GDPR Has Changed: What the Data (Use and Access) Act 2025 Means for CMA Members

GDPR
Share to your social

GDPR Has Changed: What the Data (Use and Access) Act 2025 Means for Your Practice

If you hold information about your clients – and every practitioner does – UK data protection law has just been through its most significant update since GDPR arrived in 2018. The Data (Use and Access) Act 2025 (usually shortened to “the DUAA”) received Royal Assent on 19 June 2025, and its provisions have been phased in over the past year. Most are now in force.

The good news first: the DUAA does not replace the UK GDPR or the Data Protection Act 2018. It amends them – in most cases to make compliance simpler and clearer for small organisations like yours. There is no need to tear up your privacy notice and start again. However, there are a handful of genuinely new obligations, one of which almost every practitioner will need to act on, and some welcome clarifications that make life easier.

This article explains what has changed in plain English – for Practitioners, Fellows, Students, Training Schools, and Approved Suppliers. It is general guidance rather than legal advice, and we link to the official ICO resources throughout so you can go deeper where you need to.

This article has been prepared and checked by Jayney Goddard MSc PG Dip Ed, FCMA, FRSM, President, The Complementary Medical Association.  This article has a useful CMA CPD section at the end that will help you to focus on your GDPR compliance and will help you to ascertain whether you have correctly incorporated the recent changes from the ICO.we’ll help you to ascertain whether you have correctly incorporated the recent changes from the ICO.


First, What Has Not Changed in GDPR

The foundations of good practice remain exactly as they were, and they matter more than ever:

  • Client health information is still “special category” data. Case histories, treatment notes, intake forms, and anything describing a client’s physical or mental health attract the highest level of protection under the UK GDPR. You still need both a lawful basis for processing and a separate condition for handling health data – for most practitioners this is the provision of health or care with a duty of confidentiality, supported by clear client consent in practice.
  • You still need to be transparent. A clear, plain-language privacy notice telling clients what you collect, why, how long you keep it, and their rights remains essential.
  • You still need to keep data secure. Password-protected devices, encrypted or reputable cloud storage, locked filing cabinets for paper notes, and care with email all remain baseline expectations.
  • You still need to pay the ICO data protection fee. If you keep client records electronically – on a computer, tablet, phone, or in cloud-based practice-management software – you are a data controller and must register with the regulator and pay the annual fee. Most sole practitioners fall into Tier 1, currently £52 per year with a small discount for paying by direct debit. Failing to register can attract a penalty of up to £4,000 on top of the fee, and the regulator actively cross-checks business registrations. The fee self-assessment tool takes about five minutes.

The Big One: You Must Now Have a GDPR/DUAA Compliant Complaints Process

This is the change most likely to require action in your clinic. The DUAA gives every individual a statutory right to complain directly to you – not just to the regulator – if they believe you have mishandled their personal information. In turn, you are required to:

  • Make it easy for people to complain – for example, by providing a complaint form that can be completed electronically, or a clearly signposted email route;
  • Acknowledge every data protection complaint within 30 days; and
  • Respond without undue delay, making appropriate enquiries, keeping the complainant informed of progress, and telling them the outcome.

For a sole practitioner this need not be onerous: a short paragraph in your privacy notice explaining how clients can raise a data concern, a simple form or dedicated email address, and a habit of acknowledging promptly and keeping a written record will satisfy the requirement. The ICO has published dedicated data protection complaints guidance to help organisations of every size.

It is worth noting that this sits comfortably alongside the complaints procedures you already operate as a matter of professional standards. The difference is that data protection complaints now carry specific statutory timescales – so make sure whoever handles correspondence in your practice knows to flag them.

GDPR/DUAA Subject Access Requests: Clearer, Fairer Rules

Clients have always had the right to request a copy of the information you hold about them. The DUAA writes two helpful clarifications into the law itself:

  • You are only required to carry out a “reasonable and proportionate” search for the requester’s data – you are not expected to excavate every backup and archive beyond what is sensible; and
  • The response clock can pause while you wait for the requester to confirm their identity or clarify what they are asking for.

Neither change reduces a client’s fundamental right of access – and given the sensitivity of therapeutic records, we would always encourage generosity and openness. But if you ever receive a broad or ambiguous request, the law now explicitly supports a measured, proportionate response.

Marketing: Higher Stakes, and Some Helpful Clarity

Two changes pull in opposite directions here, and both matter if you send newsletters or promotional emails.

On the one hand, the DUAA confirms in the legislation itself that direct marketing can be a legitimate interest – codifying what was previously only guidance. You still need to weigh your interests against your clients’ rights and expectations (a legitimate interests assessment), and none of this overrides the electronic marketing rules, which generally require consent or an existing customer relationship before you email promotions.

On the other hand, the maximum fine for breaching the electronic marketing rules (PECR) has risen dramatically – from £500,000 to £17.5 million or 4% of turnover, bringing it into line with UK GDPR penalties. Marketing compliance has long been the regulator’s most active enforcement area, so this is the moment to check that everyone on your mailing list either consented or is an existing client who was offered an opt-out, and that every message you send includes a working unsubscribe link.

GDPR/Duaa Compliant Cookies on Your Website

If you run a practice website, the DUAA permits certain low-risk cookies – such as basic analytics and security cookies – to be set without prior consent, provided you are transparent about them and offer visitors a way to opt out. Consent is still required for advertising and tracking cookies. If your site was built for you, it is worth asking your web developer to review your cookie banner against the updated ICO guidance – you may be able to simplify it considerably.

Other Changes Worth Knowing About

The ICO becomes the Information Commission

The regulator is being restructured from the Information Commissioner’s Office into a new body, the Information Commission, with modernised governance and strengthened investigatory powers. In day-to-day terms, its guidance, fee system, and helpline continue as before.

International transfers

The test for sending personal data outside the UK has been reworded: protection in the destination country must not be “materially lower” than UK standards. For most practitioners this arises through cloud software – booking systems, note-taking apps, email providers – so the practical step is simply to choose reputable providers and check where they store data. Training schools with international students or overseas branches should review their arrangements against the ICO’s updated transfer guidance.

Automated decision-making and AI tools

The rules on decisions made solely by automated means have been relaxed, with safeguards: people must be told about significant automated decisions, be able to challenge them, and be able to obtain human intervention. If you use AI-assisted triage, scheduling, or client-screening tools, make sure a human remains meaningfully in the loop – which, in a therapeutic context, is simply good practice anyway.

Children’s data

If you provide an online service likely to be used by children – for example, a training school’s learning platform open to under-18s – the law now explicitly requires you to take children’s needs into account when deciding how to use their information.

What This Means for Each Part of Our Community

Practitioners and Fellows

Since the great majority of our Fellows are practising clinicians, the same checklist applies to both: confirm your ICO registration is current, add a data protection complaints route to your privacy notice, review your mailing list consents, and check where your practice software stores its data. If you supervise, teach, or mentor as part of your Fellowship activities, remember that supervisee and student records are personal data too.

Students

This catches many people out: if you are a student practitioner seeing case-study clients or working in a student clinic, and you keep any client records electronically, you are a data controller in your own right. That means registering with the ICO and paying the annual fee – your training school’s registration does not cover records that you control yourself. Registration is quick and inexpensive, and being listed as a registered fee payer signals professionalism to clients from your very first case study. Build your privacy notice, consent forms, and secure storage habits now, and compliance will be second nature by the time you qualify.

Training schools

Schools handle several distinct pools of data – student records, staff records, marketing lists, and often client data from teaching clinics – and larger schools may fall into a higher ICO fee tier. Priorities under the DUAA: implement the statutory complaints process across all of these; review how student case-study data is collected, anonymised, and stored; check international transfer arrangements if you teach overseas students or run international branches; and note that the expanded definition of scientific research may make it easier to use appropriately safeguarded data in legitimate research and course development.

Approved Suppliers

If you sell products or services to practitioners or the public, the marketing changes are your headline: the dramatically increased PECR fines make clean, consented mailing lists a commercial imperative, while the codification of direct marketing as a potential legitimate interest gives you a clearer framework for postal and account-based marketing. Review your e-commerce cookie banner against the new low-risk exemptions, and implement the complaints process across your customer database.

Your Five-Point Action Plan

  1. Check your ICO registration – and if you are a student keeping electronic client records, register now.
  2. Add a data protection complaints route to your privacy notice, with a simple electronic form or dedicated email address, and diarise the 30-day acknowledgement rule.
  3. Audit your mailing list – confirm consent or an existing client relationship for everyone on it, and test your unsubscribe link.
  4. Review your website cookies against the new low-risk exemptions and update your banner if needed.
  5. Refresh your privacy notice so it reflects your actual practice today – including any new software, AI tools, or overseas storage.

Reflective Practice: Your Data Protection CPD (One hour CMA CPD)

Take fifteen minutes with your journal and work through the following prompts:

  1. What personal information do I actually collect from clients – and is every item genuinely necessary for safe, effective care?
  2. If a client asked to see everything I hold about them tomorrow, how long would it take me to compile it, and what would that process reveal about my record-keeping?
  3. How would a client raise a data protection concern with me today – and would they know how?
  4. Where does my practice software store its data, and have I ever checked?
  5. When did I last read my own privacy notice as if I were a new client?
  6. What happens to my client records if I am suddenly unable to practise – who knows where they are and what to do?

One change I will make as a result of this reflection: ________________________________________

CPD logging tip: log into your personal CMA membership section and record this as one hour of reflective CPD under professional standards and ethics, noting the date, the prompts you worked through, and the change you have committed to.

Members Outside the UK

The DUAA is a UK statute, but if you are reading this from elsewhere in the world, do not click away just yet – it may still apply to you. UK GDPR reaches beyond British borders: if you offer services to people in the UK – online consultations with UK-based clients, courses enrolling UK students, products sold to UK customers – the UK rules, including the new complaints requirement and the increased marketing fines, apply to that part of your work regardless of where you practise.

Members in the EU and EEA should also note that the UK and EU regimes are now diverging. The DUAA changed UK law only; the EU GDPR is unchanged. If you operate in both markets – as many training schools and suppliers do – you can no longer assume that compliance with one automatically means compliance with the other, particularly around international transfers, cookies, and automated decision-making.

And wherever you are based, the discipline in this article travels well. Auditing what you collect, securing it properly, being transparent with clients, offering a clear complaints route, and knowing where your software stores its data are sound practice under the EU GDPR, Canada’s PIPEDA, Australia’s Privacy Act, and the growing family of data protection laws worldwide. The five-point action plan and the reflective practice exercise above are worth completing whichever flag flies over your clinic – just check the specific registration and notification requirements with your own national data protection authority.

Where to Go for More

The definitive resources are free and written for non-lawyers:

Data protection can feel like paperwork for its own sake, but at its heart it is an extension of something complementary practitioners already excel at: treating the people in our care, and everything they entrust to us, with respect. Clients share deeply personal information with us. Handling it impeccably is part of the therapeutic relationship itself – and now, more than ever, it is also a visible mark of the professionalism that CMA Membership represents.

This article is provided for general information and does not constitute legal advice. For advice on your specific circumstances, please consult the ICO or a qualified data protection adviser.

Further Reading

Please visit the CMA Blog to find a number of useful and highly informative articles that come under the CMA’s Natural Health Business Growth and Support Initiative.


About the Author

Jayney Goddard MSc, PG Dip Ed, FCMA, FRSM is the Founder and President of The Complementary Medical Association (The CMA), the world’s leading professional body for complementary medicine. With more than three decades at the forefront of complementary and integrative healthcare, Jayney has dedicated her career to raising professional standards across the sector and to championing rigorous, evidence-based natural approaches to health and longevity. She is the author of several best-sellers, including Rewind Your Body Clock – the Complete Natural Guide to a Happier Healthier Younger You (Watkins/Penguin Random House), which debuted on the Amazon charts at No 1 of ALL books on the platform. Jayney is a sought-after international speaker, and a passionate advocate for the safe, ethical integration of complementary medicine within mainstream healthcare. Through The CMA, she supports a global community of Practitioners, Fellows, and Approved Suppliers committed to the very highest standards of practice.


This article is provided for general information and does not constitute legal advice. For advice on your specific circumstances, please consult the ICO or a qualified data protection adviser.

Share to your social
Facebook
Pinterest
Twitter
LinkedIn

The CMA Newsletter - Subscribe now

Click the button to the right to subscribe to our newsletter.