New UK Data Law Is Live: What Your Business Must Do
UK data protection law changed on 19 June 2026. Here is what the Data (Use and Access) Act means for your business – and the one new obligation that requires action right now.
What happened
The Data (Use and Access) Act 2025 – the government’s first significant update to UK data protection law since Brexit – received Royal Assent and its core data protection provisions came into force on 19 June 2026. The Act amends the UK GDPR (the UK’s main data privacy law, which applies to almost every business that holds or processes personal data about customers, staff, or suppliers) and PECR (the Privacy and Electronic Communications Regulations, which governs cookies and electronic marketing).
This is not a replacement for UK GDPR. The vast majority of your existing data protection obligations remain unchanged. However, the Act adds several new requirements – and one in particular affects virtually every business that handles personal data: a formal, legally enforceable obligation to handle data protection complaints.
The change your business most needs to act on
From 19 June 2026, if a customer, employee, or member of the public raises a data protection complaint with your organisation, you are legally required to:
- Acknowledge the complaint within 30 days
- Take reasonable steps to investigate and resolve it without undue delay
- Keep the person informed of progress and inform them of the outcome
This might sound like what a responsible business already does informally. The difference is that it is now a statutory requirement, and the ICO (the Information Commissioner’s Office, the UK’s data protection regulator) can investigate whether you complied with it.
For many small businesses, this means writing a short procedure: who receives data protection complaints, who is responsible for sending the 30-day acknowledgement, and how the outcome is recorded. Without a paper trail, you have very little to show an ICO investigation if one ever arises. The Act also gives the ICO expanded investigatory and audit powers, making it more straightforward for them to assess whether you handled a complaint properly.
Other changes worth knowing about
Cookie consent exemptions: A narrow new exemption means that cookies used solely for analytics (where data is not passed to third parties) and cookies required for fraud prevention or device security no longer need a consent banner. This is helpful if your website uses basic analytics tools, but marketing and tracking cookies still require full consent. Do not remove your cookie banner without taking specific advice first.
Automated decision-making: For decisions that do not involve sensitive personal data – such as routing a customer query or filtering a support ticket queue – the rules around notifying users have been slightly relaxed. If your business uses automated tools to process customer interactions, it is worth reviewing whether your privacy notice remains accurate.
A new ‘recognised legitimate interests’ ground: Processing for specific purposes, including crime prevention, national security, and safeguarding, can now proceed without carrying out a full balancing test. This is unlikely to affect most SMBs directly, but may be relevant if you work in professional services, healthcare, or the care sector.
Higher PECR fines: Cookie and electronic marketing breaches can now attract fines up to £17.5 million or 4% of worldwide annual turnover, bringing PECR enforcement into line with UK GDPR. This has been covered separately, but it reinforces the importance of getting your cookie and marketing practices right.
What we have already done for managed clients
IT infrastructure and data protection overlap significantly. Our managed IT service ensures your Microsoft 365 environment – where most staff handle personal data day to day – is configured with appropriate access controls, audit logging, and data retention policies. These form the technical backbone of any credible data protection response.
If the ICO requests evidence following a complaint, the ability to show exactly who had access to what, and when, is essential. We keep that evidence available and organised. We also work alongside specialist data protection advisors for clients who need a full privacy audit or Data Protection Officer support.
What to check if no one is managing this for you
- Write a short data protection complaints procedure. Even a one-page document covering who receives complaints, how the 30-day acknowledgement works, and how outcomes are recorded will demonstrate to the ICO that you take this seriously.
- Nominate a named contact for data protection. A formal DPO (Data Protection Officer) is not required for most SMBs, but someone needs to own complaints when they arrive.
- Update your privacy notice. It should state who to contact with a data protection complaint and confirm that you have a process for handling it.
- Review your website’s cookie banner. The new analytics exemption may let you simplify it, but get advice before removing any consent prompts.
- Consider Cyber Essentials certification if you have not already. It demonstrates a baseline of technical controls to customers and supply chain partners – and aligns well with the kind of access controls and audit logging that support data protection compliance.
If you are not confident your data protection house is in order, contact us. We can point you towards specialist advice and ensure your IT security and IT management arrangements give you the technical foundation you need.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


