What happened
The U.K.'s Data (Use and Access) Act 2025 is now fully in effect. The law, which received Royal Assent in June 2025, amends the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR). It does not replace them. It was switched on in stages, and with the final tranche now live, the Information Commissioner's Office has confirmed that all of the Act's data protection provisions are in force. Compliance Week's message to compliance officers is measured: the law aims to simplify compliance, but the duty to protect personal data remains paramount.
The most visible change is in consent. Five categories of recognized legitimate interest now allow processing without the usual balancing test, though standard legitimate interests assessments still apply to most commercial activity. Certain low-risk cookies, such as first-party analytics and appearance preferences, no longer require consent, provided visitors are informed and given an easy way to object. Advertising, cross-site tracking and social media pixels still need consent collected before the cookie fires.
Automated decision-making has been recast. The old Article 22 largely prohibited solely automated decisions with legal or similarly significant effects. The new Articles 22A to 22D replace that prohibition with a permission-plus-safeguards model. Significant automated decisions that do not rely on special category data can now run on broader legal bases, including legitimate interests. Those based on special category data still need a specific basis such as explicit consent, and safeguards covering transparency and contestability apply across the board.
Three operational changes round it out. Subject access requests run on a one-month clock that stops while the controller reasonably asks for more information to locate the data. PECR fines jumped from a 500,000 pound cap to 17.5 million pounds or 4% of annual worldwide turnover, whichever is higher, aligning them with the UK GDPR. And since June 2026, organizations must run a statutory complaints procedure with a 30 day acknowledgement deadline.
Why this is a GRC story
The headline issue is divergence. The UK GDPR is deliberately drifting from the EU GDPR, so an organization operating in both markets can no longer assume one program covers both. Controls now need to be mapped per regime, and a cookie banner, a lawful basis or a DSAR workflow built for one side may not satisfy the other.
The practical work lands on compliance teams: update privacy notices and consent flows for the new cookie exemptions, review any AI or automation that makes consequential decisions about people against Articles 22A to 22D, rework DSAR procedures around the stop-the-clock and the reasonable and proportionate search standard, and raise the risk register for the sharply higher PECR fine ceiling. The accountability plumbing is untouched. If you needed a data protection officer, records of processing or impact assessments before, you still do, and the core principles still apply.
What to watch
Watch for the ICO's first enforcement actions at the new fine levels, especially around cookies, and for how the recognized legitimate interests hold up in practice and in any challenge. The transformation of the ICO into the Information Commission is still pending. And for multinationals, keep an eye on how far the U.K. can diverge while the EU keeps its adequacy finding intact, because that finding is what makes the whole arrangement workable.
Attribution: Analysis based on Compliance Week's reporting and related public reporting. This article is original commentary, not a repost of the source material.
