Svetlova LLP

The UK Data (Use and Access) Bill 2025

June 17th, 2025

The UK Data (Use and Access) Bill 2025 is a significant piece of legislation set to reshape the data landscape and, by extension, the development and deployment of Artificial Intelligence in the UK. Having received parliamentary approval on June 11, 2025, and now awaiting Royal Assent (after which it will officially become the Data (Use and Access) Act 2025), this Bill introduces crucial changes that AI users must understand to ensure ongoing compliance.

What is the UK Data (Use and Access) Bill 2025?

The Data (Use and Access) Bill is the culmination of years of discussion and aims to modernise the UK’s data governance framework, building upon the foundations of the Data Protection Act 2018 and the UK GDPR. Its core objectives include unlocking the secure and effective use of data for public interest, promoting economic growth, and enhancing public services. While initially focused on broader data issues, its journey through Parliament saw significant debate regarding its implications for AI and copyright.

Key provisions of the Bill include:

* Smart Data Schemes: This is a central pillar, providing a legal framework to facilitate the secure sharing of customer data held by service providers (e.g., in finance, energy, and telecoms) with authorised third parties, upon customer request. This aims to foster competition and innovation by enabling new products and services.

* Digital Verification Services: The Bill establishes a statutory framework for digital identity providers, bringing them under government oversight.

  * Reforms to UK GDPR: While retaining the core principles of the UK GDPR, the Bill introduces some notable adjustments:

    – Clarification on Legitimate Interests: It sets out a limited number of processing activities for which “recognised legitimate interests” can serve as a lawful basis, reducing the need for a full legitimate interests assessment (LIA) in certain cases (e.g., direct marketing, intra-group data sharing, network security).

    – Streamlined Data Subject Access Requests (DSARs): Organisations’ obligations to conduct searches for information in response to DSARs are clarified as being “reasonable and proportionate.”

– Automated Decision-Making (ADM): The rules around solely automated decision-making are relaxed, offering more flexibility for AI systems, though a stricter regime will apply to special category data, and new terminology like “significant decision” and “meaningful human involvement” are introduced.

* Data Transfers: The Bill introduces subtle changes to the UK data transfer regime, which the European Commission is currently assessing to determine its impact on the UK’s adequacy decision.

* Enhanced Enforcement Powers for the ICO: The Information Commissioner’s Office (ICO) will have increased maximum fines under the Privacy and Electronic Communications Regulations (PECR) and generally enhanced enforcement capabilities.

  * New Offences for Deepfakes: Notably, Parliament used the Bill to add new offences in respect of sexually explicit images created without consent, a direct response to the rise of malicious deepfake technology.

* AI and Copyright: While the Bill itself does not introduce comprehensive AI-specific copyright protections as some had advocated, the government has committed to publishing reports on its AI and copyright proposals, including on enforcement and AI models trained abroad, within nine months of the Bill receiving Royal Assent.

Advice for AI Users: Staying Compliant

For any organisation leveraging AI, compliance with the new Data (Use and Access) Act will be paramount. Here’s practical advice to keep you compliant:

  1. Re-evaluate Your Lawful Bases for Data Processing: Leverage Recognised Legitimate Interests, Conduct Thorough LIAs Where Required. If you rely on consent, ensure it remains freely given, specific, informed, and unambiguous, particularly when personal data is used to train or operate AI models.
  2. Review and Update Your Data Protection Impact Assessments (DPIAs):
  3. Pay close attention to potential biases in your AI models and how you plan to mitigate them.
  4. Be transparent with individuals when automated decision-making is in play, explaining the logic involved, its significance, and potential consequences. Ensure individuals have a right to contest such decisions.
  5. Ensure Data Minimisation and Accuracy:
  6. Strengthen Data Governance and Accountability:
  7. Stay Abreast of AI and Copyright Developments: While the Bill itself did not enshrine specific AI copyright protections, the government’s commitment to further reports and potential legislation means this area is still evolving. Be mindful of the data used to train your AI models, particularly if it includes copyrighted material. The issue of copyright infringement in AI training data remains a hot topic and a potential area of legal risk.
  8. Consider Cross-Border Data Transfers: If your AI operations involve data transfers to or from the EU, closely monitor developments in this area and be prepared to implement alternative transfer mechanisms if adequacy is withdrawn or modified.

The UK Data (Use and Access) Bill 2025 marks a significant step in the evolution of data governance in the UK. For AI users, it presents both opportunities for innovation through increased data access and a reinforced imperative for robust data protection compliance. By proactively understanding and adapting to these changes, AI users can navigate the new legal landscape successfully and continue to harness the transformative power of artificial intelligence responsibly.

The highly experienced team at Svetlova LLP can help you navigate the changes in data regulations. Call us for a confidential chat on tel. 02033759040 or send us an email enquiry at tsvetlova@svetlovallp.com