The Data (Use and Access) Act 2025 (DUAA) received royal assent in June 2025, but its practical effect on UK businesses is landing in stages through 2026. The main package of reforms took effect on 5 February 2026, with a further duty on handling data subject complaints commencing on 19 June 2026. Unlike a single new statute with one clear compliance date, the DUAA amends UK GDPR in several places at once, and almost every amendment creates a new document, log, or record that a business did not previously need to keep. For organisations that treat data protection as a policy binder rather than a live records system, 2026 is the year that gap becomes visible.
A statutory duty to log complaints, not just receive them
From 19 June 2026, controllers must have a documented process for handling complaints from individuals who believe their data protection rights have been infringed. The Information Commissioner's Office (ICO) has indicated that organisations should acknowledge a complaint within 30 days and respond without undue delay. That timeline only means anything if there is a record showing when each complaint arrived, who reviewed it, what was decided, and when the individual was told. A verbal assurance that "we looked into it" will not satisfy a regulator asking for evidence months later.
In practice this means every business handling UK personal data needs a complaints register, at minimum, that tracks the following fields:
- Date the complaint was received and the channel it came through
- Date of acknowledgement (must fall within the 30-day window)
- Name of the staff member or team who investigated it
- Outcome and the reasoning behind it
- Date the individual was notified of the outcome
This is a smaller obligation than a data breach register, but it is a new, separate one, and the ICO has signalled it will look for this evidence during any investigation opened after 19 June 2026.
Subject access requests: "reasonable and proportionate" has to be provable
The DUAA writes into statute something the ICO had previously only stated in guidance: that a controller responding to a subject access request (SAR) need only carry out a "reasonable and proportionate search," not an exhaustive one. It also formally removes the ability to refuse a SAR simply by labelling it "vexatious or excessive," replacing that with a narrower, more specific set of grounds.
The catch is that "reasonable and proportionate" is a defence, not a shortcut, and a defence has to be documented to work. If a data subject complains to the ICO that their SAR response was incomplete, the controller needs to show which systems and custodians were searched, what search terms or date ranges were used, and why the scope chosen was proportionate to the request. Businesses that respond to SARs by an ad hoc email chain, rather than a repeatable, logged search procedure, will struggle to reconstruct that evidence after the fact. The Act also formalises a "stop the clock" rule: when a controller reasonably needs clarification from the requester to scope the search, the time between that request and the requester's reply is excluded from the one-month (extendable to three-month, for complex requests) response deadline. That pause also has to be timestamped and recorded, or the controller cannot rely on it.
Automated decision-making moves from a ban to a safeguards regime
Perhaps the most structurally significant change is to Article 22. The DUAA replaces the old near-blanket restriction on solely automated decisions with significant effects (think automated credit scoring, automated shortlisting of job applicants, or automated pricing) with a permissive regime built around documented safeguards, under new Articles 22A to 22D. Special category data is still treated more strictly, but for ordinary personal data, a business can now let an algorithm make a significant decision about someone, provided it can show:
- The individual was given information about the decision and how it was reached
- The individual had a route to make representations about the decision
- The individual could obtain meaningful human intervention
- The individual could contest the outcome, with that contest logged and answered
This flips the compliance burden from "do not automate" to "prove you built the off-ramps and that people used them." A business relying on automated decisioning without a record of how individuals were notified and what happened when they pushed back is exposed the moment a regulator or a claimant asks for evidence, even if the underlying decision itself was accurate.
Why the paperwork now carries the largest fines in the regime
The DUAA also raises the maximum penalty for breaches of the Privacy and Electronic Communications Regulations (PECR), covering cookies, direct marketing, and electronic communications, up to the same ceiling as UK GDPR: £17.5 million or 4 percent of global annual turnover, whichever is higher. Previously, PECR breaches capped out at £500,000, a fraction of the exposure under the main data protection regime. That gap is now closed, which means marketing consent records, cookie logs, and opt-in evidence carry the same financial weight as core GDPR documentation. Businesses that treated marketing recordkeeping as a lower priority than SAR or breach files no longer have that luxury, because the fine exposure is now identical.
What this means for retention schedules
None of these changes ask businesses to keep more personal data. They ask businesses to keep more evidence about how decisions were made and how rights were exercised, on a rolling basis, across every complaint, every SAR, and every automated decision. The DUAA does not set a specific retention period for complaint logs or SAR search records, so organisations should align these with their existing data protection policy retention schedule, typically reviewed alongside the DPIA framework the Act has also simplified for lower-risk processing. What has changed is that the absence of these records, not just a data breach itself, is now something the ICO can point to as a standalone failing.
