WSGR logoWSGR logo
WSGR logo
  • Experience
  • People
  • Insights
  • About Us
  • Careers

  • Practice Areas
  • Industries

  • Corporate
  • Intellectual Property
  • Litigation
  • Patents and Innovations
  • Regulatory
  • Technology Transactions

  • Capital Markets
  • Corporate Governance
  • Corporate Life Sciences
  • Derivatives
  • Emerging Companies and Venture Capital
  • Employee Benefits and Compensation
  • Energy and Climate Solutions
  • Executive Advisory Program
  • Finance and Structured Finance
  • Fund Formation
  • Greater China
  • Mergers & Acquisitions
  • Private Equity
  • Public Company Representation
  • Real Estate
  • Restructuring
  • Shareholder Engagement and Activism
  • Tax
  • U.S. Expansion
  • Wealthtech

  • Special Purpose Acquisition Companies (SPACs)

  • Environmental, Social, and Governance

  • AI and Data Center Infrastructure
  • Energy Regulation and Competition
  • Project Development and M&A
  • Project Finance and Tax Credit Transactions
  • Sustainability and Decarbonization
  • Transportation Electrification

  • U.S. Expansion Library and Resources

  • Post-Grant Review
  • Trademark and Advertising

  • Antitrust Litigation
  • Arbitration
  • Board and Internal Investigations
  • Class Action Litigation
  • Commercial Litigation
  • Consumer Litigation
  • Corporate Governance Litigation
  • Employment Litigation
  • Executive Branch Updates
  • Government Investigations
  • Internet Strategy and Litigation
  • Patent Litigation
  • Securities Litigation
  • State Attorneys General
  • Supreme Court and Appellate Practice
  • Trade Secret Litigation
  • Trademark and Copyright Litigation
  • Trial
  • White Collar Crime

  • Advertising, Promotions, and Marketing
  • Antitrust and Competition
  • Committee on Foreign Investment in the U.S. (CFIUS)
  • Communications
  • Data, Privacy, and Cybersecurity
  • Export Control and Sanctions
  • FCPA and Anti-Corruption
  • FDA Regulatory, Healthcare, and Consumer Products
  • Federal Trade Commission
  • Fintech and Financial Services
  • Government Contracts
  • National Security and Trade
  • Payments
  • State Attorneys General
  • Strategic Risk and Crisis Management
  • Tariffs, Customs, and Import Compliance

  • Antitrust and Intellectual Property
  • Antitrust Civil Enforcement
  • Antitrust Compliance and Business Strategy
  • Antitrust Criminal Enforcement
  • Antitrust Litigation
  • Antitrust Merger Clearance
  • European Competition Law
  • Third-Party Merger and Non-Merger Antitrust Representation

  • Anti-Money Laundering
  • Foreign Ownership, Control, or Influence (FOCI)
  • Team Telecom

  • AI in Healthcare
  • Animal Health
  • Artificial Intelligence and Machine Learning
  • Aviation
  • Biotech
  • Blockchain and Cryptocurrency
  • Clean Energy
  • Climate and Clean Technologies
  • Communications and Networking
  • Consumer Products and Services
  • Data Storage and Cloud
  • Defense Tech
  • Diagnostics, Life Science Tools, and Deep Tech
  • Digital Health
  • Digital Media and Entertainment
  • Electronic Gaming
  • Fintech and Financial Services
  • FoodTech and AgTech
  • Global Generics
  • Internet
  • Life Sciences
  • Medical Devices
  • Mobile Devices
  • Mobility
  • NewSpace
  • Quantum Computing
  • Semiconductors
  • Software

  • Offices
  • Country Desks
  • Events
  • Pro Bono
  • Community
  • Our Diversity
  • Sustainability
  • Our Values
  • Board of Directors
  • Management Team

  • Austin
  • Boston
  • Boulder
  • Brussels
  • Century City
  • Hong Kong
  • London
  • Los Angeles
  • New York
  • Palo Alto
  • Salt Lake City
  • San Diego
  • San Francisco
  • Seattle
  • Shanghai
  • Washington, D.C.
  • Wilmington, DE

  • Law Students
  • Judicial Clerks
  • Experienced Attorneys
  • Patent Agents
  • Business Professionals
  • Alternative Legal Careers
  • Contact Recruiting
UK Introduces New Legislation Amending Privacy Laws
Alerts
July 1, 2025

On June 19, 2025, the UK Data (Use and Access) Act 2025 was enacted, marking the culmination of a lengthy legislative process aimed at reshaping aspects of the country’s data protection regime. First proposed in 2021 as part of a government strategy titled, “Data: a new direction,” the legislation has undergone several rounds of revision since its initial introduction. Its passage reflects the UK’s desire to diverge, in measured ways, from the EU’s approach to data regulation in the post-Brexit landscape.

The Act introduces targeted amendments to the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, with a focus on clarifying lawful data use, adjusting rules for international transfers and modifying the regulation of rules on electronic marketing. While the UK GDPR and its core principles of data protection remain intact, these reforms are intended to reduce burdens on organizations and unlock economic and research opportunities.

Key Changes Under the Act

  • Relaxed restrictions on automated decision-making (ADM). Since the GDPR came into force in 2018, UK law has restricted the ability of companies to make significant decisions about individuals based solely on the automated processing of their personal data. The Act relaxes this position, providing that such decisions can in the future be made subject to the implementation of appropriate safeguards, such as a route to contest decisions and obtain human intervention. Moving forward, ADM will be prohibited only when based on the processing of special category data (e.g., health data), and if that decision produces legal or other significant effects for individuals. In practice, these changes open the door for businesses operating in the UK to make wider use of ADM technologies when special category data is not processed, by liberalizing the range of legal bases that can be relied on under the UK GDPR for such processing. The Information Commissioner’s Office (ICO) is expected to publish draft guidance on ADM for consultation in winter 2025 or early 2026.
  • Clarifying the scope of the research provisions. The Act clarifies what amounts to processing for the purposes of “scientific research,” “historical research,” and “statistical purposes” by inserting a new definition of those terms into the UK GDPR. The amendments clarify that scientific research can include commercial research, including where such research is privately funded. Examples include processing for technical development or demonstration, and fundamental or applied research, insofar as such activities can reasonably be described as scientific. The ICO is expected to publish draft guidance on these updated research provisions for consultation this autumn.
  • Modifications to the purpose limitation principle. The Act clarifies the circumstances in which organizations can lawfully process personal data for new purposes. Where personal data was originally collected based on consent of the data subject, the rules are more restrictive and require either a fresh consent, a strong public interest reason for the new processing, or that the processing otherwise falls within a limited list of “compatible purposes” prescribed by the Act. The rules are more liberal where personal data was originally collected on a legal basis other than consent.
  • Recognized “legitimate interests.” The Act sets out a defined list of recognized “legitimate interests” that can be relied on when processing personal data, such as safeguarding vulnerable people or combating criminal activity. When data processing aligns with one of these designated interests, controllers are not obligated to carry out a full balancing test against individuals’ rights and freedoms. Instead, they must determine whether the processing is necessary to achieve the stated aim. The ICO is expected to publish draft guidance for consultation on these new lawful bases in winter 2025 or early 2026.
  • Consent no longer required for certain uses of cookies. The Act introduces new exceptions to the general rule under the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) that consent must be obtained before placing or reading cookies on a user’s device. Cookies can now be placed without consent where necessary for “statistical purposes” to collect information about how an online service is used. The ICO is expected to publish draft guidance on cookies for consultation in spring and winter this year.
  • Children’s protection matters. The Act introduces a new requirement for providers of online services that are likely to be accessed by children. This requires such providers to consider the technical and organizational measures they can put in place to best protect and support children using the services, including children that fall in different age groups and that therefore have different developmental needs. The ICO is expected to produce guidance on safeguarding children in winter 2025 or early 2026.
  • An updated Information Commission with enhanced enforcement powers. The Information Commissioner’s Office will be replaced by an Information Commission (IC). The Act grants the IC additional enforcement powers, including to require individuals to attend interviews in the context of investigations, and to impose fines of up to GBP 17.5 million, or up to four percent of global worldwide turnovers, for breaches of PECR (bringing PECR fines in line with the UK GDPR). When exercising its powers, the Act requires the IC to have regard to a list of priorities, including providing special protection to the rights of children. The ICO is expected to publish guidance on changes to their processes in autumn 2025.
  • Encouragement of Smart Data schemes. The Act empowers authorities to launch new “Smart Data” initiatives. These initiatives would mandate that relevant companies enable consumers to access their personal data and share it securely with approved third parties. The goal of these provisions is to expand on the success of Open Banking by fostering comparable frameworks in other industries.

Next Steps

The Act has now been passed and will be brought into force in the coming months. The IC will be publishing new and updated guidance to reflect the changes outlined above, while companies will need to reassess and adjust their data handling practices accordingly.

Wilson Sonsini Goodrich & Rosati routinely helps companies navigate complex digital regulation and privacy compliance in the UK and EU. For more information, please contact Nikolaos Theodorakis or Tom Evans.

Claudia Chan contributed to the preparation of this alert.

Contributors

  • Nikolaos Theodorakis
  • Tom Evans
  • Claudia Chan
  • people
  • insights
  • about us
  • careers
  • Binder
  • Alumni
  • Mailing List Signup
  • Client FTP Portal
  • Privacy Policy
  • Terms of Use
  • Accessibility
WSGR logo
Twitter
LinkedIn
Facebook
Instagram
Youtube
Copyright © 2026 Wilson Sonsini Goodrich & Rosati. All Rights Reserved.