Skip to content
Blog/Compliance

The DUAA Is Now in Force: Four Changes Your Business Must Act On

The DUAA is no longer a future compliance date. Cookie exceptions, complaint handling and higher PECR penalties are now live. This is the practical work most small businesses need to finish.

//Updated //8 min read
Business manager testing cookie consent and a data protection complaints process on laptop and phone

The deadline has passed. On 19 June 2026, the final data protection provisions of the Data (Use and Access) Act 2025 came into force. The ICO now states that all DUAA provisions affecting data protection law and the Privacy and Electronic Communications Regulations are live.

That matters because much of the advice published when the Act received Royal Assent was written as a preparation guide. Businesses were told to wait for final cookie guidance and prepare for a complaint-handling duty expected around June 2026. Both have happened.

For a small business, the work is still manageable. It is also more specific than “review GDPR”. Four changes deserve attention now.

1. The DUAA amends the rules you already follow

The Data (Use and Access) Act 2025 does not replace the UK GDPR, the Data Protection Act 2018 or PECR. It changes them. Your existing privacy notices, lawful bases, retention rules and individual-rights procedures still matter.

This distinction prevents the first common mistake: treating DUAA as a fresh compliance framework that requires a new folder of policies. Most small organisations need targeted changes to existing procedures, not a second data protection system.

The ICO's current overview for organisations covers a wider set of reforms, including recognised legitimate interests, reasonable and proportionate searches for information, automated decision-making and research. The sections below concentrate on the changes most likely to alter an ordinary small business's website or daily operations.

The ICO finalised its updated guidance on storage and access technologies on 29 April 2026. It describes five circumstances in which information may be stored on or read from a person's device without prior consent:

  • transmission of a communication;
  • technology strictly necessary to provide a service the user requested;
  • statistical information about use of the service, collected to improve it;
  • adapting the service's appearance or functionality to the user's preference; and
  • locating a person who needs emergency assistance.

The statistical and appearance exceptions are the changes most websites will notice. They are not permission to relabel every tracker as “analytics”. The sole purpose must fit the exception. Statistical information must be aggregated and used to improve the service, not to identify people, build advertising audiences or follow them across sites.

For both exceptions, the business must explain the use clearly and provide a simple, free way to object. If a visitor objects, the storage or access must stop. If one technology serves an exempt purpose and a non-exempt advertising purpose, consent is still required.

The practical test: make a list of every cookie, pixel, tag and local-storage item on the site. Record its provider, purpose, retention period and whether personal data is involved. Map each purpose to a specific exception or to consent. Do not decide by the product's name. A familiar analytics tool can be configured in ways that fall inside or outside the exception.

Many brochure websites can now make their controls shorter and clearer. Sites running remarketing, behavioural advertising, embedded third-party media or cross-site measurement will usually still need a consent mechanism for those uses.

3. The complaints process is a live duty

Since 19 June 2026, every organisation handling personal data must have a process for data protection complaints. The ICO says there are no exemptions.

The law requires organisations to:

  • give people a way to make a data protection complaint;
  • acknowledge receipt within 30 days;
  • make appropriate enquiries and respond without undue delay;
  • keep the complainant informed while the matter is open; and
  • communicate the outcome without undue delay.

You do not have to buy a complaints portal or create a separate form. The ICO's complaints guidance for organisations allows an existing email address, form, telephone route, live chat, portal or in-person process. What matters is that the route is clear and the process works.

There is a second operational detail that a privacy-policy edit will not solve: people may complain through any channel. A customer might email an account manager or an employee might raise the issue with their line manager. Staff need to recognise that the message concerns personal-data handling and know where to send it. The acknowledgement clock starts when the organisation receives the complaint, not when it reaches the person responsible for privacy.

A workable small-business setup: publish a clear route in the privacy notice, nominate an owner and a deputy, create acknowledgement and outcome templates, keep a simple complaint log, and give staff a one-paragraph escalation instruction. Test the route once, including the hand-off from a general inbox.

4. PECR enforcement now has GDPR-scale ceilings

PECR covers more than cookie banners. It also governs electronic marketing, including email, text messages and automated calls.

The DUAA gives the ICO power to impose much higher penalties. For infringements in the higher tier, the statutory maximum is £17.5 million or 4% of worldwide annual turnover, whichever is higher. The explanatory notes also set a standard maximum of £8.7 million or 2% for other listed infringements.

Those figures are ceilings, not forecasts. The ICO considers the circumstances and must act proportionately. A ten-person business should not read “£17.5 million” as the likely price of one mistaken email. It should read the change as a clear end to treating marketing consent and tracking as low-stakes administration.

Audit where marketing contacts came from, which PECR rule supports each campaign, whether the unsubscribe route works, and whether suppression lists are respected. Bought and scraped data deserve particular scrutiny. Consent under data protection law and permission to send electronic marketing are related questions, but they are not interchangeable.

What to finish in the next 30 days

Do this in one pass rather than opening four disconnected compliance projects:

  1. Inventory website technologies. Record every cookie, pixel, tag and similar technology, including what it does after consent is refused.
  2. Classify each purpose. Use the ICO's five exceptions. Keep consent for anything outside them, especially advertising and tracking.
  3. Test the controls. Confirm that objecting or withdrawing consent stops the relevant technology, not merely changes the banner.
  4. Publish a complaints route. Add it to the privacy notice or existing complaints page in plain language.
  5. Assign the workflow. Name an owner and deputy, create a log and templates, and make sure all staff know how to escalate a complaint.
  6. Audit electronic marketing. Check the origin of each list, the applicable PECR rule, unsubscribe handling and suppression records.
  7. Record the review. Date the decisions and the evidence used. This is what turns a policy statement into accountable practice.

DUAA is not the same exercise as cyber security certification, but the owners and evidence often overlap. If your team is also preparing for the current Cyber Essentials requirements, schedule the two reviews together and keep the scopes separate.

The useful outcome is a working route, not a thicker policy

The legislation creates opportunities as well as duties. A carefully configured site may ask fewer pointless questions about low-risk analytics. A clear complaints route gives a customer a chance to resolve a problem with you before escalating it to the ICO.

Neither benefit appears if the work ends with replacing dates in a privacy notice. Test the website. Send a sample complaint through an ordinary inbox. Try the unsubscribe link. Ask the person covering holidays where the complaint log is. Those checks reveal more than another page of legal language.

This article explains the operational changes, not legal advice for a specific organisation. Where processing is high-risk, involves special category data or spans the UK and EU, get advice on that specific setup.

Sources


Need help turning the review into working controls on your devices, website and staff processes? Business IT support can cover the technical implementation; legal interpretation stays with your solicitor or data protection adviser. Tell us what you use.

Common questions

The DUAA amends the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations rather than replacing them. It changes areas including cookies and similar technologies, complaint handling, automated decision-making and the ICO's enforcement powers. All provisions affecting data protection law and PECR are now in force.

Only if every technology you use either meets a PECR exception or is not deployed until the user consents. The new statistical and appearance exceptions are narrow, require clear information and a simple free way to object, and do not cover advertising, profiling or cross-site tracking. Many websites can simplify their controls, but not remove them altogether.

You need a process, not necessarily a new tool. You may adapt an existing complaints route, email address, form, telephone process or portal. Staff must also recognise complaints received through other channels, because a person does not have to use your preferred route or quote the law.

For the PECR infringements subject to the higher tier, the maximum is £17.5 million or 4% of worldwide annual turnover, whichever is higher. Other listed infringements may fall under the standard maximum of £8.7 million or 2%. The ICO decides any penalty case by case and must act proportionately.

Marcin Skwiercz

Written by

Marcin Skwiercz

Founder of Evolfe. Fixing London's technology since 2014 - 12 years of hands-on repair and IT support behind every article.

About EvolfeLinkedIn

Need help with this?

We can help your business prepare.

Evolfe provides IT support and management for London businesses. If anything in this article applies to you, get in touch.

Book a Free Consultation

The Evolfe letter

Practical IT insights, straight to your inbox

One email a month, in plain English. No spam, unsubscribe any time.