Skip to main content

    Cyber Security · June 2026 · 7 min read

    What the DUAA means for UK SME websites

    On 19 June 2026 the UK's Data (Use and Access) Act 2025 (DUAA) came fully into force. It is the biggest change to UK data protection since UK GDPR itself – but if you read the headlines you'd be forgiven for thinking it only matters to big tech, AdTech and the NHS.

    It doesn't. It changes a handful of things that every UK SME website needs to be aware of, and it quietly reshapes the cookie and consent rules that most small businesses have been getting wrong for years.

    Here's what's actually changed, what you need to update, and – just as importantly – what you can ignore.

    What the DUAA actually is

    The DUAA amends three things at once:

    • the UK GDPR (the post-Brexit version of GDPR),

    • the Data Protection Act 2018, and

    • the Privacy and Electronic Communications Regulations (PECR) – the rules that govern cookies, tracking pixels, marketing emails and SMS.

    It doesn't replace UK GDPR. It tunes it. The goal, in the government's own words, is to make data protection "more proportionate" for small organisations while strengthening individual rights in a few specific places.

    The five things SME websites need to know

    1. There is now a statutory right to complain – and you must have a procedure

    This is the single biggest operational change. From 19 June 2026, individuals have a statutory right to complain to the organisation that holds their data before escalating to the ICO. In return, you must:

    • provide a clear way to complain (named contact, email address, form),

    • acknowledge complaints promptly,

    • respond within a defined timeframe (the ICO expects 30 days, extendable by two months for complex cases), and

    • keep a record of complaints and how they were resolved.

    If your privacy policy currently says "if you're unhappy, contact the ICO" – that's no longer enough. You need a documented internal procedure, and your privacy notice has to describe it.

    2. Cookies and tracking – the rules got tighter, not looser

    The DUAA amends PECR and significantly increases the maximum penalty for cookie breaches – aligning it with UK GDPR's £17.5 million / 4% of global turnover cap from 5 February 2026. The ICO also finalised its new Storage and Access Technologies guidance on 29 April 2026, which deliberately replaces the narrower term "cookies" with anything that reads or writes data on a user's device: pixels, localStorage, fingerprinting, SDKs, tags, link decoration.

    Practically, for a typical SME site, this means:

    • Consent banners must offer equal-prominence Accept and Reject – no "Accept All" button that's three times bigger than the alternative.

    • No pre-ticked boxes. Ever.

    • Cookie walls (where you can't use the site unless you accept) are effectively dead for non-essential tracking.

    • You must honour the Global Privacy Control (GPC) signal sent by browsers like Brave and Firefox.

    • Your cookie policy must list all storage technologies, not just cookies.

    3. The new "low-risk analytics" exemption – use it carefully

    This is the part that's been widely misreported. The DUAA introduces a narrow exemption that could let you run basic analytics (page views, traffic sources, performance measurement) on a notice-only basis, without a consent banner.

    The catch: the exemption is purpose-strict. The moment your analytics does any of the following, you're back to needing consent:

    • session replay or heatmaps (Hotjar, Clarity, FullStory),

    • cross-site or cross-device tracking,

    • profiling, advertising or remarketing,

    • sharing data with a third party for their own purposes (which is what GA4 arguably does).

    For most SMEs running GA4 plus a session-replay tool, the safer reading is: keep your consent banner. The exemption was written for genuinely first-party, minimal analytics – not the typical marketing stack. EU visitors are also still bound by EU GDPR, which has no equivalent exemption.

    4. Privacy policies need a refresh

    Most SME privacy policies were written against UK GDPR alone. After 19 June 2026 they should also:

    • reference the Data (Use and Access) Act 2025 alongside UK GDPR and the DPA 2018,

    • describe the new complaints procedure (see #1),

    • use the "storage and access technologies" framing in the cookies section,

    • be clear about whether you rely on the new analytics exemption (most SMEs shouldn't),

    • describe any use of AI or automated decision-making – the DUAA introduces lighter rules here for low-risk uses, but transparency obligations remain.

    5. Direct marketing – the rules just got more enforceable

    The DUAA aligns PECR's marketing penalties with UK GDPR. A non-compliant cold email campaign could now in theory attract a multi-million pound fine, where previously the cap was £500,000.

    For SMEs the practical implications are unchanged but the stakes are higher:

    • B2C marketing email and SMS still need opt-in consent.

    • B2B "soft opt-in" still works only for existing customers, for similar products, with a clear opt-out at point of capture and in every message.

    • "We bought a list of UK businesses" is still not a lawful basis for cold marketing email to sole traders or partnerships.

    What you can ignore

    Plenty of the DUAA coverage focuses on changes that don't affect typical SME websites:

    • Smart Data schemes – open banking-style data sharing for energy, telecoms, etc. Sector-specific.

    • Digital verification services – a new framework for ID providers. Only relevant if you are one.

    • National Underground Asset Register – exactly what it sounds like.

    • Most of the research and statistics provisions – aimed at universities and the NHS.

    If you're running a marketing website, a SaaS app, an e-commerce store or a professional services site, none of these need your attention.

    A short checklist

    1. Add a formal complaints procedure to your privacy policy (named contact, 30-day SLA, escalation route, register of complaints).

    2. Reference the DUAA 2025 and the ICO's 29 April 2026 Storage and Access Technologies guidance in your privacy and cookies pages.

    3. Audit your consent banner – equal prominence, no pre-ticks, no cookie wall, GPC honoured.

    4. Decide whether you're relying on the analytics exemption. Almost certainly the answer is no.

    5. Review your email marketing consent records – the penalties just got a lot bigger.

    6. Document everything. Under the DUAA, "we have a process" only counts if you can show the process.

    How Howell Tech can help

    We help UK SMEs get the compliance basics right without turning their website into a legal document. If you'd like a review of your cookie banner, privacy policy and consent flow against the new DUAA rules, get in touch – it's usually a half-day exercise and we can do it remotely.

    This article is general guidance, not legal advice. For organisations handling sensitive data, regulated sectors, or large-scale processing, get sector-specific legal advice.