Pillaraxis Cyber law, privacy & security — read plainly
Vol. 2 · 2026
Kochi, India
Brief No. 011
Law & Policy

The UK's Data (Use and Access) Act: A Quieter Departure from GDPR

Royal Assent in June 2025 started a year of staged changes to UK data law. None of them are dramatic individually. Together, they mark the UK's first real divergence from the EU regime it inherited.

When the UK left the EU, it kept GDPR almost entirely intact as 'UK GDPR' — a decision driven as much by the need to preserve the European Commission's adequacy decision, which allows personal data to keep flowing from the EU into the UK, as by any settled policy view. The Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025, is the first serious attempt to diverge from that inherited framework, and it has done so through a staged rollout rather than a single dramatic reform.

The most consequential single change is a new lawful basis: 'recognised legitimate interests' under Article 6(1)(ea) of UK GDPR, which took effect on 5 February 2026 alongside changes to how subject access requests are handled. Under the previous framework, any organisation relying on legitimate interests as its lawful basis had to complete a full Legitimate Interests Assessment — a documented balancing test weighing the organisation's interest against the individual's rights. The new recognised category, covering specific public-interest scenarios such as sharing data with government regulators, removes that balancing requirement entirely for the listed purposes. Subject access requests were also narrowed: controllers now only need to conduct a 'reasonable and proportionate' search when responding, rather than an exhaustive one, and can pause the one-month response clock while clarifying an ambiguous request.

The UK and EU regimes are not splitting apart overnight — they are diverging gradually, provision by provision, through a staged commencement schedule.

None of this repeals UK GDPR's core architecture — the principles, the rights, the enforcement structure remain recognisably the same regulation the UK inherited. The changes are best described as friction reduction: fewer documented balancing tests, narrower search obligations, streamlined cookie rules for low-risk purposes like site analytics. The government's stated goal was economic growth through lighter-touch compliance, not a rights rollback, and the European Commission appears to have agreed with that characterisation — it renewed the UK's adequacy decision in December 2025, allowing data to keep flowing from the EU without interruption, with the new decision running to 2031.

For organisations operating across both jurisdictions, the practical consequence is a UK and EU GDPR that will diverge gradually, provision by provision, rather than splitting into two obviously different regimes overnight. The commencement schedule stretches through 2026, and each new tranche is worth tracking individually rather than assuming 'UK GDPR' still means exactly what it meant in 2020.

← OlderTikTok's €530 Million Lesson: Why Cross-Border Transfers Are GDPR's Real Fault Line