duaa uk gdpr changes explain how the Data (Use and Access) Act 2025 creates named information gateways for specified public‑sector data while leaving UK GDPR duties such as data minimisation and subject rights in place. The UK Government's collection on the Data (Use and Access) Act 2025 explains the gateways and commencement powers GOV.UK, 2025.
The Information Commissioner’s Office (ICO) has published a practical summary organisations should read when reassessing data flows and records of processing under UK GDPR ICO, and government guidance explains how the new information gateway supports trusted digital verification services Enabling Digital Identity, 2026. Organisations that pull or combine public records should reassess those integrations and update UK GDPR documentation before relying on an information gateway.
- Quick summary: DUAA 2025 adds named information gateways for public‑sector data while UK GDPR obligations remain unless a specific DUAA provision applies.
- What to check: Review integrations that pull public records, update records of processing and reassess lawful bases under UK GDPR.
- Regulators: Read the Data (Use and Access) Act 2025 collection on GOV.UK GOV.UK, 2025 and the ICO summary for practical steps ICO.
- Operational step: Run or update Data Protection Impact Assessments (DPIAs) for any high‑risk DUAA data flows before relying on an information gateway, and consider how trusted digital verification services will change verification processes Enabling Digital Identity, 2026.
What is the Data Use and Access Act and what happened in 2025?
The Data Use and Access Act (DUAA) is a UK law that creates specific legal gateways for the reuse and sharing of public‑sector data and for trusted digital verification services, and in 2025 Parliament passed the Data (Use and Access) Act 2025 which set out powers for ‘‘information gateways’’ and delegated commencement arrangements (Data (Use and Access) Act: enactment impact assessment).
The Information Commissioner’s Office (ICO) and the Department for Science, Innovation and Technology (DSIT) have distinct but connected roles: the ICO interprets how DUAA sits alongside UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, while DSIT manages policy implementation and the practical roll‑out of information gateways and verification services (ICO: DUAA summary of the changes).
What changed in practice in 2025?
In 2025 DUAA authorised the creation of an information gateway framework that permits secure sharing of certain public records with approved bodies and trusted digital verification providers, subject to statutory safeguards, impact assessments and ICO oversight (UK Government enactment impact assessment, 2025).
That change does not replace UK GDPR. Organisations handling public records must still observe UK GDPR principles such as purpose limitation, data minimisation, and the need for a lawful basis where DUAA does not apply. The ICO’s guidance explains where DUAA creates a separate legal gateway and where standard data protection rules continue to govern processing (ICO guidance, 2025).
What this means for security and compliance teams
Organisations that consume or integrate public‑sector data should treat DUAA as an additional, narrowly defined route for specific data uses, not as a blanket exemption from UK GDPR. Practical steps we recommend include: update data‑flow maps to show any DUAA gateways, review or refresh Data Protection Impact Assessments (DPIAs) where DUAA is cited, confirm contractual terms with third parties who will receive public data, and log decisions on lawful basis and safeguards for audit.
At CyPro, we help clients map DUAA‑related data flows and test whether a proposed sharing arrangement genuinely relies on DUAA or still needs a UK GDPR lawful basis. Early engagement with the ICO and attention to the government’s impact assessment reduce the risk of misusing delegated powers and of underestimating compliance gaps (UK Government, 2025, ICO, 2025).
How does the Data Use and Access Act change UK GDPR rules?
The Data Use and Access Act provides a statutory route for specified public authorities to share defined public‑sector data with named recipients for prescribed purposes, it does not replace the UK General Data Protection Regulation (UK GDPR) or remove core controller and processor duties.
What the Act changes
The Act creates an "information gateway" that, when used, authorises particular disclosures by public bodies under the conditions set out in the statute and secondary regulations, and it permits Parliament to create narrow exemptions from parts of the Data Protection Act 2018 for those specific uses. The government's enactment impact assessment sets out the scope and limits of the gateways and the statutory tests public bodies must meet before sharing data under the Act (Data (Use and Access) Act: enactment impact assessment, 2025).
How UK GDPR duties interact with the Act
Under the UK GDPR, controllers remain responsible for data minimisation, purpose limitation, security and documenting processing where those duties still apply. The Information Commissioner's Office (ICO) explains that parts of UK data protection law continue to apply unless the Act and its secondary legislation explicitly set an exemption, so organisations must treat the Act as an additional legal route rather than a blanket replacement for UK GDPR obligations (ICO guidance, 2025).
Practical effects for UK organisations
Public bodies and any third parties receiving data under an information gateway should expect added compliance steps: confirm the statutory purpose, record the legal basis under the Act, assess risks to data subject rights, and apply retention and access controls aligned to the gateway conditions. Central government guidance on enabling digital verification and information gateways clarifies technical and assurance requirements for trusted digital verification services that will commonly sit alongside DUAA flows (Enabling Digital Identity blog, 2026).
Immediate steps we recommend
- Map any incoming or outgoing public‑sector data flows against the Act's information gateways and record which statutory condition applies.
- Update Data Protection Impact Assessment templates to include a DUAA assessment path, do not assume standard UK GDPR lawful bases cover gateway sharing.
- Agree retention, access and security controls with the supplying public body, and capture these in contracts or data sharing agreements.
- Engage the Information Commissioner's Office early where a proposed gateway includes exemptions to rights, and seek legal advice for novel or cross‑border uses.
In our experience, treating the Data Use and Access Act as a complementary, tightly scoped tool and documenting the statutory basis and safeguards prevents compliance gaps and reduces the risk of ICO escalation.
Who needs to change processes because of the Data Use and Access Act?
Direct answer: any organisation that receives, processes or relies on public‑sector data under the Data (Use and Access) Act must change processes, including data controllers, data processors, and third parties integrating public‑sector feeds. In the UK, this affects public bodies, private suppliers to public bodies and private firms using public records in service delivery, especially in financial services, legal, technology and other regulated industries. Organisations should treat duaa uk gdpr changes as an extra legal route, not a replacement for UK GDPR duties.
Mapping roles: controllers, processors and obligations
Data controllers must update records of processing and lawful bases where they start using DUAA‑enabled feeds; processors must ensure contractual terms reflect any DUAA constraints and security measures. Under UK GDPR, controllers remain responsible for transparency, subject rights and Data Protection Impact Assessments, so your DPIAs and Records of Processing Activities need explicit references to the DUAA flows and any "information gateway" used by public bodies (IBM, 2025).
Sector notes and practical next steps
In financial services, firms using public‑sector identity checks or fraud data must align KYC and AML processes to DUAA conditions and update supplier contracts. In legal and technology firms, automated ingestion of public records requires threat modelling and access controls. Practical checklist items: update DPIAs, revise processor agreements, log DUAA data lineage and test access controls. CyPro recommends reviewing any system that pulls public records within 30 days and documenting decisions in your UK GDPR records to show due diligence against both regimes.
Organisations should monitor operational risk: breaches tied to public feeds remain possible and external reports show system intrusions and data misuse continue to drive incidents (Verizon DBIR, 2025). Concretely, duaa uk gdpr changes mean teams must link DUAA gateways into vendor risk assessments and update incident response plans where public data is involved.
How much will complying with the Data Use and Access Act cost in the UK?
Direct answer: small UK organisations should budget roughly £2,000, £25,000 one off and £1,000, £20,000 per year; mid-market firms should expect £30,000, £250,000 one off and £10,000, £120,000 per year; large enterprises will pay substantially more.
Costs cover legal review, Data Protection Impact Assessments (DPIAs), technical changes to access controls, auditing and ongoing governance, and therefore vary with existing compliance maturity. The focus keyword duaa uk gdpr changes matters because these figures reflect adding the Data Use and Access Act flows into UK GDPR records and DPIAs rather than replacing GDPR obligations.
Cost drivers
The main drivers are legal and programme work, technical remediation, audit and vendor controls. Legal review and policy updates typically cost £1,000, £15,000 for a small organisation; DPIAs and privacy engineering range from £2,000 to £60,000 depending on complexity. Technical work, such as access controls, logging and secure transfer, often dominates for mid-market and enterprise organisations.
Government guidance on secure sharing and the preparatory work for the Act implies public bodies will offer reusable verification channels, which reduces recurring integration costs for recipients, but does not remove initial compliance spend (enablingdigitalidentity.blog.gov.uk, 2026).
What this means for budgeting
Organisations should treat the Data Use and Access Act as an additional GDPR-aligned route and budget for three workstreams: legal and DPIA; technical integration and hardening; audit and ongoing controls. The government’s rollout of information gateways and digital verification services aims to lower integration costs over time, but initial programme costs remain material (enablingdigitalidentity.blog.gov.uk, 2026).
| Organisation size | Typical one-off cost (2026) | Typical annual cost (2026) | What is included |
|---|---|---|---|
| Small (1, 50 staff) | £2,000, £25,000 | £1,000, £20,000 | Legal review, single DPIA, basic access controls, records update |
| Mid-market (51, 1,000 staff) | £30,000, £250,000 | £10,000, £120,000 | Multiple DPIAs, integration work, logging, vendor contractual updates, audits |
| Enterprise (1,000+ staff) | £200,000+ | £50,000+ | Programme governance, bespoke engineering, enterprise auditing, supplier assurance |
Include the phrase duaa uk gdpr changes in project charters and budget requests so stakeholders see this as a distinct compliance stream. Prioritise DPIAs for high‑risk flows and ask suppliers for priced estimates for secure connections and logging up front to avoid surprise costs.
How does the Data Use and Access Act compare with UK GDPR and the DPA 2018?
The Data Use and Access Act (DUAA) aligns with UK GDPR and the Data Protection Act 2018 on core protections, but it creates new statutory routes for lawful sharing of public‑sector data that sit alongside existing data protection law.
The DUAA places an extra legal basis for certain public authorities to share personal data, so organisations handling that data must map DUAA flows into their existing UK GDPR records of processing and Data Protection Act 2018 compliance work.
Key differences, plainly stated
The DUAA adds statutory powers for information gateways and verification services, while UK GDPR and the Data Protection Act 2018 remain the primary regime for consent, transparency and data subject rights. Organisations should treat DUAA as an additional legal route, not a replacement for UK GDPR.
For example, the Information Commissioner’s Office (ICO) DUAA summary explains where DUAA requires updates to DPIAs and contracts, and ENISA materials highlight operational impacts for data handling and incident reporting.
Practical overlap and where to act first
Start by mapping DUAA flows against UK GDPR lawful bases and the Data Protection Act 2018 exemptions. Where DUAA permits sharing that UK GDPR also covers, keep transparency and subject‑access processes intact. Where DUAA creates a distinct gateway, document the legal rationale and strengthen vendor controls and audit trails.
| Dimension | Data Use and Access Act | UK GDPR / Data Protection Act 2018 |
|---|---|---|
| Scope | Public‑sector and specified data sharing gateways | All personal data processing in the UK |
| Lawful basis | Statutory gateway for defined purposes | Consent, contract, legal obligation, legitimate interest, etc |
| Enforcement | Government oversight plus ICO remit where privacy impacted | ICO enforcement and fines under the Data Protection Act 2018 |
In our experience, addressing duaa uk gdpr changes means updating DPIAs, records and supplier contracts within existing UK GDPR programmes. Treat DUAA mapping as part of your 2026 compliance backlog, and use evidence trails to show why a data share relied on the DUAA route rather than a UK GDPR lawful basis.
⏱ When should you start implementing changes for the Data Use and Access Act? ⏱
Start implementing changes based on your risk profile, sector and size: organisations with high volumes of public‑sector data sharing or novel lawful bases should begin immediately (within 30 days); most mid‑market and larger organisations should plan a 90 to 180 day programme.
Prioritise short, medium and long tracks: immediate legal mapping and DPIAs, 90 day technical integration, 180 day audit and supplier assurance for DUAA compliance.
Immediate 30-day actions
Answer the basic question: where do you already receive or send public‑sector data under the Data (Use and Access) Act 2025. Map those flows into your UK GDPR records of processing and update Data Protection Impact Assessments (DPIAs). The Information Commissioner's Office (ICO) guidance and the UK Government collection on the Data (Use and Access) Act explain the statutory gateways and should be used to validate legal bases, see the National Cyber Security Centre (NCSC) advice on incident handling and the ENISA publications for practical data sharing security controls. In our experience, starting with a legal and DPIA review prevents costly rework later and aligns DUAA with ongoing UK GDPR obligations. The phrase "duaa uk gdpr changes" should appear in project briefs to keep scope clear.
90 to 180 day programme
Over 90 to 180 days, implement technical controls, supplier contracts and audit trails for information gateways and verification services. Prioritise logging, access controls and vendor SLAs, and run at least one end-to-end test of a DUAA flow. Larger programmes should include a supplier assurance sprint and pen test to demonstrate controls. We recommend tracking progress against a DUAA‑specific roadmap and referencing "duaa uk gdpr changes" in milestone reports to keep board-level visibility. After 180 days, organisations should be operating with updated contracts, trained staff and documented audit evidence ready for regulatory queries.
How to choose a provider or partner to help with DUAA changes?
Choose a provider that demonstrably understands UK data protection law, public‑sector information gateways and operationalising the Data Use and Access Act alongside UK GDPR. The right partner must show legal, technical and supplier‑assurance experience, plus clear delivery SLAs.
When assessing suppliers, ask for three concrete things: documented experience delivering DUAA flows, sample Data Protection Impact Assessments (DPIAs) that reference the Data Use and Access Act and UK GDPR, and a security architecture for information gateways. Ask for references from organisations that run public‑sector integrations or verification services.
Must‑have procurement criteria
Start with legal competence: request a named lawyer or privacy lead who can explain how the Data Use and Access Act interacts with UK GDPR and the Data Protection Act 2018. Check operational capability: prove you can map DUAA flows into records of processing, DPIAs and contractual clauses. Demand technical detail: logging, immutable audit trails, access controls and how the provider secures information gateways used for verification services.
Insist on evidence. Ask for a case summary of a DUAA or verification integration, redacted architecture diagrams and a runbook for incident response. Verify technical claims with a short penetration test or third‑party assurance report before signing major contracts.
When to build versus buy, and what SLAs matter
Choose build if you have an in‑house privacy lawyer, an experienced integration team and the ability to operate 24/7 incident response. Choose buy if you lack legal capacity, need rapid delivery within 90, 180 days, or need supplier assurance covering multiple vendors. For managed support insist on SLAs that cover availability of gateway components, forensic log retention periods and timed escalation to named security leads.
CyPro's advice is to score prospective partners against five metrics: legal expertise, technical controls, supplier assurance, delivery tempo and pricing transparency. Use the scorecard to justify your decision to the board and to track compliance with the duaa uk gdpr changes.
Finally, require a workplan that embeds the DUAA legal rationale into DPIAs and contracts, and insist the provider labels milestones with duaa uk gdpr changes so audit trails remain clear during regulator review and internal audits.
Frequently asked questions
Does the Data Use and Access Act replace UK GDPR?
Key fact: The Data Use and Access Act (DUAA) does not replace the UK General Data Protection Regulation (UK GDPR), it amends and sits alongside the Data Protection Act 2018 and UK GDPR. DUAA changes specific lawful sharing and access rules, but UK GDPR rights such as subject access, rectification and data minimisation remain in force. Organisations must keep UK GDPR controls while implementing DUAA changes.
Do I need to update my DPIA because of DUAA?
Key fact: You should update your Data Protection Impact Assessment (DPIA) if your processing or data sharing changes in scope or risk under the Data Use and Access Act (DUAA). Revisit purpose, lawful basis, data flows, security safeguards and risks to data subjects. Schedule DPIA reviews for affected projects within the first 90 days and document any new mitigations.
Will the ICO issue new guidance on DUAA compliance?
Key fact: Expect the Information Commissioner's Office (ICO) to publish guidance on the Data Use and Access Act (DUAA), but check the Department for Science, Innovation and Technology (DSIT) and ICO for commencement detail. ICO guidance typically offers practical examples, templates and enforcement expectations. Align immediate changes to existing ICO materials and update policies when formal DUAA guidance appears.
Can I rely on existing processor contracts for DUAA changes?
Key fact: Existing processor contracts will not automatically cover duties introduced by the Data Use and Access Act (DUAA); contracts are likely to need review. Check clauses on lawful basis, security obligations, audit rights, data sharing and liability. Prioritise updates for high-volume processors and document any changes to roles and responsibilities between controller and processor.
How long does implementation typically take for a mid-market UK firm?
Key fact: Typical implementation for a mid-market UK firm ranges from three to nine months depending on scope and remediation needs for the Data Use and Access Act (DUAA). Plan discovery, DPIA updates, contract changes, technical fixes and staff training. Run a focused 90-day plan to reduce immediate legal risk while scheduling longer technical work across quarters.