The Data Use and Access Act 2025 (DUAA) introduces important changes to UK data protection law that will affect charities, community groups, social enterprises and other organisations that process personal data.
While the Act does not replace existing data protection legislation, it updates and builds upon current requirements, introducing new responsibilities and greater flexibility in some areas. Organisations should take time to understand the changes and review their policies, procedures and data protection practices.
The information below provides an overview of the key changes and outlines practical steps organisations can take to prepare.
The Data Use and Access Act 2025 (DUAA)
The Data Use and Access Act 2025 (DUAA) is new UK legislation that updates how organisations use, access and manage personal data.
It received Royal Assent on 19 June 2025 and represents a significant development in UK data protection law.
The Act does not replace existing laws, but instead amends and builds on:
• UK General Data Protection Regulation (UK GDPR)
• Data Protection Act 2018
• Privacy and Electronic Communications Regulations (PECR)
Its aim is to make data use simpler, more flexible and better suited to innovation, while maintaining strong protections for individuals.
The DUAA applies to all organisations that process personal data, including charities, community groups and voluntary organisations.
It introduces changes designed to:
• Reduce unnecessary administrative burden
• Support responsible data sharing
• Improve transparency and trust with service users
• Strengthen individuals’ rights
The Data Use and Access Act 2025 (DUAA)
The Data Use and Access Act 2025 (DUAA) is new UK legislation that updates how organisations use, access and manage personal data. It received Royal Assent on 19 June 2025 and represents a significant development in UK data protection law. [gov.uk], [en.wikipedia.org]
The Act does not replace existing laws, but instead amends and builds on:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations (PECR) [ico.org.uk]
Its aim is to make data use simpler, more flexible and better suited to innovation, while maintaining strong protections for individuals. [gov.uk]
The DUAA applies to all organisations that process personal data, including charities, community groups and voluntary organisations. [legalclarity.org]
It introduces changes designed to:
- Reduce unnecessary administrative burden
- Support responsible data sharing
- Improve transparency and trust with service users
- Strengthen individuals’ rights
Key Changes for Organisations
One of the most important changes is a stronger right for individuals to complain directly to organisations about how their data is used. [alston.com]
Organisations are now expected to:
- Have a clear and accessible complaints process
- Acknowledge complaints (typically within 30 days)
- Respond in a timely and transparent way
- Keep records of complaints and outcomes
This means having a formal data protection complaints procedure is essential.
ICO guidance on handling complaints:
https://ico.org.uk/make-a-complaint/
The DUAA introduces new ways organisations can lawfully use personal data, including:
- A new lawful basis known as**“recognised legitimate interests”** [alston.com]
- Greater clarity on research and data reuse, including “broad consent” [digit.fyi]
These changes may benefit voluntary organisations carrying out research, monitoring or service evaluation.
The rules on automated decision-making have been updated, allowing more flexibility but with safeguards.
Organisations must still:
- Inform individuals about automated decisions
- Allow individuals to challenge outcomes
- Provide access to human review [gov.uk]
Cookies and Online Data
The Act allows certain low-risk cookies (e.g. for analytics or improving website performance) to be used without explicit consent in some cases. [digit.fyi]
ICO guidance on cookies and online tracking:
https://ico.org.uk/for-organisations/guide-to-pecr/cookies-and-similar-technologies/
Stronger ICO Role and Enforcement
The DUAA strengthens the role and responsibilities of the Information Commissioner’s Office (ICO), including:
- A clearer strategic focus on data protection and public trust
- Greater transparency and accountability
- Enhanced enforcement powers [gov.uk]
Learn more about the ICO and its role:
https://ico.org.uk/about-the-ico/
What Organisations Should Do Now
As the changes are introduced between 2025 and 2026, organisations should take steps to prepare and review current practices. [ico.org.uk], [bratby.law]
Key actions include:
- Reviewing and updating data protection policies
- Putting in place (or updating) a complaints handling process
- Ensuring privacy information is clear and accessible
- Training staff on updated responsibilities
- Reviewing how personal data is used, especially for new purposes
ICO overview of the Act:
Data Use and Access Act 2025 – What it means for organisations
UK Government summary of changes:
DUAA data protection changes (GOV.UK)


