UK GDPR and Data Protection Essentials for Every Employee
A plain-English refresher on core UK GDPR principles and what the Data (Use and Access) Act 2025 (DUAA) changes for everyday employees, from subject access requests to everyday data-handling habits.
Every employee who touches a colleague's, customer's or supplier's personal data — which, in practice, is almost everyone — has legal duties under UK GDPR. Most organisations already run annual data protection refreshers, but 2026 gives that training a sharper edge: the Data (Use and Access) Act 2025 (DUAA), which received Royal Assent on 19 June 2025, is reforming parts of the UK's data protection framework in stages throughout 2025 and 2026. Whether you work in finance, HR, sales, operations or the shop floor, understanding what has changed — and what hasn't — is now part of doing your job responsibly. Learnsignal's CPD training courses cover this exact refresher requirement for organisations that need to evidence up-to-date staff training.
This guide covers the core UK GDPR principles every employee should already know, what the DUAA actually changes, why refresher training matters more than ever, and practical everyday habits for handling personal data safely — in email, spreadsheets, paper files and when sharing data with third parties.
The core UK GDPR principles every employee should know
UK GDPR did not disappear after Brexit — it was retained in UK law and now sits alongside the Data Protection Act 2018 and the amendments made by the DUAA. Its foundations remain the same six data protection principles set out in Article 5, and every employee handling personal data should be able to explain them in plain terms:
- Lawful basis: you cannot process personal data just because it would be convenient. There must be a valid legal reason — consent, contract, legal obligation, vital interests, public task, or legitimate interests — before data is collected or used.
- Purpose limitation: data collected for one reason (say, processing an expense claim) shouldn't quietly be reused for an unrelated purpose (say, building a marketing list) without a fresh lawful basis.
- Data minimisation: collect and keep only what's actually needed. A form that asks for a date of birth "just in case" is a minimisation problem waiting to happen.
- Accuracy: personal data should be correct and kept up to date, with inaccurate data corrected or erased without undue delay.
- Storage limitation: data shouldn't be kept indefinitely "just in case it's useful later" — retention periods should be defined and followed.
- Integrity and confidentiality (security): appropriate technical and organisational measures must protect data against unauthorised access, loss or damage.
Alongside the principles, employees should be familiar with the individual rights UK GDPR gives to data subjects — the right of access, rectification, erasure, restriction, portability, and the right to object to certain processing. Many of these rights surface first as a request handled by a manager or an HR team, so recognising one when it lands in an inbox matters. For a detailed walkthrough of how to handle a subject access request specifically, see Learnsignal's HR guide to handling DSARs, which goes deeper into timescales, exemptions and practical response steps than this general awareness post covers.
What's changing under the Data (Use and Access) Act 2025 (DUAA)
The DUAA is a reform, not a replacement, of UK GDPR. Most of the principles above are untouched. What the Act does is adjust specific mechanics — some already in force, others still being phased in through 2026 — and every employee should know the headlines even if the detail sits with the data protection or compliance team.
Subject access requests: a "reasonable and proportionate" search
One clearer change puts on a statutory footing something the Information Commissioner's Office (ICO) had already said in guidance: when responding to a subject access request, an organisation only needs to carry out a reasonable and proportionate search for the requested information, rather than an exhaustive search of every system regardless of cost or effort. It doesn't lower an employee's obligation to respond promptly and honestly when asked to search their own inbox or files — it clarifies the scope expected of the organisation as a whole.
Automated decision-making
The Act relaxes some previous restrictions on automated decision-making (ADM) — decisions made about a person with no meaningful human involvement. Organisations now have a broader set of lawful bases available for significant automated decisions, including legitimate interests in more circumstances than before. Decisions based on special category data (health, race, religion, trade union membership and similar) remain far more tightly restricted, and safeguards — such as the ability to obtain human review of, or challenge, an automated decision — still apply. If your role involves any system that scores, filters or decides things about individuals automatically, from recruitment screening to fraud checks, flag this change to your data protection lead rather than assume it's someone else's problem.
"Recognised legitimate interests"
The DUAA introduces a narrower category called recognised legitimate interests — a short list of specific public-interest purposes (such as crime prevention, safeguarding and responding to emergencies) where an organisation can rely on legitimate interests as its lawful basis without carrying out the usual balancing test. This is a targeted carve-out, not a general licence to skip assessments — legitimate interests as an everyday lawful basis still requires the standard balancing exercise for anything outside the recognised list.
Direct marketing and the "soft opt-in"
Direct marketing rules under the Privacy and Electronic Communications Regulations (PECR) have also been extended: the "soft opt-in", which previously let commercial organisations email existing customers about similar products without fresh consent, now extends to charities and other non-commercial organisations emailing people who have previously expressed support or interest. Anyone in a marketing, fundraising or membership-facing role should check with their compliance team before assuming this applies to a specific campaign.
From the ICO to the Information Commission
The Act also provides for the Information Commissioner's Office to be reconstituted as a new body called the Information Commission — moving from a "corporation sole" (a single individual, the Commissioner) to a board-led body corporate, similar in structure to regulators such as Ofcom. This is a genuine governance change, not a rebrand, though the ICO's existing powers, guidance and enforcement functions transfer across. As of 2026 this transition is being phased in, so don't be surprised to see the regulator referred to as both the ICO and the Information Commission during the handover — the underlying rules and your obligations as an employee are unaffected either way.
Because several of these provisions were only brought into force through 2025 and 2026, and some detail is still subject to guidance, treat any specific compliance question — "can we send this email without consent", "can we automate this decision" — as one for your organisation's data protection contact, not something to self-diagnose from a blog post. If your role sits closer to the legal or compliance side of data protection, Learnsignal's UK GDPR and data protection guide for legal practice covers the DUAA reforms in more depth from that specialist angle.
Why refresher training matters: the accountability principle
UK GDPR Article 5(2) adds a seventh dimension on top of the six principles above: accountability. It isn't enough to comply with the principles — an organisation must be able to demonstrate that it complies, with evidence: policies, records of processing, training logs, and proof that staff actually understand what's expected of them. A data protection policy nobody has read is not evidence of compliance; it's a liability.
This is precisely why "refresher" training — not just onboarding training — is standard practice, and increasingly expected by regulators and auditors alike. Data protection law, systems and risks change: new tools get adopted, new categories of data get collected, staff move between teams, and now a major legislative reform is working its way through implementation. Annual or biennial refreshers keep the accountability principle real rather than theoretical, and they're the first thing an organisation will be asked to produce if something does go wrong — for example, following a data breach. Learnsignal's guide to responding to a personal data breach sets out exactly what an employer needs to do in the 72 hours after a breach is discovered, and having a well-trained workforce is the best way to reduce how often that guide gets used in anger.
Everyday data-handling habits every employee should follow
Most data protection failures aren't dramatic hacks — they're small, everyday mistakes. A handful of consistent habits go a long way:
- Email: double-check the recipient before hitting send, especially with autocomplete — misdirected email is one of the most common causes of reported data breaches. Use BCC (not CC) when emailing a list of external recipients whose addresses shouldn't be visible to each other, and think twice before forwarding a chain that contains personal data further than it needs to go.
- Spreadsheets: avoid exporting more personal data into a working spreadsheet than the task actually needs — data minimisation applies to a quick pivot table just as much as a formal database. Password-protect or restrict access to spreadsheets containing personal data, and delete working copies once the task is done rather than letting them sit in a downloads folder indefinitely.
- Physical documents: operate a clear-desk approach for anything containing personal data, lock filing cabinets, and use confidential waste/shredding rather than a general bin. A printed report left on a desk overnight or a shared printer is a live data protection risk.
- Third-party sharing: before sending personal data to a supplier, partner or contractor, check whether a data processing agreement is already in place and whether the transfer has been authorised — don't assume that because a request looks routine, it's automatically fine to action. This applies equally to data leaving the UK, where international transfer rules still apply.
- Passwords and access: use strong, unique passwords and multi-factor authentication where available, lock your screen when you step away, and only access personal data you actually need for your role — curiosity is not a lawful basis.
None of these habits require legal training to follow — they require awareness, and awareness is exactly what refresher training is designed to build and keep current.
FAQs
Does the DUAA replace UK GDPR?
No. UK GDPR and the Data Protection Act 2018 remain in force. The DUAA amends and reforms specific parts of that framework — including subject access request handling, automated decision-making, a new "recognised legitimate interests" category, direct marketing rules, and the ICO's governance structure — rather than replacing the regime wholesale.
Do employees need to do anything differently right now because of the DUAA?
For most employees, day-to-day obligations are unchanged: the core principles, individual rights, and the need for a lawful basis before processing personal data all still apply exactly as before. The DUAA mainly changes how organisations (not individual employees) structure certain processes. The main practical takeaway for staff is to stay alert to updated internal policies as your organisation implements the changes, and to flag anything involving automated decisions or marketing consent to your data protection team.
Is the ICO still the regulator, or has it become the Information Commission?
Both names may be seen during 2026 as the transition from the Information Commissioner's Office to the new Information Commission is phased in. The change is a governance restructuring — moving to a board-led body — rather than a change in the underlying rules organisations and employees must follow.
How often should GDPR refresher training happen?
There's no single legal number, but annual refreshers are widely regarded as good practice, and the accountability principle under Article 5(2) means organisations should be able to show that training is current, relevant and actually completed by staff — not just scheduled.
Keep your data protection knowledge current
UK GDPR compliance isn't a one-off box to tick — it's an ongoing responsibility that every employee shares, and one that's actively evolving as the DUAA reforms continue to roll out through 2026. Learnsignal's CPD courses include up-to-date data protection and GDPR refresher training designed to keep your whole team compliant, confident and audit-ready.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


