The Data (Use and Access) Act 2025 (DUAA) received royal assent back on 19 June 2025 and introduces several changes that directly affect how employers handle employee data.
While the Act aims to promote innovation and simplify data protection, it also places new responsibilities on organisations, particularly HR teams, who are often on the frontline of managing data requests and complaints.
Below, we’ve outlined the key changes and what they mean now fully in practice.
Subject Access Requests (SARs)
Employees have the right to request copies of the personal data an employer holds on them.
- Employers are now only required to carry out “reasonable and proportionate” searches when responding
- The one-month deadline to respond remains in place (with a possible two-month extension for complex cases)
- Employers can pause the response timeframe if further information is needed from the employee before proceeding
This clarification is welcome, but it does not significantly change how requests have been managed since 2020.
Automated Decision-Making (ADM)
ADM refers to decisions made about individuals without human involvement, for example, certain recruitment tools, rota scheduling, or performance scoring systems.
- ADM remains restricted unless it’s:
- Required by law
- Necessary for a contract
- Done with employee consent (though consent is rarely valid in employment contexts)
- The DUAA relaxes restrictions slightly, but employers must still:
- Inform individuals if ADM is being used
- Allow them to challenge decisions or request human review
- Have a lawful basis for processing data
- Using sensitive data (health, ethnicity, etc.) for ADM remains heavily restricted
Employers should review any HR technology that involves automated decision-making to ensure compliance.
New lawful basis – recognised legitimate interests
The DUAA introduces a new lawful ground for processing personal data: recognised legitimate interests.
- This removes the need for employers to balance the organisation’s interests against the employee’s rights in certain, pre-approved situations
- Further guidance will follow from the Information Commissioner’s Office (ICO)
This may simplify compliance for common business activities, but employers must stay alert for updates.
Employee complaints
One of the most notable changes is the new right for employees to raise data complaints directly with their employer before going to the ICO.
- Employers must:
- Acknowledge complaints within 30 days
- Investigate promptly
- Keep employees updated on progress
This change means HR teams must have a clear, documented internal complaints procedure for data-related issues.
What employers should do now
To prepare for full compliance with the DUAA, employers should:
- Update data protection policies – especially SAR handling, to reflect the new “reasonable and proportionate” standard
- Audit automated systems – ensure human oversight is possible and staff are informed of their rights
- Introduce or revise complaint-handling processes – including training HR staff on how to manage data complaints
- Train HR and management teams – so they understand the new obligations
- Monitor ICO guidance – more detail and codes of practice are expected in late 2025 and early 2026
Final thoughts
While the Data Act 2025 simplifies some areas of data protection, it also creates new pressure points for employers. HR teams will need to respond quickly to complaints and be proactive in reviewing data processes.
At Elcons, our experts and in-house advocates are here to support you in preparing for these changes, helping you stay compliant while managing your workforce effectively.
📞 Contact us today for further advice: 0800 014 9595