UK

The UK’s data protection framework continues to evolve following the enactment of the Data (Use and Access) Act 2025 (DUAA). One of the more operationally significant developments for organisations is the introduction of a new statutory right for individuals to complain to controllers regarding infringements of the UK General Data Protection Regulation (GDPR), as well as a framework governing how controllers must handle those complaints.

The relevant provisions will apply from 19 June 2026, pursuant to the Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026. On or before that date, organisations subject to the UK GDPR will need to update their privacy notices, and introduce formal data protection complaint handling processes that meet specific legal requirements.

Continue Reading The Data (Use and Access) Act 2025 and the new right for individuals to complain to controllers: What organisations need to do before 19 June 2026

The UK’s data protection regime is undergoing its most significant transformation since the adoption of the UK GDPR. With the successful passage through both the House of Lords and the House of Commons on 11 June 2025, the Data (Use and Access) Act 2025 (“DUAA”) received Royal Assent on 19 June 2025. Positioned as introducing incremental change rather than major reform, the DUAA is intended to address the UK government’s aim to recalibrate the balance between privacy, innovation, and regulatory pragmatism with the ultimate goal of promoting economic growth.

Continue Reading The Data (Use and Access) Act 2025: A New Chapter in the UK’s Data Protection Framework

In our earlier blog on recent changes affecting the Competition and Markets Authority (CMA), we anticipated more changes to come. The month of March has lived up to our expectations. On 12 March, the CMA launched a “call for evidence” for the review of its approach to merger remedies as well as a “Mergers Charter” for businesses, stating that:

“Both the merger remedies review and the Mergers Charter are part of the CMA’s programme of work to implement the ‘4Ps’ – pace, predictability, proportionality and process – across all its work, helping to drive growth and enhance business and investor confidence.”[1]

Continue Reading Ch-ch-ch-ch-changes… Part 2

By repeating “ch-ch-ch-ch-changes” in his famous song, David Bowie was reportedly trying to mirror the stuttered steps of growth. January 2025 was a month full of changes for the UK Competition and Markets Authority (CMA). As with any changes, it is difficult to predict their effect precisely, only time will tell. Although we do not have a crystal ball, however, our longstanding and in-depth experience in UK competition law gives us unique insights on what to expect and most importantly how to adapt. In this update, we will cover some of these key changes including:   

  • The entry into force of the Digital Markets, Competition and Consumers Act (DMCCA) and related updated guidance.
  • An anticipated reform of the UK concurrency regime to extend to consumer protection.
  • The exercise by the CMA of its new DMCCA powers to designate companies with Strategic Market Status (SMS).
  • Last but not least, perhaps the changes that grabbed the headlines the most: the CMA has a new interim Chairperson and the UK government’s “steer” to the CMA’s CEO.
Continue Reading Ch-ch-ch-ch-changes… for the UK Competition and Markets Authority

The Data (Use and Access) Bill (“DUA Bill”)[1] had its second reading on 19th November 2024 after being introduced in the House of Lords on 23 October and the Bill is anticipated to enter the Lords’ Committee stage in December. According to the Department for Science, Innovation and Technology, the DUA Bill will harness the power of data to boost the UK economy by an estimated £10 billion, free up thousands of police and NHS staff time and secure the effective use of data for the public interest.[2] The DUA Bill proposes to amend both the UK General Data Protection Regulation (“UK GDPR”) and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECRs”), despite little weight being placed on this in the Government’s initial press release.

Continue Reading Unpacking the Proposed Data (Use and Access) Bill

In case you missed it, below are recent posts from Privacy World covering the latest developments on data privacy, security and innovation. Please reach out to the authors if you are interested in additional information.

Minnesota Makes 19: Will Rhode Island’s Privacy Law Replace Vermont’s Vetoed Privacy Law as #20? | Privacy World

Summarising the

In case you missed it, below are recent posts from Privacy World covering the latest developments on data privacy, security and innovation. Please reach out to the authors if you are interested in additional information.

The FCC’s Net Neutrality Order: Going Beyond Blocking, Throttling, and Fast Lanes | Privacy World

What Happened to the UK’s