Act 2025
The Data (Use and Access) Act 2025 (DUAA) is the most significant change to UK data law since the UK GDPR. It amends how UK organisations handle personal data, use automated decision-making and respond to complaints from individuals, with its provisions coming into force in stages. Staying compliant means keeping both the UK GDPR and the DUAA changes in view.
How we help
- Compliance gap assessment: a clear review of where your current systems and processes stand against the UK GDPR and the DUAA.
- Technical safeguards: implementing the access controls, encryption, retention and monitoring needed to protect personal data.
- Subject Access Requests: efficient SAR processes that make use of new efficiencies such as the “stop the clock” rule for complex requests.
- Complaints handling: processes that meet the DUAA’s requirements for receiving and responding to data protection complaints.
- Automated decision-making: reviewing where your systems, including AI tools, make decisions about people, and putting the right safeguards in place.
- Digital verification: robust identity and digital verification frameworks that are secure and proportionate.
- Policies your team can follow: clear, practical IT and data policies, not shelfware.
