Data (Use and Access) Act 2025
Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
DUAA 2025: Part 1 - Access to Customer and Business Data (Smart Data)
Provides for the accreditation and oversight of authorised persons (third parties) who may receive customer or business data under a smart data scheme, including conditions and enforcement.
- Verification of an authorised person's accreditation before sharing data
- Records of data shared with authorised persons
- Sharing smart data with unaccredited third parties
Allows fees and levies to fund scheme operation and provides enforcement mechanisms (including for interface standards and IT supplier obligations) where data holders or others fail to comply.
- Compliance with scheme interface/technical standards
- Records demonstrating timely response and fee handling
- Non-compliant interfaces
- Failure to meet scheme enforcement requirements
Empowers the Secretary of State / Treasury to make smart data scheme regulations requiring data holders to provide customer data and business data to customers or authorised third parties on request, enabling data portability across regulated sectors.
- Identification of whether the entity is a data holder under an in-scope smart data scheme
- Capability to provide customer/business data to customers or authorised persons on request
- Not tracking applicability of smart data scheme regulations
- No mechanism to respond to authorised data-access requests
DUAA 2025: Part 2 - Digital Verification Services
Establishes a regime for digital verification services (DVS), including the DVS trust framework, a register of accredited providers, and the conditions for registration and continued listing.
- For DVS providers: registration on the DVS register and conformity to the trust framework
- Certification against the trust framework by an accredited conformity body
- Providing digital verification services without registration
- Claiming trust-framework conformity without certification
Provides an information gateway enabling public authorities to share information with registered DVS providers to support identity verification, subject to safeguards.
- Lawful-basis and safeguard records for any information shared through the gateway
- Using the gateway outside its statutory purpose or safeguards
Controls the use of the digital verification services trust mark, which only registered providers conforming to the trust framework may display.
- Trust-mark usage only by registered DVS providers in good standing
- Displaying the trust mark without registration
DUAA 2025: Part 3 - National Underground Asset Register
Establishes the National Underground Asset Register (NUAR) and obligations on undertakers to provide and keep up to date information about apparatus located underground.
- For relevant undertakers: provision and currency of underground-asset information to the NUAR
- Failing to register or update underground-asset data where required
DUAA 2025: Part 4 - Registers of Births and Deaths
Provides for the form in which registers of births and deaths are kept, enabling electronic registration and amending the Births and Deaths Registration Act 1953.
- For registration bodies: compliance with the electronic-register requirements
- Maintaining registers in a non-compliant form where digitisation is required
DUAA 2025: Part 5 - Data Protection and Privacy Reforms
Reforms the rules on automated decision-making, permitting a wider range of solely automated decisions subject to safeguards (information to data subjects, the ability to make representations, obtain human intervention and contest decisions), with tighter rules for special-category data.
- Inventory of solely automated decisions and the safeguards applied
- Mechanisms for human intervention, representations and contestation
- Solely automated decisions without the required safeguards
- Special-category ADM without the stricter conditions
Requires providers of information society services likely to be accessed by children to consider how to protect children when designing data processing, reinforcing higher protection for children's data.
- Child-protection considerations in the design of in-scope information society services
- Age-appropriate design records
- No child-protection design assessment for services likely accessed by children
Introduces a duty for controllers to facilitate and handle data protection complaints from data subjects, including acknowledging and responding within prescribed timeframes, before escalation to the regulator.
- A complaints-handling procedure with acknowledgement and response timeframes
- Records of complaints received and resolved
- No controller-level complaint channel
- Complaints not acknowledged or logged
Clarifies the handling of data subject access requests, including that controllers need only carry out reasonable and proportionate searches and that the response clock can be paused while seeking clarification or identity verification.
- DSAR procedure reflecting reasonable-and-proportionate search and stop-the-clock provisions
- Logs of DSARs, clarifications sought and timelines
- Unbounded or no-search DSAR handling
- Not documenting the basis for search scope
Reforms the lawful bases under the UK GDPR, including a new list of recognised legitimate interests for which a balancing test is not required, and clarifies the legitimate-interests assessment.
- Updated records of processing showing reliance on recognised legitimate interests where applicable
- Legitimate-interests assessments for non-recognised interests
- Treating all legitimate interests as exempt from a balancing test
- No LIA where still required
Amends the Privacy and Electronic Communications Regulations: relaxes consent for certain low-risk cookies, adjusts direct-marketing rules (including the soft opt-in for charities), and raises PECR penalties towards UK GDPR levels.
- Cookie-consent configuration reflecting the relaxed low-risk categories
- Direct-marketing consent/soft-opt-in records
- Treating all cookies as consent-exempt
- Marketing without a valid lawful basis or soft opt-in
Clarifies and consolidates the rules for processing for scientific or historical research, statistical and archiving purposes, including broad consent for areas of research subject to safeguards.
- Safeguards for research/statistical/archiving processing
- Documentation of broad-consent scope where relied on
- Research processing without the required safeguards
Reforms the international transfer regime, introducing a data protection test for adequacy regulations and transfer mechanisms (whether the standard of protection is not materially lower than under the UK regime).
- Transfer mechanism records assessed against the data protection test
- Transfer risk assessments where no adequacy applies
- Transfers without applying the data protection test
- No assessment for non-adequate destinations
DUAA 2025: Part 6 - The Information Commission
Abolishes the office of the Information Commissioner and establishes the Information Commission as a body corporate, transferring functions and setting its governance, duties and powers.
- Awareness that the Information Commission is the successor regulator to the ICO
- Updated references to the Information Commission in policies
- Outdated references assuming the ICO rather than the Information Commission
DUAA 2025: Part 7 - Other Provision (Health Information Standards)
Provides for mandatory information standards for IT used in health and adult social care in England, requiring conformance to specified standards to support interoperability.
- For health/social-care IT: conformance to the mandated information standards
- Deploying non-conformant health/social-care IT where standards apply
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Data (Use and Access) Act 2025 framework page.