Data (Use and Access) Act: What UK Businesses Need to Know

The Data (Use and Access) Act is now UK law. Our guide explains the key changes to UK GDPR, from DSARs to marketing fines, for your small business.

· News & Updates

The UK’s New Data Landscape: An Introduction to the Data (Use and Access) Act

After a protracted journey through Parliament, the Data (Use and Access) Bill received Royal Assent on 25 October 2024, officially becoming the Data (Use and Access) Act. This legislation marks the most significant evolution of the UK’s data protection framework since the country’s departure from the EU, amending the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

For small business owners, freelancers, and marketers across the UK, the arrival of this new Act brings both opportunity and a need for careful review. The government’s stated aim is to create a more flexible, “common-sense” data protection regime that reduces administrative burdens and fosters innovation. However, it also introduces much tougher penalties for non-compliance in key areas.

This article provides a clear, practical guide to what has changed, what remains the same, and the immediate steps your organisation should take to ensure compliance. It is an evolution, not a revolution, and the core principles of treating personal data lawfully and respectfully remain firmly in place.

Key Change 1: Greater Clarity on Legitimate Interests

One of the most persistent challenges for businesses under UK GDPR has been the uncertainty around using ‘legitimate interests’ as a lawful basis for processing personal data. The requirement to conduct and document a complex balancing act, weighing your interests against an individual's rights, often led organisations to default to seeking consent, which is not always practical or appropriate.

The Data (Use and Access) Act aims to simplify this. It introduces a list of specific processing activities that are recognised as a legitimate interest without the need for the balancing test. These include:

  • Processing for the purpose of direct marketing.

  • Intra-group data transfers for administrative purposes (such as HR or payroll).

  • Processing necessary to ensure the security of your network and information systems.

For a small business, this provides welcome legal certainty for routine operations. For example, sending marketing emails to your existing customer base about similar products or services can now more confidently be classed as a legitimate interest. However, this is not a free pass. The processing must still be necessary for that purpose, and individuals retain their absolute right to object. For comprehensive official guidance, it is always wise to consult the ICO Lawful Basis Guidance.

Key Change 2: The Senior Responsible Individual Replaces the DPO

The mandate to appoint a formal Data Protection Officer (DPO) was often seen as a disproportionate burden for smaller organisations that do not process large volumes of sensitive data. The role, with its specific expertise and independence requirements, could be costly and difficult to fill.

The new Act replaces this rigid requirement with a more flexible model. Most organisations will now need to designate a ‘Senior Responsible Individual’ (SRI) to oversee data protection compliance. The key difference is that this role must be assigned to a senior manager or member of your organisation's leadership.

This change embeds accountability at the very top of your business structure. Instead of an external consultant or a siloed compliance officer, responsibility now sits with those who make strategic decisions. The core tasks remain—monitoring compliance, advising on data protection impact assessments (DPIAs), and acting as the contact point for the Information Commissioner’s Office (ICO)—but the approach is designed to be more integrated. If you need to understand the previous requirements, you can read our clear guide to the UK GDPR DPO requirement to see how the role has evolved.

Key Change 3: A New Threshold for Data Subject Access Requests (DSARs)

Data Subject Access Requests (DSARs) are a cornerstone of individual data rights, but they can place a significant strain on the resources of a small business. Previously, an organisation could refuse to comply with a request only if it was “manifestly unfounded or excessive.” This was a high bar to meet, leaving many businesses struggling with requests that felt malicious or disproportionate.

The Data (Use and Access) Act adjusts this threshold, allowing organisations to refuse or charge a reasonable fee for requests that are deemed “vexatious or excessive.”

What Does ‘Vexatious’ Mean in Practice?

The term ‘vexatious’ focuses more on the motive behind the request. It could apply in situations where a request is intended to cause disruption, is part of a targeted campaign of harassment against an organisation or its staff, or represents a clear abuse of the right of access. For example, a former employee submitting weekly, repetitive requests after a contentious departure could potentially be considered vexatious.

This provides a stronger legal footing to push back against weaponised DSARs. However, this power must be used carefully. You must have a robust internal procedure for assessing each request on its own merits and be prepared to justify any refusal to the ICO. The default position must always be to comply.

Key Change 4: A Dual Approach to Cookies and Marketing Fines

The Act introduces significant changes to the rules governing cookies and electronic marketing, which fall under the Privacy and Electronic Communications Regulations (PECR). This is a classic case of giving with one hand and taking with the other.

A More Pragmatic Stance on Cookies

The endless barrage of cookie consent banners has been a source of frustration for users and website operators alike. The new law relaxes the rules by removing the need to gain consent for certain low-risk cookies. These include:

  • Cookies used for statistical purposes to gather information on how a service is used, purely to make improvements.

  • Cookies that are necessary to install security updates on a user's device.

  • Cookies used to remember user preferences for a service (e.g., language or accessibility settings).

Crucially, consent is still absolutely required for any cookies that track users for marketing and advertising purposes. If your website uses pixels or trackers to build profiles or serve targeted ads, your consent banner must remain and must meet the high standards of UK GDPR.

The Sting in the Tail: A Huge Increase in Marketing Fines

To counterbalance the relaxation on cookies, the Act dramatically increases the penalties for serious breaches of PECR. Previously, the maximum fine the ICO could issue for nuisance calls or spam emails was £500,000.

Under the new regime, the ICO can impose fines of up to £17.5 million or 4% of global annual turnover—whichever is higher. This brings PECR penalties in line with UK GDPR and sends a clear signal that unsolicited marketing is a key enforcement priority. For businesses that rely on email or telephone marketing, ensuring your practices are fully compliant is more critical than ever. This highlights the importance of understanding the fundamentals, as detailed in our clear guide to UK GDPR consent requirements.

Myth vs. Fact: What the Data (Use and Access) Act Really Means

With any new legislation, misinformation can spread quickly. Let’s clarify some common misconceptions.

Myth: UK GDPR has been scrapped and replaced.

Fact: This is incorrect. The Data (Use and Access) Act amends the existing UK GDPR and Data Protection Act 2018; it does not replace them. The seven core principles of data protection, the catalogue of individual rights, and the principle of accountability all remain firmly in place. You can refresh your knowledge by reviewing this practical breakdown of the ICO's guidance on UK GDPR.

Myth: I can now use personal data for marketing without any restrictions.

Fact: While the Act clarifies that direct marketing can be a legitimate interest, it does not remove the rules. Individuals still have an absolute right to object, and the massive increase in PECR fines means the consequences of getting it wrong are far more severe. The rules for consent for electronic marketing to new prospects remain unchanged.

Myth: I no longer need anyone to be responsible for data protection in my company.

Fact: You must appoint a Senior Responsible Individual (SRI) from your senior management team. Accountability has been elevated to the leadership level, not eliminated. This change places data protection at the heart of your organisation’s governance.

Your Action Plan: A 6-Step Checklist for Compliance

The Data (Use and Access) Act requires a proactive response. Here are the six key steps your business should take now:

  1. Review Your Lawful Bases: Examine your Record of Processing Activities (ROPA). Identify where you can now confidently rely on the newly defined legitimate interests. This could simplify your compliance documentation.

  2. Update Your Privacy Notice: Your privacy notice must be a transparent, living document. It needs to be updated to reflect any changes to your lawful bases, reference your SRI instead of a DPO, and explain your new policy on handling DSARs.

  3. Audit Your Website Cookies: Conduct a full audit of the cookies and tracking technologies on your website. Determine which, if any, no longer require a consent banner. Be absolutely certain before making changes, especially regarding third-party marketing trackers.

  4. Revise Your DSAR Procedure: Update your internal policies and staff training to incorporate the new “vexatious or excessive” standard. Ensure you have a clear process for documenting the justification for any refusal.

  5. Assess Your Marketing Compliance: In light of the new penalty levels, this is a business-critical task. Review your marketing lists, check the evidence of consent, and ensure you have a simple, effective process for honouring opt-out requests.

  6. Designate and Empower Your SRI: Formally appoint your Senior Responsible Individual. Ensure they understand the scope of their responsibilities and have the authority and resources to effectively oversee data protection across the business. You can find general guidance on accountability on the ICO's main UK GDPR hub.

The Data (Use and Access) Act presents a recalibrated data protection framework for the UK. It offers businesses greater flexibility and reduced bureaucracy in some areas but demands stricter adherence and carries heavier consequences in others. By taking these measured steps now, you can confidently navigate the new landscape, maintain compliance, and continue to build lasting trust with your customers.