On 11 June 2025, the UK’s Data (Use and Access) Bill was passed through both Houses of Parliament and received Royal Assent on 19th June 2025. Now known as the Data (Use and Access) Act (DUAA), the legislation introduces a series of reforms to the UK’s data protection regime.
The DUAA will bring about a number of wide-ranging reforms and associate solicitor Hannah Nagel, who specialises in data protection, outlines some of the key changes which will affect businesses.
- ICO’s fining powers increase to GDPR levels: The ICO’s power to issue fines to businesses under the Privacy and Electronic Communications Regulations (PECR), which govern cookies and direct marketing activities, were capped at £500k but will now rise to GDPR levels. This means that breach of PECR by a business could potentially lead to fines of up to £17.5 million or 4% of worldwide turnover.
- New exemptions to the obligation to obtain consent to cookies: The DUAA introduces a few narrowly-defined exemptions to the general obligation to ‘opt-in’ to cookies. Businesses should consider their use of cookies and whether they may now remove any consent prompts if they fall under an exemption (e.g. cookies for statistical purposes, or cookies for the sole purpose of functionality of the website).
- Recognised legitimate interests: While, generally, businesses must carry out a test to balance legitimate interests in processing the data against the potential impact on the rights and freedoms of the individual data subjects, the DUAA confirms that no balancing test is required to process data for a defined set of ‘recognised’ legitimate interests. For example, the interests of responding to an emergency, or prevention and detection of crime or safeguarding vulnerable individuals.
- Subject Access Rights (SARs): The DUAA has provided clarity and certainty for data controllers in relation to the extent of searches required following receipt of a SAR. Data controllers will only need to provide information in response to a SAR based on “reasonable and proportionate searches”.
- Complaints process for data controllers:The right of data subjects to complain to a data controller has been confirmed in the legislation. Controllers must facilitate the complaints process, such as by providing a complaint form that can be completed online. Controllers must acknowledge complaints within 30 days and take steps to respond without undue delay.
Mincoffs’ commercial services team have extensive experience in advising on data protection and privacy. For further information on compliance with the DUAA or for any other data protection queries, contact associate solicitor Hannah Nagel at hnagel@mincoffs.co.uk or call the office on 0191 281 6151.