Data protection update: Data Use and Access Act 2025

7 min read
Walter Lourens

On 5 February 2026, key provisions under the Data Use and Access Act 2025 (DUAA) came into force.

The DUAA received Royal Assent on 19 June 2025 and is being implemented in stages. This latest phase introduces practical changes that affect daily data protection compliance, particularly for organisations managing worker, candidate, client, and payroll data.

For Sabre clients, the following key areas require review:

GDPR data protection graphic with connected padlock icons representing secure data handling, compliance, and privacy updates under the Data Use and Access Act 2025.

Lawfulness and purpose limitation

A new lawful basis, known as ?recognised legitimate interests?, allows processing in specific scenarios without the need for a balancing test. The Act also provides clearer rules on the reuse of personal data for compatible purposes.

Automated decision-making

Organisations can now rely on a broader range of lawful bases for significant automated decisions, provided appropriate safeguards are in place. This may affect areas such as automated checks, eligibility processes, and worker management workflows. Where special category data is involved, stricter conditions still apply.

International data transfers

The legal threshold for international data transfers has moved to a ?not materially lower? standard of protection. This assessment must be reasonable and proportionate. The Act also introduces updated categories for transfers approved by regulations or subject to appropriate safeguards.

Data subject rights

New rules apply to requests received from 5 February 2026 onwards. These include added flexibility around response time limits and clearer definitions for handling requests considered ?manifestly unfounded or excessive?.

Direct marketing and PECR enforcement

A lighter-touch consent approach now applies to certain analytical and site-improvement cookies. However, the Information Commissioner?s enforcement powers have expanded.

Maximum fines under the Privacy and Electronic Communications Regulations (PECR) have risen to ?17.5 million or 4% of global turnover, whichever is higher, bringing them in line with UK GDPR.

The right to complain

From 19 June 2026, organisations will be required to meet new standards regarding the right to complain. This includes providing clear complaint mechanisms, acknowledging complaints within 30 days, responding without undue delay, and maintaining a review structure for individuals who are dissatisfied with a response.

Recommended action for Sabre clients

Sabre recommends that data protection leads conduct an impact assessment across their processing activities.

Priority should be given to:

  • Reviewing the lawful basis for existing data processing
  • Assessing automated decision-making processes and safeguards
  • Updating procedures for handling data subject requests
  • Auditing cookie and direct marketing practices
  • Evaluating international data transfer mechanisms
  • Preparing internal complaints procedures ahead of the June deadline

Further details are available on the Information Commissioner?s Office website:
https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/

How Sabre supports compliant recruitment operations

Recruitment businesses manage large volumes of worker, candidate, client, payroll, attendance, and compliance data. Having structured systems, clear records, and controlled access can make it easier to review, manage, and evidence day-to-day compliance activity.

Sabre supports this by helping agencies keep key recruitment workflows connected, including worker registration, bookings, compliance records, timesheets, payroll data, client approvals, and reporting.

Reviewing your recruitment data processes?

If you are assessing how your agency manages worker, candidate, client, payroll, or compliance data, speak to Sabre about software built around practical recruitment operations.


Speak to Sabre

Frequently asked questions about the Data Use and Access Act 2025

What is the Data Use and Access Act 2025?

The Data Use and Access Act 2025 is UK legislation that updates parts of the UK?s data protection and digital information framework. It introduces changes across areas including lawful basis, automated decision-making, data subject rights, international data transfers, cookies, PECR enforcement, and complaints handling.

A number of key DUAA provisions came into force on 5 February 2026. Further requirements, including new standards around the right to complain, are due to apply from 19 June 2026.

No. The DUAA does not replace UK GDPR. It amends and updates specific areas of the UK data protection framework, so organisations still need to comply with UK GDPR and related data protection requirements.

Recruitment businesses process large volumes of worker, candidate, client, payroll, attendance, and compliance data. Changes to lawful basis, automated decision-making, data subject rights, international transfers, and PECR enforcement may affect how that data is collected, reused, stored, transferred, and managed.

Recruitment businesses should review their lawful bases for processing, automated decision-making processes, data subject request procedures, cookie and marketing practices, international transfer mechanisms, and internal complaints processes.

Yes, it may. The DUAA updates the rules around significant automated decision-making. Recruitment businesses using automated checks, candidate screening, eligibility processes, or worker allocation workflows should review whether appropriate safeguards are in place.

Yes. Maximum fines under the Privacy and Electronic Communications Regulations have increased to ?17.5 million or 4% of global turnover, whichever is higher. This brings PECR enforcement closer in line with UK GDPR fine levels.

From 19 June 2026, organisations will need to provide clear ways for individuals to make data protection complaints. They will also need to acknowledge complaints within the required timeframe, respond without undue delay, and maintain a process for reviewing dissatisfaction with responses.

Yes, it may affect Sabre clients where recruitment software is used to collect, process, store, transfer, or manage worker, candidate, client, payroll, attendance, or compliance data. Each organisation should review its own processes and responsibilities.

Further details are available from the Information Commissioner?s Office:

https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025

The Data Use and Access Act 2025 is UK legislation that updates parts of the UK?s data protection and digital information framework. It introduces changes across areas including lawful basis, automated decision-making, data subject rights, international data transfers, cookies, PECR enforcement, and complaints handling.

A number of key DUAA provisions came into force on 5 February 2026. Further requirements, including new standards around the right to complain, are due to apply from 19 June 2026.

No. The DUAA does not replace UK GDPR. It amends and updates specific areas of the UK data protection framework, so organisations still need to comply with UK GDPR and related data protection requirements.

Recruitment businesses process large volumes of worker, candidate, client, payroll, attendance, and compliance data. Changes to lawful basis, automated decision-making, data subject rights, international transfers, and PECR enforcement may affect how that data is collected, reused, stored, transferred, and managed.

Recruitment businesses should review their lawful bases for processing, automated decision-making processes, data subject request procedures, cookie and marketing practices, international transfer mechanisms, and internal complaints processes.

Yes, it may. The DUAA updates the rules around significant automated decision-making. Recruitment businesses using automated checks, candidate screening, eligibility processes, or worker allocation workflows should review whether appropriate safeguards are in place.

Yes. Maximum fines under the Privacy and Electronic Communications Regulations have increased to ?17.5 million or 4% of global turnover, whichever is higher. This brings PECR enforcement closer in line with UK GDPR fine levels.

From 19 June 2026, organisations will need to provide clear ways for individuals to make data protection complaints. They will also need to acknowledge complaints within the required timeframe, respond without undue delay, and maintain a process for reviewing dissatisfaction with responses.

Yes, it may affect Sabre clients where recruitment software is used to collect, process, store, transfer, or manage worker, candidate, client, payroll, attendance, or compliance data. Each organisation should review its own processes and responsibilities.

Further details are available from the Information Commissioner?s Office:

https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025

Please share this