This site uses essential browser storage to remember this choice. Optional Vercel Web Analytics, when enabled, helps understand which pages are useful. Choose whether to allow optional analytics.
The Data (Use and Access) Act rewrote the rules on reusing personal data in February 2026, and in August the ICO opened consultation on the anonymisation standard that route depends on. What a board should establish before approving the next analytics or AI programme.
In brief: since 5 February 2026 the UK GDPR has carried a new chapter setting out when personal data may be reused for research, archiving and statistical purposes, and it defines scientific research to include privately funded commercial work. The safeguards are narrower than that definition suggests, and the whole route rests on an anonymisation standard the ICO only put out for consultation on 24 August 2026. Boards should find out which programmes are already relying on it.
Most organisations hold far more customer data than they use, and the binding constraint is rarely appetite. It is an unresolved question about what the original collection permitted, usually settled by a lawyer saying no and an analytics team quietly building something smaller.
That question now has a statutory answer, and it is more interesting than the headlines about the Data (Use and Access) Act suggested. The Act did not simply relax the rules on reuse. It replaced a vague research derogation with a test that has conditions a firm can either evidence or fail.
What changed on 5 February 2026
The Commencement No. 6 Regulations, SI 2026/82, brought the bulk of Part 5 of the Data (Use and Access) Act 2025 into force on 5 February 2026. Three of those sections reshape what a firm may do with data it already holds.
Provision
What it inserts
What it now requires
Section 67
Article 4(2) to (5) UK GDPR
Scientific research means any research that can reasonably be described as scientific, whether publicly or privately funded and whether commercial or not, including technological development and applied research
Section 71
New Article 8A, repealing Article 6(4)
A written compatibility test for further processing: the link between purposes, the context of collection, the nature of the data, the consequences for people, and the safeguards in place
Section 86
New Chapter 8A, Articles 84A to 84D
Research, archiving and statistical processing permitted only where it is the collection itself, where it converts data into non-identifying information, or where the purpose cannot otherwise be fulfilled
Section 86 also repeals Article 89 of the UK GDPR and section 19 of the Data Protection Act 2018. The old derogation is gone. What replaces it is more permissive at the front door and considerably stricter inside.
The limit is in Article 84C, not the definition
Read only the section 67 definition and you would conclude that commercial analytics has been reclassified as scientific research. Article 84C corrects that in three sentences.
Safeguards are not satisfied if the processing is likely to cause substantial damage or substantial distress. They are not satisfied if the processing is carried out for the purposes of measures or decisions with respect to a particular data subject, with a single carve-out for approved medical research. And they are only satisfied if they include technical and organisational measures for data minimisation, pseudonymisation being the named example.
The second of those decides most commercial cases. A firm may use the research route to build a model, test a hypothesis or produce a population-level insight. The moment the output is used to price, rank, screen or service a named individual, the firm is outside Chapter 8A and back under the ordinary lawful-basis analysis, with Consumer Duty asking what outcome that customer actually received. Article 4(5) says the same thing about statistical purposes from the other direction: the result must be aggregate data that is not personal data, and neither the input nor the output may support a measure or decision about a particular person.
Anonymisation is the load-bearing assumption
Every version of this route rests on a claim that data has been anonymised or adequately pseudonymised, and that is the part the ICO has left until last. Its anonymisation guidance, published on 28 March 2025, is now under review because of the Act. On 24 August 2026 the ICO opened a consultation, running to 19 October 2026, on draft guidance covering anonymisation and pseudonymisation specifically for research, archiving and statistical purposes.
The draft makes a point that most data strategies are not built for: anonymisation is a property of a holder, not of a file. The same dataset can be personal data in one organisation's hands and anonymous in another's, depending on what else that recipient can realistically use to re-identify people. Controllers are asked to consider anonymisation first, pseudonymisation second, to assess identifiability in context including who else has access, to take particular care with data such as genetic information that resists de-identification, and to consider trusted research environments and federated access rather than copying data outward.
State of the data
Status in law
What the organisation must be able to show
Identifiable personal data
Fully in scope of the UK GDPR
Lawful basis, Article 8A compatibility assessment, Article 84C safeguards if relying on Chapter 8A
Pseudonymised data
Still personal data
Who holds the key, who could combine it with other information, and why the pseudonymisation counts as data minimisation
Anonymised data
Outside the UK GDPR
A dated identifiability assessment naming the recipient, the other information available to them, and the residual risk accepted
The third row is where most estates are thin. Firms routinely describe datasets as anonymised without a written assessment of who is receiving them and what else that party holds, and under the new chapter that assessment is not documentation hygiene. It is the difference between processing that sits outside data protection law entirely and processing that needs a lawful basis nobody has identified.
What this means for an AI programme
The temptation is to reclassify model training as scientific research and move on. The ICO's draft criteria make that harder than it looks. In its April 2026 commentary on the research guidance, Bird and Bird noted that the draft expects scientific work to deliver a meaningful improvement benefiting the entire field rather than only the organisation doing it, and treats work that merely customises existing technology as an indication against scientific research. Most enterprise fine-tuning fails both tests, and the same commentary flagged this as a live problem for training large language models, where feasibility is obvious from the start.
Section 68 offers broad consent to an area of scientific research where the purposes cannot yet be fully identified, but only where seeking consent that way is consistent with generally recognised ethical standards relevant to that area of research. A pharmaceutical firm can name those standards. A retail bank's analytics function usually cannot.
The practical conclusion is that the research route is real, narrow, and worth using deliberately rather than as a general amnesty. For most enterprise reuse the workable path remains a documented Article 8A assessment on a conventional lawful basis, supported by lineage that shows which source fields entered each dataset. That lineage lets a firm answer a subject access request or a regulatory enquiry about a training set without rebuilding the pipeline, and it is the same record that already carries the organisation's Critical Data Elements.
Five questions to ask before the next approval
Which of our current analytics and model training activities are justified as research or statistical purposes, who wrote that justification, and when?
For each one, which limb of Article 84B applies, and can we show the purpose could not be met with less personal data?
Where we call a dataset anonymised, who assessed identifiability, against what information available to the recipient, and how recently?
Does any output of this processing inform a measure or decision about an individual customer, and if so, what lawful basis covers that step?
Can we trace which source fields entered each training set without reconstructing the pipeline by hand?
The Act has replaced a question of appetite with a question of evidence, and the firms that can produce the evidence will spend the next few years using data their competitors are still arguing about.