Data Use and Access Act 2025: regulatory compliance under UK health and safety law and the implications of the fifth commencement Regulations
What has changed
The fifth commencement Regulations under the Data Use and Access Act 2025 bring provisions into force, clarifying how data used to manage health and safety can be accessed by authorised persons and organisations. The change is described in the order as the fifth set of commencement for the Act.
Why it matters for UK health and safety compliance
This update affects governance of health and safety information including incident data, risk assessments and training records. It emphasises lawful data use for regulatory compliance and increases the need for robust data controls and documentation. Duty holders must ensure appropriate access controls to safeguard sensitive safety information and maintain alignment with UK health and safety law and HSE requirements.
What organisations should do next
Action points include: reviewing data policies and access controls; updating risk assessments to cover data handling and information governance; tightening data retention and sharing arrangements with contractors; consulting workers on data practices; aligning management systems with information governance obligations, for example via ISO 45001; seeking competent advice through Competent Person support; and leveraging health and safety risk assessments when implementing controls. Where relevant, consider Synergos services such as health and safety risk assessments and health and safety support packages.
data-use-and-access-act-commencement
Wrap-up: The fifth commencement Regulations under the Data Use and Access Act 2025 marks a significant step in data governance within UK health and safety law. Organisations should act promptly to align data policies, risk assessments and governance with the new provisions to maintain regulatory compliance and protect workers.