What does the Data Use and Access Act 2025 mean for a solo therapy practice
United Kingdom, Published 18 August 2026
Four minute read. Published on 18 August 2026. Last reviewed on 18 August 2026. Focus, the United Kingdom.
A note on what this is
This guide is our reading of the law and the published guidance, from a legal and compliance point of view. It is not advice about your practice, and it cannot weigh the particulars that make your situation yours. It also leaves untouched the ethical question that usually sits underneath, which is almost always the harder one. Compliance is the duller half of the problem. It is not the less important half.
In short
Most of the Data Use and Access Act 2025 does not reach a one person practice. Three things do. Since 19 June 2026 you must operate a process through which a client can complain to you about how their data has been handled, and you must acknowledge that complaint within 30 days. That is settled, and there is no exemption for small organisations. Access requests are governed by a reasonable and proportionate standard, and the clock pauses while you wait for a client to clarify. The loosening of the automated decision making rules stops at health data, so your notes are untouched.
The complaints duty is the part that bites
Section 103 of the Act inserted a new section 164A into the Data Protection Act 2018, and the commencement regulations brought it into force on 19 June 2026. This part is clear. Every controller must handle a complaint that personal data has been processed in breach of the rules, whatever the size of the organisation. The Information Commissioner's Office says in terms that you must have a process and that there are no exemptions to this.
What the statute asks for is short. Provide a way of complaining, which the section describes as a form that can be completed electronically and by other means. Acknowledge receipt within 30 days. Respond without undue delay, making appropriate enquiries and keeping the person informed. Tell them the outcome.
For a one person practice that is a paragraph, an inbox and a log. It is not a policy suite, and the statute does not ask for one.
The part that is easy to get the wrong way round
Telling a complainant they may go to the Commissioner is good practice when you give them your answer, and the regulator says so in those words. It is not an obligation at that stage. The obligation sits earlier, in the information you give when you collect someone's data, which for most practices means the privacy notice. So the wording to check is in the notice. The closing sentence of a complaint reply is a courtesy, and we would rather you extended it anyway.
What the Act did to Article 9
Health data, which includes everything in a session note, is special category data. Two points follow.
The relaxation of the automated decision making rules, which is what most of the coverage has been about, excludes decisions based on special category data. This part is clear, and it means the change does not reach clinical records at all.
The Act did touch Article 9 itself. Since 20 August 2025 the opening words of the second paragraph say that a condition applies only if the processing is also based on Article 6. That has always been the position, and the statute now says it out loud. The health care condition is unchanged in substance, as is the domestic condition sitting underneath it.
Recognised legitimate interests, and the safeguarding point
The Act added a lawful basis called recognised legitimate interests, and the list in the new Annex 1 includes safeguarding vulnerable individuals and responding to an emergency. Relying on it removes the usual balancing exercise. That much is settled on the face of the statute.
Our reading is that this is the one place the Act may make your position simpler rather than merely different, because a disclosure to protect someone at risk is close to what the safeguarding entry describes. Two cautions. It answers the Article 6 question only, so you still need an Article 9 condition for the health data, and the amendment above makes that dependency explicit. And it does nothing to your ordinary basis for keeping notes.
Access requests
Two clarifications, both regulator guidance before and now in the statute. Your search has to be reasonable and proportionate rather than exhaustive. And where you have asked someone to clarify what their request covers, the time you wait for their answer does not count towards the response period.
Neither point touches the exemptions that do the real work in a therapy context, which are the ones covering third party material and the risk of serious harm.
What did not change
Nothing changed about retention. Nothing changed in the breach reporting duty that applies to you, and the 72 hour figure the Act introduced belongs to the separate regime for communications providers. If something you read this year told you to revisit your lawful basis because of this Act, it was almost certainly written for a different kind of organisation. Whose law governs the notes when your client is abroad is a different question, and we cover it in the guide on [working with a client in another country](/resources/guides/client-in-another-country).
What to do this week
- Add a complaints paragraph to your privacy notice. Say how someone complains, that you will acknowledge within 30 days, and that they may complain to the Information Commissioner's Office. That last part belongs in the notice rather than only in your reply.
- Give people a route to complain that is not only an online form. An email address in the notice is enough.
- Decide where a complaint lands and keep a simple log with the date received, the date acknowledged and the outcome. One line per complaint. Most practitioners will never write a second line.
- Leave your lawful basis alone unless you were relying on client consent to hold notes, which is usually the wrong choice for reasons that predate this Act. Our [other guides](/resources/guides) cover the rest of the United Kingdom position.
A footnote on advice
This guide is information, not legal advice, and it is not advice about your insurance or your registration. Where a point is settled we say so, and where we are interpreting we say that too. Before acting on it, please check your wording with your insurer, check your position with your professional body, and take advice from a lawyer qualified in the country your client is in. Vestibola accepts no liability for decisions taken on the basis of this page.
References
- Data (Use and Access) Act 2025, full text
- Data (Use and Access) Act 2025, section 103, complaints by data subjects
- Data Protection Act 2018, section 164A, complaints to controllers
- The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026
- Data (Use and Access) Act 2025, section 76, time limits for responding to data subjects' requests
- Data (Use and Access) Act 2025, section 78, searches in response to data subjects' requests
- Data (Use and Access) Act 2025, section 80, automated decision-making
- Data (Use and Access) Act 2025, Schedule 4, the recognised legitimate interests in Annex 1
- Data (Use and Access) Act 2025, Schedule 11, paragraph 4, amendments to Article 9
- Data (Use and Access) Act 2025, section 111, breach notification under the PEC Regulations
- UK GDPR, Article 9, processing of special categories of personal data
- Data Protection Act 2018, Schedule 1, Part 1, health or social care purposes
- ICO, How to deal with data protection complaints
- ICO, What do we do after we have finished our investigation
- ICO, Handling complaints, a step by step guide for small organisations
- ICO, the Data Use and Access Act 2025, summary of the changes to data protection law
About this guide
Jurisdiction, the United Kingdom. Last reviewed on 18 August 2026. Commencement dates and regulator guidance change, so treat anything dated here as accurate only to that date. This guide is not legal advice, and it is not a substitute for advice on your own circumstances.
Frequently asked questions
Does the Data Use and Access Act 2025 complaints duty apply to a solo therapist
Yes. Since 19 June 2026 every controller must operate a process for handling data protection complaints, and the Information Commissioner's Office states that there are no exemptions to this. For a one person practice that means a paragraph in the privacy notice, a route to complain that is not only an online form, and a simple log.
How long do I have to acknowledge a data protection complaint
Thirty days from receipt. That is on the face of the new section 164A of the Data Protection Act 2018. You must then respond without undue delay, make appropriate enquiries, keep the person informed and tell them the outcome.
Did the Act change the lawful basis for keeping therapy notes
No. Your Article 9 condition and the domestic condition beneath it are unchanged in substance. The Act did amend the opening words of the second paragraph of Article 9 to say that a condition applies only if the processing is also based on Article 6, which restates the position rather than changing it.
Does the relaxation of automated decision making apply to clinical records
No. The relaxation excludes decisions based on special category data, and health data includes everything in a session note.
Can I pause the clock on a subject access request
Yes, where you have asked the person to clarify what their request covers. The time you wait for their answer does not count towards the response period. Your search also has to be reasonable and proportionate rather than exhaustive.
Related guides
Last reviewed 18 August 2026. General information for practitioners, not legal advice.