Data Use and Access Act 2025: What UK Directors Must Govern Now | INFORMD Executive Briefing

Data Use and Access Act 2025: What UK Directors Must Govern Now

UK directors must now govern data use under a materially reformed legal framework — the Data (Use and Access) Act 2025 (DUAA) commenced on 5 February 2026, giving the ICO new compulsion powers and creating fresh board accountability obligations.

The DUAA represents the most substantial reform of UK data protection law since the end of the EU transition period. It modifies the UK GDPR framework, grants the ICO significantly expanded investigatory and enforcement powers, and — critically from a board governance perspective — introduces a new requirement for organisations to operate a formal complaints procedure for data subjects, with that requirement coming into force on 19 June 2026. Directors who have not assessed the governance implications of the DUAA should treat this as a matter requiring board-level attention before the end of Q2 2026.

What Has the DUAA Actually Changed About UK Data Protection Law?

The Data (Use and Access) Act 2025 makes targeted but significant amendments to the UK GDPR framework rather than replacing it wholesale. Key changes that affect board governance include: a revised framework for lawful bases for processing that introduces new clarity on recognised legitimate interests, allowing certain processing activities to proceed without the need for a detailed balancing test; modified rules around automated decision-making and profiling; and reformed consent standards in the context of digital services. The ICO has confirmed that the new data protection provisions took force from 5 February 2026, with the complaints procedure requirement following on 19 June 2026.

According to Clifford Chance, the DUAA also introduces a new statutory framework for data intermediaries and smart data schemes — allowing regulated sharing of customer data between organisations in specific sectors — which has governance implications for boards in financial services, energy, and telecoms. For executive teams, the most immediately material change is the ICO’s new enforcement posture: the DUAA explicitly expands the regulator’s investigatory reach and raises the fine ceiling for Privacy and Electronic Communications Regulations (PECR) breaches to £17.5 million or 4% of global annual turnover, whichever is higher. This brings PECR enforcement parity with UK GDPR for the first time.

Executive Action

  • Commission a DUAA impact assessment across your data processing activities — focus on the revised legitimate interests framework, automated decision-making rules, and PECR exposure given the increased fine ceiling.
  • Ensure your Data Protection Officer (or equivalent) has briefed the board on DUAA changes since 5 February 2026 — directors cannot rely on the prior UK GDPR framework remaining unchanged.
  • Review all customer-facing digital communications and cookie consent mechanisms — PECR enforcement risk has materially increased and the ICO has signalled active enforcement intent.

What New ICO Powers Should UK Directors Understand?

The DUAA grants the ICO a significantly expanded toolkit for investigation and enforcement. Under the new legislation, the ICO may compel witnesses to attend interviews for the first time — a power previously unavailable that substantially increases the regulator’s ability to investigate suspected data protection failures within organisations. The ICO may also require organisations to commission and submit technical reports from approved persons, allowing the regulator to obtain independent technical analysis of data processing systems without relying solely on information provided by the organisation under investigation.

According to the ICO’s statement on the DUAA commencement, these new powers apply only to conduct occurring after 5 February 2026 — meaning that organisations cannot be compelled on the basis of historical conduct that predates commencement. However, for any data processing activities ongoing from that date, the ICO’s enhanced investigatory reach is live. The DLA Piper Privacy Matters analysis confirms that the ICO’s governance reforms — including changes to its own governance structure — will be introduced at a later date, but enforcement powers are already operational. For directors, the practical implication is clear: the ICO is now a materially more capable enforcement authority, and board-level accountability for data governance must reflect this change.

Executive Action

  • Update your board risk register to reflect the ICO’s new compulsion powers — the risk profile of data protection non-compliance has materially increased from February 2026.
  • Review your organisation’s data incident response plan — ensure it includes protocols for ICO witness interviews and technical report requests, which are now legally possible.
  • Brief your General Counsel on the implications of the compulsion powers for legal professional privilege and how your organisation would respond to an ICO compelled interview request.

What Must Directors and Boards Now Govern Under the DUAA?

Under the UK Corporate Governance Code and the Companies Act 2006, directors have existing duties to act in the best interests of the company and to exercise reasonable care, skill and diligence. The DUAA does not create new personal director liability directly — but it does raise the organisational consequences of data governance failure in ways that make board oversight of data protection materially more important. A PECR fine of £17.5 million or 4% of global turnover, imposed on the basis of an ICO investigation using the new compulsion powers, is a board-level financial and reputational event, not an operational compliance matter.

Boards should ensure they receive regular reporting on data protection risk — at minimum annually, but more frequently for organisations with significant consumer data operations. This reporting should cover: the status of data subject rights requests and complaints volumes, the outcome of any ICO engagement, the maturity of the organisation’s data governance framework against the ICO’s Accountability Framework, and any material changes to data processing activities that affect risk exposure. According to Mayer Brown’s analysis of the DUAA, the complaints procedure requirement from 19 June 2026 creates an operationally significant obligation — organisations must have a documented, accessible process for data subjects to raise concerns about their data, separate from any existing customer complaints process. Use INFORMD’s governance self-assessment tools to benchmark your board data governance oversight against current regulatory expectations.

Executive Action

  • Add data protection governance to the board’s standing agenda — at minimum a quarterly report covering ICO engagement, complaints volumes, and material processing changes.
  • Ensure a documented data subject complaints procedure is operational by 19 June 2026 — this is a legal requirement, not best practice, under the DUAA.
  • Commission an ICO Accountability Framework self-assessment to identify governance gaps — the ICO uses this framework when assessing the adequacy of an organisation’s data protection governance in enforcement proceedings.

What Should UK Boards Do About Smart Data and Data Intermediary Provisions?

Beyond data protection enforcement, the DUAA introduces a statutory framework for smart data schemes that has long-term strategic implications for boards in regulated sectors. Smart data schemes allow regulators to require businesses to share customer data — on the customer’s instruction — with authorised third parties. The model builds on Open Banking and extends the principle to energy, telecoms, and potentially other sectors. According to Hunton Andrews Kurth, the main provisions of the DUAA enabling smart data schemes entered into force in early 2026, establishing the legal infrastructure for sector-specific smart data regulations to follow.

For boards in financial services, energy, and telecoms, this is not a distant regulatory development — it is a strategic shift that will require technology investment, data architecture decisions, and customer consent framework design over the next two to three years. The FCA and sector regulators are expected to consult on specific smart data schemes using the DUAA framework throughout 2026 and 2027. Directors should ensure that their organisations are engaged in these consultations and that the board has visibility of the potential competitive and operational implications of smart data requirements before they crystallise as mandatory obligations. Explore INFORMD’s regulatory briefing library for ongoing coverage of UK data law developments affecting boards.

Executive Action

  • If your organisation operates in financial services, energy, or telecoms, identify which smart data scheme consultations are expected in 2026–27 and assign board-level ownership of the regulatory engagement process.
  • Assess the data architecture and technology investment implications of potential smart data obligations in your sector — this is a strategic board conversation, not a back-office compliance task.
  • Review your customer consent and data portability frameworks now — smart data schemes will require robust customer authorisation mechanisms and data sharing APIs that take time to build.

INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.

Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.

When did the Data (Use and Access) Act 2025 come into force?

The main data protection provisions of the DUAA came into force on 5 February 2026. The requirement for organisations to have a formal data subject complaints procedure came into force on 19 June 2026. The ICO’s new compulsion powers — including compelling witness interviews and requiring technical reports — apply to conduct from 5 February 2026 onwards.

What new enforcement powers does the ICO have under the DUAA?

Under the DUAA, the ICO can now compel witnesses to attend interviews and require organisations to commission technical reports from approved persons. PECR fines have also been raised to £17.5 million or 4% of global annual turnover — matching UK GDPR fine levels for the first time. These powers apply to conduct after 5 February 2026.

What is the DUAA data subject complaints procedure requirement?

From 19 June 2026, organisations must have a documented, accessible complaints procedure for data subjects wishing to raise concerns about how their personal data is handled. This is a legal requirement under the DUAA — separate from existing customer complaints processes — and must be operational by that date.

What are smart data schemes under the DUAA and which sectors are affected?

Smart data schemes allow regulators to require businesses to share customer data — on the customer’s instruction — with authorised third parties. Building on Open Banking, the DUAA extends this model to energy, telecoms and other sectors. Boards in financial services, energy and telecoms should expect sector-specific smart data consultations and regulations throughout 2026 and 2027.

Similar Posts