The Data Use and Access Bill

The Data Use and Access Bill

The Data Use and Access Bill (the “Bill”) was first announced in October 2024 and is largely considered to be an evolutionary step in the UK data protection regime. The Bill is heavily backed by the Information Commissioner’s Officer (“ICO”) and is expected, providing Royal Assent is obtained, to come into force later this year (2025).

At its core, the Bill sets out to facilitate the use of innovation to promote growth of the UK economy, providing organisations with additional regulatory certainty, whilst at the same time maintaining data protection levels and the essential rights and freedoms of individuals.

Some of the more significant aspects of the Bill are as follows:

  • Processes for international transfers will be streamlined. The bill proposes a new approach to the adequacy test used by the UK government to assess whether countries or international organisations provide an adequate level of data protection, such that personal data can be sent to them without additional safeguards. Where the destination country or organisation does not possess an adequacy decision, data controllers will need to conduct a Transfer Impact Assessment to assess the risks involved in transferring data, before they do so.
  • Under certain conditions, consent will no longer be needed for the use of tracking technologies and cookies, particularly ‘non-intrusive’ ones; however, the maximum fine will be increased as will the scope for enforcement, which could be extended to website publishers rather than the adtech vendors themselves.
  • More enforcement powers will be afforded to the ICO, including the ability to sanction those who fail to comply with the new regulations.
  • There will be additional protective duties to comply with when handling data concerning children.
  • Introduction of a new Digital Verification Services (“DVS”) trust framework which will set out criteria that, if met, will enable DVS providers to be listed on a statutory register which will grant them access to an “information gateway” where public bodies can disclose information to them, without it constituting a breach of the legislation.
  • Introduction of a concept of “recognised legitimate interests” which will allow personal data to be processed without undertaking the balancing assessment currently required to consider whether the organisation’s interests outweigh the individual’s privacy rights. Some examples in the Bill include processing necessary for direct marketing, ensuring the security of IT systems, and intra-group transfers for internal administrative purposes. The list can be added to by secondary legislation.
  • Information standards for suppliers of IT services to the health and social care sector will be standardised and made mandatory. The aim is to facilitate data sharing and aid innovation between organisations in the health, scientific research and technology sectors.
  • Subject to the relevant safeguarding measures, organisations will be empowered to use automated decision making (although not using special category data) where the results provided are to a required standard, and where there is a recognised legitimate reason for its use.
  • There will be scope for new categories of special category data as and when required, enabling greater flexibility to keep up with societal and technological advancements.
  • Operators of artificial intelligence in the UK will be required to comply with UK copyright laws regardless of which country the copyright breaches take place in.

If you would like more information on how these changes may affect your business, please do not hesitate get in touch with our expert team.