Law note · United Kingdom

UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025

cite Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18 stage In effect since 2018-05-25 reviewed 2026-08-24

The UK retained a copy of the General Data Protection Regulation (GDPR) at Brexit (UK GDPR) alongside the Data Protection Act 2018 (DPA 2018), but that copy has now materially diverged: the Data (Use and Access) Act 2025 (DUA Act, Royal Assent 19 June 2025), whose main data protection reforms took effect 5 February 2026, added a new closed-list "recognised legitimate interests" lawful basis (Article 6(1)(ea)) needing no balancing test, for purposes such as safeguarding, crime prevention, emergencies, national security, direct marketing, and intra-group administrative sharing.

This basis is unavailable to a public authority exercising its own core functions, and has no equivalent in the EU GDPR Article 6 list.

What it asks of an app

  • Establish and document a lawful basis under UK General Data Protection Regulation (GDPR) Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
  • Do not rely on the recognised legitimate interests basis if you are a public authority exercising your own core functions; a necessity test still applies even though no balancing test is required.

When LexLint raises it

Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics

Primary source: legislation.gov.uk, official consolidated text
ICO Data (Use and Access) Act 2025 summary

← Back to the example  ·  Lint your app →