Data (Use and Access) Act 2025 update and protecting yourself against a cyber attack

The latest data protection insights from Ashfords

Welcome to the latest edition of our data protection newsletter. In this edition, we look at the Data (Use and Access) Bill and the areas that organisations should consider as part of their internal management when facing a data breach.

Last week the Data (Use and Access) Bill received Royal Assent, becoming the Data (Use and Access) Act 2025. We unpacked the changes to UK data protection law in our webinar on 1 July, and are producing commentary on the new law.

The numerous cyber security attacks on household names such as Marks & Spencer, Co-op and Adidas has put cyber security at the top of the agenda, and prompted even the most robust organisations to reassess their cyber security protocols and procedures as a priority. Such attacks cause huge disruption and the risks are high; it can lead to data leaks (including unauthorised sharing of personal data relating to customers, clients and employees, as well as commercially sensitive business information), and interrupt the company’s ability to operate its business-as-usual. The cost of a cyber security incident is both financially and reputationally significant.

Read our latest guides on cyber attacks and data breaches

Cyber and data breaches: an eight point checklist for senior management

Absolute immunity from cyber risk is unattainable; decisive, well rehearsed response is not. This checklist briefly sets out an eight point framework for boards and senior management to deploy when preparing for - or responding to - a cyber or data security incident.

Read more
Data Breach Concept (1)

How can businesses protect themselves against cyber-attacks?

Businesses handling significant or sensitive personal data are especially vulnerable to cyber security breaches. In this guide we highlight recent cyber security trends, advise the key steps for businesses to enhance their cyber resilience and point out the legal considerations following a data breach.

Read more
Cyber Attack Concept A Padlock Disappearing

Minimising data breaches in the hybrid workplace: top tips for employers

Recent reports show a significant increase in the number of breaches of personal data over the past couple of years through incidents involving employees. It's likely that the rise in hybrid working and home working has contributed significantly to the rising data breach statistics.

Read more
Work Video Call With Some People In Office And Others At Home Hybrid Working

Data breaches – takeaways for businesses from updated ICO guidance

The consequences of data breaches can be far-reaching and may result in a hefty fine from the UK’s Information Commissioner’s Office("ICO"). This article considers the reporting obligations of UK businesses which have suffered a data breach, based on updated guidance from the ICO.

Read more
Data Breach Concept An Unlocked Padlock On A Circuit Board

Read our latest insights

Recent cyber security incidents round up 

There have been several recent high profile companies who have fallen victim to cyber attacks including Marks & Spencer, Co-op, Harrods and Adidas. The outcomes and damage caused by the attacks vary case-to-case. Read more in detail about each of the aforementioned company attacks.

Read more
Cyber Security Concept On Circuitboard (1)

IT providers beware: ICO issues its first fine under the UK GDPR against a data processor

In this article, we highlight what security obligations data processors have under UK GDPR, what the security failures were in this particular case, and whether the processing of sensitive personal data attracts any additional security obligations.

Read more
Programming Code