For businesses that spent the past year treating the Data (Use and Access) Act 2025 as something for the compliance roadmap, the deadline has arrived. The Information Commissioner's Office confirmed in June that all data-protection provisions of the Act are now in force, completing an implementation process that began after Royal Assent in June 2025.
That distinction matters. Companies do not need to throw out their existing privacy framework. They do need to understand where the rules operating underneath it have changed.
Complaints are becoming an operational issue
One of the clearest changes concerns how organisations handle data-protection complaints. Businesses now face more explicit expectations around providing people with a way to complain about the use of their personal information, acknowledging those complaints and responding appropriately.
For large companies, that sounds manageable. For smaller businesses where privacy queries disappear into a general customer-service inbox, it is considerably more significant.
The practical question is no longer simply whether a privacy policy is technically compliant. It is whether the company can demonstrate a working process when a customer actually exercises their rights. The ICO has updated its organisational guidance and complaints framework alongside the legislation — a pattern familiar to anyone who worked through the Companies House verification rules.
The law also creates more room to use data
Not every change adds compliance work. The government designed the DUAA partly to make legitimate use of data easier. The framework clarifies several areas where companies can process information and gives organisations more certainty around certain legitimate interests, research activity and automated processing.
That will be particularly relevant for businesses building AI-enabled products, fraud systems, recommendation engines and data-driven marketing platforms — the same firms already working through the government's AI regulation roadmap.
The opportunity comes with a familiar catch: a wider legal route to process information is not the same thing as permission to use it without governance. Companies still need to understand what information is being used, why it is being used and what safeguards apply. The underlying UK data-protection principles remain in place.
A compliance review worth doing now
For most companies, the sensible response is not a sprawling legal transformation project. It is a targeted review.
Check how privacy complaints enter the business and who owns them. Review legitimate-interest assessments that may now fall under the updated framework. Check automated decision-making processes, particularly where AI has been introduced since the company's privacy documentation was last reviewed. Marketing teams should also confirm that cookie and electronic-marketing practices reflect the amended rules.
Most importantly, make sure the policy on the website matches what actually happens inside the company. That is where data regulation is increasingly heading, and it is the direction the CMA has taken under the DMCC Act as well. The paperwork still matters, but regulators are becoming more interested in whether a business can show the process working when somebody tests it.
