The Data (Use and Access) Act: what has actually changed for your data rights

Data protection – subject access – complaint routes

The Data (Use and Access) Act 2025 is no longer a Bill to watch. Most of its data-protection changes are now the law in force. This guide sets out, in plain English, what has actually changed for subject access requests, data-protection complaints and the regulator itself — and, just as importantly, what has not.

Category
Data protection
Jurisdiction
United Kingdom
Reading time
c. 10 minutes
Last reviewed
8 September 2026
By-line
Legal Lens

Snapshot

The Data (Use and Access) Act 2025 amends the UK GDPR, the Data Protection Act 2018 and the privacy and electronic communications rules rather than replacing them. Its main data-protection provisions came into force on 5 February 2026, and the new duty on organisations to handle data-protection complaints followed on 19 June 2026. For an individual, three changes matter most: the search behind a subject access request is now “reasonable and proportionate” by statute, the response clock can pause while a controller waits for clarification, and there is now a legal right to complain to the organisation itself before going to the regulator.

The same framework, with moved details

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. It amends the existing framework — the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations — rather than replacing it. Anyone who learned their data rights under the old names can keep the map; what has changed is some of the detail on the roads.

The Act did not arrive all at once. Commencement regulations have brought it into force in stages: a first tranche on 20 August 2025, the main body of the data-protection changes on 5 February 2026, and the new complaints provisions on 19 June 2026. As of September 2026, the core of what the Act does to individual data rights is in force and applies to requests and complaints made now.

Two things have not moved, and both are worth stating plainly because commentary has blurred them. The headline response period for a subject access request is still one month. And the threshold that lets a controller refuse a request outright, or charge a fee, remains that the request is “manifestly unfounded or excessive”; an earlier proposal to lower that bar to “vexatious or excessive” did not survive into the Act.

The change most people will feel first concerns the subject access request — the right to ask an organisation whether it holds your personal data and for a copy of it. The Act has written a limit into the right itself. A new Article 15(1A) of the UK GDPR provides that you are entitled only to the confirmation, personal data and other information that the controller can provide “based on a reasonable and proportionate search”. The provision came into force on the day the Act was passed, and the amendments are treated as having been in force since 1 January 2024.

That phrasing is not a licence to do nothing. The regulator’s guidance requires controllers to make reasonable efforts to find and retrieve the requested information, and to be able to show why a search would be unreasonable or disproportionate, considering the circumstances of the request, the volume of information to be searched and the difficulty of finding it. A controller who searches nowhere has not carried out a proportionate search; it has carried out no search at all.

Practical point. A tightly described request is leverage, not a concession. The easier you make it to locate what you want — date ranges, systems, names of correspondents — the harder it is for a controller to argue that finding it would be disproportionate.

For requesters, the statutory wording cuts both ways. It confirms that an organisation need not reconstruct deleted backups or search every system it has ever used. It also gives you a precise question to put in writing when a response looks thin: what did you search, and why do you say a wider search would be disproportionate? A controller that cannot answer that question has a problem; one that can answer it has probably complied.

The response clock and “stop the clock”

The one-month response period now runs from a defined “relevant time” — the latest of the day the controller receives the request, the day it receives any information it reasonably requested to confirm your identity, and the day any permitted fee is paid. A controller may extend the period by two further months where necessary because of the complexity or number of requests, but only by giving you notice, with reasons, before the first month ends.

The genuinely new mechanism is the pause. Where a controller reasonably needs further information to identify the information or processing your subject access request is about, it may ask you, and the days between its question and your answer do not count towards the time limit. This is what commentary calls “stop the clock”. It is not a general power to delay: the need for clarification must be reasonable, and the request for it must actually be made.

These time-limit rules apply to requests the controller received on or after 5 February 2026; requests received before that date are handled under the old rules. The practical discipline is unchanged and still worth stating. Send requests in writing, keep proof of the date received, answer any genuine clarification question promptly and in writing, and diarise the day the month runs out. Evidence turns confusion into an argument.

The new complaint right against controllers

Since 19 June 2026 there has been a new statutory first stop. A data subject who considers that an organisation has infringed the UK GDPR or the law-enforcement provisions of the Data Protection Act 2018 may complain directly to the controller. The controller must provide a way to complain, must acknowledge the complaint within 30 days of receiving it, and must then, without undue delay, take appropriate steps to respond — including making enquiries and keeping the complainant informed of progress — and tell the complainant the outcome.

The duty applies to complaints received on or after 19 June 2026. For litigants and complainants this changes the shape of an escalation. The controller’s own process is no longer a courtesy to be tried before the real complaint; it is a legal obligation with a clock on the acknowledgement. If the outcome is unsatisfactory, the route to the regulator remains: the right to complain to the Information Commissioner’s Office now sits in section 165 of the Data Protection Act 2018, into which the old UK GDPR complaint article has been consolidated.

The sequence worth following is simple. Complain to the organisation first, in writing, and keep the acknowledgement. Give the process a fair chance to work. If the outcome is wrong or never arrives, the acknowledgement, the chronology and the outcome letter become the front of the file that goes to the regulator.

Recognised legitimate interests

The Act has added a new lawful basis to the UK GDPR: processing necessary for the purposes of a “recognised legitimate interest”. Unlike ordinary legitimate interests, which require the controller to balance its interests against yours, this basis is available only where the processing meets a condition in a fixed statutory list. The current list covers disclosures requested for processing carried out in the public interest or under official authority, safeguarding national security, public security or defence, responding to an emergency, detecting, investigating or preventing crime or apprehending or prosecuting offenders, and safeguarding children and adults at risk. The Secretary of State may add to the list, but only by regulations subject to the affirmative resolution procedure.

The new basis has been in force since 5 February 2026. For individuals, the significance is mostly defensive. Where an organisation relies on a recognised legitimate interest, it does not have to carry out the case-by-case balancing exercise that ordinary legitimate interests require. But the right to object to the processing still applies, and the transparency obligations are untouched: you are still entitled to be told what is held, why, and on what basis. If a privacy notice suddenly invokes “recognised legitimate interests” for something that looks nothing like crime prevention or safeguarding, that is a question worth putting in writing.

A regulator in transition

The Act also rebuilds the regulator itself. It establishes a new body corporate, the Information Commission, abolishes the office of Information Commissioner and transfers the Commissioner’s functions to the new body. Those transfer provisions are not yet in force. The government appointed seven non-executive members to the Information Commission’s board on 15 July 2026 and launched recruitment for its first chair, and has said the Commission will take over the ICO’s functions later in 2026.

Until that transfer happens, nothing about making a complaint changes. The Information Commissioner’s Office remains the regulator, complaints go to it in the usual way, and live casework is unaffected by the governance reforms happening above it. When the transition does take effect, the expectation on the public record is continuity: the same functions, the same statutory duties, exercised by a board rather than a single office-holder. The complaint routes described in this article are built on the legislation, not on the letterhead, and they survive the change of name.

Source anchors

These primary and official sources support the legal framework described above. They anchor what the legislation says and when each part took effect.

The closing point

None of these changes takes a right away; each of them makes the process around the right more defined. A more defined process rewards the organised complainant. Be specific about what you ask for, keep the dates, answer clarification questions promptly, and treat every acknowledgement and outcome letter as part of the record. The merits matter. But procedure decides when the merits are heard.

Data rights decision point

Legal Lens can structure a preliminary written review of a data-rights problem: which right to use, in what order, and what the paper trail needs to show before the next step.

Route selection

Subject access request, controller complaint or regulator complaint — sequenced so each step strengthens the next.

Request scoping

Framing a request narrowly enough that a proportionate search has to find it.

Assessment outputs

Issue map

The rights engaged, the routes available and the live disputes.

Document checklist

The requests, acknowledgements and chronology the file needs.

Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors’ firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

Legal Lens publishes practical legal commentary for litigants in person and the public. This article is general information about the law in force at the review date shown, not legal advice on any individual case.

Leave a Reply

Comments are public. Please do not include details of your own case — use the contact form instead.

Your email address will not be published. Required fields are marked *