As the UK continues its drive towards a modernised, innovation‑friendly data protection framework, 2025 saw significant regulatory developments that organisations should factor into their compliance planning during 2026. From reforms introduced by the Data (Use and Access) Act 2025 (DUAA) to an assertive enforcement approach from the Information Commissioner’s Office (ICO), this round‑up summarises key developments and their practical implications for businesses.
1. Data Use and Access Act 2025 (DUAA): A Reshaping of UK Data Governance
Recognised Legitimate Interests (changes implemented 5th February 2026)
A key development under DUAA is the introduction of a “recognised legitimate interests” lawful basis for processing personal data. This sits alongside, but does not amend or supplement, the conventional legitimate interests lawful basis.
It allows organisations, where necessary, to process personal data for specified purposes, such as security, defence, safeguarding, emergency response, and the detection, investigation and prevention of crime (including cybercrime).
This lawful basis also makes it easier to share personal data with third parties that have requested it for purposes in the public interest, or for a task carried out in the exercise of official authority, where set out in law.
Where this lawful basis applies, a legitimate interests assessment is not required. However, it is still necessary to tell individuals (e.g. in a privacy notice) when you are relying on this lawful basis and to explain which interests are relevant.
Automated Decision Making (changes implemented 5th February 2026)
DUAA also relaxes restrictions on solely automated decision‑making (ADM), including profiling.
Previous restrictions limited the range of circumstances in which this processing could be carried out lawfully, where it was used to make significant decisions about individuals. Now, these restrictions have been relaxed. As such, ADM can be undertaken on the “legitimate interests” lawful basis where the relevant criteria are fulfilled, provided that:
- No special categories of personal data are involved.
- Organisations provide information about how and when ADM is used, allow decisions to be contested, and enable individuals to obtain human intervention.
If ADM does involve special category personal data, additional restrictions continue to apply and businesses must consider these in advance of processing.
Following these changes:
- the ICO has published (in March 2026) a “Recruitment rewired” update on what it expects from organisations that wish to undertake ADM in a recruitment context;
- a statutory code of practice on the development and use of AI and ADM is to be produced; and
- the ICO is consulting on its draft guidance about automated decision-making, including profiling and DUAA-related updates.
For organisations utilising AI technologies to automate processes, these reforms mark a meaningful step towards greater operational flexibility while maintaining protections for data subjects.
Children’s Data (changes implemented 5th February 2026)
DUAA explicitly requires providers of certain online services (information society services) likely to be accessed by children (under 18) to take their needs into account when deciding how to use their personal data. Specifically, it is now a requirement for these providers to consider:
- How children can be protected and supported when using the services.
- The fact that children merit specific protection because they are less aware of the risks and consequences of processing and their rights.
- The fact that they have different needs at different ages and stages of development.
Organisations within scope of this provision are also expected to comply with the ICO’s Age Appropriate Design Code (also referred to as the Children’s Code). Failure to do so may make it difficult to demonstrate compliance with the UK GDPR and may invite regulatory action. However, entities that are already compliant with the Children’s Code are likely also to be meeting the new children’s data requirements under DUAA, without the need for further action.
For those assessing whether these provisions may be in scope, the ICO has made it clear that the rules are not triggered based on whether the relevant online services are specifically directed at children, but rather on whether children are likely to be using them. As such, obligations cannot be avoided by stating that services are only for users aged 18+, if the reality is that those under 18 are also likely to be using them.
New Cookies Exemptions (changes implemented 5th February 2026)
DUAA expands the circumstances in which consent for cookies (and similar storage and access technologies) is not required, by creating three new exemptions, as follows:
- Statistics exemption: where cookies are for the sole purpose of enabling a service provider to collect information for statistical purposes about how their online service is used. This allows some analytics cookies to be set without consent. However, the exemption is narrow and does not extend to engaging third-party analytics providers that link the data they receive with other information they hold, or where they use the data they receive for their own purposes.
- Appearance exemption: where cookies are for the sole purpose of enabling a service to adapt its appearance or functions in accordance with someone’s preferences.
- Emergencies exemption: where cookies are for the sole purpose of working out the subscriber or user’s geographical location when they request emergency assistance.
In addition, DUAA has increased maximum fines for ePrivacy violations (e.g. relating to direct marketing and cookies requirements) from a maximum of £500,000 to UK GDPR levels – up to £17.5 million or 4% of global annual turnover.
Data Protection Complaints (changes implemented 19th June 2026)
DUAA requires organisations to take steps to help people who want to complain that the organisation has breached the UK GDPR, such as by providing a way to make data protection complaints directly to the controller and having a process for handling those complaints. Organisations are required to acknowledge complaints within 30 days and make enquiries and provide an outcome “without undue delay”. See our Law-Now article on this requirement for more information.
ICO Restructuring (transition in progress, changes expected to be completed during 2026)
Under DUAA, the ICO is being restructured from a corporation sole to a body corporate (the Information Commission). The Information Commission will be led by a Board made up of a Chair, a Chief Executive Officer (CEO) and 7 non-executive directors.
Paul Arnold will be the first CEO of the future Information Commission. This role is described as an interim appointment for a maximum two-year period, after which a permanent recruitment process will be undertaken.
New ICO Powers (changes implemented 5th February 2026)
Beyond these reforms, DUAA has also strengthened the ICO’s enforcement toolkit. This includes extending existing powers in respect of assessment notices, allowing the ICO to require an organisation to commission and pay for independent investigative reports.
There is also a new power to issue interview notices, which enables the ICO to require a person to attend an interview to answer questions. If a person decides not to answer questions in the interview and if the ICO ultimately determines that enforcement action is appropriate, failure to respond may be considered an aggravating factor, and could result in a higher fine than would otherwise be applied. A new criminal sanction has also been introduced if an individual knowingly or recklessly makes a false statement under questioning in an interview.
2. ICO Enforcement Trends and Guidance
The ICO is empowered to issue fines of up to £17.5 million or 4% of global turnover in the preceding financial year for breaches of the UK GDPR and Data Protection Act 2018, alongside other enforcement measures such as reprimands or enforcement notices.
Where organisations fail to comply with data protection law, the ICO has demonstrated its willingness to impose meaningful financial sanctions to reinforce the importance of robust data protection and security controls.
The ICO’s recent enforcement activity has focused in particular on security, children’s privacy and online tracking.
Two of the largest fines imposed by the ICO in the last year were on companies following major cyber incidents that resulted in widespread personal data breaches (Capita, £14 million, and Advanced Computer Software, £3.07 million). Both entities acted as processors (in part, in Capita’s case), underlining that security requirements apply to all companies that process personal data, not only controllers.
In respect of children’s privacy, the ICO has recently reviewed 34 social media and video‑sharing platforms, focusing on issues such as the use of default privacy and geolocation settings, profiling for targeted advertising, and age assurance. This work has translated directly into enforcement action. Specifically, the ICO fined two platforms (Reddit and Imgur/MediaLab) in February 2026 for shortcomings in their handling of children’s personal information and age assurance measures, and for failing to carry out data protection impact assessments. The fines totalled £14.47 million (Reddit) and £247,590 (Imgur/MediaLab).
The ICO is also continuing a large‑scale review of cookie compliance across the UK’s most‑visited websites, with particular focus on ensuring that users are offered meaningful choice and that tracking technologies are not deployed without a valid lawful basis. In connection with this, it has contacted 93 organisations about website cookies, and it has taken enforcement action in this space against a betting provider (Sky Betting and Gaming). The provider was reprimanded for sharing personal data with ad tech companies before users could accept or reject advertising cookies.
Alongside this enforcement activity, updates published by the ICO have included: new guidance on storage and access technologies (April 2026); updated guidance on lawful basis (April 2026); guidance on how to deal with data protection complaints (February 2026); new guidance on international data transfers (January 2026); updated guidance on data subject access requests (December 2025); revised guidance on encryption (September 2025); new guidance on securely disclosing documents to the public (July 2025); and updated guidance on anonymisation (March 2025).
The ICO has signalled further guidance over the coming year, including:
- Updated guidance on special category data.
- New recruitment and selection guidance.
- Updated ADM guidance and a code of practice.
- Updated direct marketing advice.
- Various new pieces of guidance on data subject rights.
- New guidance on research, archiving and statistics.
3. What to Expect
For commercial organisations, the second half of 2026 will mark a period of transition as DUAA reforms move from legislative theory into daily operational reality, evidencing a shift towards greater accountability and maturity in data governance. With most DUAA provisions now in force, and increasingly backed up by regulatory guidance, organisations should expect heightened scrutiny. Prompt review and updating of policies, systems and compliance frameworks will be essential to manage regulatory risk and maintain ongoing compliance.