Disclosure: Some links on this page are affiliate links. If you make a purchase through them, Britwealth may earn a commission at no extra cost to you. We only include products and services that are relevant to the topic.
This article is general information only and does not constitute legal advice. For your specific situation, consult a qualified solicitor or data protection specialist.
The Information Commissioner’s Office (ICO) fined Capita £14 million in October 2025 for cybersecurity failures that exposed the personal data of 6.6 million people — the largest fine the regulator had issued up to that point. That figure tells you something important: the era of data protection being a box-ticking exercise is over. The UK’s data landscape has shifted significantly with the Data (Use and Access) Act 2025, which amends the UK GDPR and the Data Protection Act 2018 rather than replacing them. If your business handles personal data — and almost every business does — the rules you were following last year may no longer be enough. Here’s what you actually need to know.
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and is being rolled out in stages. The main data protection amendments came into force on 5 February 2026. That means we’re now in a period where the old rules and the new rules overlap, and the gap between them is where mistakes happen. I’ve been watching how businesses are adapting to these changes, and the pattern is clear: those who treat compliance as a one-off project are the ones who end up in trouble. The rest are treating it as an ongoing process — and that distinction matters more than ever.
Data Privacy After GDPR: Key Takeaways and What the New Rules Mean
The core of the UK GDPR remains intact, but the amendments introduced by the Data (Use and Access) Act 2025 create new flexibilities and new obligations. One term you’ll hear repeatedly is recognised legitimate interests — a new lawful basis under Article 6(1)(ea) UK GDPR that removes the need for a balancing test in specific public-interest scenarios. That’s a significant shift from the previous framework, where every legitimate interest claim required a three-part assessment.
What I tend to notice is that businesses often assume these new flexibilities mean less work. In practice, they mean different work. You still need to document your basis for processing, and the categories where you can skip the balancing test are narrow. If your processing falls outside those five areas — and for most commercial activity it will — the old rules still apply.
Why the Data (Use and Access) Act 2025 Changes the Compliance Landscape for UK Firms
The practical consequence of these changes is that your compliance framework almost certainly needs updating. The ICO’s enforcement approach has already shifted — the Capita fine wasn’t an outlier, it was a signal. The regulator now has the power to impose fines of up to £17.5 million or 4% of global annual turnover for the most serious breaches, and up to £8.7 million or 2% for standard-tier infringements. PECR fines, previously capped at £500,000, now sit at the same level.
Consider a medium-sized business that processes customer data for direct marketing. Under the old rules, you needed consent for most marketing cookies and a balancing test for legitimate interests. Under the new rules, analytics cookies may be exempt from consent, but direct marketing still requires the full three-part balancing test. Get that wrong, and you’re looking at a fine that could run into hundreds of thousands of pounds — not to mention the reputational damage.
The EU adequacy decision for the UK has been renewed until 27 December 2031, which means data can continue to flow freely from the EU to the UK. But the European Commission will reassess adequacy against the updated UK law, so divergence from the EU GDPR carries real risk. If the UK’s framework is seen as offering “not materially lower” protection — the new standard — rather than “essentially equivalent” protection, that adequacy decision could be at risk down the line.
One thing I’d flag: the international transfers framework has changed more than most businesses realise. The adequacy test has shifted from “essentially equivalent” to “not materially lower” protection, and you’re now required to conduct Transfer Impact Assessments even when using standard contractual clauses. That’s a new layer of work that many organisations haven’t yet addressed.
Where UK Firms Go Wrong With Data Privacy Compliance
Treating the Complaints Process as Optional
The new mandatory complaints process — which must be in place by 19 June 2026 — applies to every organisation, regardless of size. There’s no small business exemption. The procedure must include a 30-day acknowledgement, a written process, an assigned owner, logged timelines, and outcome delivery. I’ve seen businesses assume this is a “nice to have” rather than a legal requirement. It isn’t. The ICO will expect to see evidence of a functioning process, and if you don’t have one, you’re already non-compliant.
Misunderstanding the SAR Stop-the-Clock
The new stop-the-clock mechanism for Subject Access Requests is useful, but only if you use it correctly. You can pause the one-month deadline when you need clarification from the requester, but you must document the pause, the reason for it, and when the clock resumes. The search itself only needs to be “reasonable and proportionate” under the updated Article 15(1A), but that doesn’t mean you can skip thorough searches. If you pause the clock without proper documentation, you’re effectively in breach of the deadline.
Assuming Recognised Legitimate Interests Cover Everything
The five recognised legitimate interest categories are narrow: national security, public security and defence, emergency response, crime prevention and investigation, and safeguarding vulnerable individuals. Direct marketing, intra-group data sharing, and network security are explicitly excluded and still require the full balancing test. I’ve seen businesses try to stretch these categories to cover commercial activities, and that’s a fast track to enforcement action.
Neglecting Transfer Impact Assessments
Even if you use standard contractual clauses for international data transfers, you now need a Transfer Risk Assessment. The adequacy standard has shifted to “not materially lower” protection, and you need to document your assessment of the destination country’s data protection framework. This is a new requirement that many businesses haven’t built into their workflows yet.
→ Scroll right to see all columns
| Compliance Area | Old Requirement | New Requirement (Post-DUAA 2025) | Deadline |
|---|---|---|---|
| Complaints Process | Recommended but not mandatory | Mandatory, with 30-day acknowledgement and published procedure | 19 June 2026 |
| SAR Response | One-month deadline, no pause | Stop-the-clock mechanism available with documentation | 5 February 2026 |
| Cookie Consent | Consent required for most non-essential cookies | Exemptions for analytics, personalisation, UX, fraud prevention | 5 February 2026 |
| International Transfers | Essentially equivalent protection | Not materially lower protection; TIA required even with SCCs | 5 February 2026 |
How to Update Your Data Privacy Framework for 2026 and Beyond
Implement Your Complaints Process Now
Don’t wait until June 2026. Start building your data protection complaints procedure today. You need a written process that covers how complaints are received, acknowledged within 30 days, investigated, and resolved. Assign an owner, log timelines, and document outcomes. The process must be published — typically on your website — so data subjects can find it easily. If you’re unsure about the legal specifics, a service like JustAnswer Business Law can connect you with a solicitor who specialises in data protection compliance.
Update Your SAR Procedures
Your Subject Access Request process needs to reflect the stop-the-clock mechanism. Train your team on when and how to pause the deadline — only when you need clarification from the requester, not as a default delay tactic. Document every pause, including the date, the reason, and when the clock resumes. Your searches only need to be “reasonable and proportionate,” but you should still document the search steps you took. A simple log template can save you significant headaches if the ICO comes calling.
Review Your Lawful Basis and Legitimate Interests
Go through every processing activity in your business and identify which lawful basis you’re relying on. If you’re using legitimate interests for direct marketing, you still need the full balancing test. If you’re processing data for one of the five recognised categories, document why it qualifies and ensure the processing is necessary and proportionate. This is also a good time to audit any automated decision-making processes — the default prohibition has been lifted, but you still need appropriate safeguards including human intervention and the right to contest decisions.
Conduct Transfer Impact Assessments
For every international data transfer, even those using standard contractual clauses, you need a Transfer Risk Assessment. Document the destination country’s data protection framework, the specific risks to the data, and the mitigations in place. The standard is now “not materially lower” protection, which is a slightly lower bar than “essentially equivalent,” but you still need to demonstrate that you’ve assessed the situation. If you’re managing multiple international transfers, a data protection compliance software tool can help you track and document these assessments systematically.
Frequently Asked Questions About UK Data Privacy After GDPR
Does the Data (Use and Access) Act 2025 replace the UK GDPR? ▾
Do small businesses need a complaints process? ▾
Can I use cookies for analytics without consent now? ▾
What happens if I miss the 19 June 2026 deadline? ▾
Is direct marketing covered by recognised legitimate interests? ▾
Do I still need a Transfer Impact Assessment if I use standard contractual clauses? ▾
Data Privacy After GDPR: The Bottom Line for UK Firms
The Data (Use and Access) Act 2025 hasn’t torn up the rulebook — it’s rewritten parts of it. The flexibilities around cookies, SARs, and recognised legitimate interests are real, but they come with new obligations that many businesses haven’t yet addressed. The mandatory complaints process, the stop-the-clock documentation requirements, and the Transfer Impact Assessments are all areas where the ICO will expect to see evidence of compliance. My advice is to treat this as an ongoing process, not a one-off project. Start with the complaints procedure — that’s the most time-sensitive deadline — and work through the rest systematically. If this was useful, you might also want to read The Brexit Effect: Navigating New Realities for UK Businesses.
Remember: this article is general information only. For advice on your specific situation, speak to a qualified solicitor or data protection specialist.
Sources and Further Reading
From Start-Up to Scale-Up: The Biggest Challenges Facing UK Entrepreneurs — Explores how growing businesses can build compliance frameworks that scale with them.
GDPR Register (2026). UK Data Law Changes 2026 Checklist. 🔗
Recording Law (2026). United Kingdom Data Privacy Laws. 🔗
Blackfords (2026). Complying with UK Data Protection Laws in 2026. 🔗
Shepherd and Wedderburn (2026). Significant Changes to UK Data Protection Legislation. 🔗
