On 5 February 2026, key provisions under the Data Use and Access Act 2025 (DUAA) came into force.
The DUAA received Royal Assent on 19 June 2025 and is being implemented in stages. This latest phase introduces practical changes that affect daily data protection compliance, particularly for organisations managing worker, candidate, client, and payroll data.
For Sabre clients, the following key areas require review:

Lawfulness and purpose limitation
A new lawful basis, known as ?recognised legitimate interests?, allows processing in specific scenarios without the need for a balancing test. The Act also provides clearer rules on the reuse of personal data for compatible purposes.
Automated decision-making
Organisations can now rely on a broader range of lawful bases for significant automated decisions, provided appropriate safeguards are in place. This may affect areas such as automated checks, eligibility processes, and worker management workflows. Where special category data is involved, stricter conditions still apply.
International data transfers
The legal threshold for international data transfers has moved to a ?not materially lower? standard of protection. This assessment must be reasonable and proportionate. The Act also introduces updated categories for transfers approved by regulations or subject to appropriate safeguards.
Data subject rights
New rules apply to requests received from 5 February 2026 onwards. These include added flexibility around response time limits and clearer definitions for handling requests considered ?manifestly unfounded or excessive?.
Direct marketing and PECR enforcement
A lighter-touch consent approach now applies to certain analytical and site-improvement cookies. However, the Information Commissioner?s enforcement powers have expanded.
Maximum fines under the Privacy and Electronic Communications Regulations (PECR) have risen to ?17.5 million or 4% of global turnover, whichever is higher, bringing them in line with UK GDPR.
The right to complain
From 19 June 2026, organisations will be required to meet new standards regarding the right to complain. This includes providing clear complaint mechanisms, acknowledging complaints within 30 days, responding without undue delay, and maintaining a review structure for individuals who are dissatisfied with a response.
Recommended action for Sabre clients
Sabre recommends that data protection leads conduct an impact assessment across their processing activities.
Priority should be given to:
- Reviewing the lawful basis for existing data processing
- Assessing automated decision-making processes and safeguards
- Updating procedures for handling data subject requests
- Auditing cookie and direct marketing practices
- Evaluating international data transfer mechanisms
- Preparing internal complaints procedures ahead of the June deadline
Further details are available on the Information Commissioner?s Office website:
https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/
How Sabre supports compliant recruitment operations
Recruitment businesses manage large volumes of worker, candidate, client, payroll, attendance, and compliance data. Having structured systems, clear records, and controlled access can make it easier to review, manage, and evidence day-to-day compliance activity.
Sabre supports this by helping agencies keep key recruitment workflows connected, including worker registration, bookings, compliance records, timesheets, payroll data, client approvals, and reporting.
Reviewing your recruitment data processes?
If you are assessing how your agency manages worker, candidate, client, payroll, or compliance data, speak to Sabre about software built around practical recruitment operations.
Frequently asked questions about the Data Use and Access Act 2025
What is the Data Use and Access Act 2025?
The Data Use and Access Act 2025 is UK legislation that updates parts of the UK?s data protection and digital information framework. It introduces changes across areas including lawful basis, automated decision-making, data subject rights, international data transfers, cookies, PECR enforcement, and complaints handling.
When did the latest DUAA provisions come into force?
A number of key DUAA provisions came into force on 5 February 2026. Further requirements, including new standards around the right to complain, are due to apply from 19 June 2026.
Does the Data Use and Access Act 2025 replace UK GDPR?
No. The DUAA does not replace UK GDPR. It amends and updates specific areas of the UK data protection framework, so organisations still need to comply with UK GDPR and related data protection requirements.
Why does the DUAA matter to recruitment businesses?
Recruitment businesses process large volumes of worker, candidate, client, payroll, attendance, and compliance data. Changes to lawful basis, automated decision-making, data subject rights, international transfers, and PECR enforcement may affect how that data is collected, reused, stored, transferred, and managed.
What should recruitment businesses review first?
Recruitment businesses should review their lawful bases for processing, automated decision-making processes, data subject request procedures, cookie and marketing practices, international transfer mechanisms, and internal complaints processes.
Does the DUAA affect automated decision-making in recruitment?
Yes, it may. The DUAA updates the rules around significant automated decision-making. Recruitment businesses using automated checks, candidate screening, eligibility processes, or worker allocation workflows should review whether appropriate safeguards are in place.
Are PECR fines changing under the DUAA?
Yes. Maximum fines under the Privacy and Electronic Communications Regulations have increased to ?17.5 million or 4% of global turnover, whichever is higher. This brings PECR enforcement closer in line with UK GDPR fine levels.
What is the new right to complain?
From 19 June 2026, organisations will need to provide clear ways for individuals to make data protection complaints. They will also need to acknowledge complaints within the required timeframe, respond without undue delay, and maintain a process for reviewing dissatisfaction with responses.
Does this affect Sabre clients?
Yes, it may affect Sabre clients where recruitment software is used to collect, process, store, transfer, or manage worker, candidate, client, payroll, attendance, or compliance data. Each organisation should review its own processes and responsibilities.
Where can I find official guidance on the DUAA?
Further details are available from the Information Commissioner?s Office:
https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025
The Data Use and Access Act 2025 is UK legislation that updates parts of the UK?s data protection and digital information framework. It introduces changes across areas including lawful basis, automated decision-making, data subject rights, international data transfers, cookies, PECR enforcement, and complaints handling.
A number of key DUAA provisions came into force on 5 February 2026. Further requirements, including new standards around the right to complain, are due to apply from 19 June 2026.
No. The DUAA does not replace UK GDPR. It amends and updates specific areas of the UK data protection framework, so organisations still need to comply with UK GDPR and related data protection requirements.
Recruitment businesses process large volumes of worker, candidate, client, payroll, attendance, and compliance data. Changes to lawful basis, automated decision-making, data subject rights, international transfers, and PECR enforcement may affect how that data is collected, reused, stored, transferred, and managed.
Recruitment businesses should review their lawful bases for processing, automated decision-making processes, data subject request procedures, cookie and marketing practices, international transfer mechanisms, and internal complaints processes.
Yes, it may. The DUAA updates the rules around significant automated decision-making. Recruitment businesses using automated checks, candidate screening, eligibility processes, or worker allocation workflows should review whether appropriate safeguards are in place.
Yes. Maximum fines under the Privacy and Electronic Communications Regulations have increased to ?17.5 million or 4% of global turnover, whichever is higher. This brings PECR enforcement closer in line with UK GDPR fine levels.
From 19 June 2026, organisations will need to provide clear ways for individuals to make data protection complaints. They will also need to acknowledge complaints within the required timeframe, respond without undue delay, and maintain a process for reviewing dissatisfaction with responses.
Yes, it may affect Sabre clients where recruitment software is used to collect, process, store, transfer, or manage worker, candidate, client, payroll, attendance, or compliance data. Each organisation should review its own processes and responsibilities.
Further details are available from the Information Commissioner?s Office:
https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025