UK Data Protection Changes in 2026: What Businesses Need to Know

The rules around how UK businesses use and protect personal information have changed.

The Data (Use and Access) Act 2025, often shortened to the DUAA, introduces a number of changes to the UK's existing data protection framework, with the main reforms now in force during 2026.

If your organisation holds information about customers, employees, suppliers or other individuals, there are some changes you should be aware of.

The good news is that this isn't another GDPR-style overhaul.

Many of the fundamental principles businesses have become familiar with remain the same. You still need to use personal information fairly, lawfully and transparently, keep it secure and respect people's rights.

However, there are some new requirements and changes to existing processes that businesses should now review.

What Is the Data (Use and Access) Act 2025?

The Data (Use and Access) Act became law in June 2025 and updates a number of existing UK laws relating to data and privacy.

Importantly, it doesn't replace UK GDPR.

Instead, it amends existing legislation including UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations, commonly known as PECR.

The changes have been introduced in stages, with the main data protection reforms coming into force during 2026.

For most businesses, this means reviewing some existing policies and processes rather than starting again with data protection from scratch.

So, what should you be aware of?

You Need a Clear Process for Data Protection Complaints

One of the most practical changes for businesses is the introduction of a formal requirement around data protection complaints.

As of 19 June 2026, organisations need to provide people with a clear way to complain directly about how their personal information has been handled.

That could be through a dedicated email address, an online form or another appropriate route.

When you receive a complaint, you need to acknowledge it within 30 days, investigate it appropriately and respond without undue delay. You should also keep records of the complaint and the action you've taken.

This isn't just something your Data Protection Officer or senior management team should understand.

A customer could raise a data protection concern with somebody in customer service, finance or another department without using the words "data protection complaint".

That means the people receiving enquiries across your organisation should understand how to recognise a potential complaint and know where it needs to go.

What should you check?

Ask yourself:

    • Do people have a clear way to raise a data protection complaint with us?
    • Is that route clearly communicated?
    • Who is responsible for receiving and investigating complaints?
    • Would employees know how to recognise one?
    • Do we have a process for recording what action has been taken?

If not, this is an area worth reviewing now.

Subject Access Requests Have Changed

Subject Access Requests, or SARs, allow individuals to ask an organisation for copies of the personal information it holds about them.

The DUAA has clarified some of the rules around how organisations respond to these requests.

One important change confirms that businesses are expected to carry out a reasonable and proportionate search for personal information.

That doesn't remove your responsibility to respond to a legitimate request, but it provides greater clarity about how extensive your search needs to be.

The Act also allows the response timeframe to be paused in certain circumstances where you reasonably need to ask the individual to clarify what information they're requesting.

For businesses, this is a good opportunity to review how SARs are currently handled.

Do the people who may receive a request recognise what it is?

Do they know who to pass it to?

And importantly, could you actually locate someone's personal information across your systems if they asked for it?

Think About Where Your Data Actually Lives

That last question is particularly important.

Personal information doesn't necessarily sit neatly in one system.

Customer details might exist within your finance or CRM system.

Employee information might be held within payroll or HR software.

Other personal information could be contained within Microsoft 365, email inboxes, Teams, shared folders, spreadsheets, backups and other applications.

Understanding where information is stored, who has access to it and how it is protected remains an important part of good data management.

It's worth asking:

If somebody asked us what information we hold about them, would we know where to look?

And equally:

Are the right people able to access that information – and only the right people?

The Rules Around Cookies Have Changed Too

The DUAA also makes some changes to the rules around cookies and similar technologies.

Certain lower-risk cookies can now be used without first obtaining consent, provided the relevant requirements are met.

This includes some cookies used for statistical purposes and certain functionality.

However, that doesn't mean cookie consent banners have disappeared.

Advertising and tracking technologies may still require consent, so businesses shouldn't simply remove their existing cookie controls without first understanding what technologies their websites actually use.

If your website hasn't had a cookie or privacy review for some time, this could be a useful opportunity to revisit it.

Automated Decision-Making and AI

The legislation also changes some of the rules around automated decision-making.

This is particularly relevant as more businesses introduce AI and automated tools into areas such as recruitment, customer service, finance and other business processes.

The new rules provide organisations with greater flexibility to make certain automated decisions using non-sensitive personal information.

However, safeguards remain important.

Where automated decisions have significant effects on individuals, businesses may need to provide appropriate information and allow people to challenge a decision and request human intervention.

The important question isn't simply:

"Do we use AI?"

It's:

"Do any of our systems make significant decisions about people automatically?"

As organisations adopt more automation, understanding where and how personal information is being used becomes increasingly important. 

Marketing Rules and Penalties Have Changed

The DUAA also makes changes to PECR, the rules covering areas such as electronic marketing and cookies.

One particularly important development is the increase in potential penalties.

The maximum penalties for serious PECR breaches have been brought into line with UK GDPR, meaning fines can now reach £17.5 million or 4% of global annual turnover, whichever is higher.

For organisations carrying out email marketing, using tracking technologies or managing customer communications, this makes good data governance just as important within marketing as it is elsewhere in the business. 

What Hasn't Changed?

With any new data protection legislation, it's easy to assume businesses need to start again.

That's not the case.

The DUAA updates the UK's existing data protection framework rather than replacing it.

Many of the principles businesses already follow remain just as important.

You still need to:

    • Process personal information fairly and lawfully.
    • Be transparent about how you use it.
    • Only collect information you actually need.
    • Keep personal information accurate.
    • Avoid retaining it unnecessarily.
    • Protect it appropriately.
    • Respect individuals' data protection rights.

For many organisations, therefore, 2026 is less about creating an entirely new data protection strategy and more about reviewing what you already have and making sure it reflects the latest requirements. 

What Should Businesses Do Now?

If you haven't reviewed your data protection processes since the changes came into force, there are a few sensible places to start.

Review your privacy information.
Make sure it remains accurate and explains how individuals can raise concerns or complaints.

Establish your complaints process.
Ensure there is a clear route for receiving, recording and responding to data protection complaints.

Review how you handle Subject Access Requests.
Make sure the relevant people understand the updated rules and know what to do when a request arrives.

Understand where personal information is stored.
Consider the systems, applications, inboxes, files and other locations where customer and employee information exists.

Review access to sensitive information.
Make sure employees only have access to the information they genuinely need.

Review your website and cookie practices.
Understand which technologies your website uses before making changes to consent mechanisms.

Consider your use of automation and AI.
Understand whether any systems are making significant automated decisions involving individuals.

Make employees aware of the changes.
Data protection isn't solely the responsibility of IT or senior management. Employees across the business can receive requests, complaints or handle personal information.

Data Protection Is About More Than Compliance

Legislation is one reason to take data protection seriously.

But protecting the information your organisation holds is also simply good business practice.

Customer records, employee information, financial information and commercially sensitive data are valuable assets.

Policies and procedures determine how that information should be handled.

Your technology and security controls play an important role in determining how well it is actually protected.

That includes areas such as access controls, Microsoft 365 security, multi-factor authentication, cyber security, backups, device management and employee awareness.

The Data (Use and Access) Act doesn't fundamentally change that principle – but it provides another useful reason to review whether the processes and protections you currently have remain appropriate.

Need Help Reviewing How Your Business Protects Its Data?

The Data (Use and Access) Act is broader than IT and businesses should seek appropriate professional or legal advice where they need help understanding their specific compliance obligations.

However, if these changes have prompted questions about where your business data is stored, who can access it or how well your systems are protecting it, that's something our team can help you explore.

Whether you're an existing HBP customer or you're simply looking for advice around improving the security of your business systems and data, get in touch with our team and we'll be happy to help.

The HBP Group

Posted by The HBP Group

The HBP Group is an award-winning UK provider of Managed IT Services and ERP software. Founded in 1991, they support businesses with managed IT services, IT Support and ERP implementations for Microsoft Dynamics 365 Business Central, Sage Intacct, Sage 200 and Pegasus Opera 3.

Written by experts across the business, The HBP Group blog covers cybersecurity, IT best practice, Microsoft solutions, ERP systems, and technology strategy—helping organisations reduce risk, improve performance, and make smarter IT decisions.

The HBP Group Gradient Bar