Cybersecurity 2026

UK Trends and Developments Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP

Sidley Austin LLP 70 St Mary Axe London EC3A 8BE UK

Tel: +44 20 7360 3600 Fax: +44 20 7626 7937 Email: marketingdepteurope@sidley.com Web: www.sidley.com

Introduction Last year brought significant developments across the global data privacy and cybersecurity landscape, and this momentum shows no sign of slowing down. Cybersecurity remains a systemic concern that con - tinues to grow in importance; a cybersecurity incident can have significant operational, financial, regulatory, and reputational consequences for an organisation. As the world grows ever more dependent on technol - ogy, cybersecurity awareness and resilience become increasingly fundamental. Consequently, cybersecu - rity remains a UK government priority. The long-term pattern of the increasing intensity and sophistication of cybersecurity risks has been a driver of cyber legis - lation and policy developments in the UK. The rollout of new legislation in the UK, most notably the pro - posed Cyber Security and Resilience Bill, signals an enhanced cybersecurity-regulatory regime for busi - nesses, aimed at protecting services that are essential to the day-to-day functioning of UK society. Amid an increasingly challenging cyber threat environ - ment for UK organisations, 2025 saw the introduction of several important legislative and policy changes. Together, these measures significantly expand the UK’s privacy and cybersecurity regulatory framework, as detailed below. Data (Use and Access) Act 2025 On 19 June 2025, the UK Data (Use and Access) Act 2025 (the “DUA Act”) received Royal Assent. The DUA Act amends existing UK privacy laws (ie, the UK Gen - eral Data Protection Regulation (the “UK GDPR”), the UK Data Protection Act 2018 (the “DPA 2018”) and the Privacy and Electronic Communications Regula - tions 2003 (“PECR”)) to promote innovation and eco -

nomic growth, whilst continuing to protect individuals and their rights. Its provisions are being phased in between June 2025 and June 2026. See below for

some of the notable amendments. Cookie rules and fines under PECR

The DUA Act extends the cookie rules under PECR to any form of online tracking (including pixels) and increases the maximum fines for breaches to align them with fines under the UK GDPR (ie, up to GBP17.5 million or 4% of global turnover). Under the DUA Act, the use of “low-risk” cookies – eg, those deployed to collect statistical information about how a website is used to improve service or functionality – is now per - mitted without explicit consent, provided users have The DUA Act introduces a statutory framework for Digital Verification Services (“DVS”), intended to ena - ble individuals to securely verify their identity, attrib - utes, or eligibility online and, where appropriate, as an alternative to physical documentation. Smart data schemes The DUA Act facilitates the introduction of sector- specific “Smart Data schemes” by giving the Secre - tary of State new implementation powers accordingly. The schemes enable secure data-sharing by giving customers the right to require vendors to share their data with authorised third parties. The system is anal - ogous to the GDPR’s “right to data portability” but is broader in scope, as it also covers non-personal data and information related to goods, services or digital content. The DUA Act additionally creates a route for HM Treasury and the Financial Conduct Authority (the an opportunity to opt out. Digital verification services

457 CHAMBERS.COM

Powered by