The most dangerous response to a new data law is often a company-wide policy project that changes everything except the process where customers actually feel the risk. The Data (Use and Access) Act 2025 amended rather than replaced the UK GDPR, Data Protection Act 2018 and PECR. By 19 June 2026, all its data-protection provisions were in force, including new complaint-handling duties and changes affecting recognised legitimate interests, purpose compatibility, automated decision-making and the Information Commissioner’s powers. The commercial opportunity is therefore process-specific: select one use of personal data, decide what the change permits or requires, repair the evidence and train the owner. This reading shows how a privacy, cyber or data adviser can package that work into a paid impact sprint and a recurring change-control service. It also explains how acquisition can reach organisations with a live AI, marketing or complaints trigger without implying that the Act relaxed every UK GDPR obligation or made innovation risk-free.
What did the Data (Use and Access) Act change in 2026?
The Data (Use and Access) Act 2025 changed parts of the UK data-protection framework while leaving the UK GDPR and Data Protection Act in place. The majority of Part 5 commenced on 5 February 2026, and the remaining data-protection provisions, including complaint-handling requirements, were in force by 19 June 2026.
The correct review is provision-led and dated. Some measures offer optional ways to process or document data; others create operational duties. A team should not relabel the entire privacy programme “DUAA compliant” when only one notice or legitimate-interests assessment has been updated.
- 1What data and purpose are involved?
- 2Which lawful basis supports the use?
- 3Is automated decision-making significant?
- 4How can a person challenge or complain?
- 5Which evidence and owner must change?
Which data-protection complaints process is now required?
An organisation handling personal data must give people a clear way to make a data-protection complaint, acknowledge it within 30 days, investigate appropriately and communicate the outcome without undue delay. The process should be accessible, owned and connected to remediation, not buried inside a generic customer-service mailbox.
The complaint record links the person, issue, affected processing, evidence reviewed, response, correction and escalation. Trends should return to product and security owners. A privacy complaint is not closed merely because a template response was sent.
- Accessible intake
- Acknowledgement within 30 days
- Evidence-led investigation
- Reasoned outcome and remedy
- Root-cause action
How do recognised legitimate interests affect a business decision?
Recognised legitimate interests provide a lawful basis for specified processing where the ordinary balancing test is not required, but only when the statutory condition genuinely fits. Other legitimate-interest processing still needs the normal purpose, necessity and balancing analysis. The new label is not a shortcut for unrelated marketing, profiling or data reuse.
The process inventory should record the exact condition, dataset, recipients, safeguards and evidence. If the use drifts beyond that condition, the owner reassesses the basis instead of preserving a convenient historic conclusion.
What should a paid DUAA impact sprint deliver?
A paid impact sprint should select one customer-data process, map its purpose and systems, test the lawful basis and rights, identify the provisions that changed and issue a prioritised control plan. It should end with revised evidence, named owners and an implementation decision—not a generic legislative summary or a total privacy-framework rebuild.
Strong first scopes include an automated eligibility journey, marketing suppression process, complaint channel or planned secondary use of customer data. The adviser samples real records and interfaces, distinguishes legal interpretation from technical execution, and refers unresolved specialist questions before the use is approved.
How did the Act change significant automated decisions?
The Act broadens the lawful bases potentially available for significant solely automated decisions that do not use special-category data, while retaining safeguards for affected people. Organisations still need to identify when a decision has legal or similarly significant effects, provide information and enable human intervention, representation and challenge where the rules require it.
The decision file should describe model purpose, inputs, output, significance, lawful basis, special-category handling, human review and override. Calling a reviewer “in the loop” is not enough if that person cannot understand or change the result.
| Question | Evidence | Owner |
|---|---|---|
| What decision is made? | journey and consequence map | product |
| Which data and basis? | data inventory and assessment | privacy |
| Is it solely automated? | system and human-control test | engineering |
| How can it be challenged? | notice and review workflow | operations |
| Does it work fairly? | outcome and error monitoring | governance |
What does purpose compatibility change for data reuse?
The amended framework clarifies when further processing may be treated as compatible with the original purpose and identifies particular situations in legislation. A new analytics, AI or commercial use still needs a documented purpose analysis, transparency and safeguards. Data already collected is not automatically free to reuse because the technology or business case changed.
The reuse gate compares original notice, customer expectation, link between purposes, data sensitivity, consequence and protections. Security, minimisation and retention controls remain relevant even when the use has a lawful basis.
Why should privacy notices follow the process rather than lead it?
A privacy notice should accurately explain the processing decision after purpose, lawful basis, recipients, retention, automation and rights have been resolved. Rewriting public language first can conceal an unchanged system or create promises operations cannot meet. The evidence path should run from actual data flow to approved notice and then to customer testing.
That order also improves acquisition. Buyers are more likely to pay for a sprint that fixes an automated-decision or complaint workflow than for a vague “privacy notice refresh.” The notice becomes a visible output of deeper work, not the whole product.
- Map the real data flow
- Decide purpose and lawful basis
- Test rights and safeguards
- Implement operational controls
- Publish accurate customer information
Which organisations are most likely to buy the first sprint?
The strongest prospects are deploying automated decisions, changing customer-data uses, receiving repeated privacy complaints or operating without a clear data owner. A merger, new platform, marketing model, AI procurement or customer-service transformation creates a deadline because systems, notices and responsibilities must converge before the new process scales.
Search captures immediate interpretation questions; technology partners, lawyers and cyber networks create trusted introductions; direct account research can identify AI hiring, product releases and data-transformation programmes. Calls, email and targeted voicemail should test the decision and timing rather than lead with a long list of statutory changes.
- AI launch to automated-decision review
- New data reuse to purpose and lawful-basis sprint
- Complaint backlog to operational workflow repair
- Platform migration to data-flow and notice reconciliation
What recurring service follows the impact sprint?
The recurring service should review material process changes, monitor complaints and automated outcomes, refresh records and test whether agreed safeguards still operate. It earns a recurring fee when product releases and data uses change often enough to require active governance. It is not a monthly newsletter or a guarantee against ICO investigation.
The operating rhythm can combine a monthly change queue, quarterly evidence review and event-driven escalation. Product, privacy, security and customer operations retain their decisions; the service keeps those decisions coherent and auditable.
- Log the proposed data change
- Screen impact and lawful basis
- Implement safeguards and information
- Monitor complaints and outcomes
- Reopen the decision when evidence changes
When is a DUAA acquisition offer ready to launch?
The offer is ready when the partner can define a buyer and process, deliver a bounded evidence review, distinguish technical remediation from legal advice and maintain change control within capacity. GetFishNet’s free eligibility test checks the trigger, proof, first purchase and recurring economics before recommending channels or market expansion.
The commercial thesis depends on focus. “The law changed” is not enough; the buyer needs a process, deadline and consequence. Where the partner cannot access real flows or influence implementation, the correct eligibility result is to narrow or stop the campaign.
Authorities cited: Information Commissioner’s Office; Department for Science, Innovation and Technology; UK Legislation. Dated references remain in the private source register.
Editorial provenance
Sources used
- UK Legislation, Data (Use and Access) Act 2025
- Department for Science, Innovation and Technology, Data Use and Access Act 2025: plans for commencement
- Information Commissioner's Office, The Data Use and Access Act 2025: what does it mean for organisations?
- Information Commissioner's Office, DUAA summary of changes to data protection law
- Information Commissioner's Office, New data protection complaints law now in force
- Information Commissioner's Office, Consultation on draft guidance about automated decision-making, including profiling
The eligibility report dates and quantifies it, then tests whether it deserves action.
The topic is broken down into entities, attributes, evidence, channels, costs and decision points. Institutions are cited in the text; no external resource interrupts the reading path.