
23 July 2025
The Data (Use and Access) Act 2025 became law on 19th June and amends elements of the existing law[1] – albeit much of it is yet to come into effect. We think many of the updates are practical and business-friendly, but the regulator’s powers have also been increased, so getting it wrong carries greater risk.
This brief piece focuses on the following updates:
- DSARS – making burdensome or repetitive requests less onerous
- “Legitimate interest” ground for processing – easier to rely on in some circumstances
- Cookies – certain requirements removed
- International transfers – strict equivalence replaced by “not materially lower” standard
- New requirement for organisation to have a complaints policy
- Stronger enforcement powers for the regulator, ICO
- DSARs: mitigating the most onerous elements
The DUAA makes it easier for organisations to manage “vexatious or excessive” data subject access requests.
Key updates include:
- Clearer definitions of “manifestly unfounded or excessive” requests;
- Extended time limits for complex cases;
- The ability to ask for clarification on broad requests; and
- ICO guidance on when the response clock starts ticking.
- Recognised Legitimate Interests: a new lawful basis for doing what makes sense
The DUAA introduces recognised legitimate interests, which are pre-approved data processing purposes that no longer require a detailed balancing test each time. These include:
- Direct marketing;
- Transferring personal data intra-group for internal administration purposes; and
- Ensuring network and information security.
- Certain “low-risk” cookies are now allowed without consent:
The DUAA allows the use of some non-essential cookies without consent, where they serve limited, low-risk analytical purposes. These include:
- Analytics cookies (e.g., for website performance tracking);
- Functional cookies (e.g., to record language preferences); and
- Security cookies (e.g., for fraud detection).
This should promote a better user experience and be less onerous for website operators.
International transfers:
Rather than requiring a strictly equivalent level of data protection in the destination country, the new standard requires that protection is “not materially lower” overall, and transferring organisations can apply this test “reasonably and proportionately.
It remains to be seen whether this will ease international data flows and if it will impact the UK’s EU adequacy rating.
- New requirement re complaints process:
New rules place greater obligations on organisations to handle data protection complaints effectively. These include:
- Provide an accessible means for individuals to complain;
- Acknowledge complaints within 30 days; and
- Resolve issues “without undue delay”.
In practice, this means that even organisations that are not required to have a Data Protection Officer will likely need a dedicated person/function to oversee the complaints procedure.
- The regulator’s new powers:
While most of the changes reduce the compliance burden, falling foul of the law now comes at a greater cost, with greater powers for the ICO (now the Information Commission). It can now:
- Compel witnesses to attend interviews;
- Request technical reports and audits; and
- Impose fines of up to £17.5 million or 4% of global turnover under PECR as well as UK GDPR (previously the maximum PECR fine was £500,000).
How we can help
We’ve been on your side as in-house lawyers/compliance function and we know that privacy compliance can be a headache. Let us help!
We can help work through what the changes mean for your business, including: reviewing your internal data processing/data governance framework, updating your cookies and/or privacy policies and training your team. Do contact us if you wish to discuss anything further.
Email: [email protected]
Phone: 01256 854675
Fiona Skelton (Associate Solicitor)
Email: [email protected]
Phone: 01256 854671
[1] UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Act AKA PECR
Contact Us
Please call us or email and we’ll get back to you as soon as possible.
- 01256 460830
- [email protected]

Exploring legal careers and inspiring future solicitors Last week, Phillips Law welcomed a group of Year 10 students from Testbourne School to our offices, providing them with insights ...
More
We are pleased to announce that Joanna Moroney and Matt Blankley have joined our Corporate & Commercial team. Joanna Moroney – Legal Director Joanna brings nearly a decade of ...
More
Lessons from Standish v Standish[2025] UKSC 26 Introduction Yesterday the UK Supreme Court took the opportunity to clarify the law as to how the sharing principle applies to non-matrimo ...
More
At Phillips Law, we believe in the power of community, creativity, and connection. That’s why we were absolutely delighted to sponsor the very first Family Day at The Grange Festi ...
More
We are incredibly proud to announce that Sian Lias, legal director and co-head of the Wills, Trusts and Probate team at Phillips Law, has been shortlisted for Lawyer of the Year at the ...
More
There has been a lot of press coverage recently following the untimely death of One Direction singer, Liam Payne, and the issue of the Grant of Representation in his estate. According t ...
More