The UK Data (Use and Access) Act 2025 (DUAA) is now law several key provisions are already active – and the UK’s regulatory landscape has begun to shift.
This briefing summarises what has gone live, what is coming, and what organisations should be doing now to prepare from an information governance, records management and data protection standpoint.
This blog is also useful for anyone who that transfers personal data to the UK, or who has a UK data footprint.
What the DUAA Actually Does
The DUAA is a broad reform package that:
Creates frameworks for automated decision making, scientific research, and enhanced online protection for children.
Amends the Data Protection Act 2018, UK General Data Protection Regulation (UK GDPR) and Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) across multiple areas — including lawful basis, automated decision-making, Subject Access Requests, cookies, international transfers and complaints handling.
Gives the regulator Information Commissioner’s Office (ICO) new objectives and duties.
These changes are being implemented in four main stages, spanning June 2025 to late 2026.
[Source: UK Government “Data (Use and Access) Act 2025: data protection and privacy changes”](GOV.UK)
Stage 1 – (Commencement of the Data Use and Access Act 2025)
(Royal Assent: 19 June 2025 | First commencements completed: 20 August 2025)
What Stage 1 covers
Stage 1 brought into force the foundational and enabling provisions of the DUAA, rather than direct operational obligations on controllers or processors.
Key elements include:
Core enabling powers under the Act
Provisions allowing the Secretary of State to make further regulations and commencement orders needed to operationalise later DUAA reforms were activated on Royal Assent (19 June 2025).
Structural and constitutional changes to the ICO
The Act introduced changes to the legal framework governing the Information Commissioner, including revised statutory objectives and duties shaping how the ICO regulates going forward.
First commencement regulations (20 August 2025)
On 20 August 2025, the first substantive commencement regulations brought into force:
- technical and procedural provisions of the Act;
- the new statutory objectives for the ICO; and
- requirements for statutory Government reporting under the Act.
Statutory reporting obligations on Government
The DUAA mandates reports on specific data related policy areas, including:
- artificial intelligence and copyright; and
- the broader impact of data driven technologies. These reporting duties were enabled as part of the first commencement wave.
Smart Data foundations
Initial groundwork for Smart Data schemes was commenced, creating the legal basis for sector specific data sharing regimes to be introduced later through regulations.
Why Stage 1 is important
Although Stage 1 did not impose immediate new compliance duties on organisations, it is highly significant for everyone who works in Data Protection/Privacy because it reshapes the regulatory environment in which future obligations will be interpreted and enforced.
Changes how the ICO will regulate
The ICO’s new statutory objectives now influence enforcement priorities, guidance, proportionality assessments and how complaints and disputes are handled.
DPOs should expect a regulator that explicitly balances:
- data protection,
- innovation,
- economic growth, and
- public trust.
Signals future enforcement expectations
Stage 1 sets the tone for how later reforms (SAR changes, ADM rules, complaint handling) will be applied in practice.
DPOs should factor the ICO’s revised role into risk assessments, escalation processes and regulatory engagement strategies.
Requires governance level awareness level awareness
Even without immediate policy changes, organisations are expected to:
- brief senior leadership on the DUAA framework now in force;
- understand how regulatory accountability is shifting; and
- prepare governance structures for accelerated regulatory change across 2025–26.
Lays the groundwork for Smart Data and automation reforms
- The commencement of enabling provisions means downstream obligations will arrive quickly once sector specific regulations are made.
- DPOs should ensure data governance, records management and architecture discussions anticipate these developments rather than reacting later.
In short – what DPOs should take away
Stage 1 is about regulatory foundations, not operational compliance.
It changes how the ICO thinks and acts, which directly affects enforcement, advice, and scrutiny.
It gives DPOs an early window to:
- adjust governance narratives,
- prepare leadership, and
- position their organisations ahead of the more disruptive DUAA reforms in Stages 2–4.
Stage 2 (Completed September-December 2025)
What Stage 2 covers
Stage 2 introduced targeted, operational obligations affecting specific sectors and functions, marking the point at which the DUAA began to impose concrete compliance requirements on organisations in defined contexts.
Key elements include:
Digital Verification Services (DVS) regime
- The statutory framework for Digital Verification Services came into force, requiring identity verification providers to meet certification and assurance requirements.
- Organisations relying on third party identity verification services must ensure those providers comply with the DVS framework before use.
Child death investigation data retention duties
- New retention and preservation obligations were commenced in support of child death investigations.
- These provisions require organisations to preserve relevant personal data when formally directed, preventing routine deletion or alteration.
Data Preservation Notice (DPN) requirements
- Organisations may be required to implement Data Preservation Notice workflows, particularly where notices are issued by Ofcom.
- These notices compel organisations to retain specified datasets for investigative purposes.
Supporting operational processes
Stage 2 required updates to:
- onboarding processes involving identity verification; and
- incident response procedures to ensure data can be preserved quickly and lawfully when required.
Why Stage 2 is important
Stage 2 represents the DUAA’s shift from regulatory foundations to enforceable practice, with immediate governance and operational implications for affected organisations.
Introduces direct, enforceable compliance duties
Unlike Stage 1, Stage 2 imposes specific legal obligations, particularly around:
- identity verification assurance; and
- mandatory data retention in defined circumstances.
DPOs must ensure these duties are reflected in policies, contracts and operational playbooks.
Expands lawful data retention scenarios
Preservation duties can override standard retention schedules, meaning:
- routine deletion controls may need to be temporarily suspended; and
- audit trails must evidence compliance with preservation notices.
DPOs need to align retention governance with these new statutory exceptions.
Increases third party and supplier risk exposure
Reliance on noncompliant DVS providers could create:
- regulatory risk;
- contract noncompliance; and
- accountability gaps under UK GDPR controller obligations.
DPOs should ensure supplier assurance and due diligence processes explicitly cover DVS certification status.
Requires cross functional implementation
Effective Stage 2 compliance depends on coordination between:
- data protection and information governance;
- legal and procurement;
- IT and security; and
- operational teams responsible for onboarding and incident response.
DPOs play a central role in translating legal duties into workable operational controls.
In short – what DPOs should take away
Stage 2 is where the DUAA becomes operational for specific use cases.
It introduces mandatory, enforceable duties rather than regulatory signalling.
For DPOs, the priority is to:
- ensure DVS provider assurance is completed;
- embed preservation notice handling into retention governance; and
- confirm staff know how and when retention freezes must be applied.
Stage 3 (Commencement of the Data (Use and Access) Act 2025)
(Substantially completed December 2025 → early 2026)
What Stage 3 covers
Stage 3 delivers the most wide ranging changes affecting day-to-day data protection operations, with reforms that apply across most organisations rather than specific sectors.
Key elements include:
Subject Access Request (SAR) reforms
SAR handling is reframed around “reasonable and proportionate” searches, reducing expectations of exhaustive data trawls.
Organisations are given greater scope to:
- limit searches where requests are excessive or unclear; and
- focus on data that is realistically retrievable and relevant.
Automated Decision Making (ADM) safeguards
Revised rules for automated decision making, strengthening requirements for:
- transparency about ADM use;
- meaningful human oversight; and
- the ability for individuals to challenge outcomes.
The emphasis is on governance, accountability and demonstrable controls rather than blanket prohibitions.
Recognised Legitimate Interests (RLI)
- Introduction of Recognised Legitimate Interests, allowing certain processing activities to proceed without conducting a full Legitimate Interests Assessment (LIA), provided conditions are met.
- RLIs are intended to reduce administrative burden while maintaining safeguards for individuals.
Cookies and tracking technologies
- Updates to cookie and similar technology rules, including exemptions and consent adjustments for low risk uses.
- Cookie governance increasingly focuses on risk based compliance and transparency, rather than formalistic consent mechanisms.
Documentation and transparency updates
Organisations are expected to refresh:
- privacy notices;
- Records of Processing Activities (RoPAs); and
- Legitimate Interests documentation to reflect the new legal framework.
Why Stage 3 is important
Stage 3 reshapes core compliance processes, requiring DPOs to redesign how organisations operationalise UK GDPR obligations.
Changes how SAR compliance is delivered
SAR reform removes the assumption that “more searching is always better”.
DPOs must:
- recalibrate SAR workflows;
- document proportionality decisions; and
- train staff to apply judgement consistently.
Raises expectations for ADM governance
The focus shifts from whether ADM is used, to how well it is governed.
DPOs are expected to:
- maintain ADM inventories;
- evidence human review in practice; and
- ensure challenge and escalation mechanisms work.
Reduces burden — but increases accountability
- RLIs and cookie changes ease documentation in some areas.
- However, DPOs must still be able to justify reliance on these new flexibilities if challenged by the ICO.
Requires organisation wide updates
Stage 3 affects:
- policies and procedures;
- staff training;
- external facing notices; and
- internal accountability documentation.
DPOs lead coordination between legal, IT, digital, HR and communications teams.
In short – what DPOs should take away (Stage 3)
Stage 3 rewires core UK GDPR processes.
It introduces flexibility, but only where governance and documentation are strong.
DPO priorities should be to:
- update SAR decision making frameworks;
- strengthen ADM oversight;
- refresh public and internal documentation; and
- embed proportionality into compliance culture.
Stage 4 (Commencement of the Data (Use and Access) Act 2025)
(In progress early 2026 → June 2026 and beyond)
What Stage 4 covers
Stage 4 introduces structural and infrastructure level reforms, affecting how data protection rights are exercised and how public sector and regulated datasets are managed.
Key elements include:
Mandatory data protection complaints process
Organisations must implement a formal internal data protection complaints procedure.
Requirements include:
- acknowledgement of complaints within 30 days; and
- clear escalation routes before individuals approach the ICO.
National Underground Asset Register (NUAR)
Implementation of the NUAR, requiring utility and infrastructure organisations to:
- share and maintain high quality underground asset data; and
- meet specified data standards and governance requirements.
Electronic birth and death registration
Introduction of digital registration systems for births and deaths.
These reforms involve new data flows, interoperability requirements and identity assurance processes across public bodies.
Longer term Smart Data and digital identity integration
Stage 4 supports the wider rollout of Smart Data schemes and digital identity infrastructure first enabled in earlier stages.
Why Stage 4 is important
Stage 4 changes how individuals interact with data protection rights and embeds data protection into national scale systems.
Formalises complaints handling as a compliance obligation
Complaints handling becomes a core legal requirement, not merely good practice.
DPOs must:
- design complaint workflows;
- integrate them with SAR and incident processes; and
- ensure consistent recordkeeping and response quality.
Increases scrutiny of largescale data sharing
NUAR and digital registration schemes involve:
- complex multi controller environments; and
- heightened public and regulatory scrutiny.
DPOs must oversee governance, transparency and accountability across partner organisations.
Requires early engagement with operational teams
Compliance depends on engagement with:
- estates and infrastructure teams;
- service delivery and registry functions; and
- IT architecture and data quality leads.
DPOs act as translators between statutory requirements and operational reality.
In short – what DPOs should take away (Stage 4)
Stage 4 embeds data protection into national systems and public facing rights mechanisms.
It raises expectations for complaints handling, data quality and cross organisational governance.
DPO priorities should be to:
- establish compliant complaints procedures;
- engage early with NUAR and registration projects; and
- ensure data protection is built into system design, not retrofitted.
Conclusion / Our Thoughts
Overall, these developments are crucial for UK data privacy practitioners as they mark a significant shift towards more robust, transparent, and accountable data management practices.
The update underscores the importance of integrating data protection at the core of system design, rather than as an afterthought, ensuring that individuals’ rights and public trust remain central to digital transformation initiatives.
We can help you to navigate this, as our training materials are updated with the changes as they happen so we recommend the following courses to stay up to date wherever you work in data protection.
Further learning and training
- UK GDPR & Data Protection Training Course: Introductory course covering DPA 2018, UK GDPR, principles, lawful basis, rights, DPIAs, breach management.
- Data Protection Officer (DPO) Training Course: One‑day course covering DPO responsibilities, governance, accountability, GDPR duties and conflict‑of‑interest management.
- Certificate in Managing Data Protection Compliance: Advanced qualification for those seeking a formal data protection certification.
- Data Protection Impact Assessment (DPIA) Training Course: DPIA training listed under the Data Protection category.
- Subject Access Request (SAR) Training Course: Covers SAR rights, handling and decision‑making.
- SAR & Redaction Skills Training Course: Training on assessing SAR content and performing compliant redactions.
- Redaction & Scrutiny Training Course: Focuses on redaction and scrutiny techniques for data disclosure.




