Big changes are coming to the UK’s data protection landscape. The new Data (Use and Access) Act 2025 (DUAA) reshapes how organisations collect, manage, and share personal data. While the Act relaxes some privacy requirements, it also tightens others and the penalties for getting it wrong are anything but light.
If your business handles personal data (and let’s face it, most do), now is the time to review your data practices. Here’s a practical checklist of twelve steps every organisation should be taking to prepare for DUAA compliance.
Understand how personal data flows through your organisation
Start by mapping out how personal data is collected, stored, shared, and deleted. Identify any special category data (such as health or biometric information) and make sure it’s handled appropriately.
Review automated decision-making
If your systems make automated decisions, for example, in recruitment or customer approvals, check your processes. Update your policies to reflect DUAA’s new definitions and safeguards.
Refresh your DSAR process
Update your Data Subject Access Request (DSAR) procedures. Make sure response templates include all the required information, and train your staff so they know how to respond within the new timelines.
Audit your cookie use
Take a fresh look at the cookies on your website. Identify which are truly necessary and which are “low risk.” Update your cookie banners and notices so users can easily opt out. Transparency is key here.

Revisit your marketing practices
Review how your business relies on “legitimate interests” for direct marketing. If you’re a charity or nonprofit, you might want to explore the new soft opt-in model for communications.
Keep up with ICO guidance
The Information Commissioner’s Office (ICO) will continue releasing updates and clarifications around DUAA. Set up a process to review new guidance regularly so your compliance efforts stay current.
Introduce a clear complaints process
DUAA places new emphasis on how organisations handle complaints. Establish a transparent procedure, set timelines, and train your team on how to manage and document complaints effectively.
Review internal policies and procedures
From legitimate interest assessments to automated decision-making, take a close look at your internal policies. Make sure your documentation is up-to-date and reflects the latest DUAA requirements.
Update cookie banners and notices
DUAA provides more flexibility here, for instance, statistical and functionality improvement cookies may now fall outside cookie consent requirements. Update your notices accordingly.
Refresh privacy notices
Your privacy notices should accurately reflect how personal data is processed, both at a global and UK level. Ensure they’re aligned with DUAA changes and written in clear, accessible language.
Reassess your business model
DUAA could impact your organisation beyond simple compliance. Consider how the reforms interact with the UK GDPR, DPA, and PECR and what opportunities or risks they might create for your business model.
Keep an eye on EU adequacy status
The European Commission’s current adequacy decision for the UK remains valid until 27 December 2025, but this could change. Staying informed will help you plan for any cross-border data transfer implications.
Why the Data Use and Access Act matters
The Data (Use and Access) Act 2025 is more than just a legislative update it’s a signal that the UK is charting its own course on data protection. For businesses, that means adapting quickly to stay compliant while identifying new opportunities that greater flexibility might bring.
Taking proactive steps now will help your organisation stay on the right side of the law and demonstrate to customers, partners, and regulators that you take data responsibility seriously.
Author: Deborah Holmwood, Client Change & Transformation Partner.
Follow our LinkedIn company page to stay up to date with all our new blogs!

