The Data Use and Access Act

The Data Use and Access Act changes the Data Protection Act, the UK GDPR, and the Privacy and Electronic Communication Regulations.

In this briefing we cover some of the main changes, what they mean, and crucially what they mean for you. Be sure to scroll down to the bottom and join our free, expert-led event on 30 July to learn more.

 

GDPR

 

Research

Sections 67, 68 and 69 of the Act expand definitions to include scientific and historic research. They vary the definition of consent to make it easier to collect consent for scientific research. The definitions apply to things that can be “reasonably” described as scientific research. It is clear that research does not need to be publicly funded and can be commercial in nature.

 

What this means

People can give broader consent for scientific research without needing to give specific consent for each research activity. It must be appropriate and ethical for the broad consent for scientific research to be sought (rather than granular consent).

The test of reasonableness applies. It broadly means “would an average person agree that this data processing is part of scientific research?”.

People’s GDPR rights remain the same and they can still withdraw consent if they wish.

 

What You Should Do

Reflect on whether you do or would like to use personal data for scientific research and if so:

  • See if your privacy statement needs to be updated to reflect these changes
  • Ensure that if you do use personal data for scientific research without detailed granular consent for each research activity this is captured in your Record of Processing Activity
  • Develop mechanisms for people with withdraw consent, and act if they do, from the use of their data for research

 

Lawful Bases for Data Processing

Section 70 and Schedule 4 of the Act adds a new lawful basis. This is in addition to the six that have existed since 2018.

This new, seventh lawful basis is called “recognised legitimate interests”.  Section 70

Schedule 4 sets out the lawfulness of some recognised legitimate interests. They include:

  • safeguarding vulnerable individuals or types of individuals
  • certain disclosures relating to crime, and emergencies, national security and defence
  • disclosures to data processors by data controllers whose legal basis for processing is the public authority basis

Section 70 also add as examples of processing that can be done under the legitimate interests lawful basis. This include direct marketing activity, and sharing information within groups of companies or institutions.

Section 70 also slightly amends the Public Authority basis to be clear this only applies to data controllers and data processors performing tasks for public authorities cannot rely on this lawful basis.

 

What This Means

“here a legitimate interest is defined and a “balancing test” is done to ensure there is not an unreasonable negative impact on the people whose data you want to use under this lawful basis.

“Recognised legitimate interests” still require the identification of a legitimate interest but the balancing test is no longer needed.

Activities like direct marketing are not covered by the recognised legitimate interests basis. Instead people and organisations that engage in direct marketing can be confident they do not have to rely on explicit consent to process personal data for this purpose. This helps align the GDPR with the PECR.

Like legitimate interests the use of recognised legitimate interests is restricted. Public authorities cannot use it for public tasks.

 

What You Should Do

You should look at the lawful basis of your data processing for activities like direct marketing. See if, based on these changes, you are relying on the best one. If your organisation has a role in safeguarding children and / or vulnerable adults you should also consider whether the new lawful basis, recognised legitimate interests, might apply.

 

Purpose Limitation

Section 71 of the Act changes the second data privacy principle: purpose limitation. The wording is tightened to clarity what purpose limitation means.

It now makes clear that even if you are re-using data in a manner that is consistent or compatible with the original purpose you cannot automatically rely on the lawful basis used for the original purpose. That means when reusing data for a new purpose you must consider what the lawful basis for this data processing is.

Section 71 also adds a new annex to the UK GDPR. This sets out what things are automatically compatible with the original purpose of the data processing. These are broadly the same as the processing activities set out in relation to recognised legitimate interests.

 

What This Means

When you realise you need to reuse personal data you still, as now, need to assess whether this is compatible with the original purpose.

Now you also need to check whether is a purpose set out in Annex 2 of the GDPR (e.g. safeguarding) and reflect on what the lawful basis of this further processing is.

 

What You Should Do

Ensure that when you identify a need to process personal data that you have a process to check if and how it is compatible with the original purpose; assess the lawful basis for this further processing; and update your privacy information to set out this now processing activity.

 

Subject Access Requests

Section 76 of the Act makes small but interesting changes to the way that organisations can respond when people exercise their data rights.

The GDPR originally said you must respond to subject access requests without delay. This has been tweaked to read “without undue delay”. It is now explicit that you can ‘pause the clock’ on your response if you need to clarify the request, confirm the requestor’s identity, or charge a fee for compliance.

It is also now explicit that you can ask the requestor to clarify their request to help manage the burden of it, by the insertion of paragraph 6: “An example of a case in which a controller may reasonably require further information is where the controller processes a large amount of information concerning the data subject.

 

What This Means

This makes what is already common practice explicit in law. It does make life easier by removing some of the uncertainties around how you can approach responding to subject access requests and engage with requestors.

 

What You Should Do

You should continue to respond when people exercise their data rights fully and openly. However, recognising the burden on organisations of dealing with subject access requests you can where it is appropriate ask requestors if they wish to clarify their request or make it more focussed. You should still comply if they refuse.

 

Searching for Data

Again relating to subject access requests Section 78 of the Act inserts a new paragraph into the GDPR. This clarifies that people making subject access requests are only entitled to information found after a “reasonable and proportionate” search.

Unusually this is back dated to 1 January 2024, so it will affect requests received before the Act became law.

What This Means

Exhaustive searches for information when responding to subject access requests are a burden. There is always the risk that you may miss a piece of information that you should disclose. This change makes life a little easier. It allows for this possibility so long as you can show your efforts to collate and share the information were reasonable and proportionate.

What do reasonable and proportionate mean? The principle of accountability still applies. It will be for you to demonstrate that you met this standard but in general it means going to the extent that an average person would consider appropriate.

 

What You Should Do

It is not difficult to find information when it is stored electronically and can be searched via automated means. Therefore you should not use this as a reason not to give a full response to a subject access request due to the volume of data involved. Instead you should consider how far you can reasonably go in your search for information. This will help you respond to the request within both the resources you have available and the statutory timescales for those responses.

 

Legal Professional Privilege

Section 79 of the Data Use and Access Act inserts a new section 45A, into the Data Protection Act. This makes clear that information is exempt from disclosure to data subjects if sharing it would compromise legal professional privilege or a duty of confidentiality exists relating to the information between a legal advisor and a client.

 

What This Means

The Data Use and Access Act has made it much clearer that things covered by legal professional privilege or a similar duty of confidentiality is excluded from disclosure. This is helpful if, as can happen, subject access requests are made by people with an ongoing dispute or case against a data controller.

 

What You Should Do

You can consider the extent to which disclosing information would compromise legal professional privilege when deciding whether or not to disclose it. As before if you do withhold or redact it you should explain this to the data subject in most instances.

 

Privacy Notices

Section 77 of the new Act makes changes to the requirements around privacy notices.

Currently you do not need to provide a privacy notice is the data subject already knows what their data is going to be used for. The new Act goes a little further. It sets out you do not need to provide a privacy statement if doing so would involve disproportionate effort. It says:

“disproportionate effort depends on, among other things, the number of data subjects, the age of the personal data and any appropriate safeguards applied to the processing.”

However, if you do rely on this you should explain that as part of your wider privacy notice.

 

What This Means

This means that you do not need to provide an exhaustive fully detailed privacy notice in some circumstances. But if you are not able to provide a full breakdown of your data processing activity you should make that clear.

 

What You Should Do

If you understand your data processing there should not be too much difficulty in providing a clear and comprehensive privacy notice. However, in some circumstances it is easier not to update you privacy notice. Examples of this having to do an audit of old personal data (for example, medical records or legal documents) for a one-off purpose.

Privacy and Electronic Communication Regulations

Finally the Data Use and Access Act makes two consequential changes to the Privacy and Electronic Communication Regulations (PECR)

 

Data Breaches

The timescales for reporting a data breach under the PECR has been aligned with the GDPR. That is, within 72 hours of you becoming aware of it.

 

Soft Opt In

The Data Use and Access Act explicitly allows charities to use personal data for electronic marketing communications under the “soft opt in” provision of the PECR. The soft opt in allows businesses to follow up expressions of interest in products or services with direct marketing emails, for example, or to up or cross sell products and services to existing or past customers. The marketing by charities must be for the purpose of delivering the charity’s aims.

 

Find Out More

Join our free, expert-led event on the Data Use and Access Act.  On 30 July 2025 we will explore the changes outline above. We will also answer your questions, and give more tips and tools for ongoing GSPR compliance

Name
Would You Like to Subscribe to the Newsletter?
Get insights, updates and exclusive offers direct to your inbox. You can unsubscribe at any time and we won't use your data for anything else.