Most businesses missed it. On 19 June 2026, new legal requirements came into force under the Data (Use and Access) Act 2025, and most business owners have no idea it happened. That is not a criticism. It is a busy piece of law with a quiet rollout. The consequences of doing nothing are real, and worth understanding.
The Data (Use and Access) Act 2025 is the most significant update to UK data protection law since GDPR arrived eight years ago. It does not replace UK GDPR. It amends it, in ways that directly affect how businesses handle personal data.
From 19 June 2026, every organisation that processes personal data is legally required to have a data protection complaints procedure in place. There is no exemption, regardless of size. That means a written policy, a route for people to submit complaints, and a 30 day acknowledgement requirement. Without it, you are already outside the rules.
Privacy notices need to reflect the new complaints right. If your policy was written before this year and has not been reviewed since, it almost certainly does not include what it now needs to.
The maximum fine for breaches of PECR, the regulation covering email marketing and cookies, rose from £500,000 to £17.5 million. If you send marketing emails or use cookies on your website, that is the environment you are now operating in.
At a minimum, UK businesses now need:
Most businesses already have some version of these documents. The issue is that they were written under the old rules and have not been updated since.
Worth checking at the same time: whether your cookie banner actually blocks tracking until consent is given. That is one of the most common gaps I find, and it sits alongside the other pre-launch checks in what a proper website launch actually includes.
I offer a fixed-fee DUAA Compliance Update at £450.
The service covers a full review of your existing privacy policy and compliance documents, updates based on solicitor-drafted DUAA templates, a ready-to-publish privacy policy tailored to your business, a data protection complaints policy and acknowledgement template, and a plain-English summary of what changed and why. Everything delivered within five working days.
These documents are based on professionally drafted legal templates. I am not a solicitor and this is not legal advice. For the vast majority of businesses this service covers exactly what you need. If your situation is more complex, I will tell you upfront.
Yes. The requirement applies to every organisation that processes personal data, including sole traders and partnerships. If you have a contact form, a mailing list or a booking system on your website, this applies to you.
Almost certainly. Privacy policies written before 2026 will not include the new complaints right or reflect the updated legal position under the DUAA. The question is not whether you have a policy, it is whether it matches current law.
Having documents is a good start. The issue is that documents written under the old rules do not reflect what the law now requires. An update is faster and cheaper than starting from scratch, which is exactly what this service covers.
No. MARS is a digital marketing consultancy rather than a law firm. The documents are based on solicitor-drafted templates and reflect current UK data protection law. If your business has complex data processing needs, I will say so and point you toward the right specialist.
Consent settings affect what your analytics can record, which affects every decision you make from that data. If you want the compliance work and the tracking looked at together, the Marketing Audit covers both alongside website, SEO and paid search.
The deadline has passed. The longer this sits, the longer your business runs without the documentation the law now requires. If you would like it sorted, use the link below and I will come back to you within one working day.

Free
SEO Audit