The Data (Use and Access) Act 2025 doesn't replace UK data protection law. It does, however, change some of the rules behind ordinary business tasks: using customer data, answering subject access requests, managing website cookies, sending marketing emails and dealing with complaints about personal data.
For most businesses, this will not mean starting again. It is more likely to mean checking whether the documents and processes already in place still reflect what the business actually does.
That matters because data protection paperwork can look fine on the surface. A privacy notice may still be sitting on the website. A cookie banner may still appear. A marketing consent process may still exist. A subject access request procedure may have been written years ago.
But if those documents do not match the way data is now collected, used, shared, tracked or challenged, they may not give the business the protection it needs.
What has changed?
The Act makes several targeted changes. The ones most likely to matter for businesses include:
- clearer rules on reusing personal data for a new purpose;
- a new recognised legitimate interests’ basis for certain specified purposes;
- clearer examples of ordinary legitimate interests, including direct marketing, intra-group administration and network security;
- confirmation that searches in response to subject access requests only need to be reasonable and proportionate;
- changes to the subject access request timetable where identity checks, fees or clarification are needed;
- wider scope for solely automated decision-making, but with safeguards;
- changes to cookies and similar technologies under PECR; and
- a new requirement to operate a data protection complaints process.
These are practical changes rather than a wholesale rewrite. But they touch many of the documents, systems and routines businesses rely on every day.
The key areas to consider are set out below.
Privacy notices
A privacy notice does not need to be updated just to mention the Data (Use and Access) Act 2025. It should, however, be reviewed if it no longer reflects what the business does with personal data.
For most businesses, a useful exercise is therefore to check customer and website privacy notices against current practice.
This should include looking at:
- CRM use;
- fraud prevention;
- analytics;
- product improvement;
- customer profiling;
- intra-group sharing;
- complaints handling;
- marketing; and cookies
If the purposes for which data is used, the lawful bases relied upon, sharing arrangements, complaint routes, automated decisions, cookies, marketing or retention periods have changed, the privacy notice may need to change too.
Cookies, tracking and marketing
Cookies, tracking tools and electronic marketing should also be reviewed. Some limited uses may be easier to justify without consent, but businesses still need to understand what each cookie, tag, pixel or tool does, and whether an exception really applies.
This is not a reason to assume all website tracking is now fine.
In practice, businesses should check:
- what cookies, tags, pixels and similar tools are currently used;
- what each tool does;
- whether it is strictly necessary or used for analytics, marketing or profiling;
- what the cookie banner says;
- whether consent is needed and, if so, how it is obtained;
- how people can opt out; and
- whether the privacy notice and cookie policy match the reality of the website.
The financial risk in this area has also increased, with penalties for breaches of the cookie and marketing rules now brought closer to the UK GDPR penalty regime.
Marketing and legitimate interests
Some uses of personal data may now be easier to justify, although the change should not be read too widely.
The Act introduces a recognised legitimate interests basis for a limited list of purposes. Where it applies, the usual balancing test may not be needed. That is useful, but it is narrow.
The use must still be necessary, and the new basis should not be treated as a general reason to use personal data simply because the business would find it helpful.
The Act also gives clearer examples of processing which may fall within ordinary legitimate interests. These include direct marketing, intra-group transfers for administrative purposes and ensuring the security of network and information systems.
Importantly, this does not remove the separate rules for marketing emails, text messages, cookies or tracking tools. Having a lawful basis under UK GDPR does not, by itself, make a marketing email, text message, cookie or tracking tool compliant.
Subject access requests
The Act confirms that searches in response to subject access requests need only be reasonable and proportionate.
That should help businesses dealing with particularly broad requests from customers, former customers, complainants or others whose personal data they hold.
But “reasonable and proportionate” does not mean a casual search is enough. A business should still be able to explain what it searched, who was involved and why the search was sufficient in the circumstances.
It is therefore sensible to keep a record of:
- which systems were searched;
- who checked their records;
- the date range used;
- the search terms used;
- whether archived material was considered; and
- where appropriate, why the search was considered sufficient.
The Act also allows the response timetable to be paused where clarification is reasonably required to respond to a subject access request.
Businesses should check that their standard acknowledgements, identity check wording, clarification letters, search logs and response timetables reflect the new rules.
Complaints
Complaints may be one of the biggest immediate gaps for many businesses. Individuals must have a clear way to complain about how their data has been handled. Complaints must be acknowledged within 30 days, properly investigated and answered without unnecessary delay.
This is not just a legal or compliance issue. Customer service teams, account managers, call handlers, sales teams and operational staff may all receive complaints about personal data, and those complaints may not arrive neatly labelled as a “data protection complaint”.
For example, a complaint about unwanted marketing, inaccurate records, a delayed subject access response, tracking technology, customer profiling or an automated decision may need to be handled as a data protection complaint.
Businesses should therefore make sure staff know how to recognise a potential data protection complaint and where to send it.
Automated decision-making
The Act allows wider use of solely automated decision-making, provided the right safeguards are in place. This may affect fraud checks, customer onboarding, account suspension, eligibility tools, pricing tools and other automated systems.
That greater flexibility does not mean automated decisions can be left to run unchecked. Individuals must still be told about the relevant decision and be able to make representations, give their side, request human review and challenge the outcome. Stricter rules also still apply to special category data.
Businesses using these systems should therefore be able to explain:
- what the tool does;
- what data it uses;
- whether it profiles individuals;
- who reviews the result; and
- how an unfair or incorrect outcome can be challenged.
What should businesses do now?
Most organisations do not need a brand-new Data (Use and Access) Act policy. In most cases, it will be more useful to update the documents and procedures people use than to create another policy which simply sits in a folder.
For commercial organisations, the priority should be to check:
- customer and website privacy notices;
- cookie banners and cookie policies;
- CRM use;
- analytics and customer profiling;
- fraud prevention processes;
- marketing permissions and opt-out processes;
- subject access request procedures;
- data protection complaint handling; and
- automated customer decisions.
The Act is not a reason for businesses to panic or completely redesign their approach to data protection. It is, however, a good reason to check that the documents and systems already in place still reflect how personal data is being used, and that staff know what to do when a request, complaint or data issue arises.
Key FAQs
Do businesses need a new data protection policy?
Usually not. Most businesses will be better off reviewing the documents and processes they already use, including website privacy notices, cookie wording, marketing permissions, subject access request procedures and complaints processes.
Do privacy notices need updating because of the Act?
Not automatically. They should be reviewed if they no longer reflect how the business actually uses personal data, including CRM activity, analytics, marketing, cookies, customer profiling, fraud prevention or automated decisions.
What should businesses check first?
Start with the public-facing and day-to-day areas: website and customer privacy notices, cookie banners, marketing opt-outs, customer data use, complaints handling and subject access request processes.
These are the area’s most likely to be noticed by customers, complainants or regulators.
If you are not sure whether your privacy notices, cookie wording or data protection processes still reflect how your business works, we can help you review the area’s most likely to be affected.
