The DUA Act is now in force. What changes for your privacy notice?
A pragmatic walkthrough of the Data (Use and Access) Act changes that genuinely affect day-to-day compliance.
The Data (Use and Access) Act 2025 came into force earlier this year, and the initial wave of commentary has understandably focused on the headline reforms: the new recognised legitimate interests, the revised approach to automated decision-making, and the changes to research and statistical processing. What has received less attention is the practical question every privacy team is now facing: what actually needs to change in your privacy notice?
The short answer is: less than you might fear, but more than you can safely ignore. The UK GDPR framework survives largely intact. Article 13 and 14 information requirements are unchanged. The lawful basis you rely on for most processing is unchanged. What has shifted is the language around a small number of specific processing activities, and the ability to rely on "recognised legitimate interests" without conducting a full balancing test.
Recognised legitimate interests are the most visible change. The Act sets out a defined list — including safeguarding, crime prevention, and responding to emergencies — where the balancing test is treated as satisfied by the legislation itself. If your organisation relies on any of these grounds, your privacy notice should name the recognised interest explicitly, rather than pointing to a generic "legitimate interests" clause. The transparency benefit is real: individuals can see which specific interest applies and why.
Automated decision-making has been meaningfully rewritten. Article 22's near-total prohibition has been replaced with a more permissive regime, provided appropriate safeguards are in place. If your privacy notice still describes automated decisions as "only permitted with your explicit consent or where necessary for a contract", it is out of date. The new language should describe the safeguards you have implemented — meaningful human review, the right to contest a decision, and information about the logic involved — rather than the narrow legal gateways of the old regime.
Research and statistical processing has been clarified rather than transformed. The Act codifies a broader definition of scientific research and provides clearer conditions for reuse of personal data for research purposes. Privacy notices for organisations that conduct research — universities, healthcare providers, market research agencies — should update the relevant sections to reference the new statutory conditions rather than the previous case-law-derived interpretations.
Cookie and similar-technology rules have been eased for a narrow category of low-risk uses, including analytics that meet specific conditions. Your cookie notice, rather than your main privacy notice, is where this change lands. Review your consent banner logic to check whether any categories can now sit outside the consent gate — but be conservative, because the conditions are narrower than the headlines suggested.
International transfers are largely unchanged in substance, but the ICO's revised guidance on transfer risk assessments has been updated to reflect the Act's approach to adequacy. If your privacy notice describes your international transfer safeguards, check that the specific mechanisms named (adequacy regulations, standard contractual clauses, binding corporate rules) are still current.
Our recommendation is a single sweep of the privacy notice, focused on the five areas above, rather than a wholesale rewrite. Attach a short internal note to the reviewed version explaining what changed and why, so that future updates have a clear audit trail. The Act is a refinement, not a revolution — and your privacy notice should read that way.






