...

New updates to UK data laws change how businesses can use your personal information without asking first

The use of electronic devices – ever since their introduction into our lives – has led to the inevitable collection and storage of information, a process we consent to daily without even realizing it. Whether visiting a bank, purchasing household appliances, or even ordering something online, we provide data to various businesses. We provide personal data – such as names, addresses, and phone numbers – so frequently that we rarely stop to consider the potential consequences. It has become such an integral part of everyday life and almost every purchase that we share this information casually, without a second thought as to how it is subsequently used or stored, or whether it might be disseminated to others. That isn’t the main reason, but it is part of the reason why many people fall victim to all kinds of scams.

In this regard, the Data Use and Access Act of 2025 (DUAA) introduced phased clarifications aimed at raising public awareness regarding personal information. The DUAA amends, but does not replace, the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA) and the Privacy and Electronic Communications Regulations (PECR). It changes data protection laws in order to promote innovation and economic growth and make things easier for organisations, whilst it still protects people and their rights.

Key changes:

  1. Automated decision-making (ADM) – for the organisations  to be able to make decisions based solely on automated processing that have legal or similarily significant effects on individuals. Organisations will be able to make such decisions in wider circumstances but must implement certain safeguards. However, for those processing under the law enforcement regime, the Act provides for an exemption to the safeguards for certain, limited, reasons, such as to safeguard national security, or to avoid the obstruction of an inquiry.
  2. Subject Access – requests by individuals to access and receive a copy of their personal data The DUAA clarifies the time limits for respond to subject access requests. Like the “stop the clock” rule, allowing organisations to pause the response time if they need more information from the requester.
  3. Children’s Data Protection – new rules require certain online services likely to be accessed by children to consider how to protect and support them when designing these services
  4. Scientific Research (including commercial research) – It allows researchers to seek consent for broad areas of related research and clearly outlines the safeguards required for using personal data in research.
  5. Recognised Legitimate Interests – the Act gives businesses more confidence to use data for crime prevention, safeguarding, responding to emergencies, and other specified legitimate interests.
  6. International Data Transfers – the Act simplifies rules and clarification for transferring personal data internationally.
  7. Responding to Complaints – from individuals who are concerned that the way their information is used breaches the data protection legislation
  8. Storage and Access Technologies (such as cookies) – the Act allows the use of storage and access technologies without explicit consent in certain, low-risk situations.

The law is moving in a direction that enables both individuals and organizations to cooperate in the interest of a society that is better protected, better informed, and more engaged. This points toward a potential future where things are elevated to a new level-one that prevents unauthorized individuals from misusing personal information. Many people fall victim to fraud due to system breaches or data leaks, often with little to no protection against the consequences. These key changes aim not only to make it easier for businesses to use information and take specific necessary actions but also to ensure a more controlled and regulated level of consumer protection. A regulated environment in which user data is used within a defined framework, with the option for any user to request a copy of the data stored about them. An environment that enables data usage – including when necessary to support investigations or provide protection against national or other threats. An environment that introduces new safeguards and rules regarding children and their safety online. An environment that is transparent to the public – ensuring citizens are well-informed while also having the opportunity to lodge a complaint if they perceive an improper exercise of authority concerning consumer rights. An environment focused on updating and modernizing operations within the virtual world – a necessity in a landscape that is constantly evolving and changing.

share this Article

Recent Articles

Written By: