The UK Data Act reshapes how businesses collect, use, store, share, and automate decisions with customer data. It introduces new rights, new obligations, new penalties, and new expectations — especially around AI, transparency, and human oversight.
Become Compliant — Register TodayAll new members receive a FREE UK Data Act Checklist + EU AI Act Checklist.
The UK Data Act is the UK's modernised data protection and digital governance framework, designed to:
It builds on the UK GDPR but introduces new rules, new rights, and new responsibilities for businesses.
If your business collects or uses customer data — you must comply.
Customers must be able to request a human to intervene in automated decisions.
If AI tools influence a decision indirectly, you are still held responsible.
AI-generated synthetic content must be explicitly labelled to the user.
Businesses must prove that humans actively supervise AI processes.
Fines extend beyond GDPR limits, reaching £17.5M or 4% of global turnover.
You are legally required to test your systems for bias and discrimination.
You must be able to explain exactly how automated decisions were formulated.
Company size does not grant immunity — the nature of data usage does.
Businesses must clearly disclose:
Businesses must ensure:
Customers must be able to:
Customers have the right to:
Businesses must maintain:
Enforcement actions include:
The Act affects Trades, Local services, E‑commerce, Agencies, SaaS, Consultants, Recruiters, Finance, Healthcare, and Education.
If you use any of the following, you must comply:
Identify what data you collect, why you collect it, how you use it, and where AI is involved.
Document where AI influences outcomes, scoring, recommendations, or affects customers.
Ensure humans review outputs, approve sensitive decisions, and handle escalations.
Disclose AI usage, data usage, decision processes, and human escalation options.
Cover data governance, AI usage, human oversight, error handling, and transparency.
Staff must understand data rights, AI risks, oversight responsibilities, and communication.
Actively monitor AI accuracy, bias, fairness, complaints, and algorithmic errors.
Compliance is an advantage.
The Act protects people.
Non-compliance is dangerous.
Yes — size does not matter. Data usage determines scope.
Yes — transparency is required. Synthetic content must be labelled.
Yes — for any automated decision that affects them.
No — it builds upon the foundation of GDPR with modern requirements.
Compliance is mandatory. Human oversight is essential.
Register for ComplianceAll new members receive a FREE UK Data Act Checklist + EU AI Act Checklist.
Select your path: Self-certify your own business, or become a Partner and monetize the movement.
Discover our Corporate & Partner Certification Tiers to cover your entire footprint.
View Enterprise PackagesYour self-certification details have been securely logged. A member of our team will contact you shortly to complete the setup process.