Data (Use and Access) Act 2025: What UK Boards Must Act On Now

Data (Use and Access) Act 2025: What UK Boards Must Act On Now

The Data (Use and Access) Act 2025 makes changes to the framework for data protection complaints procedures for every UK organisation processing personal data — and the obligation comes into force on 19 June 2026. UK boards that have treated this legislation as an IT governance update are misreading the accountability exposure. This is a board-level compliance matter with direct implications for operational process, customer trust, and regulatory standing under the Information Commission.

The Act, which received Royal Assent on 19 June 2025, phases its changes across 2025 and 2026. Several significant provisions — including updates to automated decision-making rules and cookie consent requirements — came into force in February 2026. The complaints regime is the next critical milestone. With days to go, many organisations are still treating it as a work-in-progress.

What Does the June 2026 Deadline Actually Require?

From 19 June 2026, every organisation subject to UK GDPR must provide a formal mechanism through which individuals can complain directly about how their personal data has been handled. This is not a best-practice recommendation — it is a statutory obligation, and the Information Commission (the successor body to the ICO, now governed by a board of executive and non-executive members) will be able to assess compliance against it.

The requirements are specific. Organisations must provide a complaint form that can be completed electronically and by other means. They must acknowledge complaints within 30 days, take appropriate steps to resolve the complaint without undue delay, and inform the data subject of both progress and the final outcome. The mechanism by which complaints reach the Information Commission has also changed: individuals can now only escalate to the regulator once they have first complained directly to the controller and are dissatisfied with the response.

For larger organisations — those processing high volumes of personal data across multiple touchpoints — this creates a material operational requirement. Customer service teams, HR functions, and digital product owners all need to know the process exists, where it lives, and how to triage and respond within the 30-day window. That requires governance, not just a form on a webpage.

Executive Action:

  • Confirm with your DPO or legal team that an electronic complaints form is live and accessible across all consumer and employee-facing platforms before 19 June 2026.
  • Establish a 30-day acknowledgement and response SLA with clear ownership — this should sit with a named function, not default to IT or legal alone.
  • Brief your board or audit committee on the new complaints pathway and the reputational implications of systemic non-compliance. Use the INFORMD tools library to run a quick executive readiness check.

Similar Posts