New changes to UK data protection law – do you know how it affects your business?
New changes to UK data protection law – do you know how it affects your business?
Jacqueline Drury

23 July 2025

The Data (Use and Access) Act 2025 became law on 19th June and amends elements of the existing law[1] – albeit much of it is yet to come into effect. We think many of the updates are practical and business-friendly, but the regulator’s powers have also been increased, so getting it wrong carries greater risk.

This brief piece focuses on the following updates:

  • DSARS – making burdensome or repetitive requests less onerous
  • “Legitimate interest” ground for processing – easier to rely on in some circumstances
  • Cookies – certain requirements removed
  • International transfers – strict equivalence replaced by “not materially lower” standard
  • New requirement for organisation to have a complaints policy
  • Stronger enforcement powers for the regulator, ICO

 

  1. DSARs: mitigating the most onerous elements

 The DUAA makes it easier for organisations to manage “vexatious or excessive” data subject access requests.

Key updates include:

  • Clearer definitions of “manifestly unfounded or excessive” requests;
  • Extended time limits for complex cases;
  • The ability to ask for clarification on broad requests; and
  • ICO guidance on when the response clock starts ticking.
  1. Recognised Legitimate Interests: a new lawful basis for doing what makes sense

The DUAA introduces recognised legitimate interests, which are pre-approved data processing purposes that no longer require a detailed balancing test each time. These include:

  • Direct marketing;
  • Transferring personal data intra-group for internal administration purposes; and
  • Ensuring network and information security.
  1. Certain “low-risk” cookies are now allowed without consent:

The DUAA allows the use of some non-essential cookies without consent, where they serve limited, low-risk analytical purposes. These include:

  • Analytics cookies (e.g., for website performance tracking);
  • Functional cookies (e.g., to record language preferences); and
  • Security cookies (e.g., for fraud detection).

This should promote a better user experience and be less onerous for website operators.

 International transfers:

Rather than requiring a strictly equivalent level of data protection in the destination country, the new standard requires that protection is “not materially lower” overall, and transferring organisations can apply this test “reasonably and proportionately.

It remains to be seen whether this will ease international data flows and if it will impact the UK’s EU adequacy rating.

  1. New requirement re complaints process:

New rules place greater obligations on organisations to handle data protection complaints effectively. These include:

  • Provide an accessible means for individuals to complain;
  • Acknowledge complaints within 30 days; and
  • Resolve issues “without undue delay”.

In practice, this means that even organisations that are not required to have a Data Protection Officer will likely need a dedicated person/function to oversee the complaints procedure.

  1. The regulator’s new powers:

While most of the changes reduce the compliance burden, falling foul of the law now comes at a greater cost, with greater powers for the ICO (now the Information Commission). It can now:

  • Compel witnesses to attend interviews;
  • Request technical reports and audits; and
  • Impose fines of up to £17.5 million or 4% of global turnover under PECR as well as UK GDPR (previously the maximum PECR fine was £500,000).

How we can help

We’ve been on your side as in-house lawyers/compliance function and we know that privacy compliance can be a headache. Let us help!

We can help work through what the changes mean for your business, including: reviewing your internal data processing/data governance framework, updating your cookies and/or privacy policies and training your team. Do contact us if you wish to discuss anything further.

Jacqueline Drury (Partner)

Email: [email protected]

Phone: 01256 854675

Fiona Skelton (Associate Solicitor)

Email: [email protected]

Phone: 01256 854671

[1] UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Act AKA PECR

Contact Us

Have more questions?
Our expert solicitors are here to take the worry off your hands.
Please call us or email and we’ll get back to you as soon as possible.
News
Community Raises £39k for Treloar’s
Community Raises £39k for Treloar’s

Phillips Law was delighted to support the Dummer Fair as headline sponsor, held from 8 to 9 October 2025 at the Dummer Cricket Centre in Basingstoke. The Fair is one of Hampshire’s prem ...

More
Phillips Law’s Success at Basingstoke Half Marathon
Phillips Law’s Success at Basingstoke Half Marathon

Phillips Law was proud to once again be the main sponsor of the Basingstoke Half Marathon, 10K and 5K, which took place on Sunday, 5 October 2025. The event, organised by Destination Ba ...

More
Phillips Law Sponsors Unforgettable Evening with Dame Mary Berry at Winchester Books Festival
Phillips Law Sponsors Unforgettable Evening with Dame Mary Berry at Winchester Books Festival

Phillips Law was delighted to be the headline sponsor of a truly exceptional evening at Winchester Books Festival, hosting Dame Mary Berry as she celebrated her 90th birthday and the re ...

More
Supporting the Next Generation of Local Rugby 🏉
Supporting the Next Generation of Local Rugby 🏉

Phillips Law is delighted to announce our sponsorship of the Basingstoke Rugby Football Club U15 team for the 2025/26 season. We are proud to back a squad of 30 talented young players w ...

More
Phillips Law sponsors Dummer Fair in support of Treloars
Phillips Law sponsors Dummer Fair in support of Treloars

Hot on the heels of Sunday’s Basingstoke Half Marathon, Phillips Law was back in the community this week as headline sponsor of the Dummer Fair at Dummer Cricket Centre. The two-d ...

More
Another great day at the Phillips Law Basingstoke Half Marathon!
Another great day at the Phillips Law Basingstoke Half Marathon!

Sunday 5th October was a day to remember for Team Phillips. We fielded our biggest team yet at the Phillips Law Basingstoke Half Marathon, 10k, 5k and kids’ races, and what a day ...

More