Jurisdictions / United Kingdom
United KingdomNotable recent legislation
Europe · Law stated as at Jun 2025
Data (Use and Access) Act 2025 — significant post-Brexit divergence from EU GDPR
The United Kingdom protects data through a structured framework of copyright, retained sui generis database rights, trade secrets, contract, and data protection law, but Brexit has introduced significant divergence from the EU. The Copyright, Designs and Patents Act 1988 protects original databases as literary works and — distinctively — recognizes computer-generated works under Section 9(3), deeming the author to be the person who made the arrangements necessary for creation, a provision that may extend limited protection to AI-generated datasets where human oversight can be demonstrated.
Sui generis database rights survive under the Copyright and Rights in Databases Regulations 1997, but reciprocity was lost: UK databases no longer receive automatic protection in the EU, and EU databases created after January 1, 2021 are unprotected in the UK absent contractual rights. Trade secret protection is strong, combining the Trade Secrets (Enforcement, etc.) Regulations 2018 with the common law of breach of confidence (Coco v. A.N. Clark) and, unlike the EU, criminal enforcement under the Computer Misuse Act 1990.
Unlike the EU, the UK limits text and data mining to non-commercial research, so AI developers must license training data; a 2022 proposal to broaden the exception was withdrawn in early 2023 after rightsholder opposition; the government's March 2026 statutory report kept the status quo. Getty Images v Stability AI [2025] EWHC 2863 (Ch) — the first UK judgment on AI models as 'infringing copies', now on appeal — and the pre-action Mumsnet–OpenAI scraping dispute are shaping copyright rules for AI training. The UK GDPR and Data Protection Act 2018 anchor personal data regulation, with the Data (Use and Access) Act 2025 marking the most significant post-Brexit reform of the regime.
Key takeaways
- Section 9(3) CDPA gives the UK a rare statutory route to copyright in computer-generated works, potentially covering some AI-generated datasets.
- Post-Brexit, UK and EU databases no longer enjoy reciprocal sui generis protection, so cross-border operators must secure contractual safeguards.
- UK trade secret law adds criminal enforcement through the Computer Misuse Act 1990, a deterrent the EU's civil-only directive does not itself provide, though several member states criminalize trade-secret theft under national law.
- Commercial text and data mining requires rights holder permission, making licensing essential for AI training in the UK.
- The Data (Use and Access) Act 2025 and pending AI copyright litigation signal continuing post-Brexit divergence from EU data law.
Primary legal instruments
AI-assisted summary of the report, editorially reviewed before publication · AI transparency
Protection mechanisms
Report-derived analysis per mechanism. The report text is fixed; committee members with contributor access can revise the rating (with an audit trail) and add notes below each block.
Recent Developments
Live updates contributed by committee members and the AI research bot — separate from the fixed report content above.
Proposed legislation to regulate financial services and markets
This bill aims to establish a comprehensive regulatory framework for financial services and markets. Such legislation often includes provisions related to data governance, security, and the handling of proprietary financial information, which are crucial for protecting data as a valuable asset within the financial sector. It can indirectly strengthen the treatment of financial data as a protected business asset, aligning with aspects of trade secret protection and data governance.
Proposed legislation to enhance cybersecurity and resilience of critical systems
This Bill aims to strengthen the security and resilience of network and information systems, including by amending the existing 2018 Regulations. Its provisions are designed to protect systems vital for essential activities, which inherently involves safeguarding the data processed and stored within them. This legislative effort contributes to the broader framework for protecting valuable data assets from unauthorized access or compromise.
National Security (State Threats) Act 2026 Enacted
This new Act introduces measures to identify and address foreign power threat activities, including the designation of involved bodies and the creation of related offenses. It aims to bolster national security by protecting sensitive information and data from state-sponsored interference, thereby safeguarding valuable intellectual assets like trade secrets. The legislation provides a framework to counter threats that could compromise confidential data and national interests.
UK government publishes statutory Report on Copyright and AI, shelving broad TDM exception with opt-out
On 18 March 2026 DSIT, DCMS and the IPO published the Report on Copyright and Artificial Intelligence with an impact assessment, as required by sections 135-136 of the Data (Use and Access) Act 2025. Drawing on more than 11,000 consultation responses, the government abandoned its previously preferred option of a broad commercial text-and-data-mining exception with rightsholder opt-out, concluding there is no consensus for reform. It will instead keep the existing copyright framework, gather further evidence, and monitor EU and US developments before proposing any legislative change to how AI developers may use protected works and data for training.
High Court continues injunction over scraped CRM data in Infinni Innovations v OFMS [2026] EWHC 470 (Comm)
On 3 March 2026 Mr Justice Saini in the Commercial Court ruled on interim relief in a dispute between rival CRM platforms serving OnlyFans management agencies, where the claimant alleged the defendants unlawfully scraped confidential customer and fan data from its Infloww platform. The court continued the breach-of-confidence injunction until trial but narrowed its terms, barring the defendants from commercially exploiting the scraped dataset while permitting third-party agencies continued access to mitigate harm to non-parties. The judgment illustrates how English courts protect proprietary datasets through confidentiality and trade-secrets theories against scraping.
DUAA Commencement No. 6 Regulations bring main data provisions of the Data (Use and Access) Act into force
The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), made on 29 January 2026, commenced the bulk of the Act's Part 5 data protection reforms on 5 February 2026. Provisions now in force include the recognised legitimate interests lawful basis, relaxed rules on scientific research and purpose limitation, reformed automated decision-making rules, international transfer changes, and strengthened enforcement powers, with the data-subject complaints regime following on 19 June 2026. Transitional provisions preserve pre-commencement rules for pending requests and enforcement.