JDI-UK
JDI-UK
  • Home
  • Data Protection Services
  • Digitialisation Services
  • Cyber Security Services
  • IT Support Services
  • News
  • Contact
  • More
    • Home
    • Data Protection Services
    • Digitialisation Services
    • Cyber Security Services
    • IT Support Services
    • News
    • Contact
  • Home
  • Data Protection Services
  • Digitialisation Services
  • Cyber Security Services
  • IT Support Services
  • News
  • Contact

Understanding the Data Use and Access Act 2025 (DUAA)

What is DUAA?

  • A major update to UK data protection law, amending UK GDPR, Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
  • Designed to simplify compliance, reduce administrative burden, and enable innovation while maintaining strong privacy protections.

How Does It Affect Micro & Small Companies?

  • Introduces “Recognised Legitimate Interests” for certain processing (e.g., direct marketing, fraud prevention) without a balancing test.
  • Eases cookie consent rules for analytics and functionality cookies.
  • Expands flexibility for automated decision-making and scientific research use of data.

What to Look Out For

  • New Complaints Handling Rules: Companies must implement clear processes for data subject complaints.
  • DSAR Changes: “Reasonable and proportionate” searches allowed; ability to pause response clock for clarification.
  •  Higher Penalties: PECR fines now match GDPR—up to £17.5M or 4% of global turnover.

Processes & Procedures to Review

  • Privacy Notices & Policies: Update to reflect new lawful bases and cookie rules.
  • Direct Marketing Practices: Ensure opt-outs and consent mechanisms comply with DUAA and PECR.
  • Data Sharing Agreements: Review contracts for international transfers under new adequacy test.
  • Automated Decision-Making: Add transparency and human review safeguards.

Role of a DPO

  • Oversee compliance with DUAA alongside GDPR obligations.
  • Conduct risk assessments for AI and automated decision-making.
  • Train staff on new DSAR handling and complaint processes.
  • Act as liaison with the Information Commission (new regulator replacing ICO). 

Real Examples of Issues Companies Could Face

  • Marketing Breaches: Sending unsolicited emails without updated opt-out processes could trigger fines.
  • Cookie Non-Compliance: Failing to update cookie banners for analytics exemptions may lead to enforcement.
  • DSAR Mishandling: Ignoring the new “reasonable search” standard could result in complaints and audits.
  • AI Misuse: Using automated profiling in recruitment without transparency could lead to discrimination claims.

DATA USE AND ACCESS ACT 2025 (DUAA)

Download PDF

How JDI-UK Can Help

  • ✅ Compliance Audits & Gap Analysis – Identify risks and align policies with DUAA.
  • ✅ Policy & Process Updates – Privacy notices, SAR workflows, and cookie compliance.
  • ✅ Staff Training – Equip your team to handle new obligations confidently.
  • ✅ Fully Managed Service – End-to-end compliance support for peace of mind.

Lets start a conversation

Attach Files
Attachments (0)

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Lets start a conversation

 Contact JDI-UK today for a free consultation and discover how we can help you transition smoothly and securely. 

Message us on WhatsApp

JDI UK Limited

T: 01772 802702 M: 07486 860990 E: it.support@jdi-uk.com

Hours

Mon

09:00 – 17:00

Tue

09:00 – 17:00

Wed

09:00 – 17:00

Thu

09:00 – 17:00

Fri

09:00 – 17:00

Sat

By Appointment

Sun

Closed

Copyright © 2025 JDI-UK - All Rights Reserved.

Powered by

  • Privacy Policy

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept