August 27, 2026

UK Data Protection in 2026: What the Data (Use and Access) Act Changes for Small Businesses

This article is general information, not legal advice. Data protection obligations depend on your specific business and how you handle personal data — for anything consequential, consult a solicitor or the Information Commissioner’s Office (ICO) directly.


If you’ve seen headlines about “GDPR changing” this year, here’s the plain-English version: it hasn’t been replaced or overhauled. The Data (Use and Access) Act 2025 (commonly shortened to the DUAA) received Royal Assent in June 2025 and amends the existing UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) — it doesn’t tear any of them up and start again.

The Change That Actually Applies to Every Business

The most immediately relevant requirement: as of 19 June 2026, every organisation that processes personal data must have a clear, accessible process for individuals to raise data protection complaints directly with the business — before escalating to the ICO. There’s no exemption based on business size. In practice, this means:

  • A visible, accessible way for someone to raise a complaint (a dedicated email address or an online form is generally sufficient)
  • Acknowledging complaints within 30 days
  • Investigating appropriately and responding without undue delay

For most small businesses, this is a policy-and-process addition rather than a large undertaking — a short section in your privacy policy explaining how to raise a concern, and an internal process (even an informal one) for handling it when it happens, covers the core requirement.

Other Changes Worth Knowing About

  • Increased PECR penalties. The maximum fine under PECR — which governs cookies, and electronic marketing by email, text, and call — rose substantially, up to £17.5 million or 4% of global turnover, aligning it much more closely with UK GDPR’s own penalty regime. This matters directly for any business running email or SMS marketing campaigns.
  • A new list of “recognised legitimate interests.” The Act introduces specific, pre-approved legitimate interest grounds for processing data in certain circumstances, intended to reduce ambiguity for organisations relying on that legal basis.
  • Changes to subject access request handling, including a “stop the clock” mechanism that pauses the response deadline while a business reasonably seeks clarification from the requester about what they’re asking for.
  • Expanded ICO powers, including greater investigatory and audit capability — a signal that enforcement is likely to become more active, not less, going forward.

What Hasn’t Changed

It’s worth being equally clear about what this Act does not do, given the amount of “act now or face huge fines” marketing that’s circulated around it. The fundamental principles of UK GDPR are unchanged: you still need a lawful basis for processing personal data, you still need to be transparent about how it’s used, individuals still have the same core rights (access, correction, deletion, and so on), and the definition of personal data itself hasn’t moved. This is a targeted amendment, not a rewrite — and the myth that small businesses are exempt from data protection law generally remains just that: a myth. UK GDPR applies to any organisation handling personal data of people in the UK, regardless of headcount.

A Reasonable Starting Point

For most small and medium businesses, a sensible response to these changes is: add a brief, clear complaints-handling clause to your privacy policy; make sure there’s an actual accessible route for someone to raise a concern (and that someone internally is responsible for responding to it); and, if you run email or SMS marketing, revisit your consent practices given the higher PECR penalties now in play. Beyond that, if your existing data protection practices were already reasonably solid, this is a review-and-update exercise, not a rebuild.




If part of that review involves updating your website’s privacy policy, cookie consent, or contact/complaints process, Verivanta AI can help implement those changes — though for the legal substance of what your policies need to say, we’d always recommend pairing that with proper legal advice.

From the Same Category