If your business handles personal data in the UK, then the Data Use and Access Act 2025 will affect you.
Introduced in June 2025 and now largely effective, the DUAA represents the biggest shake-up in UK data protection law since 2018.
It’s meant to create a new balance: offering businesses more freedom to process data, but also improving individuals’ rights and giving ICO more powers to investigate and enforce compliance. Read on to understand what’s changed.
Details of the new DUAA requirements and complaints procedure
The DUAA amends existing frameworks like the UK General Data Protection Regulation (GDPR) and the Privacy and Electronic Communications Regulations (PECR) rather than replacing them. Organizations must be aware of several key shifts in how they handle data:
- Mandatory complaints procedure: Starting June 19, 2026, Section 103 of the Act requires all data controllers to have a formal process for handling complaints. Individuals must now attempt to resolve issues with the organization first before escalating to the ICO. This process must include an electronic submission form, acknowledgement within 30 days, and clear communication of decisions in plain language.
- Recognized legitimate interests: A new lawful basis lets organization process data for specific public-interest tasks — like protecting national security or responding to emergencies, without needing to run the usual balancing test.
- New rules for website cookies and higher fines: You no longer need to ask users for permission (via those annoying pop-up banners) to use “low-risk” cookies that handle basic things like website security or counting how many people visit a page. However, while the rules for basic cookies are more relaxed, the penalties for breaking marketing laws (like spamming) have skyrocketed. Fines have increased from a maximum of £500,000 to up to £17.5 million or 4% of a company’s global turnover.
- Automated decision making (ADM): Businesses can now use automated systems to make significant decisions about individuals — even using sensitive data, as long as human can step in to review or override the outcome.
What this means for skilled workers
For employees and international contractors, these changes provide a more structured way to voice concerns about how their personal data is used.
Workers can expect more transparent privacy notices that clearly outline how to submit a complaint and what the expected timelines for resolution are. Additionally, the strengthened “Children’s Code” protections ensure that younger workers or those in family-oriented service sectors benefit from data-minimization practices and design-by-default privacy.
What it means for employers
UK employers must act now — starting with auditing cookie banners and automated systems, and prioritising the implementation of new complaints framework, to avoid the heightened fines associated with the DUAA.
Organizations looking to hire international talent—such as researchers or tech experts attracted by the UK’s Global Talent Task Force—must ensure their global data workflows remain compliant with these new UK-specific rules. Navigating these “stop-the-clock” DSAR mechanics and localized complaints procedures can be complex for companies without a local legal presence.
How Multiplier can help
By partnering with an Employer of Record (EOR) Service like Multiplier, UK businesses can offload the administrative and legal burden of maintaining compliance across different jurisdictions. Multiplier’s platform is compliant-by-design, meaning it automatically adapts to local employment and data protection laws, allowing you to hire and manage talent in 150+ countries without worrying about the intricacies of the DUAA or foreign equivalents.
Navigating the future of data compliance with Multiplier
The Data (Use and Access) Act 2025 offers a window for UK businesses to modernize their operations, but it demands strict attention to new complaints-handling timelines and increased PECR penalties. Whether you are managing domestic staff or a distributed global team, staying compliant is essential for long-term growth.
Partnering with Multiplier for Employee of Record (EOR) Service, Contractor of Record (COR) Service, or Global Payroll services ensures that your international expansion remains seamless, secure, and fully aligned with the latest regulatory reforms.
FAQs
What is the Data Use and Access Act 2025 complaints procedure requirement?
The Data Use and Access Act 2025 (DUAA) introduces a mandatory requirement for all organizations to establish a formal, written process for handling data protection complaints by June 19, 2026. This requires providing accessible submission channels (like electronic forms), acknowledging receipts within 30 days, and informing individuals of their right to escalate the matter to the Information Commissioner's Office (ICO).
How much can a business be fined under the Data Use and Access Act 2025 for PECR violations?
Under the new DUAA reforms, fines for violating the Privacy and Electronic Communications Regulations (PECR)—which cover cookies and direct marketing—have been increased to align with UK GDPR standards. Organizations can now face fines of up to £17.5 million or 4% of their total annual global turnover, whichever is higher.
What are recognized legitimate interests under the Data Use and Access Act 2025?
Recognized legitimate interests are a new lawful basis for data processing that allows organizations to bypass the traditional "balancing test" for specific purposes. These purposes include preventing crime, safeguarding national security, responding to emergencies, safeguarding vulnerable individuals, or assisting public bodies in their duties.
When does the mandatory complaints procedure under the Data Use and Access Act 2025 take effect?
The mandatory requirement for organizations to have a compliant data protection complaints process in place becomes law on June 19, 2026. This gives businesses a transition period to update their privacy notices, train staff, and implement the necessary submission forms and tracking logs.
Does the Data Use and Access Act 2025 change how Subject Access Requests (DSARs) are handled?
Yes, the DUAA clarifies that data controllers only need to perform a "reasonable and proportionate search" when responding to a DSAR. It also brings into law the "stop-the-clock" mechanic, which allows organizations to pause the statutory response timer while they wait for the individual to provide more information needed to identify the requested data.