What changed
On 5 February 2026, the Information Commissioner’s Office confirmed that most remaining data protection provisions of the Data (Use and Access) Act had commenced.
The main exception is the new complaints procedure requirement, which is due to take effect on 19 June 2026. The ICO also confirmed that it had updated guidance in several areas and highlighted stronger enforcement powers, including higher potential fines under PECR.
What does this mean in simple terms?
In practical terms, this means the UK data protection framework has moved on. Organisations should now review whether their policies, procedures and compliance documents still reflect the current law rather than the previous position. That includes the records, governance and evidence expected under the accountability principle under UK GDPR. It also includes reviewing whether higher-risk processing activities require a Data Protection Impact Assessment (DPIA). It also includes reviewing any overseas suppliers or platforms in light of International Data Transfers Under UK GDPR Explained. Where direct marketing or cookie compliance is part of that review, see our guide What is PECR? A practical guide to the Privacy and Electronic Communications Regulations.
Why this matters
This is not just a technical legal update. It is a key review point for UK organisations handling personal data, particularly where privacy governance, subject access requests (SARs), complaints processes, direct marketing, international transfers, or law enforcement processing are involved.
The fact that the complaints procedure requirement is delayed until 19 June 2026 gives organisations a short preparation window, but the wider commencement means businesses should already be updating their understanding of the framework. You can also monitor future developments through the Regulatory Updates page.
What organisations should do
Organisations should consider taking the following steps now.
- Review privacy policies, internal procedures and guidance notes to make sure they reflect the current legal position.
- Prepare a documented process for handling data protection complaints ahead of 19 June 2026.
- Check whether staff handling subject access requests, complaints, transfer arrangements or marketing compliance need updated internal guidance.
- Review PECR risk exposure, particularly where electronic marketing practices could attract higher fines.
Practical takeaway
Organisations should treat 5 February 2026 as a meaningful compliance review point. The legal framework has shifted, guidance has been updated, and complaints handling should now be prepared in advance of the June commencement date.
Grounded in
Data (Use and Access) Act commencement changes confirmed by the ICO on 5 February 2026, including updated guidance areas and the delayed commencement of the complaints procedure requirement until 19 June 2026.
Sources
- Information Commissioner’s Office: statement on the commencement of the Data (Use and Access) Act , February 2026.
- ICO guidance updates relating to accountability, complaints handling, subject access, international transfers and enforcement context.