The demand that hasn’t called yet Log in
getfishnet
Test my eligibility

Change your language and country?

You are currently viewing the Switzerland version, in English. Another version may be better suited to your situation.

Stay on this version Change version
Market reading · IT & cybersecurity

Data Use and Access Act: which customer-data process needs a 2026 decision?

How UK organisations can turn DUAA changes to complaints, legitimate interests and automated decisions into a bounded data-governance service.

Cellule études getfishnetAnalyse des marchés et acquisition client5 min read

The most dangerous response to a new data law is often a company-wide policy project that changes everything except the process where customers actually feel the risk. The Data (Use and Access) Act 2025 amended rather than replaced the UK GDPR, Data Protection Act 2018 and PECR. By 19 June 2026, all its data-protection provisions were in force, including new complaint-handling duties and changes affecting recognised legitimate interests, purpose compatibility, automated decision-making and the Information Commissioner’s powers. The commercial opportunity is therefore process-specific: select one use of personal data, decide what the change permits or requires, repair the evidence and train the owner. This reading shows how a privacy, cyber or data adviser can package that work into a paid impact sprint and a recurring change-control service. It also explains how acquisition can reach organisations with a live AI, marketing or complaints trigger without implying that the Act relaxed every UK GDPR obligation or made innovation risk-free.

What did the Data (Use and Access) Act change in 2026?

The Data (Use and Access) Act 2025 changed parts of the UK data-protection framework while leaving the UK GDPR and Data Protection Act in place. The majority of Part 5 commenced on 5 February 2026, and the remaining data-protection provisions, including complaint-handling requirements, were in force by 19 June 2026.

The correct review is provision-led and dated. Some measures offer optional ways to process or document data; others create operational duties. A team should not relabel the entire privacy programme “DUAA compliant” when only one notice or legitimate-interests assessment has been updated.

Start with one decision that uses personal dataStart with one decision that uses personal data
  1. 1What data and purpose are involved?
  2. 2Which lawful basis supports the use?
  3. 3Is automated decision-making significant?
  4. 4How can a person challenge or complain?
  5. 5Which evidence and owner must change?

Which data-protection complaints process is now required?

An organisation handling personal data must give people a clear way to make a data-protection complaint, acknowledge it within 30 days, investigate appropriately and communicate the outcome without undue delay. The process should be accessible, owned and connected to remediation, not buried inside a generic customer-service mailbox.

The complaint record links the person, issue, affected processing, evidence reviewed, response, correction and escalation. Trends should return to product and security owners. A privacy complaint is not closed merely because a template response was sent.

A complaint should improve the underlying data processA complaint should improve the underlying data process
  • Accessible intake
  • Acknowledgement within 30 days
  • Evidence-led investigation
  • Reasoned outcome and remedy
  • Root-cause action

How do recognised legitimate interests affect a business decision?

Recognised legitimate interests provide a lawful basis for specified processing where the ordinary balancing test is not required, but only when the statutory condition genuinely fits. Other legitimate-interest processing still needs the normal purpose, necessity and balancing analysis. The new label is not a shortcut for unrelated marketing, profiling or data reuse.

The process inventory should record the exact condition, dataset, recipients, safeguards and evidence. If the use drifts beyond that condition, the owner reassesses the basis instead of preserving a convenient historic conclusion.

What should a paid DUAA impact sprint deliver?

A paid impact sprint should select one customer-data process, map its purpose and systems, test the lawful basis and rights, identify the provisions that changed and issue a prioritised control plan. It should end with revised evidence, named owners and an implementation decision—not a generic legislative summary or a total privacy-framework rebuild.

Strong first scopes include an automated eligibility journey, marketing suppression process, complaint channel or planned secondary use of customer data. The adviser samples real records and interfaces, distinguishes legal interpretation from technical execution, and refers unresolved specialist questions before the use is approved.

How did the Act change significant automated decisions?

The Act broadens the lawful bases potentially available for significant solely automated decisions that do not use special-category data, while retaining safeguards for affected people. Organisations still need to identify when a decision has legal or similarly significant effects, provide information and enable human intervention, representation and challenge where the rules require it.

The decision file should describe model purpose, inputs, output, significance, lawful basis, special-category handling, human review and override. Calling a reviewer “in the loop” is not enough if that person cannot understand or change the result.

QuestionEvidenceOwner
What decision is made?journey and consequence mapproduct
Which data and basis?data inventory and assessmentprivacy
Is it solely automated?system and human-control testengineering
How can it be challenged?notice and review workflowoperations
Does it work fairly?outcome and error monitoringgovernance

What does purpose compatibility change for data reuse?

The amended framework clarifies when further processing may be treated as compatible with the original purpose and identifies particular situations in legislation. A new analytics, AI or commercial use still needs a documented purpose analysis, transparency and safeguards. Data already collected is not automatically free to reuse because the technology or business case changed.

The reuse gate compares original notice, customer expectation, link between purposes, data sensitivity, consequence and protections. Security, minimisation and retention controls remain relevant even when the use has a lawful basis.

Why should privacy notices follow the process rather than lead it?

A privacy notice should accurately explain the processing decision after purpose, lawful basis, recipients, retention, automation and rights have been resolved. Rewriting public language first can conceal an unchanged system or create promises operations cannot meet. The evidence path should run from actual data flow to approved notice and then to customer testing.

That order also improves acquisition. Buyers are more likely to pay for a sprint that fixes an automated-decision or complaint workflow than for a vague “privacy notice refresh.” The notice becomes a visible output of deeper work, not the whole product.

Public wording is the last mile of the controlPublic wording is the last mile of the control
  • Map the real data flow
  • Decide purpose and lawful basis
  • Test rights and safeguards
  • Implement operational controls
  • Publish accurate customer information

Which organisations are most likely to buy the first sprint?

The strongest prospects are deploying automated decisions, changing customer-data uses, receiving repeated privacy complaints or operating without a clear data owner. A merger, new platform, marketing model, AI procurement or customer-service transformation creates a deadline because systems, notices and responsibilities must converge before the new process scales.

Search captures immediate interpretation questions; technology partners, lawyers and cyber networks create trusted introductions; direct account research can identify AI hiring, product releases and data-transformation programmes. Calls, email and targeted voicemail should test the decision and timing rather than lead with a long list of statutory changes.

Match the trigger to one decision-ready scopeMatch the trigger to one decision-ready scope
  • AI launch to automated-decision review
  • New data reuse to purpose and lawful-basis sprint
  • Complaint backlog to operational workflow repair
  • Platform migration to data-flow and notice reconciliation

What recurring service follows the impact sprint?

The recurring service should review material process changes, monitor complaints and automated outcomes, refresh records and test whether agreed safeguards still operate. It earns a recurring fee when product releases and data uses change often enough to require active governance. It is not a monthly newsletter or a guarantee against ICO investigation.

The operating rhythm can combine a monthly change queue, quarterly evidence review and event-driven escalation. Product, privacy, security and customer operations retain their decisions; the service keeps those decisions coherent and auditable.

Keep the evidence aligned as the product changesKeep the evidence aligned as the product changes
  • Log the proposed data change
  • Screen impact and lawful basis
  • Implement safeguards and information
  • Monitor complaints and outcomes
  • Reopen the decision when evidence changes

When is a DUAA acquisition offer ready to launch?

The offer is ready when the partner can define a buyer and process, deliver a bounded evidence review, distinguish technical remediation from legal advice and maintain change control within capacity. GetFishNet’s free eligibility test checks the trigger, proof, first purchase and recurring economics before recommending channels or market expansion.

The commercial thesis depends on focus. “The law changed” is not enough; the buyer needs a process, deadline and consequence. Where the partner cannot access real flows or influence implementation, the correct eligibility result is to narrow or stop the campaign.

Authorities cited: Information Commissioner’s Office; Department for Science, Innovation and Technology; UK Legislation. Dated references remain in the private source register.

Editorial provenance

Cellule études getfishnetAnalyse des marchés et acquisition clientPublished Updated

Sources used

  1. UK Legislation, Data (Use and Access) Act 2025
  2. Department for Science, Innovation and Technology, Data Use and Access Act 2025: plans for commencement
  3. Information Commissioner's Office, The Data Use and Access Act 2025: what does it mean for organisations?
  4. Information Commissioner's Office, DUAA summary of changes to data protection law
  5. Information Commissioner's Office, New data protection complaints law now in force
  6. Information Commissioner's Office, Consultation on draft guidance about automated decision-making, including profiling
Does your market present a comparable window?

The eligibility report dates and quantifies it, then tests whether it deserves action.

Test my eligibility
g
getfishnet editorial team

The topic is broken down into entities, attributes, evidence, channels, costs and decision points. Institutions are cited in the text; no external resource interrupts the reading path.

documented

All market readings.

Could data-change governance become your next acquisition engine?

Test the audience, evidence, first purchase and recurring service with GetFishNet. The eligibility review is 100% free and looks for genuine development synergies.

Test your eligibility
Test d'éligibilité

Vérifions votre marché.

Dossier reçu.

Nous étudions votre marché et rendons le verdict sous 48 heures.

Fermer

Deux minutes. Verdict sous 48 heures, sans engagement.

Vérifier mon éligibilité