Data Use and Access Act Marketing Rules: What Changed for B2B
Recognised legitimate interests, B2B email, cookie exceptions, fines and complaints: what the Act changed and when
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and most changes took effect on 5 February 2026. It did not change PECR's rule letting you email limited companies and LLPs without prior consent, but it raised maximum PECR fines to £17.5 million or 4% of global turnover.
In short
- Most of the Data (Use and Access) Act's data protection changes came into force on 5 February 2026 under SI 2026/82.
- Direct marketing is named as an example of an ordinary legitimate interest, not listed as a recognised legitimate interest in Annex 1.
- PECR still lets you email limited companies and LLPs without prior consent; sole traders and ordinary partnerships are treated as individuals.
- Maximum PECR fines rose to £17.5 million or 4% of global turnover.
- Since 19 June 2026 every controller must have a complaints procedure.
The Data (Use and Access) Act 2025 is the biggest change to UK data protection law since Brexit, and most of it is now in force. For anyone checking the Data Use and Access Act marketing rules, the honest answer is: less than the headlines suggest for B2B email, more for cookies and fines, and nothing that makes visitor identification or outreach automatic. This guide walks through each change with the dates. It is general information, not legal advice.
What is the Data (Use and Access) Act 2025?
It is the UK's update to the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR). The Act received Royal Assent on 19 June 20251. Rather than switching on all at once, it has been commenced in stages through regulations1.
The main stage arrived on 5 February 2026. The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, SI 2026/82, made on 29 January 2026, brought a long list of provisions into force that day, including the sections on lawfulness of processing, recognised legitimate interests, storing information on a user's device, and the Commissioner's enforcement powers2. The ICO's statement that day said "most of the remaining data protection provisions of the Act have come into force", except for the complaints procedure due on 19 June 2026 and "some ICO governance provisions which will follow at a later date"3.
What is a "recognised legitimate interest"?
It is a new lawful basis, added to Article 6 of the UK GDPR as point (ea), for processing that is "necessary for the purposes of a recognised legitimate interest"4. The Act says processing only qualifies if it meets a condition in a new Annex 14. Those conditions, set out in Schedule 4, cover5:
- disclosures to another person who needs the data for a public-interest task;
- national security, public security and defence;
- responding to emergencies;
- detecting, investigating or preventing crime;
- safeguarding vulnerable individuals.
Direct marketing is not on that list. It appears elsewhere in the Act. A new paragraph 11 of Article 6 says that, for the ordinary legitimate interests basis in point (f), "examples of types of processing that may be processing that is necessary for the purposes of a legitimate interest include (a) processing that is necessary for the purposes of direct marketing"4.
That wording matters. Some summaries describe direct marketing as a recognised legitimate interest. On the text of the Act, it is an example of something that may be a legitimate interest under the ordinary basis, which still involves weighing your interests against the individual's. The Act also extends the right to object to the new basis4. Law firm DLA Piper notes that, under the ICO's draft guidance, a controller relying on a recognised legitimate interest "must still assess whether the processing is necessary"1.
In practice: if you rely on legitimate interests for B2B marketing, you still need a legitimate interests assessment. The Act made direct marketing an explicitly named example, not a pre-approved purpose.
Did the B2B email rules change?
No. The Act did not change PECR's corporate subscriber rule. The ICO explains that "the PECR rule on direct marketing by electronic mail does not apply to corporate subscribers", so you can email companies, limited liability partnerships and other corporate bodies without their prior consent under PECR6. You must still "not disguise or conceal your identity" and must "give a valid address for business to opt-out or unsubscribe"6.
Sole traders and some partnerships are different. The ICO says they "are classed as 'individual subscribers' and PECR treats them the same as individuals"6. The consent rules for electronic mail apply to them.
The UK GDPR still applies too. In the ICO's words: "If you are processing personal data for direct marketing purposes, even in a business context, the UK GDPR applies."6 A named contact at a company is personal data, so you need a lawful basis and must tell them how you use their details.
What did change is the penalty. The ICO says the Act gave it the power to "issue fines of up to £17.5 million or 4% of global turnover under the Privacy and Electronic Communications Regulations (PECR)", in force from 5 February 20263. That brings PECR in line with UK GDPR levels. A careless email campaign now carries the same maximum exposure as a data breach.
What changed for cookies and tracking scripts?
Section 112 of the Act, which amends PECR's rule on storing information on a user's device, commenced on 5 February 20262. It added exceptions to the consent requirement, including storage used only for statistical purposes to improve a service, and storage that adapts how a site appears or functions to the user's preference. The ICO says that to rely on either you must give clear information and "a 'simple and free' means to object"7.
The statistical exception is narrower than it sounds. The ICO says it "is about how your service is used, not about who uses it. It is not for identifying, tracking or monitoring people or groups of people who use your service."7
The ICO finalised its guidance on these rules on 29 April 20268. We cover what it means for visitor-identification scripts in the ICO's 2026 storage and access guidance explained.
What about complaints and DSARs?
Two process changes affect every organisation holding personal data, including marketing teams.
Complaints procedure, from 19 June 2026. SI 2026/82 brought section 103 into force on 19 June 20262. Clifford Chance summarises the duty: controllers must facilitate complaints, for example with a complaint form "which can be completed electronically and by other means", acknowledge complaints within 30 days, resolve them without undue delay, and tell the person about progress and the outcome9. If someone objects to your marketing and complains, you now need a defined route for handling it.
Subject access requests, from 5 February 2026. DLA Piper notes the Act clarifies that searches are limited to "reasonable and proportionate" searches and codifies "stopping the clock" where you reasonably need clarification1. The time-limit change in section 76 was among the provisions commenced on 5 February 20262.
What does this mean for website visitor identification?
Nothing in the Act makes it automatic, in either direction.
Identifying the company behind a visit remains a UK GDPR lawful-basis question, usually legitimate interests, supported by a legitimate interests assessment and a clear privacy notice. The Act did not add visitor identification to the recognised list5. If your tool stores or reads anything on the visitor's device, PECR's storage rules apply as well, and the new statistical exception does not cover identifying who visited7.
Contacting people at those companies is a separate question. PECR decides whether you can send the email: generally yes for a limited company or LLP, not without consent for a sole trader or ordinary partnership6. UK GDPR decides whether you can process the named person's data to do it. A company visiting your pricing page is a reason to consider outreach, not a legal basis for it.
For a fuller treatment, see our guide to visitor identification and GDPR and whether it is legal to contact companies that visited your website. When you do reach out, how to follow up with companies that visited your site covers the practical side.
Tools can make compliance easier or harder. Scout identifies companies, not individuals, and never stores raw IP addresses. Each match carries a confidence score from 1 to 99, so you are not building outreach on a residential broadband match. Contact data comes from business databases through Forager, and those contacts are not the visitors themselves.
Timeline
| Date | What happened |
|---|---|
| 19 June 2025 | Royal Assent |
| 29 January 2026 | SI 2026/82 made |
| 5 February 2026 | Most data protection and PECR changes in force, including recognised legitimate interests, cookie exceptions and higher PECR fines |
| 29 April 2026 | ICO final storage and access technologies guidance |
| 19 June 2026 | Complaints procedure duty in force |
| To be confirmed | Remaining ICO governance changes |
The short version
For B2B marketers, the Act tidied up rather than tore up. Emailing corporate subscribers works as it did, direct marketing is a named example of a legitimate interest rather than a free pass, cookie exceptions are real but narrow, and PECR fines have caught up with the UK GDPR. If you are unsure how any of this applies to your own processing, speak to a solicitor or your data protection officer.
Read how Scout handles lawful basis and IP data in our GDPR guide, then start a 14-day free trial, no card needed.
Frequently asked questions
Is the DUAA the same as GDPR?
No. The Data (Use and Access) Act 2025 amends the UK GDPR, the Data Protection Act 2018 and PECR rather than replacing them. The UK GDPR remains the core law, with the Act's changes written into it.
Do I still need a legitimate interests assessment?
For B2B marketing, generally yes. Direct marketing is named in the Act as an example of a legitimate interest under the ordinary basis, which still requires balancing your interests against the individual's. The recognised legitimate interests that skip the balancing test cover purposes such as crime prevention, security and safeguarding, not marketing.
When does the Information Commission replace the ICO?
The date is to be confirmed. The ICO said on 5 February 2026 that some ICO governance provisions would follow at a later date. Until then the ICO continues to regulate.
Can I still email companies without consent?
Under PECR you can send marketing emails to corporate subscribers such as limited companies and LLPs without prior consent, as long as you identify yourself and give a valid opt-out address. Sole traders and some partnerships need consent. The UK GDPR still applies to the named person's data.
Sources
- DLA Piper Privacy Matters: UK: Commencement of the data protection provisions in the Data (Use and Access) Act privacymatters.dlapiper.com
- legislation.gov.uk: The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82) legislation.gov.uk
- ICO: Statement on the commencement of the Data (Use and Access) Act (DUAA) ico.org.uk
- legislation.gov.uk: Data (Use and Access) Act 2025, section 70 (lawfulness of processing) legislation.gov.uk
- legislation.gov.uk: Data (Use and Access) Act 2025, Schedule 4 (recognised legitimate interests) legislation.gov.uk
- ICO: Business-to-business marketing ico.org.uk
- ICO: What are the exceptions? (storage and access technologies) ico.org.uk
- ICO: Final storage and access technologies guidance published ico.org.uk
- Clifford Chance: Key aspects of the Data (Use and Access) Act take effect cliffordchance.com