Onfido competitors

UK Digital Verification Services: What the Data (Use and Access) Act 2025 Creates for IDV Providers

Table of Contents

Key Takeaways

  • The Data Use and Access Act 2025 is an update on GDPR that modernizes how companies handle data. 
  • DUAA removes repetitive consent clicks, but companies have much harsher penalties if they misuse customers’ private information.
  • The Act establishes a statutory framework for Digital Verification Services (DVS), alongside broader reforms to data use and governance 
  • The DVS framework has five parts: 1. Trust framework, 2. Supplementary codes 3. Public Register, 4. Information gateway 5. Trust mark
  • Companies based inside and outside the UK that process UK residents’ data need to understand and correctly implement DUAA. 

 

The UK’s data privacy landscape is undergoing an enormous transformation with their latest regulation The Data (Use and Access) Act. At a high level, it makes identity checks faster and digital-first. 

Book a Demo

Give your business the boost of a fully automated, KYC process. No geographical limits and fast, frictionless onboarding verification processes enhance customer’s experience. 

If your company handles UK user data, stick with us. We’ll go over everything you need to know to stay compliant. 

 

What Is the Data (Use and Access) Act 2025?


The Data Use and Access Act (DUAA) 2025 is an updated regulation on the UK GDPR laws. Much like KYC regulations, DUAA aims to ethically verify users and keep their data safe.

DUAA’s main objective is to loosen the reins on certain administrative data-sharing restrictions, while majorly cracking down on intrusive or non-compliant organizations. In a nutshell, it’s designed to improve data accessibility, security, and public trust. 

Here are the new rules you need to know:

1. Relaxed Cookie Consent Rules 

Businesses no longer need user consent for specific cookie types (e.g., appearance cookies, emergency assistance cookies, and strictly necessary cookies) if they give users an easy way to opt out. 

2. Massive Increase in Cookie/Marketing Fines

Before DUAA, the maximum fine for violating the UK’s Privacy and Electronic Communications Regulations (PECR) was £500,000. Under the new rules, fines can total up to £17.5 million or 4% of a company’s global annual turnover, whichever is higher. 

3. Automated Decision-Making (ADM) Restrictions Lifted

Before, there was a broad ban on using solely automated AI or software to make significant decisions about users and customers. The new rules are narrower:

  • The ban only applies if the automated decision is based on “special category” data (like health, religious, or racial data)
  • If a business is using regular personal data for automated decisions, the legal pathway is broader, though transparency and the right for a human to decline are still required.

4. Recognized Legitimate Interests 

To process data under “legitimate interests,” a business has to ensure its objectives don’t infringe on the user’s privacy rights. Rule 4 introduces a shortlist of legitimate interests:

  • National security, public security, and defense
  • Detecting, investigating, or preventing crime
  • Safeguarding vulnerable individuals
  • Responding to legal requests from public interest bodies

5. Broader Rules for Research and Data Re-use

The definition of “scientific research” now includes public and privately funded research; AKA it’s easier for businesses to use data for scientific or statistical purposes without violating the rules. It also gives users a single, “broad consent” that covers an entire area of research.

6. The ICO Has More Power 

The Information Commissioner’s Office (ICO), the UK’s data watchdog, has new privileges. They can now:

  • Force a business to pay for a third-party report that investigates its own data breaches
  • Compel witnesses (like managers or employees) to attend interviews, where lying is a criminal offense
  • Legally demand specific internal documents like Risk Assessments

7. New International Data Transfer Test

When moving data from the UK to a third country, the old standard required the destination country to have “essentially equivalent” data protection. The Act now has a “not materially lower” standard test, so the UK government has more flexibility when approving data-sharing clauses with different countries.

8. Coming Soon: Mandatory Customer Complaint Systems

The last rule, which will take effect on June 19, 2026, states:

  • Customers/users have the legal right to complain directly to businesses about data practices.
  • Businesses must provide an easy, electronic way to track these complaints, acknowledge them within 30 days, and work to resolve them without delay. (This rule does not exist in the EU GDPR, making it unique to the UK).

What Is the Digital Verification Services Regime?

The Digital Verification Services (DVS) framework establishes strict privacy and interoperability around UK digital identity verification. Under the DVS framework, a person can easily use verified credentials for multiple purposes (e.g., opening an account, buying property, or completing Right to Work checks).

 

The Office for Digital Identities and Attributes (OfDIA), oversees the framework and allows organizations to prove their services meet the standards for security, reliability, and data privacy. Organizations that meet the criteria earn the “trust mark.”

 

The DVS trust mark isn’t just given out, though. Organizations must be independently certified against the DVS trust framework and listed on the official public register to legally display the mark. For organizations, the trust mark is a visual sign of compliance that lets users and businesses know that their data is handled according to strict criteria. 

Book a Demo

Give your business the boost of a fully automated, KYC process. No geographical limits and fast, frictionless onboarding verification processes enhance customer’s experience. 

DVS has five parts:

 

  1. Trust framework: Rules and standards for DVS
  2. Supplementary codes: Different DVS may be subject to different codes 
  3. Register: A public record of organizations with DVS services
  4. Information gateway: Allows public authorities to disclose information to a registered DVS provider for digital verification *more on this below
  5. Trust mark: A certification for organizations on the DVS register

The Data-Sharing Gateway: What It Enables

Some parts of the DVS framework are straightforward (i.e. the trust mark) but others are slightly trickier, like part 4, which states that public authorities can disclose information to a registered DVS provider for digital verification purposes. 

Essentially, this gateway allows public authorities (like His Majesty’s Revenue and Customs or the Department for Education) to securely share data about an individual with certified, private-sector DVS providers.

Instead of having citizens print or scan physical documents to prove who they are, public authorities can now digitally verify the user’s information as long as they follow specific rules around:

1. Sharing

A public authority can’t share data with just anyone. They can only disclose information if:

  • The business requesting it is certified and registered on the official UK DVS register
  • The individual has explicitly requested the check (e.g., they’re trying to open a bank account or prove their age and need ID verification) 
  • The request complies with all existing data protection laws (like GDPR)

2. How the Data is Shared 

The law doesn’t force public authorities to use a specific method, but it includes two ways they can disclose information by using:

  • Secure APIs: Instead of handing over an entire record, the authority will use an API to verify a single “attribute” (e.g., answering “Yes, this person is over 18”) 
  • Digital Credentials: Some authorities might issue official digital documents directly into secure smartphone apps, like the GOV.UK Wallet 
  1. Charging Fees

Public authorities are legally allowed to charge DVS providers a fee that covers the costs of setting up, running, and maintaining the secure data-sharing systems.

  1. Direct Contracts 

Before any data changes hands, the public authority and DVS provider must sign a formal contract and a Data Sharing Agreement that outlines who is responsible for what, the security safeguards used, and the fees being charged.

5. Cooperating with DVS providers 

Public authorities have the final say on processing requests, butthe framework sets out circumstances in which public authorities may refuse requests and requires them to provide reasons for doing so



How the DUAA Affects Identity Verification Providers Operating in the UK

Organizations operating in the UK have been getting ahead of these regulations by revisiting their strategies around data protection. You can start by:

  1. Reviewing Current Data Protection Policies (i.e.) Assessing how automated decision-making rules, legitimate interests, and children’s data protections apply to operations
  2. Developing Review Procedures (i.e.) Protocols for investigating, acknowledging, and replying to complaints within the required timeframes
  3. Updating Processes (i.e.) Creating search principles in data subject access request procedures
  4. Training Staff (i.e.) Ensuring teams understand the changes and how they impact daily operations

Companies based outside the UK that process UK residents’ data also need to know the ins and outs of DUAA. This is mostly relevant for US companies, who should review whether GDPR applies to US companies under the new framework. If applicable, US companies may also need to rework current data protection policies, review complaint procedures, update processes, and train staff on the new legislation. 

Steps IDV Providers Should Take in 2026

The Data Use and Access Act 2025 isn’t just about compliance; it’s also about how to maintain trust with customers. To make the transition as successful as possible, IDV providers can:

  1. Review DUAA rules: Study how the changes affect your operations and compliance responsibilities
  2. Update Policies and Procedures: Rework data protection policies to meet the new requirements around automated decision-making, legitimate interests, handling complaints 
  3. Create Training Programmes: Train staff to understand the changes and how to implement them correctly 
  4. Monitor Regulations: Tune in and mark ICO guidance releases throughout 2026
  5. Enlist The Help Of Professional Support: With changes so complex, many organizations could gain a strategic advantage from enlisting a specialist

Understanding and embracing DUAA will help your company stay ahead in the UK market and keep customers’ trust.

Book a Demo

Give your business the boost of a fully automated, KYC process. No geographical limits and fast, frictionless onboarding verification processes enhance customer’s experience. 

FAQs

What is the Office for Digital Identities and Attributes (OfDIA)?

The Office for Identities and Attributes (OfDIA) governs the UK's digital identity market. The office works to maintain transparency within the trust framework and enforce its standards, explore new avenues for citizens and businesses to benefit from digital identity, and support 

development of digital identities that are reusable. In essence, OfDIA works to support UK digital identity solutions for all who choose to use them.

Is the DVS Trust Mark mandatory for identity verification providers in the UK?

No, the UK CertifID trust mark is optional for identity verification providers. While the UK Digital Verification Services (DVS) Trust Framework has rules for providers to appear on the official government register, providers do not have to show the trust mark. However, many providers choose to display the DVS Trust Mark to gain users’ trust and show they comply with the framework.

What data can public authorities share with DVS-registered providers?

Under the UK's Data (Use and Access) Act 2025, public authorities can share specific personal information with registered DVS providers under the following conditions: 

 

  • User Consent: Public authorities can only share information with a DVS provider if the individual has explicitly requested digital verification
  • Permissible Information: The data shared is restricted to personal attributes and can only share what’s necessary to fulfill the requested DVS
  • Data Protection Laws: Disclosures must comply with UK data protection legislation that says authorities can only share information they gathered through public functions
  • Registered Providers Only: Data is only accessible to providers that are listed on the statutory DVS Register and have been independently certified against the UK digital identity and attributes trust framework

How does the DUAA relate to UK GDPR?

DUAA is an update to GDPR. It makes it easier for companies to share data to verify users’ identities, but it also makes non-compliance penalties much harsher. DUAA is a collection of digital-first identity checks for all companies that use UK citizens’ data. 

What is the difference between the DVS regime and the GOV.UK One Login service?

The DVS (Digital Verification Services) regime and the GOV.UK One Login service are both part of the UK’s digital identity strategy, but they serve different purposes.

  • DVS Regime: A regulatory framework that allows private companies to become certified to verify a person's identity.

  • GOV.UK One Login: The sign-in system citizens use to access public services online. 

When you create a GOV.UK One Login, the system will securely check your identity, using the DVS infrastructure to pull data from certified DVS providers or trusted government databases (like the DWP) to verify your identity.  

You may also like

What is KYC Onboarding?

What is KYC Onboarding?

AI Image detector

AI Image detector: best 10 free tools for 2026

Understanding the Key Components of KYC

Understanding the Key Components of KYC