Data & Regulation

UK GDPR Regulatory Updates

Published by ScaleUp Accounting Ltd — June 2026

The Data Use and Access Act 2025 has brought important changes to the UK data protection landscape. Here is what small businesses and our accounting clients need to know for 2026.

The Data Use and Access Act 2025

The Data Use and Access Act 2025 received Royal Assent in June 2025 and came into force progressively through 2025 and 2026. It amends UK GDPR and the Data Protection Act 2018, with the stated aim of reducing compliance burdens on UK businesses while maintaining robust protections for individuals.

Key changes include a clearer and broader legitimate interests framework (reducing reliance on consent in some business contexts), reformed rules on automated decision-making, and a more proportionate approach to the requirement to maintain detailed records of processing activities for smaller organisations. The ICO has published updated guidance to help businesses apply these changes.

What Stays the Same

Despite the changes introduced by the Act, the core framework of UK GDPR remains substantially intact. Businesses must still: identify a lawful basis before processing personal data; maintain appropriate security measures; respond to data subject access requests within one calendar month; notify the ICO of reportable breaches within 72 hours; and ensure data transfers to countries outside the UK comply with the international transfer regime.

The data subject rights of access, rectification, erasure, portability, and objection are all preserved under the new Act.

Impact on Payroll and Accounting Data

Accounting and payroll functions inherently involve processing personal data — employee names, addresses, National Insurance numbers, pay and tax records, and bank details. These processing activities are typically covered by the legal obligation basis under UK GDPR (Article 6(1)(c)), as payroll and tax compliance are statutory requirements.

However, businesses must ensure that employees are properly informed of how their data is used (through a staff privacy notice), that data is retained only for as long as legally required (generally six years for payroll records in line with HMRC guidance), and that access to payroll data is appropriately restricted.

Action Checklist for 2026

  • 01.Review and update your privacy policy and staff privacy notice to reflect the changes introduced by the Data Use and Access Act 2025.
  • 02.Confirm your ICO registration is current and that the fee tier is correct for your organisation size.
  • 03.Check that any data processors you use (including cloud software, payroll providers, or accountants) have appropriate data processing agreements in place.
  • 04.Document your lawful basis for each category of personal data you process — updated ICO templates are available at ico.org.uk.
  • 05.Review your data breach response procedure to ensure your 72-hour notification obligations are clearly understood by relevant staff.
Frequently Asked Questions

Does UK GDPR still apply after Brexit?

Yes. The UK retained GDPR into domestic law as UK GDPR, supplemented by the Data Protection Act 2018. The Data Use and Access Act 2025 has since amended certain aspects of UK GDPR to reduce administrative burden on businesses, but the core obligations — including lawful basis for processing, data subject rights, and breach notification — remain in force.

What is the Data Use and Access Act 2025?

The Data Use and Access Act 2025 is UK legislation that modernises aspects of the data protection framework. Key changes include a more flexible approach to legitimate interests, reduced administrative requirements for record-keeping in some cases, and updated rules on automated decision-making. It also establishes a new information governance framework for public bodies.

Does my small business need to register with the ICO?

Most businesses that process personal data must pay a data protection fee to the ICO (Information Commissioner's Office), unless they qualify for an exemption. Exemptions apply to some organisations processing data only for staff administration, accounts, or personal purposes. Check the ICO self-assessment tool at ico.org.uk to confirm your position.

How do accounting firms handle client GDPR compliance?

As your accountant, ScaleUp Accounting Ltd is a data controller for the personal data you share with us about your business and its directors, employees, and clients where relevant. We are also a data processor when we process personal data on your behalf (e.g. payroll). We maintain a data processing agreement framework and operate under our published Privacy Policy.

What should I do if my business suffers a personal data breach?

You must assess whether the breach is likely to result in a risk to individuals' rights and freedoms. If so, you must report it to the ICO within 72 hours. If the breach is likely to result in a high risk to individuals, you must also notify those individuals without undue delay. Maintain a record of all breaches, including those not reported, in your breach register.

Data protection in your accounting practice

ScaleUp Accounting Ltd handles all client data under strict confidentiality and in compliance with UK GDPR. Contact us to understand how we protect your financial records.

Get in Touch