The Data (Use and Access) Act 2025 is a UK statute (Chapter 18 of the Acts of the Parliament of the United Kingdom, 2025) that reforms data protection and information rights by amending UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). It is not AI-specific legislation, but several of its provisions bear on AI, principally a reform of the rules on automated decision-making, a reconstitution of the data-protection regulator, and the deferral of disputed copyright-and-AI-training questions. AI-specific rules were left to a separately delayed AI Bill (see UK AI Bill — Status and Delay (Source Summary)).
Status and timeline
The Act was enacted by the Parliament of the United Kingdom (House of Commons and House of Lords), with Royal Assent granted by the Sovereign. The lead department is the Department for Science, Innovation and Technology (DSIT), under Secretary of State Peter Kyle. It is a Labour-government successor to the Conservative government's Data Protection and Digital Information Bill (DPDI), which fell at the 2024 general election.
The bill received its House of Lords first reading in October 2024. Royal Assent was granted on 19 June 2025. Commencement is phased, with most provisions active or commencing through 2025–2026 by Statutory Instrument.
Scope
The Act primarily amends UK GDPR, the Data Protection Act 2018, and PECR. Beyond data-protection amendments it creates a Smart Data framework for customer and business data portability (Part 1); a Digital Verification Services regime (Part 2); the National Underground Asset Register (Part 3); reforms to births and deaths registration (Part 4); and reconstitutes the Information Commissioner's Office as the Information Commission (Part 6).
The Act does not create AI-specific regulation, an AI regulator, foundation-model duties, compute-threshold registration, or algorithmic-accountability obligations beyond existing data-protection impact assessments.
Key provisions
Automated decision-making reform (Part 5)
The provision most directly relevant to AI replaces UK GDPR Article 22's narrow "solely automated" prohibition with a framework organised around significant decisions — decisions producing legal effects, or similarly significant effects, on a data subject. Solely automated significant decisions are permitted subject to safeguards: notice to the data subject, a right to obtain human intervention, a right to make representations, and a right to contest the decision. Special-category data (health, race, political opinion, trade-union membership, and similar) retains the stricter Article 22-style regime unless a lawful exception applies. The Secretary of State may make regulations defining "meaningful human involvement" and adequate safeguards.
This reform changes the legal baseline for AI-assisted and AI-driven decisions in lending, hiring, benefits, policing, and similar contexts. DSIT frames it as providing clarity for AI deployment; civil-society critics characterise it as a loosening of AI accountability. (Source: source summary)
Recognised Legitimate Interests
The Act creates a new lawful basis, Recognised Legitimate Interests (RLI), for specified processing without a balancing test. The listed bases are national security, emergency response, safeguarding, and crime prevention, and the list is expandable by statutory instrument. AI training is not listed; a text-and-data-mining exception for AI training was debated during the Lords stages and withdrawn.
Scientific research clarification
The Act clarifies that "scientific research" in UK GDPR explicitly includes commercial research, and permits broad consent for "an area of scientific research", under which data subjects may consent at a high level of generality. Commentary from the FT, Linklaters, and Bird & Bird notes this could reduce friction for AI-training pipelines framed as research, though it does not create a standalone AI-training exemption.
ICO-to-Information-Commission reform (Part 6)
Part 6 reconstitutes the Information Commissioner's Office as the Information Commission, a corporate body with a board structure. It adds enforcement powers, including higher fines for nuisance communications and powers to compel witnesses. It imposes a new statutory duty to have regard to (a) innovation and competition, (b) public safety, and (c) children's interests. The innovation duty is the most contested feature of Part 6: civil-society critics including the Ada Lovelace Institute and the Open Rights Group argue it weakens regulator independence on AI matters.
Copyright and AI training (deferred)
Baroness Kidron's amendments, which would have required disclosure of copyrighted training data and rightsholder opt-out mechanisms, were defeated after an extended Lords–Commons standoff. The government committed to a separate consultation and a report to Parliament within 9 months of Royal Assent (by March 2026). As of April 2026 the consultation outcome was still pending. Rightsholder groups including the Society of Authors, the News Media Association, and the Creators' Rights Alliance treated the defeat of the Kidron amendments as a major loss, while AI developers treated the deferral as a favourable outcome; the pending consultation remains a second contest yet to be resolved.
Smart Data framework (Part 1)
Part 1 establishes a generic framework for customer-data portability across sectors, extending an Open Banking-style model beyond banking. It is not directly AI-specific but may enable AI-driven, data-intensive services.
Digital Verification Services (Part 2)
Part 2 creates a statutory trust framework for third-party identity-verification providers. It is not AI-specific but is relevant to verification pipelines that deploy AI models.
Comparison with other approaches
The Act's coverage is data-protection-only, with AI-specific rules deferred to a promised separate bill (see UK AI Bill — Status and Delay (Source Summary)), in contrast to comprehensive and sector-specific regimes elsewhere.
| Regime | AI scope | Frontier duties | ADM rules |
|---|---|---|---|
| UK DUAA 2025 | Data-protection only; AI deferred to promised separate bill | None | Article 22 loosened: solely automated significant decisions permitted with safeguards |
| EU AI Act (Regulation 2024/1689) | Comprehensive horizontal AI statute | Yes (GPAI Annex VIII/IX) | Tighter Art. 22 retained under GDPR |
| California SB 53 — Transparency in Frontier AI Act | Frontier transparency | Yes | N/A (not a data law) |
| Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) | High-risk decisions | No | Duty of care on deployers |
| Texas Responsible AI Governance Act (TRAIGA / HB 149) — Source Summary | Intent-based prohibited uses + sandbox | No | N/A |
| China (multiple) | Generative AI interim measures; algorithm recommendation rules | Yes | Regulated under PIPL |
Reactions and debates
DSIT argues that the automated-decision-making reform provides certainty for AI deployment, while the Ada Lovelace Institute, the Open Rights Group, and Connected by Data warn that it weakens protections. The new Information Commission innovation duty adds to this disagreement by requiring the regulator to weigh innovation explicitly against individual rights. Commentary frames the UK posture under the Act as light-touch and pro-innovation relative to other major jurisdictions; the government's preference for data-protection incrementalism combined with voluntary AISI access, rather than horizontal AI regulation, is embedded in statute through the Act.
Because the Act is data-protection legislation rather than AI legislation, algorithmic accountability, foundation-model governance, and AI-specific transparency are left to the separately delayed AI Bill (see UK AI Bill — Status and Delay (Source Summary)). The result is partial coverage of AI risks via data-protection law, alongside voluntary arrangements via the AI Safety Institute (AISI), with no statutory AI regime. AISI continues to operate pre-deployment access arrangements with Anthropic, OpenAI, and Google DeepMind on a voluntary basis; the Act does not change this, and the UK retains no statutory mechanism to compel model access, capability evaluation, or incident reporting. That gap is expected to be filled narrowly by the AI Bill, which remains delayed.
The loosening of the automated-decision-making rules and the new RLI bases increase UK–EU regulatory distance. Legal commentary flags adequacy-decision risk, although the European Commission reconfirmed UK adequacy through 2031 in December 2025.
The Act is the first UK statute with material AI-relevant provisions, though deliberately narrow in scope, and its deferral of the copyright-versus-training question leaves that issue unresolved as a data point for AI Copyright Litigation — Analysis globally. The voluntary baseline for frontier-lab governance in the UK is unchanged by the Act (see UK AI Safety Institute (AI Security Institute) and UK AI Bill — Status and Delay (Source Summary)).
Relationships
- related: UK AI Bill — Status and Delay (Source Summary) — the separately delayed AI-specific bill DUAA does NOT substitute for
- related: UK AI Safety Institute (AI Security Institute) — DUAA does not give AISI statutory footing or compel model access
- contradicts: none in the wiki currently
- related: EU AI Act (Regulation 2024/1689) — contrast: comprehensive AI regulation vs. UK's data-protection-only approach
- related: EU General-Purpose AI Code of Practice (Final Version, 2025) — EU's GPAI governance has no UK equivalent post-DUAA
- related: Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment), California SB 53 — Transparency in Frontier AI Act, Texas Responsible AI Governance Act (TRAIGA / HB 149) — Source Summary — contrasting state-level AI activity in a jurisdiction with no national AI statute
- related: AI Copyright Litigation — Analysis — UK deferred the copyright question; Kidron amendments defeated
- depends-on: The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), Frontier AI Safety Commitments (Seoul, 2024) — the voluntary framework DUAA leaves in place
- related: Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race — parallel dynamic: UK and US both leaving frontier-AI rules to sub-national or voluntary regimes
Sources
- DUAA source summary
- Raw text: (Source: Raw Sources/UK Data Use and Access Act 2025.md)
- Legislation.gov.uk:
https://www.legislation.gov.uk/ukpga/2025/18/contents - Parliamentary record:
https://bills.parliament.uk/bills/3825