The UK Data (Use and Access) Act 2025 (DUAA) entered into effect in stages, introducing a series of targeted amendments to the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). Rather than overhauling the UK's privacy framework, the legislation refines specific areas where organizations have long sought greater clarity, particularly around storage and access technologies, privacy rights, complaint handling, and automated processing.
The latest implementation milestone arrived on June 19, 2026, when new data protection complaint handling requirements became effective. Individuals must now raise complaints with organizations before escalating them to the Information Commission, which will replace the Information Commissioner's Office (ICO) creating new operational responsibilities for handling, investigating, and documenting complaints.
Many of the broader DUAA changes require a similar operational response. Organizations must review how consent experiences are configured, how cookies are classified, how privacy requests are managed, and where UK-specific approaches may begin to diverge from EU practices.
Key Takeaways
- The DUAA introduces targeted amendments to UK privacy law, with practical implications for consent, complaint handling, and privacy operations.
- New PECR exceptions create greater flexibility for some analytics and functionality cookies when statutory conditions are met.
- Purpose classification, transparency, and meaningful user choice remain central to compliant consent experiences.
- OneTrust has introduced UK-specific Consent & Preferences features and updates, and supports operational changes through Privacy Automation capabilities.
Where the DUAA Changes Day-to-Day Privacy Operations
Organizations Need Formal Complaint Handling Processes
The most immediate operational change is the new complaint handling process.
Under the DUAA, organizations must provide a way for individuals to submit complaints directly, acknowledge receipt within the required timeframe, investigate the complaint, communicate progress where appropriate, and provide an outcome before the matter reaches the ICO.
For organizations with mature privacy rights programs, this introduces a new workflow alongside existing DSAR and incident response processes. For others, it creates a need to establish documented intake, investigation, approval, and recordkeeping procedures that demonstrate complaints are handled consistently and within the required timelines.
Consent Models Are Becoming More Granular
The DUAA introduces several new PECR exceptions where consent is no longer required for specific storage and access technologies, including certain statistical and appearance or functionality purposes, provided the statutory conditions are satisfied.
On the surface, this appears to simplify cookie compliance. In practice, it shifts the focus toward more precise consent configuration.
Consider two common examples. A website uses a cookie solely to remember a visitor's language preference. That activity may fall within the appearance exception, allowing the organization to configure the experience differently from a traditional opt-in model.
Now consider an analytics technology that measures user journeys. If that technology is used exclusively for qualifying statistical purposes, it may benefit from the statistical exception. If the same technology also contributes data for advertising measurement or profiling, the exception no longer applies and consent requirements change.
These distinctions place greater emphasis on understanding how each technology is used rather than relying on broad cookie categories.
Purpose Classification Matters More Than Cookie Categories
One of the most significant operational shifts introduced by the DUAA is the increased importance of purpose limitation.
The ICO's updated approach makes clear that exceptions apply only where storage or access takes place solely for the qualifying purpose. Once a technology serves multiple purposes, organizations should reassess whether the exception still applies.
That creates practical work for consent and digital teams. Existing cookie inventories may need to be reviewed. Vendor configurations may need updating. Tagging strategies may need to separate activities that were previously grouped together under a single implementation.
The result is a more accurate consent model that reflects the actual purpose of each technology.
Stronger Enforcement Raises the Importance of Consent Governance
The DUAA also aligns maximum PECR fines with the UK GDPR, significantly increasing the potential consequences for non-compliance.
Alongside the new exceptions to requiring consent, the legislation reinforces expectations around transparency and user control. Organizations relying on the new exceptions still need to provide clear information and appropriate mechanisms for individuals to exercise choice where required. Consent experiences should continue to present balanced options, including clear access to granular controls.
Turning DUAA Requirements Into Operational Controls
Configure UK-Specific Consent Without Rebuilding Your Strategy
OneTrust has introduced a dedicated UK GDPR CMP template that reflects the DUAA's amendments to PECR rather than treating the UK as an extension of EU consent requirements. This enables organizations to apply UK-specific consent configurations while maintaining consistent governance across broader privacy programs.
For multinational organizations operating across both the UK and EU, this provides greater flexibility as the two regulatory frameworks gradually diverge in selected areas while continuing to share the same underlying principles.
Apply Cookie Exceptions with Greater Precision
OneTrust has embedded DUAA exception logic into CMP configuration, supporting scenarios where qualifying functionality or performance cookies may be enabled by default when organizations determine they satisfy the appearance or statistical exceptions.
Equally important is what remains under the organization's control: the platform reflects legal decisions, it does not make them.
Organizations remain responsible for determining whether a technology genuinely qualifies for an exception based on its purpose and use. That distinction supports greater flexibility while reducing the risk of applying exceptions too broadly.
Preserve User Choice Across Digital Experiences
The DUAA continues to place significant weight on transparency and meaningful user choice. OneTrust supports these expectations through consent experiences that include equally prominent Accept All and Reject All options, clear pathways to granular preference centers, and user experiences designed to avoid nudging individuals toward a particular decision.
When an individual updates their preferences, the preference center provides the customer-facing experience for expressing those choices. Behind the scenes, the underlying consent and preference management layer captures those signals and helps ensure they are applied consistently across connected systems, creating a stronger foundation for enforcement, governance, and auditability.
Support Evolving Privacy Workflows
The DUAA's complaint handling requirements also increase the importance of structured privacy operations. OneTrust Privacy Automation supports organizations as they manage complaint workflows, privacy rights requests, documentation, and internal processes that help demonstrate how privacy obligations are handled consistently over time.
Five Practical Steps Before Updating Your UK Privacy Program
As implementation continues, organizations should review how the DUAA affects existing operational practices rather than treating the legislation as a simple legal update.
- Review whether analytics and functionality technologies qualify for the new PECR exceptions based on their actual purpose.
- Revisit cookie inventories and vendor configurations where technologies support multiple processing activities.
- Validate UK-specific CMP configurations and consent experiences.
- Establish documented complaint handling processes that align with the new requirements.
- Finally, assess whether differences between UK and EU privacy requirements warrant separate operational approaches for your organization.
Continue Your DUAA Readiness
Stay informed on UK privacy developments. The DUAA will continue to roll out through phased implementation. Explore OneTrust DataGuidance for ongoing regulatory analysis, implementation updates, and practical guidance on UK privacy developments.
Review your UK consent configuration. See how OneTrust Consent & Preferences helps organizations configure UK-specific consent experiences, apply purpose-based controls, and operationalize customer choice across websites and applications.
Strengthen privacy operations. Learn how OneTrust Privacy Automation supports complaint handling, privacy rights workflows, and the documentation needed to manage evolving regulatory requirements with greater consistency.
Key Questions About the UK Data (Use and Access) Act