Data (Use and Access) Act 2025 Compliance Check
Check whether your business has adapted to the Data (Use and Access) Act 2025 reforms to UK GDPR and PECR.
Why this matters
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and makes the first significant changes to UK data protection law since GDPR was introduced. It creates a new “recognised legitimate interests” lawful basis that lets businesses process personal data for specific purposes — such as safeguarding, crime prevention, and responding to legal obligations — without carrying out the usual legitimate interests balancing test. It also relaxes the rules on solely automated decision-making, extends the direct marketing “soft opt-in” rule beyond commercial organisations to charities and other non-commercial bodies, eases cookie consent requirements for low-risk purposes like analytics and security, and reforms how Subject Access Requests are handled. The ICO itself is being restructured into the Information Commission, with a chair and board rather than a single Commissioner.
For most UK businesses, these changes mean existing GDPR compliance work needs a fresh look rather than a rebuild. A new requirement to have a clear internal complaints-handling process for data subjects — so people can complain to the business before escalating to the regulator — is now expected to be in place. Businesses using automated tools for recruitment screening, credit decisions, or customer scoring need to reassess whether their safeguards still meet the revised Article 22 rules. And any organisation relying on “soft opt-in” marketing, or claiming legitimate interests as a lawful basis, should check whether the new rules change what they can do — getting it wrong still exposes a business to ICO enforcement action and fines under the existing UK GDPR penalty regime.
What you'll need
- Your current privacy policy and lawful basis documentation
- Whether you use automated decision-making or profiling on customers or staff
- Your current process (if any) for handling data protection complaints internally
- Whether you send direct marketing emails or texts, and how you currently obtain consent
- Whether your website uses cookies or similar tracking technologies
What you'll get
A personalised compliance report covering: a score out of 100, an executive summary, a list of findings ranked by severity, and a prioritised action plan with timeframes.
This check reviews your data protection practices against the Data (Use and Access) Act 2025 reforms, highlighting where your lawful bases, marketing consent, automated decision-making safeguards, or complaints process may need updating.
General guidance only — not legal advice. Consult a qualified UK solicitor for specific issues.