One Year On Marking The 12 Month Commencement Of The Data Use And Access Act
Summary
The Data Use and Access Act (DUAA) commenced on June 19, 2026, marking one year since it received Royal Assent. This legislation introduces significant changes for UK organizations and the public, aiming to foster innovation while protecting personal information and building trust. Over the past year, the Information Commissioner's Office (ICO) has focused on providing practical support, publishing new and updated guidance across 13 high-priority areas, and conducting 11 DUAA-related consultations that garnered over 300 responses. The Act also grants the ICO new powers, including compelling witness interviews, requesting reports from approved persons, and issuing fines up to £17.5 million or 4% of global turnover under the Privacy and Electronic Communications Regulations (PECR). Future plans include continued guidance publication and developing a new statutory code of practice on artificial intelligence and automated decision-making.
Key takeaway
Compliance Officers overseeing UK data operations should note the Data Use and Access Act's commencement. This requires reviewing your data protection practices. You must ensure compliance with updated guidance, especially regarding complaints handling and automated decision-making. Be aware of the ICO's new enforcement powers, including potential fines up to £17.5 million or 4% of global turnover under PECR. Proactively consult the ICO's guidance pipeline and engage in upcoming consultations to mitigate risks and maintain regulatory alignment.
Key insights
The DUAA's commencement empowers UK regulators with new tools and guidance to balance data innovation with privacy protection.
Principles
- Regulatory certainty is prioritized through guidance.
- Enforcement powers are reserved for serious cases.
- Risk-based approaches guide future regulatory focus.
Method
The ICO develops guidance by identifying high-priority areas, conducting consultations to gather insights, and then publishing updated resources to provide regulatory certainty.
In practice
- Consult guidance pipeline for updates.
- Engage in DUAA-related consultations.
- Prepare for new data protection processes.
Topics
- Data Use and Access Act
- UK Data Regulation
- ICO Enforcement Powers
- Data Protection Compliance
- Automated Decision-Making
- AI Governance
Best for: CTO, VP of Engineering/Data, Executive, Legal Professional, Consultant, Director of AI/ML
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by ico.org.uk.