Back to Blog
strategy

The Data (Use and Access) Act 2025 is in force: what UK SMEs must do now

By Dee KhabraPublished Last reviewed
Overhead view of a dark walnut meeting table with a closed black document folder, plain paper and a fountain pen, and a pair of hands resting on the folder

The Data (Use and Access) Act 2025 is no longer forthcoming legislation. Its data protection provisions commenced on 5 February 2026, the duty on controllers to handle data protection complaints followed on 19 June 2026, and the Information Commissioner's Office confirmed in a 19 June 2026 update to its guidance for organisations that all the data protection provisions are now in force.

For most UK SMEs that means two concrete obligations rather than a general change in atmosphere. Every controller now needs a route by which people can complain to it directly, with a statutory acknowledgement period attached. And any decision your business takes by automated means, including anything an AI assistant materially decides, now sits under a rewritten framework with four named safeguards.

This is a practical checklist, written for the person who owns data protection in a firm without a full-time DPO. Provisions are cited so you can check them yourself, and where the summaries in circulation are looser than the statute, the statute is what appears here.

What commenced, and exactly when

The Act received Royal Assent on 19 June 2025. The instrument that matters for the data protection regime is The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, SI 2026/82, made on 29 January 2026 by the Department for Science, Innovation and Technology. Note the full title: it is commonly shortened to "the Commencement No. 6 Regulations", which drops the transitional and saving provisions that do a good deal of the practical work.

The instrument appoints two dates and no others.

DateWhat came into forceWhere
5 February 2026The bulk of the Act's data protection provisions, including section 80 and Schedule 6 on automated decision-making, section 70 and Schedule 4 (recognised legitimate interests), section 76 (time limits for data subject requests) and section 101 (penalty notices)Regulation 2
19 June 2026Section 103 and Schedule 10: complaints by data subjectsRegulation 3

Regulation 2 commences its list "so far as not already in force", because several provisions had been commenced earlier. As at 12 August 2026 the most recent commencement instrument for the Act is Commencement No. 8, SI 2026/317, made 18 March 2026, and nothing specific to automated decision-making remains uncommenced.

Automated decision-making: the new test

Section 80 replaces Article 22 of the UK GDPR with new Articles 22A to 22D. Two definitions carry the whole regime.

First, when is a decision automated? Article 22A provides that a decision is "based solely on automated processing if there is no meaningful human involvement in the taking of the decision". The pivot is meaningful human involvement, and Article 22A(2) requires that in assessing it a person must consider, among other things, the extent to which the decision is reached by means of profiling. A human who rubber-stamps an output has not supplied meaningful involvement, and this is where most SME deployments will actually be tested.

Second, when is a decision significant? Article 22A(1)(b) sets the test as whether the decision "produces a legal effect for the data subject" or "has a similarly significant effect for the data subject".

Where a decision is both significant and solely automated, Article 22C requires the controller to have safeguards. There are four, and they read as a checklist:

  • measures to provide information to the data subject about the decision
  • measures to enable the data subject to make representations about the decision
  • measures to enable the data subject to obtain human intervention on the part of the controller in relation to such decisions
  • measures to enable the data subject to contest such decisions

An important nuance about those four safeguards, because it is regularly overstated in the other direction: they are all post-decision rights. Article 22C requires that a person can obtain human intervention, make representations and contest the decision afterwards. It does not require a human in the loop before the decision is taken. Article 22C(2) also says the safeguards must "consist of or include" those measures, which sets a floor rather than a ceiling.

Two restrictions sit alongside. Article 22B narrows the position sharply where the decision is based entirely or partly on special category data. Note "entirely or partly": a decision using special category data as one input among several is caught. Two conditions can lift the prohibition, and both are narrower than they first appear. The consent route requires the decision to be based entirely on personal data to which the data subject has given explicit consent, not partly. The alternative route requires either contractual necessity or legal requirement or authorisation, and in addition that point (g) of Article 9(2), substantial public interest, applies. That second limb is cumulative, so contractual necessity on its own will not carry a solely automated special category decision. The old Article 22(4) had allowed Article 9(2)(a) or 9(2)(g); the new provision is tighter.

Article 22B also prohibits a significant solely automated decision where the processing for the purposes of the decision is carried out entirely or partly in reliance on Article 6(1)(ea), the new recognised legitimate interests basis introduced by section 70 and Schedule 4 on the same day. That interaction is easy to miss and it links the Act's two headline reforms: if you rely on a recognised legitimate interest to process, you cannot then take the significant decision on a solely automated basis at all.

One further point of context worth having. What the Act removed was a right, not just a set of conditions. Pre-Act Article 22(1) gave the data subject a right not to be subject to a solely automated decision with legal or similarly significant effects, subject to three exceptions. The new framework replaces that starting position with a permission plus safeguards, which is why "the DUAA relaxed the rules" and "the DUAA imposed new duties" are both true statements about the same change.

Law enforcement processing has its own version. Section 80 also replaces sections 49 and 50 of the Data Protection Act 2018 with new sections 50A to 50D, where the significance test is narrower and requires an adverse legal effect or a similarly significant adverse effect.

The transitional provision, stated precisely

Most summaries say the new regime applies only to decisions taken on or after 5 February 2026. That is the Government's stated intent, and the Explanatory Note to SI 2026/82 puts it in those words. But the Explanatory Note carries the standard disclaimer that it is not part of the Regulations, and regulation 5 as drafted is narrower: the section 80 and Schedule 6 amendments "do not apply in relation to any decision taken before 5th February 2026 to which Article 22(3) of the UK GDPR ... or section 14 or 50(2) of the 2018 Act ... applied".

For a live deployment the distinction is academic, because decisions taken now are unambiguously under the new regime. It matters if you are reviewing a historic decision or defending one, and it is the sort of detail worth having right before a conversation with a regulator or a claimant.

Two other savings in the same instrument are worth noting because they follow the same pattern. Regulation 4 preserves the previous time limits for data subject requests received before 5 February 2026, so a request that arrived on 4 February runs on the old clock. Regulation 6 disapplies the section 101 penalty notice amendments where the Commissioner gave a notice of intent before that date.

The complaints duty: the change most SMEs have not actioned

Section 103 inserts new sections 164A and 164B into the Data Protection Act 2018. Section 164A gives a data subject the right to complain to the controller where they consider there is an infringement of the UK GDPR or Part 3 of the 2018 Act in connection with their personal data. It then imposes duties on the controller:

  • Facilitate complaints. The controller "must facilitate the making of complaints under this section by taking steps such as providing a complaint form which can be completed electronically and by other means".
  • Acknowledge within 30 days. The controller must acknowledge receipt "within the period of 30 days beginning when the complaint is received". Thirty days, not a month.
  • Respond without undue delay. The controller must, without undue delay, take appropriate steps to respond and inform the complainant of the outcome. Section 164A(5) explains that appropriate steps include making enquiries into the subject matter to the extent appropriate, and informing the complainant about progress.

Under regulation 7 of SI 2026/82 the acknowledgement and response duties apply only to complaints received on or after 19 June 2026. The duty to facilitate is not caught by that transitional provision.

Section 103 also does something structural that is easy to overlook: it omits Article 77 of the UK GDPR, the right to lodge a complaint with the Commissioner, along with Article 57(1)(f) and Article 57(2), and it omits section 165(1) of the 2018 Act while amending section 165(2) to cover the UK GDPR as well as Part 3. The effect is a controller-first complaints stage, with the route to the ICO running through section 165 of the Data Protection Act rather than directly through Article 77. If your privacy notice still tells people their route of complaint is Article 77 of the UK GDPR, that reference needs updating.

Section 164B is a power, not a duty: it allows the Secretary of State to require controllers by regulations to notify the Commissioner of the number of section 164A complaints received. Whether any such regulations exist is a separate question and should be checked rather than assumed.

What the ICO has actually published, and what it has not

The two halves of this Act are at very different stages of regulatory guidance, and conflating them is the most common error in circulation.

Complaints: published and current. The ICO's guidance "How to deal with data protection complaints" was published on 12 February 2026 and updated on 8 May 2026. It states plainly that you must have a process for handling data protection complaints within your organisation and that there are no exemptions, and that however you receive a complaint, you must accept it. It expects organisations to tell people they can complain to the organisation as well as to the ICO, both at the point of collection and when responding to a subject access request. Usefully for a small firm, the ICO frames the mechanism as a choice rather than a mandate: a form, an email address, a phone line, a portal, live chat with escalation to a human, or in person are listed as options, it says a separate data-protection-specific tool is not required, and an existing complaints process can be adapted. Writing a formal complaints procedure is presented as something you could do, not something you must.

Automated decision-making: still draft. The ICO's detailed ADM and profiling guidance is a consultation draft. The consultation ran from 31 March 2026 to 29 May 2026 and is closed, and the ICO's own guidance plans page lists the final version as due for publication in Winter 2026. Treat that as an expectation and a season, not a date. The ICO has also said the draft will inform a statutory code of practice on AI and ADM that it intends to develop, and no publication window is given for that code.

The trap. The ICO maintains both a detailed guidance page and a shorter "in brief" page on rights related to automated decision-making. The shorter one, which is the page an SME searching for this is most likely to land on, still describes the pre-Act position: it works from Article 22 and the old three grounds of contract, legal authorisation and explicit consent, with no reference to Articles 22A to 22D. The ICO has said the in-brief material will be updated in due course. Until it is, a compliance file that rests on that page is resting on a description of the previous regime.

One further gap worth planning around: the ICO's "Guidance on AI and data protection" is live but flagged as under review because of this Act, and its substantive content was last updated on 15 March 2023. The AI and data protection risk toolkit carries the same under-review banner. They remain the most useful available material, but they are pre-Act in substance.

The checklist: what to do this quarter

Six actions, in the order we would run them for a UK SME with an AI assistant deployed or about to be.

1. Stand up a complaints route and name an owner. If you already have a complaints process, adapt it and say so in your privacy notice. Section 164A(2) requires you to facilitate the making of complaints and offers a form completable electronically and by other means as its example of how, so the statutory duty is the facilitation rather than any one mechanism. Set a diary rule that acknowledges within 30 days of receipt rather than 30 days of someone noticing.

2. Fix the Article 77 reference. Check your privacy notice, your subject access response template and your terms for references to the right to complain to the Commissioner under Article 77. Update them to describe the controller-first route and the onward route to the ICO, and add the statement that people can complain to you as well as to the ICO.

3. Inventory your automated decisions honestly. List every point where an outcome affecting a person is produced without a human genuinely deciding. Recruitment screening, credit or affordability checks, pricing, fraud flags, performance summaries, automated eligibility. For each one, record whether it is significant on the Article 22A test and whether a human is doing something more than confirming.

4. Where a decision is significant and solely automated, build the four Article 22C safeguards. Information about the decision, a way to make representations, human intervention on the part of the controller, and a way to contest. These are four separate mechanisms, not one appeals inbox described four ways.

5. Check the special category and lawful basis interactions. If special category data is anywhere in the decision, Article 22B narrows your options sharply. If you have adopted the new recognised legitimate interests basis under Article 6(1)(ea), confirm it is not underpinning any significant automated decision, because that combination is prohibited.

6. Revisit your DPIA rather than starting one. The Act did not change the test for when a DPIA is required: the Article 35 trigger is unchanged. What changed is the safeguards a DPIA has to document. If you produced one before February 2026, it is very likely describing the old Article 22 framework. Our DPIA screening test for a UK AI assistant rollout sets out both the screening criteria and what an assessment needs to contain to be worth anything.

What this means if you are deploying an AI assistant

Most AI assistant deployments in UK SMEs are not automated decision-making, and it is worth saying so plainly rather than manufacturing an obligation. A tool that drafts correspondence, summarises documents or answers questions from a knowledge base, with a person reading and sending the output, does not take a decision at all. The regime bites where an output becomes an outcome without a person meaningfully in between.

The risk in practice is drift. A tool introduced to draft a first response gets wired into a workflow where its output is auto-sent. A screening assistant that was advisory becomes the filter. Nobody decides to cross the line, which is why the inventory in step three is worth repeating on a schedule rather than once. The Act's test is about what actually happens, not what the deployment was designed to do.

For the wider compliance picture, our UK AI compliance checklist covers the surrounding obligations, and is Claude GDPR compliant for UK business deals with the vendor-side questions that come up in the same conversation.

Where The AI Consultancy fits

Working through an automated decision-making inventory, building the Article 22C safeguards into a live process rather than a policy document, and getting a complaints route that survives contact with an actual complaint is the kind of work our AI readiness engagements cover. If AI is already deployed and nobody has mapped it against the current regime, that is a scoped piece of assessment rather than a project.

All provisions verified on 12 August 2026 against legislation.gov.uk: the Data (Use and Access) Act 2025 (c. 18), sections 80 and 103, and The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82). ICO guidance statuses verified the same day at ico.org.uk. This is general information about the law as it stands on 12 August 2026, not legal advice; decisions on your own compliance position should be taken with your data protection adviser.

Frequently asked questions

Is the Data (Use and Access) Act 2025 in force?
Its data protection provisions are. The Act received Royal Assent on 19 June 2025, and The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), made on 29 January 2026, brought the bulk of them into force on 5 February 2026, including section 80 and Schedule 6 on automated decision-making. The complaints provisions, section 103 and Schedule 10, followed on 19 June 2026. The ICO's own summary for organisations was updated on 19 June 2026 to record that all the data protection provisions are now in force. The Act is wider than data protection, and the commencement position for its other Parts should be checked against the current commencement instruments rather than assumed from this article.
What does the new automated decision-making regime require?
Section 80 replaced Article 22 of the UK GDPR with new Articles 22A to 22D. The test for whether a decision is caught is whether there is meaningful human involvement in taking it: if there is none, the decision is based solely on automated processing. A decision is significant if it produces a legal effect or a similarly significant effect for the person. Where a significant decision is taken solely by automated means, Article 22C requires safeguards that include providing information about the decision, enabling the person to make representations, enabling them to obtain human intervention on the part of the controller, and enabling them to contest the decision. Special category data is more tightly restricted under Article 22B, and a significant automated decision cannot be taken in reliance on the new recognised legitimate interests basis.
Does the new regime apply to decisions taken before 5 February 2026?
The saving provision is narrower than the summaries suggest, and the distinction matters if you are reviewing historic decisions. Regulation 5 of SI 2026/82 provides that the section 80 and Schedule 6 amendments do not apply in relation to any decision taken before 5 February 2026 to which Article 22(3) of the UK GDPR, or section 14 or 50(2) of the Data Protection Act 2018, applied. The Explanatory Note to the Regulations states the broader proposition that the changes apply only to decisions taken on or after section 80 comes into force, but that note is expressly not part of the Regulations. The practical position for a live deployment is the same either way: decisions you take now are under the new regime.
Does every UK business need a data protection complaints process?
Yes. Section 103 of the Act inserted section 164A into the Data Protection Act 2018, which gives data subjects a right to complain to the controller and requires the controller to facilitate the making of such complaints, giving the example of a complaint form that can be completed electronically and by other means. The ICO's published guidance is unambiguous that you must have a process for handling data protection complaints and that there are no exemptions. It also says that however you receive a complaint, you must accept it. What the ICO does not require is a dedicated data protection complaints form or portal, or a separate written procedure: it lists those as options, and expressly says an existing complaints process can be adapted.
How quickly must a controller respond to a data protection complaint?
Section 164A(3) of the Data Protection Act 2018 requires the controller to acknowledge receipt within the period of 30 days beginning when the complaint is received. Note that it is 30 days, not one month. Section 164A(4) then requires the controller, without undue delay, to take appropriate steps to respond to the complaint and to inform the complainant of the outcome, and section 164A(5) explains that appropriate steps include making enquiries into the subject matter to the extent appropriate and informing the complainant about progress. There is no fixed statutory deadline for the substantive response. Under regulation 7 of SI 2026/82 the acknowledgement and response duties apply only to complaints received on or after 19 June 2026.
Has the ICO published final guidance on automated decision-making?
Not as at 12 August 2026. The detailed ADM and profiling guidance is a consultation draft: the consultation ran from 31 March 2026 to 29 May 2026 and is closed, and the ICO's guidance plans page lists the final version as due for publication in Winter 2026, which is a season rather than a date. There is a trap here worth knowing. The shorter, more discoverable ICO page on rights related to automated decision-making still describes the pre-Act framework, citing Article 22 and the old three grounds, and the ICO has said the in-brief material will be updated in due course. If you are checking your position against an ICO page, check which page you are on. The complaints guidance, by contrast, is published and current.

Get new briefings by email

The AI Consultancy newsletter delivers briefings and analysis for UK businesses. We use your address only to send it, and you can unsubscribe at any time.

By subscribing you consent to receive The AI Consultancy newsletter by email. You can unsubscribe at any time. See our privacy policy.

Related Articles

strategy

What is a Fractional Chief AI Officer? A UK Guide for 2026

strategy

Fractional CAIO Cost in the UK 2026: Day Rates, Monthly Retainers, Real Examples

strategy

Fractional CAIO vs AI Consultant: Which Does Your UK Business Need?

Ready to explore AI for your business?

Book a free 20-minute consultation. No obligation, no jargon.