The DUAA is being phased in over a year, with the most recent changes coming into force last month. This article walks you through three changes that may simplify your day-to-day compliance, and provides a heads-up on the new complaints’ regime arriving this summer.
Easier justification for certain data uses
Some good news: certain types of data processing now require less paperwork.
Previously, if you wanted to use customer or employee data for specific purposes, you needed to document a detailed ‘balancing test’ weighing the impact on individuals against the benefits of processing. That requirement has been removed for particular activities, including where processing is for:
- Preventing or detecting crime (e.g. fraud prevention)
- Safeguarding vulnerable individuals
- National or public security
- Responding to emergencies
Admittedly, this is a limited set of exclusions, but they may benefit those in the financial services sector, security and tech companies, and healthcare and social care providers, amongst others.
Remember, individuals can still request that you stop processing their data, so ensure you have a process in place to handle such requests promptly.
If you wish to rely on these exclusions, you must review and update your privacy notice to reflect the new rules.
Simpler cookie compliance?
We have all grown used to the cookie banner which appears when you first land on a website. Under the DUAA, you may no longer need consent for certain cookies, which could streamline your cookie banner and improve user experience.
The following cookie types are now exempt from consent requirements:
- Analytics/statistical cookies – those collecting anonymous usage data
- Preference cookies – those remembering display settings (e.g. dark mode)
- Emergency location cookies – those finding a user’s location for emergency services
Whilst you do not need consent to set these cookies, you must still offer users an easy, free way to opt out of analytics and preference cookies. This can be achieved using clear toggle options on your cookie banner.
With good news, less good news follows. The DUAA clarifies that cookie rules extend beyond traditional cookies to include any technology that stores or accesses information on a user’s equipment, including tracking pixels, link decoration, navigational tracking, web storage, fingerprinting techniques, scripts and tags. If you use such technologies, you may need to update your cookie policy.
Take heed: cookie compliance matters more than ever, as maximum fines have increased dramatically from £500,000 to £17.5 million or 4% of global turnover. A thorough cookie audit is now essential for every business with a website.
Automated decisions: more flexibility for your business
If your business uses technology to make decisions without human involvement – such as automated credit checks, algorithmic hiring tools, or AI-driven customer profiling – the rules have been relaxed. This should be welcome news for businesses investing in automation and artificial intelligence.
Previously, automated decision-making that significantly affected individuals required either explicit consent or a contractual basis. Now you have more flexibility, unless you are processing sensitive data such as health information or details about ethnic origin.
The key requirement remains: you must still give individuals the right to challenge automated decisions and request human review. This safeguard protects people from decisions made entirely by machines.
If you have been collecting explicit consent for automated decision-making, consider whether this is still necessary. You may be able to streamline your approach, but you must ensure you have a clear process for handling challenges and requests for human review.
New complaints procedure coming in June 2026
Here is one to prepare for. From 19 June 2026, individuals will have a formal legal right to complain directly to your business about how you handle their personal data. This applies to all organisations.
Your business must acknowledge complaints within 30 days and respond fully ‘as soon as possible’. Failure to comply may result in financial penalties.
We recommend you start preparing now by auditing your current complaints process, adopting a data complaints policy, and ensuring you have systems in place to track deadlines and document responses.
Need help? If you would like support reviewing your data protection compliance or preparing for these changes, contact our Commercial team by email or call 01293 558562.