The Data (Use and Access) Act 2025
A plain-English guide for adult social care providers in England — what’s changed, what hasn’t, and what to check.
- The Data (Use and Access) Act 2025: What It Means for Your Care Service
- A new option: “recognised legitimate interests”
- Clearer rules on responding to SARs
- More flexibility for automated decision-making — with extra protection for health data
- A formal right for people to complain to you directly
- The regulator has a new governance structure
- A note on your DSPT
- Your DUAA checklist
- Sources and further reading
If you’ve heard people in the sector mention “the DUAA” or “the new data law” over the past year, this article is for you. The Data (Use and Access) Act 2025 (DUAA) is now fully in force. It sits alongside the UK GDPR and the Data Protection Act 2018, updating parts of the existing framework rather than replacing it. The core duties around lawful processing, accountability, transparency and keeping personal information secure remain unchanged.
Previously, if you wanted to rely on “legitimate interests” as your lawful basis for using personal data, you had to carry out a formal balancing test every time. The DUAA introduces a shorter list of “recognised legitimate interests” — including certain activies such as safeguarding, preventing crime and protecting vulnerable individuals — where that full balancing test isn’t required.
What this means for you: For most day-to-day care data (like care plans and health information), you’ll likely continue relying on the same lawful bases you use now — this is more relevant to admin processing such as safeguarding referrals. It’s a helpful new option, not a requirement to change anything.
As adult social care providers routinely process special category data, they must still identify both an appropriate Article 6 lawful basis and a separate Article 9 condition for processing. The DUAA does not change this requirement.
The Act confirms that you only need to carry out “reasonable and proportionate” searches when responding to a subject access request (SAR) — you don’t need to search every possible location. It also formalises a “stop the clock” rule: if you genuinely need more information from the requester to identify them or understand the scope of their request, the one-month response clock pauses until they reply.
What this means for you: If a resident, family member, or staff member submits a SAR, you can now pause the timer while waiting for clarification — but only where it’s genuinely needed, not as a delaying tactic. Keep a record of when you paused and why.
The DUAA widens the situations in which organisations can use automated or AIassisted decision-making. Importantly, where a decision is based on special category data — including health and care information — the stronger existing safeguards still apply. These include meaningful human review before a solely automated decision significantly affecting an individual in relied upon, transparency about the decisionmaking process, and the ability for someone to challenge the outcome.
What this means for you: If your service doesn’t use automated decision-making tools (most care providers don’t, beyond basic rostering or scheduling software), this change has little practical effect day-to-day. If you do use any AI-assisted tools that influence decisions about residents, make sure a human always reviews the outcome.
This is the change with the most direct, practical impact. From 19 June 2026, individuals have a statutory right to raise a data protection complaint directly with your organisation. You must provide an accessible way for people to do this, acknowledge complaints without undue delay and within the statutory timescale, investigate them promptly, and let people know the outcome and any action taken.
What this means for you: Every provider needs a simple, written data protection complaints procedure — covering how people raise a concern, who handles it, and your 30-day acknowledgement commitment — referenced in your privacy notice. If you don’t already have one in place, this is the change to act on first.
The Data (Use and Access) Act establishes the Information Commission as the new statutory body responsible for regulating data protection. It replaces the previous corporation sole model with a board comprising a Chair (the Information
Commissioner), and a Chief Executive, and executive and non-executive members. The Act also gives the regulator additional investigatory powers. For most organisations, these governance changes do not require any action.
What this means for you: No action required. The Act establishes the Information Commission as the regulator’s new statutory body, but these governance changes do not alter your day-to-day data protection obligations.
The bottom line: the DUAA doesn’t ask you to rebuild your data protection practice from scratch. It builds on UK GDPR and the Data Protection Act 2018.
As adult social care providers routinely process special category data, they must still identify both an appropriate Article 6 lawful basis and a separate Article 9 condition for processing. The DUAA does not change this requirement.
Many providers have just completed their annual DSPT republish, and this is an ideal moment to make sure everything aligns. As you review your evidence against the National Data Guardian standards, take the opportunity to check that your complaints procedure, privacy notice, and SAR process all incorporate the DUAA updates outlined above.
Use this as a working checklist for your service. It’s designed to be referred back to, not completed in one sitting.
Use the button bellow to view the checklist
This article provides general guidance for adult social care providers in England and does not constitute legal advice. For advice on your organisation’s specific circumstances, consult a qualified data protection professional or the Information Commissioner’s Office (ICO).
This guide is based on the following legislation and official guidance:
https://www.gov.uk/government/publications/data-use-and-access-act-2025-factsheets
https://www.legislation.gov.uk/ukpga/2018/12/contents
https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/