Back to Frameworks

Data (Use and Access) Act 2025

United Kingdom
v1.0
7 domains
18 controls

The Data (Use and Access) Act 2025 amends and supplements the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003. It introduces new rules on data sharing, access, and use, aiming to facilitate responsible data use while maintaining strong privacy protections.

Verified

Data (Use and Access) Act 2025 is a compliance framework from United Kingdom with 7 domains and 18 controls that map to 2 other frameworks. The largest domains are DUAA 2025: Part 5 - Data Protection and Privacy Reforms (8 controls), DUAA 2025: Part 1 - Access to Customer and Business Data (Smart Data) (3 controls), DUAA 2025: Part 2 - Digital Verification Services (3 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

DUAA 2025: Part 1 - Access to Customer and Business Data (Smart Data)

3 controls
Controls in the DUAA 2025: Part 1 - Access to Customer and Business Data (Smart Data) domain of Data (Use and Access) Act 20253 controls
CodeTitle
DUAA-P1-AUTHAuthorised persons and accreditation under smart data schemes
DUAA-P1-FEESENFFees, levies and enforcement of smart data schemes
DUAA-P1-SMARTDATASmart data schemes for customer and business data

DUAA 2025: Part 2 - Digital Verification Services

3 controls
Controls in the DUAA 2025: Part 2 - Digital Verification Services domain of Data (Use and Access) Act 20253 controls
CodeTitle
DUAA-P2-DVSDigital verification services and the DVS trust framework
DUAA-P2-GATEWAYInformation gateway for identity verification
DUAA-P2-TRUSTMARKDVS trust mark usage

DUAA 2025: Part 3 - National Underground Asset Register

1 controls
Controls in the DUAA 2025: Part 3 - National Underground Asset Register domain of Data (Use and Access) Act 20251 controls
CodeTitle
DUAA-P3-NUARNational Underground Asset Register

DUAA 2025: Part 4 - Registers of Births and Deaths

1 controls
Controls in the DUAA 2025: Part 4 - Registers of Births and Deaths domain of Data (Use and Access) Act 20251 controls
CodeTitle
DUAA-P4-REGISTERSDigitisation of registers of births and deaths

DUAA 2025: Part 5 - Data Protection and Privacy Reforms

8 controls
Controls in the DUAA 2025: Part 5 - Data Protection and Privacy Reforms domain of Data (Use and Access) Act 20258 controls
CodeTitle
DUAA-P5-ADMAutomated decision-making reforms
DUAA-P5-CHILDRENChildren's data protection by design (ISS)
DUAA-P5-COMPLAINTSComplaints to data controllers
DUAA-P5-DSRData subject access requests (reasonable and proportionate searches)
DUAA-P5-LAWFULLawful processing and recognised legitimate interests
DUAA-P5-PECRPECR reforms (cookies, direct marketing, penalties)
DUAA-P5-RESEARCHResearch, statistics and archiving processing
DUAA-P5-TRANSFERSInternational transfers data protection test

DUAA 2025: Part 6 - The Information Commission

1 controls
Controls in the DUAA 2025: Part 6 - The Information Commission domain of Data (Use and Access) Act 20251 controls
CodeTitle
DUAA-P6-INFOCOMMThe Information Commission

DUAA 2025: Part 7 - Other Provision (Health Information Standards)

1 controls
Controls in the DUAA 2025: Part 7 - Other Provision (Health Information Standards) domain of Data (Use and Access) Act 20251 controls
CodeTitle
DUAA-P7-HEALTHInformation standards for health and adult social care

Maps to 2 other frameworks

18 total controls
GDPR
4 source controls mapped|4 target controls covered
22%
ISO 27701:2019
1 source controls mapped|1 target controls covered
6%

What is Data (Use and Access) Act 2025 and who does it apply to?

Data (Use and Access) Act 2025 is a compliance framework from United Kingdom with 7 domains and 18 controls. The Data (Use and Access) Act 2025 amends and supplements the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003. It introduces new rules on data sharing, access, and use, aiming to facilitate responsible data use while maintaining strong privacy protections. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Data (Use and Access) Act 2025 actually require?

Data (Use and Access) Act 2025 has 18 controls organised across 7 domains. The largest domains are DUAA 2025: Part 5 - Data Protection and Privacy Reforms (8 controls), DUAA 2025: Part 1 - Access to Customer and Business Data (Smart Data) (3 controls), DUAA 2025: Part 2 - Digital Verification Services (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Data (Use and Access) Act 2025 do I already cover?

Data (Use and Access) Act 2025 maps to 2 other compliance frameworks. The top mapping partners are GDPR (22% coverage), ISO 27701:2019 (6% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Data (Use and Access) Act 2025?

Start your Data (Use and Access) Act 2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Data (Use and Access) Act 2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 18 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required