UK GDPR Update: What the Data (Use and Access) Act 2025 Means for Organisations
While several updates under the Data (Use and Access) Act 2025 came into force on 5 February 2026, the next key development for organisations is still to come. From 19 June 2026, organisations will be legally required to implement a formal complaint handling process for data protection matters. This is a significant shift, placing greater emphasis on resolving issues internally before they escalate to the regulator.


The Changes
Any concern raised by an individual about how their personal data is handled, whether it relates to access requests, accuracy, retention, or security, must now be treated within a structured complaints framework.
Organisations will be required to:
- provide a clear and accessible way for individuals to raise complaints;
- acknowledge complaints within 30 days;
- investigate and respond without undue delay; and
- keep complainants informed throughout.
What it means in practice
This is more than a procedural update, as it requires organisations to embed complaints handling into their data protection governance.
To prepare, organisations should:
1. Formalise a complaints process - with a clear internal procedure that defines how complaints are logged, assessed, escalated, and resolved.
2. Train staff - ensure employees can recognise what constitutes a data protection complaint and know how to escalate it appropriately.
3. Update privacy notices - privacy information must explain how individuals can raise a complaint and what they can expect from the process.
4. Maintain records - keep an audit trail of complaints received, how they were handled, and outcomes reached. This will be critical in demonstrating compliance.
5. Align with DSARs and incident processes - complaints often overlap with data subject access requests (“DSARs”) or breach responses, so processes should be combined to avoid inconsistencies.
Why it matters
This change signals a clear regulatory direction:organisations are expected to take greater ownership of data protectionconcerns at an early stage. A well-handled complaint can reduce escalationrisk, reputational damage, and potential enforcement action.
In brief: The Data (Use and Access) Act 2025
Alongside this upcoming requirement, organisations should be aware of several updates under the Data (Use and Access) Act 2025that came into force on 5 February 2026, including:
- a new category of “recognised legitimate interests”;
- more flexible DSAR response rules;
- increased PECR fines;
- relaxed restrictions on certain AI-driven decisions;
- a broader definition of scientific research; and
- enhanced expectations around children’s data protection.
For more information on how our Corporate & Commercial Team can assist with navigating these changes, and how they may impact your organisation, please contact us via emailat info@leathesprior.co.uk or by telephone at 01603 610911.


EPCs for Non-Domestic Property: The Latest Changes
The UK Government has announced a significant change to its proposed approach to energy efficiency standards for non-domestic property in England and Wales. For owners, investors and occupiers of commercial property, this is one of the most important developments in the EPC regime since the introduction of MEES. Rebecca Millard, Senior Associate in our Commercial Property Team explains...



Leathes Prior advises Complete Strategy on sale to Flint Global
Alex Saunders, Partner in Leathes Prior's Corporate Team, advised Complete Strategy on the sale of its business to Flint Global. The acquisition marks Flint Global's first acquisition and represents the first step in its M&A growth strategy.

.jpg)

Maternity Services in England: Recent Reports and What They Mean for Families
In a follow up to our recent article on maternity safety, Polly Langford, Partner in our Personal Injury & Clinical Negligence Team has written on the findings of the Ockenden Report and what this means for families.




















%20cropped.jpg)






.jpg)

%20website.jpg)

.jpg)




%20cropped.jpg)
