Data Protection Changes: What Businesses Need to Know

Data Protection Changes: What Businesses Need to Know

Data Protection Changes: What Businesses Need to Know

The UK data protection landscape has seen some important changes following the implementation of the Data (Use and Access) Act 2025, with the Information Commissioner's Office (ICO) becoming the Information Commission from 30 September 2026.

While many of the updates will not significantly affect how businesses use personal information on a day-to-day basis, there are some key changes that organisations should be aware of to remain compliant and avoid potential penalties.

Changes to Complaints Handling

Businesses must now ensure they have a clear process for handling complaints relating to personal data. This includes:

  • Providing an electronic method for individuals to submit complaints.
  • Acknowledging complaints within 30 days.
  • Responding to concerns in a timely manner.

Having a transparent and accessible complaints procedure can help build trust with customers and demonstrate a commitment to data protection.

Updates to the Use of Personal Information

Organisations may now have more flexibility to use personal information for certain automated decision-making processes where they can demonstrate a legitimate business interest that outweighs any impact on an individual's rights and freedoms.

However, stricter protections remain in place for special category data, including information relating to ethnic origin, health information, religious beliefs, and sexual orientation.

There are also new provisions affecting charities, public-interest archiving, and law enforcement agencies, although these are unlikely to affect most small and medium-sized businesses directly.

Children's Data Remains a Priority

Businesses providing online services must continue to ensure that children's personal information is appropriately protected.

With increased regulatory focus on safeguarding young users online, organisations should review privacy notices, consent mechanisms, and data collection practices where children may access their services.

Cookie Rules Simplified

One welcome change for many website owners is that consent will no longer be required for certain cookies where their primary purpose is to improve website functionality.

This may simplify website compliance requirements, although businesses should still ensure their cookie policies remain accurate and up to date.

Stronger Regulatory Powers and Higher Penalties

The Information Commission has been granted enhanced enforcement powers, including the ability to compel witnesses to attend interviews and request additional information where necessary.

Businesses should also note that maximum fines for breaches of Privacy and Electronic Communications Regulations (PECR) have increased significantly and can now reach up to £17.5 million or 4% of global annual turnover, aligning them with major data protection breaches.

What Should Businesses Do Now?

To remain compliant, organisations should consider:

  • Reviewing privacy policies and data protection procedures.
  • Ensuring complaints processes meet the new requirements.
  • Checking website cookie policies and consent mechanisms.
  • Assessing how personal data is collected, stored, and used.
  • Providing regular data protection training for staff.

Need Advice?

Data protection regulations continue to evolve, and keeping up with changes can be challenging. If you're unsure whether your business processes meet current requirements, seeking professional advice can help reduce risk and ensure compliance.

For guidance on business compliance and best practice, please get in touch with our team. We're here to help.

Payroll Hub
Payroll Hub