Four senior public‑sector leaders around a table reviewing printed data flow diagrams and a laptop, representing collective governance of data sharing under DUAA.

Insights

How senior leaders should operationalise the Data (Use and Access) Act (2025): a practical 90‑day plan for public bodies

Antares Consultancy

On 22 August 2026 senior leaders in public bodies face a practical problem: the Data (Use and Access) Act 2025 is now embedded in the UK regulatory environment, and programmes that depend on cross‑organisational data sharing must convert legal change into operational controls, procurement requirements and board evidence. This briefing gives an executable 90‑day plan, the exact items SROs and DPOs must present to boards, a supplier assurance checklist for commercial teams, and the minimum security and transparency controls that protect public trust while allowing data‑led transformation to proceed.

Why this matters now

The Data (Use and Access) Act (DUAA) changes how public data can be reused and how controllers and processors must demonstrate lawful, proportionate handling. For senior leaders the commercial question is straightforward: how do you unlock value from data while avoiding regulatory, reputational and operational risk? The practical answer is not legal theory but operational evidence — documented DPIAs, robust data sharing agreements, supplier controls, secure technical measures and a clear public‑facing transparency narrative that boards can defend.

Delay is costly. Programmes that wait for perfect certainty incur time and procurement premium; programmes that rush without controls risk enforcement action, public complaints and irreversible data leakage. The right executive decision in August 2026 is to move to a short, measurable programme of assurance that converts DUAA obligations into contracts, security artefacts and board evidence within 90 days.

90‑day plan at a glance

Days 1–15: Rapid governance and discovery. Convene a 90‑day SRO squad (SRO, DPO, CIO, Head of Procurement, senior commercial lawyer). Produce a one‑page evidence plan for the board listing three deliverables for day 45 and three for day 90. Immediately run a discovery to inventory candidate data sets, current legal bases, existing DPIAs and supplier relationships.

Days 16–45: Technical and legal assurance. Complete DPIAs for top three candidate datasets; run threat modelling against data flows and supplier connections; require suppliers to produce a small evidence pack (access controls, segmentation, export controls, logs and portability capability). For any use of third‑party LLMs or model services insist on documented model provenance and a technical runbook for data ingress/egress.

Days 46–90: Contractual controls, operational tests and public transparency. Negotiate or issue short data sharing agreements that include: bespoke security annexes, audit and portability rights, retention terms and explicit incident escalation to the board evidence pack. Execute at least two operational tests — a supplier audit and a simulated data portability / exit exercise — and publish a short transparency statement that explains why data is being shared, the safeguards and the contact point for complaints.

Governance and board evidence (what the board will want)

Boards do not want policy. They want three things: (1) a clear statement of benefit and the metrics that will show it; (2) evidence that legal and safety checks have been completed; and (3) operational controls that limit blast radius if something goes wrong. Prepare a board pack that contains: the DPIA executive summary, a register of affected datasets, copies of the supplier evidence packs, the procurement or contract changes you will seek, and the results of your two operational tests.

Make the pack SRO‑ready: include a short risk register with residual risk assessed after the mitigations, a public transparency line for press enquiries, and a recommended 90‑day change to oversight (weekly SRO webinars until full assurance is achieved).

Minimum technical and security expectations

Security must be demonstrable and proportionate. Adopt the NCSC principles for secure AI and for secure development as baseline expectations for suppliers that handle or transform public data. Minimum artefacts to demand from suppliers: architecture diagrams showing separation of environments, evidence of access control (MFA, role‑based policies), logging and immutable audit trails, encryption in transit and at rest, documented vulnerability management and a tested incident response plan.

If suppliers use external models or APIs require explicit controls on what data is sent for inference, an ability to disable model access quickly, and certificates of model provenance — who trained the model, on what data, and whether that data included shared public datasets or restricted personal data.

How senior leaders should operationalise the Data (Use and Access) Act (2025): a practical 90‑day plan for public bodies: editorial image for Minimum technical and security expectations

Procurement and contract levers (practical clauses)

Insist on modular clauses in any new or refreshed contract. Key clauses to include: (1) Data segregation and minimisation — only the exact fields required may be exported; (2) Right to audit and evidence packs — supplier must produce configuration, logs and test reports within 10 working days; (3) Portability and exit — export format, timelines and assisted migration obligations; (4) Sub‑processor transparency — suppliers must disclose sub‑processors and seek approval for any new ones handling specified datasets; (5) Incident obligations — immediate notification for suspected data loss, plus a 24‑hour executive contact and an agreed escalation route to the SRO; (6) Performance and penalties — link a tranche of commercial milestone payments to evidence of compliance (DPIA sign‑off, successful audit, and a passed portability test).

For frameworks and high‑value procurements, lean on existing commercial vehicles but append these bespoke data annexes. Where speed matters use short bilateral data sharing agreements rather than lengthy contract negotiations, but do not waive audits or exit rights.

Operational tests (what to run and what success looks like)

Test 1 — Supplier evidence review and light audit: select the highest‑risk supplier and validate their claims against logs and configuration. Success: supplier produces matching logs, access controls and a remediation plan for any gaps within 10 working days.

Test 2 — Portability and exit simulation: request a dump of the shared dataset in the agreed format and perform an import to a sandbox. Success: data is exported with expected fidelity, no unauthorised records included, and the timeline is within contractual SLA.

Document both tests and put the outputs in the board evidence pack. Failure on either test should trigger a stop‑go decision and contractual remediation actions.

Public transparency and proportionality

Public trust is not optional. For every data use that relies on DUAA produce a short public transparency notice that explains the purpose, lawful basis, retention, sharing partners and the simplest way to complain. For high‑risk uses consider a short public consultation or pre‑implementation notice to affected communities. This mitigates reputational risk and reduces the chance of later enforcement action.

Proportionality means you do not need to over‑engineer low‑risk uses. Apply full technical and contractual rigour to high‑sensitivity datasets; apply lighter governance to aggregated, non‑identifiable sets but still produce a DPIA‑style record that justifies the decision.

How senior leaders should operationalise the Data (Use and Access) Act (2025): a practical 90‑day plan for public bodies: editorial image for Public transparency and proportionality

Who delivers what (roles and immediate tasks)

SRO — owns the 90‑day plan and the board evidence pack; chairs weekly assurance meetings. DPO — signs DPIAs and advises on lawful basis for sharing. CIO/CISO — owns threat modelling, supplier evidence review and operational tests. Head of Procurement / Commercial counsel — issues contract amendments and negotiates clauses. Supplier delivery lead — provides evidence packs, remediation timelines and participates in tests.

Fix responsibilities in the first 48 hours. Without clear ownership decisions will stall.

What success looks like at day 90

A deliverable set that the board can defend: DPIA executive summaries for the top three datasets; signed data sharing agreements or revised contracts with the required security annexes; completed supplier evidence reviews and at least one portability test; and a published transparency statement. Operationally, teams should be able to demonstrate a working process for any new data request that follows the same path, reducing time‑to‑share for low‑risk cases and ensuring high‑risk uses get appropriate scrutiny.

Boards need evidence, not essays. Convert the DUAA into three board deliverables: measurable benefit, legal sign‑off (DPIA) and operational controls that survive a supplier failure.

Antares recommended actions

These are Antares's recommended first actions for organisations turning the issues in this article into practical governance and delivery.

  1. Within 48 hours form a 90‑day SRO squad (SRO, DPO, CIO, Head of Procurement, senior legal); publish a one‑page board evidence plan.
  2. Complete DPIAs for the top three candidate datasets within 30 days; treat DPIAs as live risk‑management documents, not paperwork.
  3. Require a short supplier evidence pack (architecture, access control, logging, retention and export capability) from all suppliers handling candidate datasets; add an audit right clause to every contract.
  4. Run two operational tests before day 90: a supplier evidence validation audit and a portability/exit simulation; document results in the board pack.
  5. Adopt NCSC secure development/security expectations for any AI or model usage, and require model provenance documentation when suppliers use third‑party models.
  6. Publish a short public transparency notice for each dataset shared under DUAA; include a contact for complaints and an accessible explanation of benefits and safeguards.
  7. Where speed is important, use short bilateral data sharing agreements with strong security annexes rather than delaying for full contract renegotiation; reserve full commercial penalties for higher‑value or higher‑risk uses.

Our insights are provided for general information only and reflect the position at the date of publication. They do not constitute legal, financial, regulatory, cybersecurity or other advice tailored to your circumstances and should not be relied upon as a substitute for appropriate professional advice.

While we take reasonable care over our content, we do not guarantee that it is complete, accurate or current. Reading our insights does not create a client relationship with Antares Consultancy. To the fullest extent permitted by law, we accept no liability for decisions made or losses arising from reliance on this content. External links are provided for convenience and do not imply endorsement.

If you'd like to discuss your own transformation, we'd be pleased to start the conversation.