Legislation – Data (Use and Access) Act 2025
Changes to legislation:
There are currently no known outstanding effects for the Data (Use and Access) Act 2025, Section 3.![]()
Changes to Legislation
Revised legislation carried on this site may not be fully up to date. At the current time any known changes or effects made by subsequent legislation have been applied to the text of the legislation you are viewing by the editorial team. Please see ‘Frequently Asked Questions’ for details regarding the timescales for which new effects are identified and recorded on this site.
Part 1Access to customer data and business data
Data regulations
3Customer data: supplementary
(1)
This section is about provision that regulations under section 2 may (among other things) contain.
(2)
The regulations may include—
(a)
provision about the procedure by which customers authorise persons to receive customer data or to do other things;
(b)
provision restricting the persons that may be authorised to persons that comply with specified conditions;
(c)
provision for a specified person to decide whether a person satisfies the conditions for authorisation (and see section 6 for further provision about decision-makers).
(3)
The regulations may make provision about requests relating to customer data, including provision about the circumstances in which a data holder may or must refuse to act on a request.
(4)
The regulations may make provision about the providing of customer data and the taking of action described in section 2(4), including—
(a)
provision requiring a data holder to provide customer data on one or more occasions, for a specified period or at specified intervals;
(b)
provision requiring a data holder, customer or third party recipient to use specified facilities or services, including dashboard services, other electronic communications services or application programming interfaces;
(c)
provision requiring a data holder or third party recipient to comply with specified standards, or participate in specified arrangements, relating to, or to the use of, such facilities or services;
(d)
provision requiring a data holder or third party recipient to provide, or arrange for, specified assistance in connection with the establishment, maintenance or management of such facilities or services;
(e)
provision about interface bodies (see section 7).
(5)
The regulations may include—
(a)
provision enabling or requiring a data holder to produce, collect or retain, or arrange for the production, collection or retention of, records of customer data provided in accordance with the regulations;
(b)
provision enabling or requiring a third party recipient to produce or retain, or arrange for the production or retention of, records of customer data received in accordance with the regulations.
(6)
The regulations may make provision requiring a person who, in the course of a business, processes customer data of a trader to assist, or take specified steps to assist, the trader in complying with regulations under this Part.
(7)
The regulations may make provision about the processing of customer data provided to a third party recipient in accordance with the regulations, including—
(a)
provision requiring a third party recipient to use specified facilities or services, including dashboard services, other electronic communications services or application programming interfaces;
(b)
provision requiring a third party recipient to comply with specified standards, or participate in specified arrangements, relating to, or to the use of, such facilities or services;
(c)
provision requiring a third party recipient to provide, or arrange for, specified assistance in connection with the establishment, maintenance or management of such facilities or services;
(d)
provision about interface bodies (see section 7);
(e)
provision about further disclosure of the data, including provision for a person to whom customer data is further disclosed to be subject to—
(i)
some or all of the obligations imposed on a third party recipient by the regulations in relation to the customer data;
(ii)
conditions imposed by the third party recipient.
(8)
The regulations may make provision enabling or requiring a data holder or a third party recipient to publish specified information relating to the rights and obligations of persons under the regulations, including—
(a)
information about the rights of customers in relation to customer data processed by the data holder or a third party recipient;
(b)
information about the activities carried out by the data holder or a third party recipient in performance of their obligations under the regulations.
(9)
The regulations may make provision about complaints, including provision requiring data holders or third party recipients to implement procedures for the handling of complaints.
(10)
The regulations may make provision about procedures for the resolution of disputes, including—
(a)
provision appointing, or providing for the appointment of, a person to determine disputes;
(b)
provision about the person’s powers when determining disputes;
(c)
provision about the effect of decisions relating to disputes;
(d)
provision about the review of decisions relating to disputes;
(e)
provision about appeals to a court or tribunal.
(11)
In subsections (4)(d) and (7)(c), references to assistance include actual or contingent financial assistance (such as, for example, a grant, loan, guarantee or indemnity or buying a company’s share capital).