UK Data Protection 2026: Complete GDPR Compliance Guide for Businesses

UK data protection law was significantly amended in 2025, but not replaced. The UK GDPR and the Data Protection Act 2018 remain the framework; the Data (Use and Access) Act 2025 sits on top of them, adjusting the rules on complaints, subject access, cookies, automated decisions and enforcement. This guide explains what the reforms change, what has stayed the same, and the practical steps a business needs to take to stay compliant.

Understanding UK Data Protection After the 2025 Reforms

Quick Answer — What Changed in 2025?

The UK GDPR and Data Protection Act 2018 still apply. The Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025, amends them — introducing a complaints procedure for controllers, easing subject access searches and some cookie rules, relaxing certain automated-decision restrictions, and raising fines for electronic marketing breaches. The core duties and rights remain.

The Data (Use and Access) Act 2025: Key Changes

The Data (Use and Access) Act 2025 is the most important recent development, but its effect is to overlay and reform the existing regime rather than repeal it. The seven data-protection principles, the lawful bases for processing, and the rights of individuals all continue as before. What the Act does is adjust specific mechanics that matter to businesses day to day.

Among the key changes: controllers must put in place a procedure to handle data protection complaints from individuals; the rules on automated decision-making are relaxed so that the strictest safeguards apply mainly to significant decisions based on special category data; a set of "recognised legitimate interests" can be relied on without the usual balancing test; and the framework for international data transfers is restated around a data-protection test. The Act also creates powers for smart data schemes and digital verification services, and reforms the data regulator's governance. The regulator's own guidance on the Data (Use and Access) Act 2025 is the authoritative source as detailed rules are phased in.

Uk Data Protection Compliance Infographic — Uk Gdpr Still Applies, Subject Access, 72-Hour Breach Notification, Fines Up To £17.5M Or 4% Turnover, Pecr Cookies

Enforcement remains substantial. The maximum fine under the UK GDPR is the higher of £17.5 million or 4% of total annual worldwide turnover for the most serious breaches, with a lower tier of £8.75 million or 2% for others. The regulator can also issue enforcement notices, assessment notices and reprimands, and require changes to how an organisation processes personal data.

The Act also reforms the regulator itself, replacing the Information Commissioner's Office with a new statutory body, the Information Commission, with updated governance and duties. For businesses the practical position is unchanged in substance: a well-documented compliance programme, a lawful basis for each processing activity, and a tested breach response plan remain the best protection against enforcement action, because much enforcement flows from not knowing what data is held rather than from the breach itself.

Electronic marketing and cookies are governed by the Privacy and Electronic Communications Regulations (PECR), which sit alongside the UK GDPR. The most significant change here is enforcement: the Data (Use and Access) Act 2025 raised the maximum PECR fine dramatically, from £500,000 to the UK GDPR level of up to £17.5 million or 4% of turnover. Marketing and cookie compliance is therefore now backed by far heavier penalties.

On cookies, the Act relaxes the consent requirement for certain low-risk purposes — such as some analytics — provided the user is given clear information and a straightforward way to opt out. Consent-based direct marketing rules otherwise remain, so businesses should review their cookie banners and marketing consents against the new position rather than assume nothing has changed.

Data Breach Notification and Security

The breach regime is unchanged in its essentials. A personal data breach that is likely to result in a risk to individuals' rights and freedoms must be reported to the regulator without undue delay and, where feasible, within 72 hours of the organisation becoming aware of it. Where the risk to individuals is high, those individuals must also be told. Records of all breaches must be kept, whether or not they are reportable.

Underpinning this is the security principle, which requires appropriate technical and organisational measures to protect personal data. In practice that means access controls, encryption where appropriate, staff training and an incident response plan that can be activated quickly. The 72-hour clock is short, so knowing in advance who does what after a breach is essential.

Note — The 72-Hour Clock Is Tight

The obligation to notify a reportable breach within 72 hours runs from awareness, not from when the investigation is complete. Having a breach response plan ready — including who assesses risk and who notifies — is what makes the deadline achievable.

Subject Access Requests

Individuals retain the right to make a subject access request and to receive a copy of their personal data, normally within one month, extendable by up to two further months for complex or numerous requests. The Data (Use and Access) Act 2025 clarified how these are handled: an organisation need only carry out a reasonable and proportionate search, and it may pause the time limit — a "stop the clock" — while it seeks information reasonably needed to confirm the requester's identity or to clarify the request.

These changes make the process more manageable for businesses, but they do not weaken the underlying right. With subject access request volumes rising, the practical answer is to template the response process — identity checks, search scope, redaction of third-party data and exemptions — so that each request is handled consistently and within time. Where a data dispute escalates, our litigation team can advise on complaints, claims and enforcement.

Frequently Asked Questions

Did the Data (Use and Access) Act 2025 replace UK GDPR?

No. The UK GDPR and the Data Protection Act 2018 remain the framework. The Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025, amends specific parts of them — on complaints, subject access, cookies, automated decisions and enforcement — rather than repealing the regime.

What are the maximum data protection fines?

For the most serious breaches, the maximum fine is the higher of £17.5 million or 4% of total annual worldwide turnover, with a lower tier of £8.75 million or 2%. The 2025 Act raised the maximum fine for electronic marketing and cookie breaches under PECR to the same £17.5 million level.

What is the new complaints procedure requirement?

The Data (Use and Access) Act 2025 requires controllers to put in place a procedure that allows individuals to complain about how their personal data is handled, including acknowledging and responding to complaints. Organisations should have a clear, documented process in place to meet this duty.

How long do I have to respond to a subject access request?

Normally one month, extendable by up to two further months for complex or numerous requests. Under the 2025 Act you need only conduct a reasonable and proportionate search, and you can pause the time limit while confirming identity or clarifying the request.

How quickly must a data breach be reported?

A personal data breach likely to result in a risk to individuals must be reported to the regulator without undue delay and, where feasible, within 72 hours of the organisation becoming aware of it. High-risk breaches must also be notified to the affected individuals.

Do the cookie rules still require consent?

For most purposes, yes, but the 2025 Act relaxes the requirement for certain low-risk uses such as some analytics, provided users receive clear information and an easy way to opt out. Direct marketing consent rules under PECR otherwise remain, so cookie banners should be reviewed.

What changed for automated decision-making?

The strict restrictions now apply mainly to significant decisions based on special category data, giving organisations more scope to use automated processing in other contexts — subject to safeguards such as informing individuals and allowing them to contest a decision.

What should a business do to stay compliant?

Maintain a record of what personal data you hold and why, ensure a lawful basis for each processing activity, keep a tested breach response plan, template your subject access and complaints procedures, and review cookie and marketing consents against the 2025 changes.

Expert Data Protection Support
Compliance Review

We audit your processing, records and policies against the current framework and the 2025 reforms.

Breach Response

We help you build and run a breach response plan that meets the 72-hour notification deadline.

Requests and Disputes

We advise on subject access requests, complaints and enforcement, from templating to defending action.

Data protection now carries penalties reaching millions, and the 2025 reforms change what compliance looks like — the team at Connaught Law can review your position and help you meet your obligations with confidence.

Speak to Us

Disclaimer:

The information in this blog is for general information purposes only and does not purport to be comprehensive or to provide legal advice. Whilst every effort is made to ensure the information and law is current as of the date of publication it should be stressed that, due to the passage of time, this does not necessarily reflect the present legal position. Connaught Law and authors accept no responsibility for loss that may arise from accessing or reliance on information contained in this blog. For formal advice on the current law please don't hesitate to contact Connaught Law. Legal advice is only provided pursuant to a written agreement, identified as such, and signed by the client and by or on behalf of Connaught Law.