The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. Its main data protection provisions came into force on 5 February 2026. It is the first substantive amendment to UK data protection law since the UK GDPR came into existence in 2021, and it ends four years in which UK and EU data protection were functionally identical.
The DUAA does not replace the UK GDPR. It amends it, along with the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations. The changes create genuine divergence in five areas: recognised legitimate interests, automated decision-making, subject access requests, cookies, and international transfers.
The change with the greatest consequence for AI deployment is the automated decision-making restructure. The EU GDPR prohibits solely automated decisions with legal or similarly significant effects, subject to three narrow exceptions. The DUAA moves the UK to a permission-with-safeguards model. For organisations deploying AI decisioning across both jurisdictions, the two frameworks now require materially different architectures for the same system.
The European Commission renewed UK adequacy on 19 December 2025, extending free EEA-to-UK data flows to 27 December 2031. Adequacy survived the DUAA. It is monitored, not guaranteed.
Key Definitions
| Term | Definition |
|---|---|
| DUAA | Data (Use and Access) Act 2025. Royal Assent 19 June 2025. Main provisions in force 5 February 2026 |
| UK GDPR | The EU GDPR as retained in UK domestic law, as amended by the DPA 2018 and the DUAA |
| Recognised legitimate interests | A new lawful basis under UK GDPR Article 6 covering a closed list of purposes, requiring no balancing test |
| LIA | Legitimate Interests Assessment. The three-part balancing test required for Article 6(1)(f) processing |
| ADM | Automated decision-making. Decisions taken without meaningful human involvement |
| Information Commission | The successor body to the ICO, created by the DUAA |
| Adequacy | A European Commission determination permitting personal data transfers to a third country without additional safeguards |
| Shift-left compliance | Addressing regulatory requirements at design and development stage rather than at release or audit |
What the DUAA Is
The Data (Use and Access) Act 2025 is a UK statute that amends the existing data protection framework rather than replacing it. Three instruments are affected: the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations.
It is the successor to the Data Protection and Digital Information Bill, which fell when Parliament was dissolved ahead of the 2024 general election. The policy objective across both attempts was the same: reduce compliance burden on UK organisations while preserving enough alignment with the EU framework to protect adequacy.
Commencement was phased.
| Date | Provisions |
|---|---|
| 19 June 2025 | Royal Assent |
| 5 February 2026 | Main data protection provisions in force |
| 19 June 2026 | Complaints handling requirement in force |
| Late 2026 (expected) | ICO transitions to the Information Commission |
The Five Areas of DUAA Divergence
1. Recognised Legitimate Interests
Under EU GDPR Article 6(1)(f), any controller relying on legitimate interests must complete a three-part balancing test and document it in a Legitimate Interests Assessment.
The DUAA inserts a new lawful basis into UK GDPR Article 6: recognised legitimate interests. For a closed list of purposes, no balancing test is required. The other GDPR principles still apply, but the LIA obligation falls away.
The listed purposes include safeguarding vulnerable individuals, crime prevention and detection, emergencies, national security, and defence.
| Feature | EU GDPR | UK GDPR post-DUAA |
|---|---|---|
| Legitimate interests basis | Article 6(1)(f), balancing test required | Retained, balancing test required |
| Recognised legitimate interests | Does not exist | New basis, no balancing test for listed purposes |
| Scope | Not applicable | Closed list, narrowly drawn |
| Documentation | LIA required | No LIA for recognised purposes |
The practical effect is narrower than the headlines suggested. The list is closed and specific. Most commercial processing still requires a full LIA. For organisations doing safeguarding or fraud prevention work at scale, the reduction is material.
2. Automated Decision-Making
This is the divergence that matters most for AI.
EU GDPR Article 22 gives data subjects the right not to be subject to decisions based solely on automated processing producing legal or similarly significant effects, subject to three exceptions: contractual necessity, authorisation by law, and explicit consent. The Dutch DPA’s ā¬825 million fine against Uber in August 2026 for automated driver deactivations demonstrated that this provision is enforced seriously.
The DUAA restructures the UK equivalent. It permits a wider range of automated decisions provided safeguards are in place: the ability to obtain human intervention, to make representations, and to contest the decision.
The structural shift is from prohibition-with-exceptions to permission-with-safeguards.
| Feature | EU GDPR | UK GDPR post-DUAA |
|---|---|---|
| Default position | Prohibited for decisions with significant effects | Permitted subject to safeguards |
| Exceptions | Contract, law, explicit consent | Broader, safeguard-based |
| Special category data | Stricter restrictions retained | Restrictions retained |
| Required safeguards | Human intervention, right to contest | Human intervention, representations, contest |
| Enforcement track record | Active | Untested at scale |
For a company deploying an AI decisioning system in hiring, credit, or service access across both markets, the EU architecture is the binding constraint. A system designed to the UK standard will not survive EU scrutiny. A system designed to Article 22 will satisfy the UK requirement.
3. Subject Access Requests
Two changes. Controllers are required to conduct a reasonable and proportionate search rather than an exhaustive one. A stop-the-clock mechanism allows the response deadline to be paused while seeking clarification or verifying identity.
The refusal threshold also shifts from “manifestly unfounded or excessive” to “vexatious or excessive”, importing a lower bar from freedom of information law.
| Feature | EU GDPR | UK GDPR post-DUAA |
|---|---|---|
| Deadline | One month, extendable by two | One month, extendable by two |
| Search standard | Not expressly qualified | Reasonable and proportionate |
| Stop the clock | Not provided | Permitted for clarification or ID verification |
| Refusal threshold | Manifestly unfounded or excessive | Vexatious or excessive |
4. Cookies and PECR
The DUAA amends PECR to create consent exemptions for certain cookie categories, including some analytics and functionality cookies. EU law under the ePrivacy Directive continues to require consent for analytics.
A UK-configured banner served to EU users is an ePrivacy breach. This is the divergence most likely to create a visible compliance failure in an organisation running a single configuration across both markets.
5. International Transfers
The adequacy test moves from “essentially equivalent” to “not materially lower”. The standard is lower. The government has signalled no immediate plans to approve new destinations on that basis, but the capacity now exists for the UK to diverge from the EU adequacy list over time.
Transfer mechanism requirements are unchanged. UK exporters still use the IDTA or the UK Addendum to the EU SCCs, and still complete a Transfer Risk Assessment.
What the DUAA Did Not Change
The divergence is bounded. The following remain aligned:
| Element | Status |
|---|---|
| Data protection principles, Article 5 | Unchanged |
| Special category data conditions, Article 9 | Substantially aligned |
| Transparency obligations, Articles 13-14 | Unchanged |
| Controller and processor definitions | Unchanged |
| Article 28 DPA requirements | Unchanged |
| Security obligations, Article 32 | Unchanged |
| Breach notification, Articles 33-34 | Unchanged |
| DPIA requirements, Article 35 | Substantially aligned |
| Fine structure | 4% worldwide turnover in both regimes |
A DPA drafted to EU GDPR Article 28 remains valid in the UK. Records of processing, security measures, and breach procedures carry across unchanged.
The Adequacy Position
The European Commission renewed the UK’s adequacy decisions on 19 December 2025, with a new expiry of 27 December 2031. The Commission reviewed the DUAA before renewing.
Renewal is conditional and monitored. The Commission retains power to suspend, amend, or withdraw adequacy if it concludes the UK framework has fallen below the essentially equivalent standard. The EDPB noted during the DUAA process that some changes move meaningfully away from EU GDPR principles.
Two factors will determine whether adequacy holds to 2031. The first is whether the UK diverges further, particularly on automated decision-making or international transfers. The second is how the regulator enforces. Adequacy assessments consider practice, not only text.
A regulator that reads recognised legitimate interests expansively or declines to enforce the ADM safeguards will strain the finding more than the statute does on its own.
DUAA: The AI Governance Asymmetry
The DUAA relaxed UK data protection requirements for automated decision-making at the same time as the EU was building an AI-specific regulatory layer on top of the GDPR.
An organisation deploying a high-risk AI system to EU data subjects faces GDPR Article 22, plus EU AI Act Article 9 risk management, Article 10 data governance, Article 14 human oversight design, Article 26 deployer obligations, Article 27 fundamental rights impact assessment, Annex IV technical documentation, Article 43 conformity assessment, and Article 49 registration.
The same system deployed to UK data subjects faces the DUAA’s restructured ADM provisions and no equivalent AI statute. The UK has not enacted comprehensive AI legislation and the AI Regulation and Safety Bill, which passed its second Lords reading in July 2026, is not yet law.
| Requirement | EU | UK |
|---|---|---|
| AI-specific statute | EU AI Act | None in force |
| Risk classification | Mandatory, Article 6 | None |
| Risk management system | Article 9 | None |
| Data governance for AI training data | Article 10 | General GDPR principles only |
| Technical documentation | Annex IV | None |
| Human oversight design | Article 14 | Safeguards under DUAA ADM provisions |
| Conformity assessment | Article 43 | None |
| Registration | Article 49 | None |
| AI literacy | Article 4, in force February 2025 | None |
The gap is widening rather than closing. For organisations operating across both, this is not a case of one framework being a subset of the other. It is two structurally different regulatory architectures applied to the same technology, and the mapping between them has to be maintained deliberately.
The Dual Compliance Trap
The most common error since February 2026 has been applying the more permissive UK standard across all processing.
The DUAA changed UK law. It did not change what the EU requires. A UK-established organisation processing personal data of EU residents remains fully subject to the EU GDPR for that processing, enforced by the relevant EU supervisory authority under Article 3(2).
| Processing scenario | Applicable regime |
|---|---|
| UK entity, UK data subjects | UK GDPR and DPA 2018 as amended |
| UK entity, EU data subjects | EU GDPR |
| EU entity, EU data subjects | EU GDPR |
| EU entity, UK data subjects | UK GDPR |
| Global entity, both | Both, mapped by data subject location |
The practical answer for most organisations is to build to the EU standard and use the UK flexibilities only where processing is genuinely UK-only and the saving is material. Running two full parallel programmes is expensive and error-prone. Running one programme at the EU standard is defensible in both jurisdictions.
That answer only works if you can demonstrate, per system, which data subjects it touches and which framework governs it. Most organisations cannot currently do that at the granularity a regulator would ask for.
Where Compliance Architecture Has to Change
The DUAA makes a structural problem visible that was previously easy to ignore.
When UK and EU data protection were identical, a single compliance programme covered both. Divergence removes that convenience. Every AI system now needs a determination of which framework applies to which processing, and that determination has to be evidenced, current, and defensible.
Doing this at audit time does not work. By the time a system is in production, the design decisions that determine its compliance posture have already been made. Whether the human review step is meaningful, whether the training data governance is documented, whether the decision is genuinely contestable: these are architectural properties, not documentation exercises.
Shift-left product compliance means making those determinations at the point of design rather than reconstructing them at the point of audit. Classification before build. Data governance decisions recorded as they are made. Human oversight designed in rather than added on. Evidence generated as a by-product of development rather than assembled afterwards from memory and Slack threads.
The alternative is what most organisations do now: build the system, then commission a compliance review that either passes it or requires rework the roadmap cannot absorb.
Multi-Framework Compliance Infrastructure With Grecta
Grecta is compliance infrastructure built for organisations operating across multiple regulatory frameworks simultaneously.
The DUAA divergence is a specific instance of a general problem. An organisation running AI systems in the UK, the EU, Colorado, and Vietnam faces four different regulatory architectures applied to the same underlying facts: what the system does, what data it processes, what decisions it influences, and who it affects. Those facts are stable. The obligations mapped onto them are not.
Grecta separates the two. A single system inventory and evidence base supports obligations across the EU AI Act, GDPR, UK GDPR as amended by the DUAA, DORA, the Data Act, the Cyber Resilience Act, and US state AI laws. When a framework changes, the mapping updates. The underlying record does not have to be rebuilt.
Shift-left product compliance is built into how this works. Classification happens at design stage, not at release. Data governance decisions are recorded as engineering makes them. Human oversight requirements surface as design constraints before the architecture is fixed. Technical documentation is generated from the development record rather than reconstructed after the fact.
For teams building AI products across jurisdictions, this is the difference between compliance as a release blocker and compliance as a design input.
Contact Grecta to discuss multi-framework compliance infrastructure for your AI systems.
What is the Data (Use and Access) Act?
The DUAA is a UK statute that amends the UK GDPR, the Data Protection Act 2018, and PECR. It received Royal Assent on 19 June 2025 and its main data protection provisions came into force on 5 February 2026. It is the first substantive UK divergence from the EU GDPR framework since Brexit.
Did the DUAA replace the UK GDPR?
No. It amends the UK GDPR. The UK GDPR remains the primary UK data protection instrument, now in amended form.
When did the DUAA come into force?
Main data protection provisions on 5 February 2026. The complaints handling requirement on 19 June 2026. The transition from the ICO to the Information Commission is expected to complete in late 2026.
What are recognised legitimate interests?
A new lawful basis in UK GDPR Article 6 covering a closed list of purposes including safeguarding, crime prevention, emergencies, and national security. Where it applies, no legitimate interests balancing assessment is required. The basis does not exist under EU GDPR.
How did the DUAA change automated decision-making?
EU GDPR Article 22 prohibits solely automated decisions with legal or similarly significant effects except in three narrow circumstances. The DUAA permits a wider range of such decisions provided safeguards are in place, including human intervention, the right to make representations, and the right to contest. The EU model is prohibition with exceptions. The UK model is closer to permission with safeguards.
Does the DUAA affect our EU GDPR obligations?
No. The DUAA changes UK law only. Processing of EU residents’ personal data remains fully subject to the EU GDPR under Article 3(2), enforced by EU supervisory authorities, regardless of where your organisation is established.
Is UK adequacy still in place after the DUAA?
Yes. The European Commission renewed UK adequacy on 19 December 2025 with a new expiry of 27 December 2031, having reviewed the DUAA before renewing. Adequacy is monitored and can be withdrawn if the UK framework diverges further.
Can we use one cookie banner for UK and EU users?
Not safely. The DUAA created PECR exemptions for certain analytics and functionality cookies. EU law still requires consent for those categories. A UK-configured banner served to EU users breaches the ePrivacy Directive. Either geolocate and serve different configurations, or apply the EU standard to all users. Grecta recommends the necessary engineering and design steps to comply with applicable regulations.
Does the DUAA change our Data Processing Agreements?
No. Article 28 requirements are unchanged in both regimes. A DPA that satisfies EU GDPR Article 28 satisfies UK GDPR Article 28.
Does the UK have an equivalent to the EU AI Act?
Not in force. The AI Regulation and Safety Bill passed its second House of Lords reading on 3 July 2026 and would introduce a duty of care for frontier AI developers, mandatory pre-deployment safety evaluations, and statutory audit authority for the UK AI Safety Institute. It is not yet law.
UK AI governance currently operates through data protection law, sector regulation, and the DUAA’s ADM provisions.
Which standard should our compliance programme be built to?
For organisations processing personal data in both jurisdictions, build to the EU standard and treat UK flexibilities as available where processing is genuinely UK-only and the saving justifies the divergence. The EU standard is stricter in every area where the regimes differ, so an EU-compliant programme is generally UK-compliant. The reverse is not true.
Disclaimer
This guide reflects the Data (Use and Access) Act 2025, the UK GDPR as amended, the EU GDPR, and the European Commission’s adequacy decisions as at August 2026. It is published by Grecta for general informational purposes and does not constitute legal advice. Organisations processing personal data across both jurisdictions should obtain advice specific to their processing activities and data subject populations.