UK GDPR Just Changed Again — What Retailers Holding Customer Data Need to Know

On 5 February 2026, major provisions of the Data (Use and Access) Act 2025 came into force, amending the UK GDPR in several significant ways. If your business holds any customer data — through a POS system, loyalty programme, email list, or online shop — these changes affect you.

The most immediately impactful change for retailers: PECR fines are now aligned with UK GDPR levels. That means cookie consent violations, email marketing breaches, and electronic communications failures now carry the same potential penalty as a major data breach — up to £17.5 million or 4% of global turnover.

A new right-to-complain obligation arrives in June 2026. Controllers must acknowledge complaints within 30 days and provide a full response without undue delay. In practice, this means you need a documented complaints handling procedure before June.

Cookie consent rules have been tightened. The reject option must have equal prominence to the accept button. Non-essential cookies must not fire before consent is given. And dark patterns that pressure users into accepting are explicitly targeted.

New rules on automated decision-making have also been introduced, which may be relevant if you use any algorithmic tools for pricing, customer segmentation, or fraud detection.

The key takeaway for independent retailers: if your POS system stores customer names, addresses, purchase history, or payment information, you are a data controller with specific legal obligations. The DUA Act doesn’t change that fundamental fact — but it does raise the stakes.

At ITS4, we audit POS data handling practices, configure appropriate retention policies, and ensure your systems support GDPR-compliant customer data management. It’s not just about avoiding fines — it’s about maintaining the trust your customers place in you.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top