Skip to main content

DUA Act 2025

Data (Use and Access) Act 2025

Omnibus data legislation covering customer data access, digital verification services, the Information Commission, and AI-related provisions including copyright/training transparency requirements and new criminal offenses for creating AI-generated intimate images (deepfakes).

Jurisdiction

United Kingdom

GB

Enacted

Jun 19, 2025

Effective

Jun 19, 2025

Enforcement

Crown Prosecution Service (criminal); Information Commission (data provisions)

Royal Assent 19 June 2025

Who Must Comply

This law applies to:

  • Anyone creating AI-generated intimate imagery (criminal provisions)
  • AI developers using copyrighted training data (future regulation subject to reports)
  • Data holders and customer data processors

Who bears obligations:

Exemptions

Reasonable Excuse Defense

high confidence

Defense available for creating purported intimate images if person had reasonable excuse

Conditions:

  • • Must prove reasonable excuse for creation

Safety Provisions

  • Creates criminal offense for creating 'purported intimate images' (AI deepfakes) of adults without consent (s.66E SOA 2003)
  • Creates criminal offense for requesting creation of such images (s.66F SOA 2003)
  • Mandates economic impact assessment on AI training using copyrighted works
  • Mandates report on copyright works in AI development including transparency and disclosure requirements

Compliance Timeline

Mar 19, 2026

  • Secretary of State must publish economic impact assessment on AI training and copyright (s.135)
  • Secretary of State must publish report on use of copyright works in AI development (s.136)

Enforcement

Enforced by

Crown Prosecution Service (criminal); Information Commission (data provisions)

Penalties

Criminal: up to 51 weeks imprisonment and/or fine for deepfake intimate image offenses

Quick Facts

Binding
Yes
Mental Health Focus
No
Child Safety Focus
Yes
Algorithmic Scope
No

Why It Matters

Creates criminal liability for AI-generated intimate imagery. The mandated reports on AI training and copyright may lead to future disclosure requirements for AI developers. Primarily relevant for platforms dealing with synthetic media.

Recent Developments

Enacted June 2025. AI/copyright provisions require reports within 9 months but defer substantive regulation. Deepfake intimate image provisions in force immediately.

Cite This

APA

United Kingdom. (2025). Data (Use and Access) Act 2025. Retrieved from https://nope.net/regs/uk-dua-act-2025

BibTeX

@misc{uk_dua_act_2025,
  title = {Data (Use and Access) Act 2025},
  author = {United Kingdom},
  year = {2025},
  url = {https://nope.net/regs/uk-dua-act-2025}
}

Related Regulations

In Effect GB Data Protection

UK DPA 2018

The UK's foundational data protection law, incorporating the UK GDPR (retained EU GDPR post-Brexit). Substantively mirrors EU GDPR with ICO as sole enforcer. Article 22 restricts automated decision-making; Article 9 classifies mental health as special category data; children's consent age set at 13. Parent framework for UK Children's Code; amended by DUA Act 2025.

In Effect GB Child Protection

Ofcom Children's Codes

Ofcom codes requiring user-to-user services and search services to protect children from harmful content including suicide, self-harm, and eating disorder content. Explicitly covers AI chatbots that enable content sharing between users. Requires detection technology, content moderation, and recommender system controls.

In Effect US-TX Data Protection

TX TDPSA + SCOPE

Texas AG Paxton is the MOST AGGRESSIVE enforcer against AI companion companies. December 2024 investigations launched against Character.AI, Reddit, Instagram, Discord.

In Effect BN Data Protection

Brunei PDPO

Brunei's personal data protection order requiring DPIA and imposing penalties up to 10% Brunei turnover or $1M.

In Effect UK Child Protection

UK Children's Code

UK's enforceable "privacy-by-design for kids" regime. Applies to online services likely to be accessed by children under 18. Forces high-privacy defaults, limits on profiling/nudges, DPIA-style risk work, safety-by-design.

In Effect UK Online Safety

UK OSA

One of the most comprehensive platform content moderation regimes globally. Creates specific duties around suicide, self-harm, and eating disorder content for children with 'highly effective' age assurance requirements.