Heimdell Tech Ai - TPV Verification for Telecom Resellers HEIMDELL TECH AI ← Back to Compliance Hub

Data Use Act 2025 & PECR: Implementation Guide for UK Businesses

What the Data Use and Access Act means for UK telecom providers. Updated consent rules, PECR amendments, and Smart Data scheme implications.

What You Learn

  • ✓ DUAA 2025 requirements
  • ✓ Smart data consent rules
  • ✓ Compliance deadlines
  • ✓ Business impact assessment

Who It's For

  • • Data controllers
  • • Business owners
  • • Legal/compliance teams
  • • Anyone processing UK customer data
BOTTOM LINE UP FRONT
The Data Use and Access Act 2025 received Royal Assent in November 2025, reforming UK data protection and amending PECR. Key changes for telecoms: simplified analytics cookies (no consent for first-party analytics), expanded B2B soft opt-in for marketing, legitimate interests codification, and Smart Data framework preparation. Most provisions apply from Q2 2026. ICO fines remain at £17.5 million maximum.

What is the Data Use and Access Act 2025?

The Data Use and Access Act 2025 (DUA) is the Government's post-Brexit reform of UK data protection law, replacing the failed Data Protection and Digital Information Bill. It amends:

The Act introduces Smart Data schemes (building on Open Banking), establishes a digital ID framework, and creates new National Underground Asset Register requirements.

Key PECR Changes for Telecoms

The most impactful changes for communication providers relate to PECR amendments:

PECR Before DUA 2025

  • Consent required for all non-essential cookies
  • Soft opt-in limited to existing customer relationships
  • B2B marketing required individual consent
  • Analytics cookies treated same as advertising
  • No distinction between service and tracking cookies

PECR After DUA 2025

  • First-party analytics exempt from consent
  • Soft opt-in expanded to B2B communications
  • Corporate subscriber can consent for employees
  • Clear separation: functional vs tracking cookies
  • "Recognised legitimate interests" for essential processing

Cookie Consent Changes

Cookie Type Before DUA 2025 After DUA 2025
Strictly necessary (login, security) No consent required No consent required (unchanged)
First-party analytics Consent required No consent required
Third-party analytics (Google Analytics) Consent required Consent still required
Advertising/tracking Consent required Consent still required
Preference cookies Consent required Legitimate interest may apply

Direct Marketing Amendments

The DUA modifies PECR's direct marketing rules:

Implementation Timeline

November 2025
DUA receives Royal Assent. Core framework provisions in force.
January 2026
ICO publishes updated PECR guidance incorporating DUA changes.
February 2026 (NOW)
Providers should be updating cookie consent mechanisms and marketing processes.
April 2026
Key PECR amendments come into force via statutory instrument.
Q3 2026
Smart Data scheme regulations expected for initial designated sectors.
2027+
Potential Smart Data designation for telecommunications sector (TBC).

Action Items for Telecom Providers

Update Cookie Banner

Revise cookie consent mechanism to reflect first-party analytics exemption. Remove unnecessary consent requests.

HIGH PRIORITY

Review Marketing Processes

Update B2B marketing workflows to leverage expanded soft opt-in. Ensure proper documentation of relationship basis.

HIGH PRIORITY

Update Privacy Policy

Revise privacy policy to reflect DUA changes: legitimate interests explanations, new cookie categories, Smart Data references.

MEDIUM PRIORITY

Legitimate Interests Assessment

Document LIAs for processing now covered by "recognised legitimate interests" in DUA. Maintain evidence.

MEDIUM PRIORITY

Staff Training

Train marketing and customer service teams on new B2B soft opt-in rules and consent requirements.

MEDIUM PRIORITY

Monitor Smart Data Developments

Track DSIT announcements on sector designation. Prepare for potential Smart Data requirements in telecoms.

LOW PRIORITY

Smart Data: Future Implications

The DUA establishes a framework for Smart Data schemes, allowing customers to securely share their data with authorised third parties. While Open Banking pioneered this in financial services, telecoms may be designated in future:

Potential Telecom Applications

Preparation Steps

ICO Enforcement Under DUA

The DUA maintains ICO's enforcement powers with some modifications:

Relationship with Existing PECR Compliance

If you're already PECR compliant, the DUA changes are relatively minor adjustments:

See our full PECR compliance guide for the complete framework.

Stay Compliant with DUA 2025

TELECOM COMPLIANCE provides automated compliance monitoring across PECR, UK GDPR, and DUA requirements. Get alerts on regulatory changes affecting your operations.

Request Assessment

Related Pages

UK GDPR for Telecoms

Data protection obligations

PECR Compliance

Marketing and consent rules

ICO GDPR Compliance Audit

Free compliance assessment