Skip to content
UK GDPR

UK Data Protection and Digital Information Act: What Changed

4 min readUpdated 2 September 2026

The Data Protection and Digital Information Act (DPDI Act) received Royal Assent in 2025 and amends UK GDPR, the Data Protection Act 2018, and PECR. It represents the most significant divergence between UK and EU data protection law since Brexit. This article covers what changed and what it means for your compliance programme.


Background: Why the DPDI Act Was Passed

The UK government's stated objective was to reduce compliance burden on UK businesses while maintaining data protection standards. The EU adequacy decision for the UK was a constraint — significant divergence from EU GDPR could jeopardise adequacy, which would require UK → EU transfers to revert to using IDTAs.

The DPDI Act navigated this tension by making targeted changes rather than a wholesale rewrite. Most of the changes simplify or clarify existing requirements rather than fundamentally changing data subject rights or enforcement powers.


Key Changes Under the DPDI Act

1. Senior Responsible Individual (SRI) — Replaces DPO in Some Cases

The mandatory DPO requirement under UK GDPR Article 37 has been modified. The DPDI Act introduces a "Senior Responsible Individual" (SRI) requirement for some organisations where a DPO was previously required.

What changed:

  • Organisations that previously needed a DPO may now designate an SRI instead
  • The SRI must be a member of senior management (not an external third party)
  • The SRI takes on responsibility for data protection oversight at the senior leadership level

What stayed the same:

  • Public authorities: still require a DPO equivalent
  • High-volume or high-risk processing organisations: still have enhanced obligations
  • The substance of the oversight requirement has not been reduced — senior leadership responsibility for data protection is maintained or strengthened

Practical implication: Many SMEs that had engaged external DPO services may find the SRI model more practical — designating their COO or General Counsel as SRI. Review your DPO arrangements against the new requirements.

2. Legitimate Interest — Simplified Assessment for Listed Purposes

The DPDI Act introduced a list of purposes for which legitimate interest can be used without a full balancing test:

  • Democratic engagement activities
  • Safeguarding purposes
  • Research, journalism, and education
  • Emergency response
  • Internal administrative purposes
  • Security and crime prevention

What changed: For these listed purposes, a controller can rely on legitimate interest without the full three-part balancing assessment required under standard legitimate interest.

What stayed the same: For processing not in the listed categories, the full legitimate interest balancing test still applies.

Practical implication: For most commercial SaaS companies, the listed categories are not the primary use cases. Standard commercial legitimate interest processing (marketing to customers, fraud detection, product analytics) still requires a full balancing test.

3. Cookies — Modified Consent for Analytics

The DPDI Act modified PECR to allow certain analytics cookies to be deployed under legitimate interest rather than consent. The criteria for the analytics exemption are narrow:

  • Analytics must be solely for improving the service for users
  • Not for advertising or cross-site tracking
  • Limited in their technical scope

What changed: Some first-party analytics that meet the criteria may not require a consent banner.

What stayed the same: Third-party advertising and retargeting cookies still require consent. Most Google Analytics implementations (which feed into advertising) still require consent. The practical impact for most websites is limited.

4. Research Exemptions — Expanded

The DPDI Act broadened the UK GDPR research exemptions, making it easier for organisations to process personal data for scientific, historical, and statistical research. This is primarily relevant for healthcare research, academic institutions, and data analytics firms.

5. Automated Decision-Making — Modified Article 22

The DPDI Act modified the UK GDPR equivalent of Article 22 (automated decisions). Key changes:

  • The prohibition on solely automated decisions with significant effects has been modified
  • Safeguards remain but the absolute prohibition is replaced with a requirement to provide appropriate safeguards and human review pathways
  • This brings UK automated decision-making law closer to what GDPR already permitted with some flexibility

Practical implication: Organisations using automated decision-making for credit, employment, or other significant purposes should review their Article 22/SRI policies against the new requirements.

6. Direct Marketing — Minor Clarifications

PECR amendments include clarifications on direct marketing rules — primarily around business-to-business communications and the treatment of corporate subscribers.


What Did Not Change

  • Data subject rights (access, erasure, portability, objection) — unchanged
  • Breach notification (72 hours to ICO) — unchanged
  • Records of Processing Activities — unchanged
  • Data Protection by Design — unchanged
  • ICO enforcement powers and fine levels — unchanged

EU Adequacy Implications

The EU Commission monitors UK law for continued adequacy. The DPDI Act was designed to avoid adequacy-threatening divergence — the Commission has not revoked adequacy following the Act. But continued monitoring of EU-UK adequacy is warranted.

ComplyOne covers UK GDPR and EU GDPR in one platform — identifying the specific gaps between the two frameworks.

Check your UK GDPR compliance →