Law note · United Kingdom
UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025
The UK retained a copy of the General Data Protection Regulation (GDPR) at Brexit (UK GDPR) alongside the Data Protection Act 2018 (DPA 2018), but that copy has now materially diverged: the Data (Use and Access) Act 2025 (DUA Act, Royal Assent 19 June 2025), whose main data protection reforms took effect 5 February 2026, added a new closed-list "recognised legitimate interests" lawful basis (Article 6(1)(ea)) needing no balancing test, for purposes such as safeguarding, crime prevention, emergencies, national security, direct marketing, and intra-group administrative sharing.
This basis is unavailable to a public authority exercising its own core functions, and has no equivalent in the EU GDPR Article 6 list.
What it asks of an app
- Establish and document a lawful basis under UK General Data Protection Regulation (GDPR) Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
- Do not rely on the recognised legitimate interests basis if you are a public authority exercising your own core functions; a necessity test still applies even though no balancing test is required.
When LexLint raises it
Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics
Primary source: legislation.gov.uk, official consolidated text
ICO Data (Use and Access) Act 2025 summary