Hand touching and signing a tablet.

DATA PROTECTION

Has data protection compliance become a little easier?

GDPR has significantly impacted businesses across the UK and EU. Recognising scope for improvement, the UK government enacted the Data (Use and Access) Act 2025 (DUAA) last summer to reduce administrative burdens and encourage economic growth. The EU is now looking at similar reforms.

The DUAA is being phased in over a year, with the most recent changes coming into force last month. This article walks you through three changes that may simplify your day-to-day compliance, and provides a heads-up on the new complaints’ regime arriving this summer.

Easier justification for certain data uses

Some good news: certain types of data processing now require less paperwork. 

Previously, if you wanted to use customer or employee data for specific purposes, you needed to document a detailed ‘balancing test’ weighing the impact on individuals against the benefits of processing. That requirement has been removed for particular activities, including where processing is for:

  • Preventing or detecting crime (e.g. fraud prevention)
  • Safeguarding vulnerable individuals
  • National or public security
  • Responding to emergencies

Admittedly, this is a limited set of exclusions, but they may benefit those in the financial services sector, security and tech companies, and healthcare and social care providers, amongst others.

Remember, individuals can still request that you stop processing their data, so ensure you have a process in place to handle such requests promptly.

If you wish to rely on these exclusions, you must review and update your privacy notice to reflect the new rules.

Simpler cookie compliance?

We have all grown used to the cookie banner which appears when you first land on a website. Under the DUAA, you may no longer need consent for certain cookies, which could streamline your cookie banner and improve user experience.

The following cookie types are now exempt from consent requirements:

  • Analytics/statistical cookies – those collecting anonymous usage data
  • Preference cookies – those remembering display settings (e.g. dark mode)
  • Emergency location cookies – those finding a user’s location for emergency services

Whilst you do not need consent to set these cookies, you must still offer users an easy, free way to opt out of analytics and preference cookies. This can be achieved using clear toggle options on your cookie banner.

With good news, less good news follows. The DUAA clarifies that cookie rules extend beyond traditional cookies to include any technology that stores or accesses information on a user’s equipment, including tracking pixels, link decoration, navigational tracking, web storage, fingerprinting techniques, scripts and tags. If you use such technologies, you may need to update your cookie policy.

Take heed: cookie compliance matters more than ever, as maximum fines have increased dramatically from £500,000 to £17.5 million or 4% of global turnover. A thorough cookie audit is now essential for every business with a website.

Automated decisions: more flexibility for your business

If your business uses technology to make decisions without human involvement – such as automated credit checks, algorithmic hiring tools, or AI-driven customer profiling – the rules have been relaxed. This should be welcome news for businesses investing in automation and artificial intelligence.

Previously, automated decision-making that significantly affected individuals required either explicit consent or a contractual basis. Now you have more flexibility, unless you are processing sensitive data such as health information or details about ethnic origin.

The key requirement remains: you must still give individuals the right to challenge automated decisions and request human review. This safeguard protects people from decisions made entirely by machines.

If you have been collecting explicit consent for automated decision-making, consider whether this is still necessary. You may be able to streamline your approach, but you must ensure you have a clear process for handling challenges and requests for human review.

New complaints procedure coming in June 2026

Here is one to prepare for. From 19 June 2026, individuals will have a formal legal right to complain directly to your business about how you handle their personal data. This applies to all organisations.

Your business must acknowledge complaints within 30 days and respond fully ‘as soon as possible’. Failure to comply may result in financial penalties.

We recommend you start preparing now by auditing your current complaints process, adopting a data complaints policy, and ensuring you have systems in place to track deadlines and document responses.

Need help? If you would like support reviewing your data protection compliance or preparing for these changes, contact our Commercial team by email or call 01293 558562.

About the authors


about the author img

Jay Barnett

Partner

Advises on all areas of commercial law including business contracts, data protection compliance, IT and intellectual property.
about the author img

John Yates

Partner

Legal expert who helps clients protect their IP and navigate the complex legal landscape relating to technology, business, and Data Protection.

Stay connected, sign up for updates

Stay connected

Recent articles

Insights

The EU’s new AI transparency rules: what you need to know

If in doubt, stick to the core principle: make it clear when AI is being used in a way that could mislead people.

29/06/2026

Insights

Data protection update: are you ready for data complaints?

From 19 June 2026, all organisations must have a clear and accessible process for handling data protection complaints.

18/06/2026

Insights

DMH Stallard advises SAVANA on first international acquisition of Gutter Games portfolio

Leading South East law firm DMH Stallard has advised French board game publisher SAVANA SAS on the acquisition of the Gutter Games brand portfolio from Razor Group...

27/05/2026

Insights

The Data (Use and Access) Act 2025 and Subject Access Requests

The Data Act 2025 brings a significant update, introducing reforms to the UK GDPR and the Data Protection Act 2018.

07/10/2025

DISCLAIMER:

THIS INFORMATION IS FOR ILLUSTRATIVE PURPOSES AND IS NOT INTENDED TO AMOUNT TO LEGAL ADVICE ON WHICH RELIANCE SHOULD BE PLACED. WE, DMH STALLARD LLP, DISCLAIM ALL LIABILITY AND RESPONSIBILITY ARISING FROM ANY RELIANCE PLACED ON THIS INFORMATION. ANY RELIANCE ON THIS INFORMATION IS SOLELY AT YOUR RISK. The provision of this information does not create a business or professional services relationship. This information is not exhaustive and does not attempt to address every issue relevant to a particular situation. If you require advice on a specific legal issue, please contact a lawyer listed on our website, dmhstallard.com, or send an email to [email protected].