Regulation, Governance & ComplianceNazeeha Hasan-Rao

Your GDPR Setup Is Probably Out of Date: Here's What You Need to Do in June 2026

If your GDPR setup hasn't changed this year, parts of it are already out of date. The rules have quietly shifted, and most small businesses haven't caught up yet.

The Data (Use and Access) Act 2025 (DUAA) is now in full force as of 19th June 2026, and it brings real changes to how you handle data, complaints, emails, cookies, and more.

If you're running a business with an email list, a website, or any kind of client data, this applies to you.

Here's what's changed, what it means in practice, and what you need to do.

What's Actually Changed? Five Things That Matter

1. You Now Have a Legal Obligation to Handle Data Complaints

This is the biggest change for most small businesses, and the one with the most immediate deadline.

From 19th June 2026, individuals have a formal right to complain about how you handle their personal data. That means you must now:

  • Have a clear way for people to raise a data protection complaint
  • Acknowledge complaints within 30 days
  • Explain how complaints will be handled and resolved
  • Deal with them before they escalate to the ICO

This is not the same as your general customer complaints process. It's specifically about data and privacy rights, and it must be detailed in your Privacy Notice.

If your Privacy Notice was auto-generated by your website platform, or written by AI, it almost certainly doesn't include this, so it will need to be updated as soon as possible.

2. Subject Access Requests Are Now "Reasonable and Proportionate"

Previously, responding to a Subject Access Request (SAR; where someone asks what data you hold on them) could feel like an open-ended obligation. The DUAA now clarifies that your searches only need to be reasonable and proportionate. You can also pause the clock if you need clarification from the individual before you can respond.

The deadline to respond remains one calendar month. What's changed is that you're no longer expected to turn your entire business upside down for a request that might be vague or disproportionate.

3. Cookie Rules Have Shifted

The DUAA introduced new exceptions that allow certain cookies to be used without requiring consent first. These include cookies used for:

  • Basic website analytics
  • Security and fraud detection
  • Remembering user preferences
  • Improving services

But if your website uses marketing or tracking cookies (e.g. Meta Pixel, Google Analytics with advertising features, retargeting), you still need consent. The old rules still apply to those.

For most businesses with a standard marketing setup, the safest approach is to keep your cookie banner in place, don’t ditch it. It's better to ask permission you don't strictly need than to skip consent that you do.

4. Legitimate Interests Is Broader, But PECR Still Applies to Email

Under the DUAA, direct marketing is now formally recognised as a legitimate interest under UK GDPR. This sounds like it might make email marketing easier, but it doesn’t necessarily. PECR (the Privacy and Electronic Communications Regulations) still governs email and SMS marketing separately. So even with the updated GDPR position, you still need:

  • Consent (or soft opt-in) to email non-corporate individuals
  • A working unsubscribe link in every email
  • Opt-outs actioned immediately, not "within 28 days"
  • Consent records: who signed up, when, how, and what they were told

This change helps with postal marketing and certain other activities, but for email the rules remain just as strict.

5. AI Tools and Automation Now Have Specific GDPR Requirements

This one is catching a lot of businesses off guard, because the tools crept in quietly and the compliance obligations are only now beginning to catch up.

If you use AI in any part of your business - a CRM with lead scoring, an AI chatbot, automated email sequences, recruitment screening tools, or even AI-assisted note-taking during client calls - UK GDPR applies to all of it. And your Privacy Notice needs to reflect that.

According to the ICO's AI and data protection guidance and the DPO Centre's practical guidance on updating Privacy Notices for AI, your Privacy Notice must now:

  • Name the AI tools you use that process personal data (not just vague references to "automated tools")
  • Explain what the AI does with people's data and what outputs it produces
  • State whether decisions are fully automated or human-reviewed, and if automated, what the effect on individuals is
  • Explain how people can request human review of a decision made by or with AI
  • Confirm the lawful basis for the AI processing, and document it

The ICO has been explicit: a brief mention buried in a general privacy notice is not enough. If AI is making or influencing decisions that affect your clients, patients, or contacts, that needs to be clearly and specifically disclosed.

On top of the Privacy Notice requirement, there are three other things businesses using AI should have in place:

  • A Data Protection Impact Assessment (DPIA) is required before deploying any AI tool that processes personal data in a high-risk way: this includes AI used in healthcare, recruitment, profiling, or large-scale behavioural tracking. An ICO report from March 2026 found the majority of organisations outside formal EU AI Act scope have no AI impact assessment at all.
  • A Data Processor Agreement (DPA) with every AI tool vendor. If your AI tool (chatbot, CRM, scheduling software) processes client or patient data on your behalf, you need a Data Processing Agreement with that provider. Not just their terms of service but a proper DPA.
  • An internal AI tools inventory. The ICO's March 2026 guidance advises organisations to list every AI tool in use, who owns it, what personal data goes in, what comes out, and whether it connects to other systems. This doesn't need to be complex (a simple spreadsheet is fine) but it needs to exist.

If You're in Healthcare, Pay Particular Attention

For medical clinics, GP practices, private health providers, and healthcare marketers, GDPR was already high-stakes. The DUAA raises those stakes.

Here's why healthcare businesses face specific and serious risks:

**Patient data is special category data. **Health information falls under Article 9 of UK GDPR, which requires explicit consent (not just opt-in) and additional legal conditions for processing. This applies to everything from appointment bookings to marketing follow-ups to automated appointment reminders.

**The new complaints process is particularly critical. **A patient who feels their data was mishandled now has a clear, formalised route to complain, and the ICO takes healthcare complaints seriously. Without a documented complaints procedure in your Privacy Notice, (and the operating bandwidth to uphold that procedure), you're dangerously exposed.

**Fines for healthcare breaches are significant. **PECR fine levels have increased from £500k to up to £17.5 million. Healthcare providers routinely hold high volumes of sensitive personal data, making them a higher-value target for ICO enforcement action.

Specific risks for healthcare businesses include:

  • Sending appointment reminders or health newsletters without a compliant lawful basis
  • Using Meta Pixel or Google Analytics on a booking page without a GDPR-compliant cookie banner
  • Uploading patient email lists to ad platforms (e.g. for Facebook custom audiences) without a documented lawful basis
  • Using third-party booking software or CRM platforms without a Data Processing Agreement in place
  • Failing to screen telephone marketing lists against TPS/CTPS
  • Not having an updated Privacy Notice that includes the new data complaints process
  • Using AI-powered tools (diagnostic aids, triage chatbots, appointment scheduling automation) without a DPIA. The ICO considers AI processing of health data high-risk and a DPIA is mandatory before deployment
  • Not disclosing AI use in your Privacy Notice - patients have a right to know if AI is involved in decisions or communications affecting their care or data
  • Using AI tools that process patient data without a Data Processing Agreement with the AI vendor

If you run a clinic or health business and you haven't reviewed your GDPR documentation since before June 2026, it needs attention now.

Your 2026 GDPR Compliance Checklist

Work through this list. If you can't tick everything, prioritise the ones in bold - they carry the highest risk.

Privacy Notice

  • Privacy Notice updated to include a data complaints procedure (deadline: 19 June 2026)
  • Privacy Notice mentions every AI tool that processes personal data [AI]
  • Privacy Notice explains what AI does with people's data and whether decisions are automated or human-reviewed [AI]
  • Privacy Notice explains how individuals can request human review of an automated decision [AI]
  • Privacy Notice discloses AI use in patient communications or triage tools [Healthcare] [AI]
  • Privacy Notice linked at every data collection point on your website (not just the footer)

Data Complaints Process

  • Clear process for acknowledging complaints within 30 days
  • Data complaints handled separately from general customer complaints
  • Complaints process covers data collected via AI tools and automated systems [AI]

Email Marketing

  • Consent records in place (who, when, how, what they were told)
  • Every marketing email includes a working unsubscribe link
  • Opt-outs actioned immediately and added to a suppression list
  • Not purchasing, scraping or adding contacts without a lawful basis
  • Soft opt-in use reviewed - only applied where conditions are genuinely met
  • Automated email sequences reviewed - confirm the lawful basis covers automated, not just manual, sending [AI]
  • Health newsletters or appointment marketing reviewed for explicit lawful basis [Healthcare]

Lead Magnets & Sign-Up Forms

  • Marketing consent is separate from downloading a freebie
  • Users know at the point of sign-up that they're joining a marketing list
  • AI-powered chatbots or lead capture tools disclose data use at point of collection [AI]

Cookies & Tracking

  • Non-essential cookies are not loaded before consent is given
  • Cookie banner has clear accept/reject options (no dark patterns)
  • Cookie policy lists all cookies, their purpose and duration
  • Meta Pixel, Google Analytics and retargeting tools covered by consent
  • Tracking pixels or session recording tools on healthcare booking pages have explicit consent [Healthcare]

AI Tools & Automation

  • Internal inventory of all AI tools in use - what data goes in, what comes out, who owns each tool [AI]
  • Data Processing Agreement in place with every AI tool vendor that handles personal data [AI]
  • Lawful basis documented for every AI processing activity [AI]
  • DPIA completed before deploying any AI tool that processes data at scale or makes significant decisions [AI]
  • DPIA completed for AI tools processing patient or health data - mandatory, not optional [Healthcare] [AI]
  • Human review process in place for any AI-driven decisions that affect individuals [AI]
  • AI recruitment or screening tools reviewed for bias and Equality Act compliance [AI]

Data Management

  • Data Processing Agreements in place with all processors (Mailchimp, CRM, booking software, etc.)
  • Data is not kept indefinitely - retention periods documented and followed
  • International transfers reviewed (especially US-based tools and AI platforms)
  • US tools checked against the UK-US Data Bridge certification list
  • Explicit consent in place for any processing of special category (health) data [Healthcare]
  • Patient data not uploaded to ad platforms without documented lawful basis [Healthcare]

Not Sure Where to Start?

If you're reading this and feeling a bit overwhelmed - that's normal, GDPR isn't designed to be easy to navigate. The good news: most businesses just need a few specific things updated, documented, and filed away. If you'd like help reviewing your marketing compliance, your data processes, or your documentation as a business or healthcare provider, get in touch with NH Consulting.

Get in Touch