The Data (Use and Access) Act is the first proper reshaping of UK data law since GDPR landed in 2018, and I would put money on most small SaaS founders never having read a word of it. I run several software businesses that all handle customer data in one form or another, so I have had to actually sit down and work out what it changes for a company my size. The short version is that it is not the disaster some of the scarier headlines suggested, but it is also not nothing, and ignoring it is a mistake.
Most of what got written about this Act when it passed focused on the big structural stuff, the renamed regulator and the changes to how research data gets used by universities and the NHS. None of that touches a normal SaaS business day to day. What actually matters if you are running CampSuite or Crocodile HR sized software is a handful of practical changes buried in the detail, and that is what I want to walk through.
What The Data Use And Access Act Actually Changes
At a high level, this Act tweaks UK GDPR and the old electronic privacy rules rather than replacing them outright. If you already have a reasonable data protection setup, most of your existing work still stands. What changes is a set of specific rules around cookies, marketing, subject access requests and automated decision making that were previously stricter in the UK than they needed to be, or that had become genuinely unworkable for a small team to comply with properly.
I am not a data protection lawyer and this is not legal advice, it is a founder telling you what I actually changed in my own businesses. If you process anything remotely sensitive, get proper advice rather than relying on a blog post, however well intentioned.
The Bits That Matter To A Small SaaS Business
Cookie Consent Gets Slightly Less Painful
The rules around cookies and similar technologies now allow consent to be skipped for a narrower set of low risk purposes, things like basic analytics used only to improve your own service, rather than every single non essential cookie needing an explicit opt in banner. That does not mean rip your cookie banner out. It means you can be more precise about which cookies genuinely need consent and which ones fall into the narrower exemption, which is worth revisiting if your current banner asks for consent to things it never actually needed to.
Direct Marketing Rules Widen A Little
The soft opt in for marketing, where you can email an existing customer about similar products without fresh consent, gets extended to non commercial organisations like charities, who previously could not use it at all. For a SaaS business the practical effect is smaller, but it is worth checking your own marketing consent logic still matches the current rules rather than one you copied from a template three years ago and never revisited.
Subject Access Requests Get A Clearer Clock
This is the one I actually care about. The Act clarifies when you can stop the clock on a subject access request while you wait for clarification from the person asking, and confirms what counts as a reasonable and proportionate search for their data. If you have ever had a disgruntled ex customer fire off a vague subject access request and watched your team spend two days trying to work out what a reasonable search even looks like, this genuinely helps. Document your search process once, properly, and you have a defensible answer every time it happens again.
Automated Decision Making Loosens Slightly
If your product makes any automated decisions about people, credit style scoring, automated approval or rejection workflows, risk flags, the rules around when you need a human in the loop have loosened outside of special category data. That is relevant if you are building anything in the fintech or HR tech space, which is exactly where Crocodile HR sits, so this was one I read twice.
The Enforcement Side Nobody Talks About
The bit that should actually get your attention is enforcement, not the consumer facing changes. Fines under the old electronic privacy rules, the ones covering cookies and electronic marketing specifically, were capped at a fraction of what UK GDPR allows. This Act brings those fines up to the same maximum levels as GDPR itself. In plain terms, a cookie consent mess up that used to carry a modest ceiling can now theoretically be fined at GDPR scale. I doubt the regulator is about to start hammering small SaaS companies over an imperfect cookie banner, but "we are too small to bother with" was never a great compliance strategy and it is an even worse one now the ceiling has moved.
What I Am Actually Doing About It
Practically, I did three things across my own businesses. First, I had someone actually read our cookie banner logic against the narrower low risk exemption rather than assuming the old blanket approach was still the safest option. Second, I wrote down our actual process for handling a subject access request, start to finish, so nobody is improvising under pressure when a real one lands. Third, I flagged the automated decision making changes to the product team at Crocodile HR because that is exactly the kind of feature area where a legal change like this quietly becomes a product requirement nobody planned for.
None of that took more than a few hours, and it is the same instinct I write about in securing a SaaS application without a dedicated security team, small, deliberate steps beat one big compliance project that never actually gets scheduled. If you are weighing up how UK policy keeps shifting under small tech businesses generally, it is worth reading alongside my take on UK AI policy and what it actually means for small business, because the pattern is the same, changes that sound huge in the press release and turn out to be a handful of practical adjustments once you read the actual text.
My Honest Take
I do not think the Data Use and Access Act is the deregulation win some commentators claimed, and I do not think it is the burden others warned about either. It is a sensible tidy up of rules that had genuinely become impractical for smaller teams to apply properly, alongside a quiet increase in the cost of getting it wrong. If you run a SaaS business handling UK customer data, spend the afternoon it takes to check your cookie logic, your subject access process and anything automated that makes decisions about real people. That is a far better use of your time than waiting for a regulator letter to force the conversation.
This is exactly the kind of unglamorous groundwork I help clients with through business consulting, the boring stuff that quietly protects everything else you have built. It is also part of why I keep coming back to getting the foundations right early, which is the whole premise behind The 28 Day Startup. Compliance is never the exciting bit of building a business, but neither is it optional just because you are small.


