Data Protection Update 2026

Aug 14, 2026 | Data Protection | 0 comments

Data protection has moved on over the past year, and a few developments are worth the attention of cultural organisations in particular. A change to the law now makes it easier for charities to stay in touch with their supporters, it sits within a broader package of reforms to UK data protection law, and the regulator has just launched a free training resource aimed squarely at smaller organisations that do not have a data protection specialist on the team.

The charity soft opt-in

For years, the so-called soft opt-in was available to commercial organisations but not to charities. It lets an organisation send electronic marketing (by email or text) without prior consent, provided the contact details were obtained in the course of a sale, or negotiations for a sale, of a product or service. Charities, which raise funds rather than sell, could not use it, and generally had to rely on consent to contact supporters electronically.

The Data (Use and Access) Act 2025 changed that. Since 5 February 2026, charities have been able to rely on a soft opt-in of their own. In broad terms, a charity can send electronic marketing for its charitable purposes without prior consent where three conditions are met: the person's contact details were obtained when they expressed an interest in, or offered or provided support to, the charity's charitable purposes; the marketing relates only to those charitable purposes; and the person was given a simple way to opt out both when their details were collected and in every message since.

The right to opt out does not go away. A supporter can ask to stop receiving messages at any point, and every communication must offer an easy way to do so. The change removes the need to obtain consent up front in qualifying cases; it does not remove the individual's control over how they are contacted.

For cultural organisations, many of which are charities or operate charitable arms alongside their commercial activity, this is a practical easing. It is worth checking how your supporter data was collected, and what people were told at the point of collection, before relying on the new provision. Where consent was previously gathered, that consent remains valid, and there is no need to unpick existing permissions. The soft opt-in is an additional route, not a replacement for good record-keeping about how each contact came to be on your list.

The wider reforms

The soft opt-in is one part of a larger set of changes the Data (Use and Access) Act 2025 makes to UK data protection law, commenced in phases through 2026. Most build on the existing regime rather than replacing it, but several are worth knowing about.

The Act introduces a new lawful basis, "recognised legitimate interests", for a defined list of purposes such as safeguarding, responding to emergencies and preventing crime. Where it applies, an organisation does not need to carry out the usual balancing exercise weighing its interests against the individual's. It also confirms that, when responding to a subject access request, organisations need only carry out reasonable and proportionate searches, and it allows the clock to be paused where further information is reasonably needed to identify the requester or clarify the request. On complaints, organisations are now expected to make it easier for people to complain about how their data is used, for example through an electronic complaints form, to acknowledge a complaint within 30 days, and to respond without undue delay.

The Act widens the lawful bases available for significant automated decisions about individuals, though additional safeguards apply and the wider flexibility does not extend to special category data. It relaxes the cookie rules so that certain low-risk cookies, such as those used purely for statistical or analytics purposes, can be set without consent. It raises the fines available for breaches of the marketing and cookie rules under PECR to the same level as the UK GDPR, a significant increase on the previous ceiling. And it reconstitutes the Information Commissioner's Office as the Information Commission, with new powers to support its investigations.

None of this requires a wholesale overhaul of a well-run compliance approach, but it does reward a review of the areas most relevant to how your organisation actually operates, from marketing and cookies to how you handle access requests and complaints.

A new free resource from the ICO

Alongside the legal change, the Information Commissioner's Office has launched Data Protection Essentials, a free online training programme aimed at small and medium-sized organisations, sole traders and their staff. Announced on 11 August 2026, it is self-paced and covers the practical situations that most often cause difficulty: sharing information with third parties, keeping records securely, marketing and engaging with customers or supporters, and reducing the risk of a data breach. It includes examples tailored to particular sectors, and organisations that complete it can take a self-assessment and receive a certificate, with the option of appearing on a public register.

The training is free, funded through the data protection fee organisations already pay, and open even to those exempt from the fee. For a cultural organisation running participation programmes, box office, membership schemes and fundraising, often with a small team wearing several hats, it is a useful way to get consistent, regulator-backed training in front of the people who handle personal data day to day.

You can find the ICO's announcement and a link to the training here: https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/08/boost-your-business-fitness-ico-offers-new-free-data-protection-training-for-smes/

If you would like help reviewing how your organisation collects and uses supporter data, or checking whether you can rely on the new soft opt-in, do get in touch.

Please note: This blog is for informational purposes only and is not intended as legal advice. 

Written By Keith Arrowsmith

Explore More Insights

No Results Found

The page you requested could not be found. Try refining your search, or use the navigation above to locate the post.

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *