Data protection reform 2026: what the DUAA means for UK organisations

22nd September 2026

Laura Crowe, Senior Associate

The Data (Use and Access) Act 2025 (“DUAA”) has driven many of the data protection developments taking effect in 2026. It amended the UK GDPR, the Data Protection Act and PECR to reflect changes in how personal data is used and in data subjects’ expectations about that use.

This note explains the main practical changes introduced by the DUAA and what they mean for organisations managing day-to-day data protection compliance.

Broadly, the changes seek to balance the rights of organisations with those of individual data subjects by introducing greater clarity and flexibility, while strengthening protections where necessary.

Key Changes:

  • Increased flexibility on automated decision-making (ADM): ADM can be used in a wider range of circumstances where organisations implement appropriate safeguards, including transparency, a right to challenge decisions, and access to human intervention and review. (Schedule 6 to the DUAA).
  • New “recognised legitimate interests”: Certain processing activities can rely on a statutory legitimate interest without undertaking the traditional balancing test, reducing the associated administrative burden. Examples include safeguarding, crime prevention and some public interest activities. (Schedule 4 to the DUAA).
  • Changes to Subject Access Requests (SARs): the scope of a “reasonable and proportionate” search has been clarified, and organisations can now pause the response timeframe in specified circumstances. (Part 5, Chapter 1, Sections 76-78 to the DUAA).
  • New requirements for handling data protection complaints: From 19 June 2026, all organisations that process personal data must have a formal process and policy in place to enable data subjects to raise complaints, and those complaints must be handled in accordance with statutory requirements. (Schedule 10 to the DUAA). Also see our earlier article on the topic for more information New statutory right to complain – what this means for employers | Kuits Solicitors
  • Children’s data protections strengthened: Organisations that provide online services likely to be accessed by children must take children’s needs into account when designing and delivering those services. (Part 5, Chapter 1, Section 81 to the DUAA).
  • Research provisions expanded: The DUAA broadens and clarifies when personal data may be used for scientific research, making research activities easier to conduct while maintaining safeguards. (Part 5, Chapter 1, Section 67 to the DUAA).
  • Changes to international transfers: The framework for assessing overseas data transfers has been updated to provide greater flexibility while maintaining protection standards. (Schedules 7-9 to the DUAA).
  • PECR and cookie enforcement changes: The regulator’s powers have increased significantly, with PECR breaches potentially attracting fines comparable to those available under UK GDPR. (Schedule 13 to the DUAA).

Priorities arising from DUAA:

For most organisations, the DUAA changes create six immediate data protection compliance priorities:

  • Implement / update formal complaints processes.
  • Review / update privacy policies and notices, and lawful basis assessments.
  • Review / update SAR procedures.
  • Assess use of AI or automated decision-making tools.
  • Review cookie and electronic marketing compliance.
  • Identify whether any processing activities undertaken can rely on new recognised legitimate interest provisions.  

The DUAA does not fundamentally change UK data protection law, but it does require organisations to revisit key compliance processes and documents. Immediate attention should focus on complaints handling, subject access requests, privacy notices, lawful basis assessments and governance of automated decision-making.

For each priority, organisations should identify an owner, record the required changes, set a completion date and retain evidence of the review. This will help convert the reforms into demonstrable operational compliance. Organisations that act early will be better placed to support innovation while demonstrating accountability.

If your organisation needs support reviewing its data protection policies, SAR procedures, complaints process or approach to automated decision-making under the DUAA, our data protection solicitors can help you identify the practical steps required and evidence compliance.

Kuits FSQS registered
Kuits good employment supporter