Key Definitions and Scope of the Data Use and Access Act 2025 (DUAA)
Understanding the DUAA starts with the basics. Learn the key definitions—like data user, data provider, access agreement—and the scope of the Data Use and Access Act 2025.
Understanding the DUAA starts with the basics. Learn the key definitions—like data user, data provider, access agreement—and the scope of the Data Use and Access Act 2025.
The Data Use and Access Act 2025 (DUAA) is a landmark UK law that regulates access, sharing, and processing of data across sectors. Learn what DUAA is and how it complements GDPR.
Under GDPR, companies can refuse rights requests that are manifestly unfounded or excessive. Learn when and how to lawfully say no.
You can ask for ID before fulfilling GDPR requests — but only when necessary. Here’s how to verify identity without breaching privacy.
Companies must respond to GDPR rights requests within strict timeframes. Here’s what counts as a valid request — and when deadlines can be extended.
Understand the key differences between Articles 13 and 14 of the UK GDPR, and why your company must tailor privacy notices depending on how personal data is collected.
Under Article 22 of the UK GDPR, individuals have rights related to automated decision-making and profiling. Learn how companies should respond.
Children have enhanced data protection rights under UK GDPR. Learn how companies working with under-18s should comply.
The right to be informed (Articles 13 and 14 of the UK GDPR) requires companies to explain how they use personal data. Learn how to comply with transparency obligations.
Article 21 of the UK GDPR gives people the right to object to certain types of data processing. Learn how your company should handle objections.