Open 9am–9pm, 7 days a week 0115 990 4332 support@hucknallit.co.uk
← All Articles Compliance Business

The Data (Use and Access) Act: what actually changed for small businesses

The biggest shake-up to UK data protection since GDPR took effect in phases from February 2026. Most of it is good news for small businesses — but one part needs action.

6 min read By the Hucknall IT team

01

What this is

The Data (Use and Access) Act — DUAA — became law on 19 June 2025 and is being implemented in phases, with many provisions taking effect on 5 February 2026. It amends UK GDPR rather than replacing it, so nothing you have already done is wasted.

For most organisations the relevant part is Part 5, which contains the data protection and privacy amendments. The framing from the ICO has been that UK organisations stand to benefit, and that is broadly fair: much of this reduces friction rather than adding it.

02

The one thing that needs doing

You need a process for people to complain to you about how you have handled their personal data. Not a policy document — a route: a named way in, someone who owns it, and a record that it was dealt with.

For a small business this is genuinely small. An email address that reaches a real person, a note of who is responsible, and a simple log of complaints and what happened. What you cannot have is nothing, or a form that goes to an inbox nobody reads.

The point is that people should be able to raise a concern with you before they escalate to the regulator, which is better for you than the alternative.

03

The parts that make life easier

A new lawful basis called "recognised legitimate interests" joins the existing six under Article 6. Where it applies, it removes the requirement to run the balancing test that legitimate interests normally demands — useful for things like safeguarding and preventing crime.

There is also updated ICO guidance on international transfers, published in January 2026. If you use US-hosted software — and virtually every small business does — it is worth a look at your transfer mechanisms, though for most firms using mainstream providers this is a review rather than a rebuild.

04

What has not changed

This is the important bit, because "data protection law has changed" gets heard as "the rules are relaxed now". They are not.

You still need a lawful basis for processing. You still need to answer subject access requests, and the deadline has not become generous. You still need to report qualifying breaches to the ICO within 72 hours. Cookies still need consent for anything non-essential. Security obligations are untouched.

DUAA sands the edges off some genuinely awkward parts of UK GDPR. It does not turn it into a set of suggestions, and anybody selling you a compliance package on the basis that everything has changed is overselling it.

05

A sensible afternoon's work

Put the complaints route in place and write down who owns it. Re-read your privacy notice and check it still describes what you actually do — most do not, because the business changed and the notice did not. Confirm you know where personal data lives, including the spreadsheet on somebody's desktop. Check your breach process names a person, not a department.

That is most of it. The ICO has published resources aimed specifically at helping smaller organisations, and they are worth reading before paying anyone for a compliance audit.

Sources

Where the facts in this article came from. If any of it goes out of date, tell us and we will correct it.

Found this useful? Pass it on. LinkedIn Facebook X Email
Keep Reading

Related articles

Cyber Essentials: what the Danzell update means

New assessment accounts moved to the v3.3 Danzell question set on 27 April 2026, following the Willow changes. If you certify annually, the goalposts have moved.

AI voice scams, and the code word that beats them

A few seconds of audio is now enough to clone a voice convincingly. The defence is not clever technology — it is one agreed word and a habit of hanging up.

Is a Copilot+ PC actually worth it in 2026?

Copilot+ machines need a 40+ TOPS neural processor, 16GB RAM and 256GB storage. The AI features are real, but the reason to buy one is probably the battery.

Want a straight answer about your setup?

Tell us what you are running and we will tell you honestly whether this affects you, what it would cost to put right, and how quickly we can do it. No hard sell.

Open 9am–9pm, 7 days a week
Call Now