The new complaints duty and its 30-day acknowledgement deadline, the subject access changes, the cookie exemptions, and the marketing fines that just rose thirty-five-fold.
If your data protection folder was last opened in 2018, this is the year that stopped being survivable. The main data protection changes under the Data (Use and Access) Act 2025 took effect on 5 February 2026, and on 19 June 2026 a genuinely new duty arrived that most owners still have not heard of: a statutory complaints process, with a 30-day acknowledgement deadline and no small-business exemption.
One point before the detail, because it is the misunderstanding I hear most. The Act amends the existing law; it does not replace it. UK GDPR, the Data Protection Act 2018 and the marketing rules in PECR are all still there, doing the same jobs. Anyone telling you “GDPR is gone” is wrong. Anyone telling you nothing has changed is now wrong too. Here is what actually moved, and what to update.
1. What changed, and when
The Act received Royal Assent on 19 June 2025 and has been switched on in stages: the bulk of the data protection changes on 5 February 2026, the complaints duty on 19 June 2026. The ICO has confirmed that all of the Act’s data protection provisions are now in force. The core principles are untouched, and the accountability plumbing survived: if you needed a data protection officer, records of processing or impact assessments before, you still do. Most of the changes give you room you did not have. One is a hard new obligation with a deadline attached, so we will start there. The ICO is still updating its guidance as the Act beds in; do not read that as a grace period, because the rules are in force now and the ceiling on marketing and cookie fines has moved dramatically.
2. The complaints duty nobody has noticed
Since 19 June 2026, anyone who thinks you have mishandled their personal data has a statutory right to complain to you directly, alongside their right to go to the ICO — and in practice the ICO will generally expect them to have raised it with you first. You must run a process for it. The requirements sit in a new section 164A of the Data Protection Act 2018 and they are specific: make it easy to complain, including electronically; acknowledge within 30 days of receipt; investigate and respond without undue delay; and tell the complainant the outcome. Your privacy notice should now explain how to complain to you, and your responses to rights requests must signpost it.
The definition is deliberately broad: an expression of dissatisfaction which, fairly read, says you have got something wrong with someone’s data. It can arrive on any channel, in anyone’s inbox. “Why am I still getting your newsletters after I unsubscribed?” sent to a sales address is a complaint, and the 30-day acknowledgement clock starts whether or not anyone notices. (A customer-service gripe that merely touches on data is not automatically one; where it is unclear, ask, and record the answer.) Understand what the duty is for and it works in your favour: Parliament wants problems resolved with you rather than the regulator, and a complaint handled well usually ends there. One ignored for five weeks arrives at the ICO with your missed statutory deadline attached.
3. Subject access requests: a fairer clock, a defined search
Anyone can ask for a copy of the personal data you hold on them, with no magic words and, in most cases, no fee. Two February changes make these requests more manageable. The one-month clock now runs from the “relevant time”, the latest of receiving the request, confirming identity, or receiving any fee that applies, and it pauses while you await clarification of a genuinely unclear request — clarification you ask for because you need it, not to buy time. For complex or numerous requests it can be extended by up to two further months, provided you say so within the first month. And the search standard is now in the statute: reasonable and proportionate. That does not mean minimal; it means reasonable efforts, and a record of where you stopped searching and why. Exemptions still apply to other people’s data, privileged material and certain management information. Redact rather than refuse, and note that your response must now also signpost the complaint rights in section 2.
4. Marketing: the rules stayed, the fines grew
Electronic marketing answers to two regimes at once: UK GDPR for your use of the data, PECR for the act of sending the email or text. A “legitimate interests” assessment never overrides PECR. The Act even names direct marketing as an example of what may be a legitimate interest, and the balancing test still applies, but for unsolicited email and texts to individual subscribers you still need consent or the soft opt-in — and sole traders count as individuals, while a named contact at a company is still personal data with an absolute right to object. The soft opt-in’s conditions: existing customer, your own similar products or services, details collected directly from them during a sale or negotiation, and an opt-out offered at collection and in every message. The direct-collection condition means it can never rescue a bought list, and consent a broker collected for “selected partners” is not consent for you. The Act extended the same mechanism to charities for fundraising, for supporters recruited from now on. And the stakes changed in February: the maximum PECR fine rose from £500,000 to £17.5 million or 4% of global annual turnover, whichever is higher, in one of the ICO’s most active enforcement areas.
5. Cookies: the banner can shrink, carefully
From 5 February 2026, consent is no longer required for cookies used solely for statistical and analytics purposes, or solely to remember appearance and functionality preferences, provided you give clear information and a simple, free way to object — and under the ICO’s finalised guidance the objection can live in the banner, with exempt cookies on by default and an easy off-switch. Narrower provision covers software updates and emergency assistance on their own terms, with genuine security uses generally inside the long-standing strictly-necessary exception. Advertising cookies, cross-site tracking and social media pixels need prior consent exactly as before, and “solely” is load-bearing: analytics that also feeds ad targeting is advertising, and the exemption falls away — which is worth checking with third-party analytics providers in particular. Two cautions. The UK carve-outs do not travel: if meaningful EEA traffic reaches your site, do not assume they apply to those visitors. And most owners do not actually know what their site sets; the audit comes before the simplification.
6. Privacy notices: the truth test
The test of a privacy notice is truth, not length. Read it against what the business does today; every mismatch is a disclosure to add or a processing activity to justify, and the complaint-rights signposting in section 2 is a concrete update almost every notice now needs. If AI tools have crept into recruitment, customer scoring or marketing since the notice was written, it should say so honestly.
7. The suppliers quietly holding your data
The payroll bureau, the CRM, the mailing platform and the IT firm with admin access are your processors, and a written contract with each, containing the required terms, is mandatory. The commonest gap is not a bad clause but a missing one: a service bought years ago on the supplier’s standard terms, with no data terms at all. Make sure each contract obliges the supplier to tell you promptly about requests, complaints and breaches, because those clocks are yours and they run whether or not the message gets passed on. One more design point: if your website, app or online service is likely to be used by children, the Act now expects children’s needs to be reflected in how it is designed and set up by default — not every business is touched, but nurseries, education providers and anyone with young users are.
8. Transfers, retention and breaches: what buyers and regulators check
Three quicker checks. First, transfers: your data leaves the UK more than you think, through US-hosted software and offshore support teams with access to your records, and a transfer includes making data accessible outside the UK, not just sending it. Every route out needs a lawful mechanism in the contract, and the Act restates the underlying standard as a “data protection test”: protection not materially lower than the UK’s. Flowing inward, the EU renewed the UK’s adequacy decisions in December 2025, through to 27 December 2031, following its assessment of the UK framework including the 2025 Act’s changes — renewed, not permanent, so keep half an eye on divergence — and data keeps moving freely from Europe. Second, retention: “we keep everything forever” is non-compliant and expensive, because every extra year of data is breach exposure, subject access burden and a worse answer in due diligence. Set a schedule anchored to statute and limitation periods, and make deletion actually happen. Third, breaches: where the risk threshold is met you must report to the ICO without undue delay and, where feasible, within 72 hours, weekends included — late needs justifying; the report can go in before the investigation is complete, with detail to follow; you must record every breach even where you decide not to report; and people must be told where the risk to them is high. A one-page plan, written before you need it, is the difference between a bad Friday and a bad year.
The takeaway
The Act did not tear anything up. It moved the furniture and raised the fines. The complaints duty has been live since 19 June, so if you do not have a process, that is this week’s job; the notice, the subject access procedure, the marketing lists and the cookie audit follow close behind. The cheapest time to fix any of it is before the request, the breach or the buyer’s lawyers arrive. If any of this is news to you, ring me, or book a data protection health check and we will tell you, plainly, what needs doing and what does not.
| One line on enforcement and disputes. This is the advisory and compliance side of data protection: notices, processes, contracts, and handling requests, complaints and incidents properly. Where a matter becomes genuinely contentious, such as ICO enforcement proceedings or litigation, we support the preparatory work and refer the contentious element to specialist counsel, keeping your compliance position and commercial relationships aligned. |
Quick answers
Does the Data (Use and Access) Act 2025 replace UK GDPR?
No. It amends UK GDPR, the Data Protection Act 2018 and PECR. The core principles and your existing obligations remain; the Act adjusts specific rules within that framework.
What is the new data protection complaints duty?
From 19 June 2026, every controller must operate a process for data protection complaints: an easy route in (including electronic), acknowledgement within 30 days, investigation and a response without undue delay, and signposting in the privacy notice. There is no small-business exemption.
Do I still need a cookie banner?
For advertising and tracking, yes: consent is required as before. Since 5 February 2026, certain cookies and similar technologies used solely for specified low-risk purposes — statistical analytics, and remembering appearance or functionality preferences — no longer need consent where the statutory conditions are met, including clear information and a free way to object. EU visitors remain subject to EU rules.
How long do I have to answer a subject access request?
One month from the “relevant time”: the latest of receiving the request, confirming identity, or receiving any applicable fee. The clock pauses while you await clarification, and genuinely complex requests can be extended by up to two further months. In most cases you cannot charge a fee.
Download the full guide: Data Protection After the Data (Use and Access) Act 2025 — What You Actually Need to Update (PDF).
This article is general information, not legal advice. Law stated as at 6 July 2026.







