The Data (Use and Access) Act 2025 (DUAA) amends the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR) rather than replacing them. Most of its data protection changes have been in force since 5 February 2026, and for website owners the practical effects sit in four areas: cookie consent, subject access handling, lawful bases, and a steep rise in the fines available under PECR.
The detail matters, because some of the changes cut compliance work while others add new duties.
The DUAA received Royal Assent on 19 June 2025 and commenced in stages, with the main data protection package taking effect on 5 February 2026.
Amended PECR now lists five purposes that are exempt from cookie consent, including first-party statistics and appearance preferences, provided visitors are informed and can easily object.
The maximum PECR fine rose from GBP 500,000 to GBP 17.5 million or 4% of worldwide annual turnover, matching the UK GDPR ceiling.
Access request searches are now limited to what is reasonable and proportionate, and the one-month response clock pauses while a controller waits for clarification or identity checks.
The European Commission renewed the UK adequacy decisions on 19 December 2025, so personal data continues to flow freely from the EEA to the UK until at least 27 December 2031.
What Is the Data Use and Access Act?
The Data (Use and Access) Act 2025 is a UK statute that reforms existing data protection and e-privacy law instead of writing a new rulebook. It is the largest single revision of UK data law since Brexit, yet it keeps the UK GDPR's principles, rights and lawful bases intact.
The Act runs to seven parts. Alongside the privacy reforms in Part 5, it creates frameworks for smart data schemes and digital verification services, and Part 6 restructures the regulator itself. For a working website, Part 5 and the PECR amendments carry nearly all of the weight, with targeted changes to purpose limitation, scientific research provisions and international transfer terminology rounding out the package.
Because the DUAA amends rather than replaces, compliance work done for the UK GDPR still stands. What changes is a set of specific rules layered on top.
When Did the DUAA Take Effect?
In stages, not on a single day. A first tranche of technical provisions and new statutory objectives for the Information Commissioner's Office (ICO) commenced on 20 August 2025. The main data protection and e-privacy package followed on 5 February 2026 under the Commencement No. 6 Regulations, and the duty to operate a complaints procedure applies from 19 June 2026.
As of August 2026, every change described in this guide is in force except the transformation of the ICO into the Information Commission, which is still pending. The short gap between the Commencement No. 6 Regulations being made on 29 January 2026 and the rules applying a week later drew criticism, and it left many organisations updating policies after the law had already changed. If that includes your site, the changes below are live obligations rather than items on a horizon-scanning list.
| Area | Before the DUAA | Since the DUAA |
|---|---|---|
| First-party analytics | Prior consent required under PECR | Exempt for statistical service improvement, with information and an opt-out (from 5 February 2026) |
| Appearance and preference storage | Consent unless strictly necessary | Exempt where it adapts the service to user preferences, with the same objection right |
| Advertising and tracking cookies | Prior consent required | Prior consent still required |
| Maximum PECR fine | GBP 500,000 | GBP 17.5 million or 4% of worldwide turnover |
| Access request searches | Scope set by case law and guidance | "Reasonable and proportionate" standard written into Article 15 |
| Access request deadline | One month, pausing by guidance only | One month with a statutory stop-the-clock rule in Article 12A |
| Automated decision-making | Prohibited by Article 22, narrow gateways | Permitted with safeguards under Articles 22A to 22D |
| Complaints to controllers | No statutory duty | Procedure required, acknowledgement within 30 days (from 19 June 2026) |
How Does the DUAA Change Cookie Consent?
Amended regulation 6 of PECR now lists five purposes for which storing or reading information on a visitor's device does not need consent: transmitting a communication, delivering a service the user asked for, collecting statistical information to improve the service, adapting the appearance of the service to the user's preferences, and locating someone who needs emergency assistance. The first two restate exceptions that already existed; the other three are new, and the statistical and appearance exceptions only apply if visitors get clear information and a simple, free way to object.
That last condition is the part many summaries skip. An exempt analytics setup is not invisible: the visitor must still be told about it and offered an opt-out, so the UK has moved from prior consent to an objection model for this narrow category, not to silence. Everything outside the listed purposes, including advertising, cross-site tracking and social media pixels, still needs consent collected before the cookie fires.
The ICO published its final guidance on the use of storage and access technologies on 29 April 2026 after two consultation rounds. The name change from the old cookies guidance is deliberate: it covers tracking pixels, device fingerprinting, web storage, scripts, tags and link decoration on the same terms as cookies, and it adds detail on what a simple means of objecting looks like and how to treat tools used for several purposes at once. The exemption conditions have real teeth, so check the mechanics against the five cookie exemptions in detail before switching your analytics cookies away from a consent flow.
What Are the New PECR Fine Levels?
The DUAA aligns PECR enforcement with the UK GDPR. The old ceiling of GBP 500,000 has been replaced by fines of up to GBP 17.5 million or 4% of worldwide annual turnover, whichever is higher, a 35-fold jump in the cash maximum that has applied since 5 February 2026. A misconfigured cookie banner now carries the same theoretical exposure as a data breach under the UK GDPR penalty structure.
Enforcement appetite matters as much as the ceiling. The ICO updated its online tracking strategy alongside the April 2026 guidance and has signalled that advertising-related tracking without valid consent is where it intends to focus, particularly where sites offer no meaningful opt-out or stretch the statistical exception past its wording. Recent cookie consent fines across Europe show regulators are comfortable acting on banner-level detail, and the UK regulator now has a penalty range to match.
What Are Recognised Legitimate Interests?
A new lawful basis in Article 6(1)(ea) of the UK GDPR lets controllers process personal data for a recognised legitimate interest without running the usual balancing test. The list in Annex 1 covers disclosures to public bodies that request information for their public tasks, national security, public security and defence, responding to emergencies, detecting, investigating and preventing crime, and safeguarding vulnerable individuals. The Secretary of State can amend the list, which is one of the divergence points the EU is watching.
Routine commercial processing is not on it. Direct marketing, intra-group data sharing and network security stay under ordinary legitimate interests, where the Act now confirms in the operative text that direct marketing can qualify, subject to the full balancing assessment. For most websites the recognised list changes little day to day; its value shows up when the police request data during an incident, or when a safeguarding disclosure needs a clear legal footing without a documented balancing exercise.
How Do Subject Access Requests Change?
Two long-standing ICO positions on the data subject access request (DSAR) are now statute. A new Article 12A codifies the stop-the-clock rule: the one-month deadline pauses while you wait for information you reasonably need from the requester, such as identity verification or clarification of scope, and resumes once it arrives. Article 15 now states that a controller only has to carry out a reasonable and proportionate search, replacing exhaustive trawls through every mailbox and backup with a defensible, documented scope.
The clock also starts later than many workflows assume, running from receipt of the request plus any identity check or applicable fee rather than from the first email alone. The two-month extension for complex or multiple requests remains available. If your subject access requests process was written before 2026, it is worth rewriting the timeline logic and adding a field to record why a given search scope was proportionate.
What Changed for Automated Decision-Making?
Articles 22A to 22D replace the old Article 22 prohibition with a permission-plus-safeguards model. Significant decisions taken solely by automated means are now allowed on any lawful basis except a recognised legitimate interest, provided the person receives information about the decision, can obtain human review, and can contest the outcome. Decisions involving special category data remain under the stricter former approach.
For a typical website this touches things like automated account suspensions, credit-style scoring at checkout or algorithmic content restrictions. The decisions become easier to run lawfully and harder to run quietly.
Do You Need a Complaints Procedure Now?
Yes. Since 19 June 2026, section 164A of the Data Protection Act 2018 requires every controller to help people complain about how their personal data has been handled, for example through a complaints form, and to acknowledge each complaint within 30 days before responding without undue delay. The duty applies to small sites as much as large platforms.
A short, findable "data protection complaints" section in your privacy policy, backed by a monitored inbox, covers the mechanics for most site owners.
What Happens to the ICO?
Part 6 of the Act turns the Information Commissioner, legally a single officeholder, into the Information Commission, a body corporate governed by a board with a chair, a chief executive and non-executive directors, in line with regulators such as the Financial Conduct Authority. The transition had not completed by August 2026: the ICO continues to operate under its current name while board appointments and transfer legislation are finalised, with the switch expected during 2026 or 2027.
Keep referencing the ICO in your documents for now, and use wording flexible enough to survive the rename.
Does the DUAA Affect EU Adequacy?
The risk was real, and it has passed for now. The European Commission assessed the DUAA before renewing both UK adequacy decisions on 19 December 2025, following an opinion from the European Data Protection Board (EDPB) and approval by the member states. The renewed adequacy decisions run until 27 December 2031, with a joint review after four years, so personal data keeps flowing from the EEA to the UK without extra transfer mechanisms.
Renewal is not indifference. The Commission flagged the UK's new powers to amend the recognised interests list and the softened cookie and automated decision-making rules as areas it will monitor, which is a further reason not to apply the UK's relaxed cookie model to EU visitors.
What Should Website Owners Do Now?
Start with facts rather than settings. Run a cookie audit so you know exactly which cookies and similar technologies fire, when, and for what purpose, because the new exemptions are purpose-limited and a tool that mixes statistics with marketing falls outside them.
Then make one deliberate decision: whether to move UK analytics onto the statistical exemption or keep prior consent everywhere. Using the exemption means publishing clear information and wiring a working objection control; keeping consent means fewer moving parts and one model for all visitors. Neither answer is wrong, but drifting into the exemption without the opt-out mechanism is the specific failure the ICO has said it will look for.
Sites with international traffic need a geo-aware setup, because EU visitors remain under the ePrivacy Directive and the EU General Data Protection Regulation (GDPR), which still demand prior consent for analytics and marketing. A consent management platform (CMP) with geolocation rules can serve the UK objection model to UK visitors and a consent-first flow to everyone in the EU, while Google Consent Mode v2 continues to apply wherever Google advertising or measurement runs for UK and EEA traffic. Kukie.io's cookie scanner and geo-targeting run the two models side by side from one configuration.
Round it off with paperwork: refresh the cookie and lawful-basis sections of your privacy notice, add the complaints route, restructure DSAR timelines around Article 12A, and keep your cookie banner in place for everything the exemptions do not cover.
Frequently Asked Questions
Do UK websites still need a cookie banner after the DUAA?
Yes, in most cases. Advertising, cross-site tracking and social media cookies still require prior consent, and sites with EU visitors remain under the stricter EU rules. Only a narrow set of purposes, such as first-party statistics with an opt-out, is exempt.
When did the Data Use and Access Act come into force?
In stages. The first provisions commenced on 20 August 2025, the main data protection package took effect on 5 February 2026, and the duty to operate a complaints procedure applies from 19 June 2026.
What is the maximum fine under PECR after the DUAA?
Up to GBP 17.5 million or 4% of worldwide annual turnover, whichever is higher. Before the DUAA the ceiling was GBP 500,000, so cookie and marketing breaches now carry the same exposure as UK GDPR infringements.
Does the DUAA replace the UK GDPR?
No. It amends the UK GDPR, the Data Protection Act 2018 and PECR, so existing compliance work remains valid and the core principles, rights and lawful bases stay in place.
Do EU visitors to a UK website still need cookie consent?
Yes. The DUAA changes UK law only, so the ePrivacy Directive and the EU GDPR still require prior consent for analytics and marketing cookies served to visitors in the EU. Geo-targeted consent settings solve this.
Did the EU renew the UK adequacy decision after the DUAA?
Yes. The European Commission renewed both UK adequacy decisions on 19 December 2025, keeping EEA-to-UK data flows open until 27 December 2031, with a review after four years.
Get Your Cookie Setup Ready for the New UK Rules
If you are unsure which of your cookies qualify for a UK exemption and which still need consent, start with a scan. Kukie.io detects and categorises every cookie your site sets, and geolocation rules let you run the UK objection model and EU prior consent side by side.
