Articles Posted in Data (Use and Access) Act 2025 (DUAA)

Posted

The European Union’s AI Act entered a new phase on August 2, 2026, marking two years since its entry into force. Most immediately, the transparency obligations in Article 50 now apply to a broad range of AI systems and their providers and deployers, and the AI Act’s enforcement machinery is operational for obligations that are already in force.

August 2, 2026, was also the date on which the core requirements for “high-risk” AI systems were due to become applicable. That did not happen, however. Following political agreement reached by the EU institutions and the later publication of the Digital Omnibus Regulation on AI (“AI Omnibus Regulation”), those requirements have been postponed until December 2, 2027, for Annex III standalone use cases and August 2, 2028, for most product-related systems.

Continue reading

Posted

As of June 19, 2026, the Data (Use and Access) Act 2025 (DUAA) has brought into force new complaints-handling requirements for controllers under the UK data protection regime. (See our previous post on the DUAA here.) While many businesses already operate customer complaint or data subject rights processes, the DUAA now places specific statutory obligations on controllers to receive, acknowledge, investigate and respond to data protection complaints received on or after June 19, 2026.

Continue reading