Home / Data protection reform 2026: what the DUAA means for UK organisations
22nd September 2026
Laura Crowe, Senior Associate
The Data (Use and Access) Act 2025 (“DUAA”) has driven many of the data protection developments taking effect in 2026. It amended the UK GDPR, the Data Protection Act and PECR to reflect changes in how personal data is used and in data subjects’ expectations about that use.
This note explains the main practical changes introduced by the DUAA and what they mean for organisations managing day-to-day data protection compliance.
Broadly, the changes seek to balance the rights of organisations with those of individual data subjects by introducing greater clarity and flexibility, while strengthening protections where necessary.
For most organisations, the DUAA changes create six immediate data protection compliance priorities:
The DUAA does not fundamentally change UK data protection law, but it does require organisations to revisit key compliance processes and documents. Immediate attention should focus on complaints handling, subject access requests, privacy notices, lawful basis assessments and governance of automated decision-making.
For each priority, organisations should identify an owner, record the required changes, set a completion date and retain evidence of the review. This will help convert the reforms into demonstrable operational compliance. Organisations that act early will be better placed to support innovation while demonstrating accountability.
If your organisation needs support reviewing its data protection policies, SAR procedures, complaints process or approach to automated decision-making under the DUAA, our data protection solicitors can help you identify the practical steps required and evidence compliance.