Westminster eForum

For booking-related queries or information on speaking please email us at info@forumsupport.co.uk, or contact us: +44 (0)1344 864796.

Next steps for data protection in the UK

TO BE PUBLISHED January 2027


Starting from: £99 + VAT
Format: DOWNLOADABLE PDF


This conference will consider next steps for data protection in the UK. Areas for discussion include implementation of the Data (Use and Access) Act 2025, data rights, accountability and redress, regulatory enforcement and organisational compliance, responsible data use in AI and other data-intensive technologies, data intermediaries, Smart Data and trusted data-sharing services, and UK-EU and international data flows.


It will be an opportunity for key stakeholders and policymakers to examine priorities for implementing recent reforms, supporting consistent interpretation and application of the framework, and enabling responsible data use while maintaining individual rights and public confidence. The discussion takes place in the context of the recently concluded Government consultation on Empowering people through data intermediaries, calls for evidence on Data regulation in the age of AI and other data-intensive technologies and Data flows you can trust, and the full commencement of the data protection provisions of the Data (Use and Access) Act 2025. Delegates will assess where existing legal and governance arrangements are working effectively, where uncertainty or unnecessary friction remains, and whether further guidance, targeted regulatory changes or wider reform may be required.


The agenda will examine practical experience of the Data (Use and Access) Act, including the impact of revised data-protection requirements, changes to lawful bases and subject access requests, the ICO’s new investigatory and enforcement powers and the introduction of mandatory processes for handling complaints from data subjects. Attendees will consider requirements for accountability, redress, organisational governance and regulatory certainty, alongside the support needed by SMEs, charities and public-sector bodies to apply the framework consistently. Further discussion will focus on responsible use of data in AI systems, including access to and provenance of data, transparency, automated decision-making, privacy-enhancing technologies, assurance and the management of risk across complex supply chains.


Further sessions will consider how trusted access to and sharing of data can support research, competition, improved public services and the development of new products while maintaining individual rights and public confidence. Delegates will examine the legal status and responsibilities of data intermediaries, delegation of data rights, data portability, and approaches to increasing public awareness, trust and control. Discussion will also consider the development of trusted data-sharing and intermediary services, the potential contribution of Smart Data schemes and interoperable governance models, and requirements for secure cross-sector and international data flows. Consideration will also be given to the renewed EU adequacy decisions for the UK, the implications of future UK regulatory development for alignment with EU requirements and the scope for a distinct UK approach, and priorities for supporting digital trade, investment and international interoperability over the longer term.


Overall areas for discussion include:


  • post-consultation policy direction:
    • next steps following the 2026 consultations and calls for evidence - priorities for 2027, further guidance, codes of practice
    • areas requiring regulatory certainty - targeted reform versus more fundamental changes to the UK data framework - secondary legislation
  • DUAA implementation, enforcement & redress:
    • early experience of revised data-protection requirements, including recognised legitimate interests and subject access requests, and the Information Commissioner’s strengthened powers
    • complaints handling, investigation and redress - consistency, proportionality, record-keeping and regulatory escalation
    • compliance capability across SMEs, charities and public bodies - guidance, training and organisational accountability
  • data intermediaries, portability & Smart Data:
    • legal roles, liability and delegation of data-subject rights - reducing friction in third-party access requests
    • lessons from Open Banking and development of Open Finance and wider Smart Data schemes
    • consent, interoperability, digital identity and trusted models for consumer control and data sharing
  • AI, data-intensive technologies & assurance:
    • training-data access and provenance - automated decision-making, transparency and accountability across AI supply chains
    • synthetic data, federated learning, confidential computing and privacy-enhancing technologies
    • AI assurance, auditing and governance - managing risk while supporting research and commercial adoption
  • trusted data use, security & public confidence:
    • secure data sharing across health, research, financial services and public services - governance, access and public benefit
    • cyber resilience, incident response and the relationship between data protection and information security
    • awareness of rights, responsible stewardship and approaches to strengthening trust in public- and private-sector data use
  • international transfers, adequacy & digital trade:
    • operation of renewed UK-EU adequacy arrangements - alignment, divergence and implications for future reform
    • UK-US and wider international transfer mechanisms - interoperability between regulatory regimes
    • supporting cross-border innovation, investment and digital trade while maintaining effective safeguards


This on-demand pack includes

  • A full video recording of the conference as it took place, with all presentations, Q&A sessions, and remarks from chairs
  • An automated transcript of the conference
  • Copies of the slides used to accompany speaker presentations (subject to permission
  • Access to on-the-day materials, including speaker biographies, attendee lists and the agenda