Data (Use and Access) Act 2025: What the New Rules Mean for Employers

 

Employees today expect transparency about what their employer is doing with their personal information.  

On the 19th of June this year, s103 of the Data (Use and Access) Act 2025 (Act) came into effect requiring employers to have a compliant data protection complaints process in place by this date. This follows the implementation of other aspects of the act intended to build on the foundations of UK GDPR and the Data Protection Act 2018, with targeted changes designed to strengthen employee rights and tighten how organisations handle data complaints. 

A more structured complaints process

section 103 of the Act introduces clearer requirements around how organisations handle data protection complaints specifically, before an employee escalates things to the Information Commissioner’s Office (ICO).

Under the new framework, if an employee raises a concern about how their personal data has been handled, employers are expected to: 

Acknowledge and investigate the complaint promptlyRespond within one monthExplain clearly what happened, what action was taken, and, if none, whyCommunicate proactively if more time is needed 

A well-handled complaint can stop a relatively minor concern from becoming an ICO referral, a tribunal claim, or a reputational risk.

Why this matters for employers

A business can process a vast amount of data on any given day; recruitment information, payroll records, sick/absence notes, performance reviews, disciplinary files – it adds up quickly, and employees expect it to be handled with care.

Most employers already have data protection policies in place relating to the handling of employee data, but with the ICO increasingly active in enforcing compliance, and employee awareness of data rights continuing to grow, it’s worth reviewing in light of the recent changes under the Act. 

Practical steps to take now

For many employers, reviewing what’s already in place and filling the gaps could be all the action needed.

Review your data protection and employee privacy policies to ensure they reflect current legislative requirements Introduce or update a formal, well-documented complaints process that’s consistently followed, and easy to accessRetrain your managers and HR teams so they know how to identify and handle a data complaint from the moment it’s raisedKeep clear records of every complaint received, investigated and responded toAudit your data retention practices – are you holding onto personal information for longer than you need to?Make sure employees know how to raise concerns, if they can’t navigate the process easily, it might as well not exist. 

Make data protection part of your culture

As HR systems, cloud platforms and AI-assisted tools become standard across most workplaces, employees are increasingly, and quite rightly, conscious of how their personal information is being used.

The organisations that handle this transparently (with clear policies, prompt responses and genuine accountability) are more likely to attract and retain the right people and avoid complaints to the ICO.

If you’d like support reviewing your data protection procedures, updating your policies, or simply making sure your processes are fit for purpose in relation to employee data our team is here to help.

Get in touch with Glaisyers ETL’s employment team today for clear, practical advice on staying compliant.

Digital Immortality: When Technology Meets Legacy

Digital Immortality: When Technology Meets Legacy

 

Artificial intelligence is rapidly changing how we create, distribute and consume content. It is also creating legal questions that would have sounded like science fiction only a few years ago.  

Technology can now recover voices from historic recordings, recreate performances and generate increasingly realistic digital versions of people long after their deaths. What was once the preserve of Hollywood visual effects studios is becoming increasingly accessible to brands, agencies, content creators and technology platforms. 

For businesses operating in the creative, digital and media sectors, the question is no longer whether this technology works, but whether it’s legal, and what regulatory and reputational risks it introduces. 

From preservation to recreation 

Recent projects have demonstrated the remarkable capabilities of modern AI and digital production technologies.

Peter Jackson’s team used machine-learning technology to isolate John Lennon’s voice from historic recordings, enabling the release of what became the final Beatles song.   

Meanwhile, Rogue One: A Star Wars Story saw the digital recreation of actor Peter Cushing, allowing his character Grand Moff Tarkin to appear on screen more than two decades after the actor’s death.  

These projects are often discussed as technological achievements. 

However, the more interesting questions may be legal and commercial rather than technical. 

The Peter Cushing Dispute: the agency impact

The litigation which followed Peter Cushing’s appearance in Rogue One provides an important insight into how courts may approach these issues.

 At first glance, the dispute appeared to concern digital recreation and visual effects technology. In reality, the arguments centred on historic contractual arrangements and the rights associated with Cushing’s likeness. A third party claimed that an earlier agreement restricted how his likeness could be commercially exploited in the future, notwithstanding the permissions obtained from his estate. 

Whilst the claim ultimately failed on the particular legal basis advanced, the case remains significant because it demonstrates that disputes in this area are unlikely to be decided solely by reference to technology. The courts are more likely to focus on issues such as:  

who has authority to grant permissions; what contractual rights exist; whether historic agreements remain enforceable; and  how commercial rights relating to a person’s image, likeness or performance should be interpreted.   

The key lesson is a simple one:

Technology may enable a particular use. Contracts and rights determine whether that use is authorised. 

The UK’s existing legal framework

Unlike some jurisdictions, the UK does not currently recognise a standalone image right or personality right. 

Instead, protection arises from a combination of legal principles, including: 

copyright;performers’ rights;  data protection law;  privacy rights;  contractual protections; and  passing off and false endorsement claims.  

This creates a legal landscape which can be highly fact-specific. 

As AI-generated content becomes more sophisticated, businesses may increasingly find themselves navigating multiple legal frameworks simultaneously. 

Regulatory risk: The ASA and CMA 

Legal rights are only part of the picture. 

Regulators are also likely to play an increasingly important role. 

The Advertising Standards Authority (ASA) focuses on whether advertising is misleading, whilst the Competition and Markets Authority (CMA) has a broader remit relating to consumer protection and transparency.

This becomes particularly relevant where digital recreations, synthetic voices or AI-generated content risk creating misleading impressions about endorsement, participation or approval.

For example:  

Does a digitally recreated individual appear to endorse a product? Could consumers believe a person actively participated in a campaign when they did not? Has the commercial use of AI-generated content been communicated transparently?  

These issues may become increasingly significant as synthetic media becomes more difficult for consumers to distinguish from authentic human-created content. 

Lessons from Rhianna v Topshop 

Although predating the current AI boom, the Rihanna v Topshop litigation remains highly relevant. 

In that case, Rihanna successfully argued that Topshop’s use of her image created a misleading impression that she had approved or endorsed the product. The court’s focus was not simply on the image itself but on how consumers would interpret it. 

That principle translates naturally into the world of digital recreation. When assessing risk, businesses should consider not only whether they possess the necessary permissions, but also how audiences are likely to understand and interpret the content they encounter.  

To read more on AI voice cloning, read our recent article here

What this means for agencies and brands  

As these technologies become more widely adopted, agencies and brands may need to ask more sophisticated questions than they have in the past. 

Historically, the focus may have been on obtaining permission to use a photograph, recording or performance. 

Today, businesses may also need to consider: 

whether a likeness can be recreated or modified;  whether synthetic versions of an individual are permitted; who is entitled to authorise those uses; what legacy or estate arrangements exist; and whether audiences may be misled by the final output.  

Those considerations become even more important where multiple parties are involved in creating and distributing content, including brands, agencies, production companies and technology providers.

Looking ahead

The discussion around digital immortality is often framed as a debate about artificial intelligence. In reality, it may be more accurately viewed as a debate about legacy. 

Technology is increasingly allowing voices, performances and likenesses to be reused, adapted and extended beyond their original context. Some will see that as preserving a legacy.  Others may regard it as exploiting one. 

Either way, the legal, regulatory and commercial implications are only beginning to emerge. 

For businesses operating in creative, digital and media sectors, understanding those implications now may prove significantly easier than dealing with them after the fact.

Steve Kuncewicz is Partner and Head of Creative, Digital & Media at Glaisyers ETL, advising agencies, brands, rights holders and tech companies on intellectual property, media, marketing, reputation and digital regulation. 

Partner, Head of Creative, Digital & Media

Steve Kuncewicz

Voices have value; the law just hasn’t caught up.

Voices have value; the law just hasn’t caught up.

 

As AI voice cloning becomes cheaper, faster and more convincing, agencies, brands, creators and talent are confronting a new commercial reality: our voices are yet to be adequately protected.

Distinctive voices can now be replicated with remarkable accuracy and deployed across multiple channels at scale, yet UK law provides surprisingly little clarity on how those voices can be controlled, licensed or protected.

Recent headlines brought this issue into focus when Stephen Fry revealed that his voice had been recreated using AI trained on recordings of his Harry Potter audiobooks, generating entirely new narration that he had never recorded.

The story resonated because it exposed something that feels instinctively wrong to most people. A highly recognisable voice had been replicated and used to create new content without the speaker’s involvement, yet the legal position surrounding that use was far from straightforward. 

As AI-generated content, voice cloning and digital replicas become increasingly sophisticated, businesses are asking a question UK law does not clearly answer: who controls a voice, and what legal rights arise when artificial intelligence reproduces it?

Voices as Commercial Assets

For many individuals and businesses, a voice can be every bit as valuable as a name, image, reputation or trademark.

Presenters, broadcasters, actors, voice artists, influencers and founders frequently build significant commercial value around a distinctive tone, delivery or style. Audiences often recognise a voice before any visual branding appears, making it a source of:

TrustRecognitionCommercial differentiation. 

This is far from theoretical. Brands routinely invest heavily in recognisable voices because of the authenticity and audience engagement they generate. Increasingly, a distinctive voice has become a commercially valuable asset in its own right. 

Technology has made that asset easier than ever to reproduce, whilst the legal framework governing its use has not evolved at the same pace. 

The Pre-AI Case of Bette Midler

Although AI has accelerated the issue, disputes involving the commercial value of voices are not new.

A well-known example is the dispute between singer Bette Midler and Ford in the United States. After Midler declined to appear in an advertising campaign, Ford instructed one of her former backing singers to imitate her voice as closely as possible. Many listeners believed Midler had participated in the campaign.

Whilst decided under a different legal framework, the underlying issue remains highly relevant. The commercial value Ford sought was not simply the song, but the goodwill attached to Midler’s distinctive voice.  

The difference today is scale. Businesses no longer need a convincing human soundalike. AI can generate highly realistic synthetic voices from relatively small amounts of source material, separating the commercial value of a voice from the individual who created it. That shift lies at the heart of many of the legal questions now emerging.

The UK’s Patchwork of Protection

One of the greatest challenges is that UK law does not recognise a standalone right in a person’s voice. Many clients are surprised to discover there is no single legal principle preventing someone from recreating or imitating another person’s voice. Instead, protection comes from several different areas of law. 

Data protection legislation may apply where voice recordings constitute personal data or biometric information.Copyright and performers’ rights can protect recordings and performances.Privacy and human rights principles may be relevant where private material is involved.Passing off may assist where use of a voice falsely suggests endorsement or commercial association.Defamation may provide a remedy where synthetic content causes reputational harm.  

What these rights share is that they protect something connected to the voice rather than the voice itself. The law can often address the consequences of misuse, but it remains far less clear about ownership or control of the voice.

Why Contracts Are Becoming Increasingly Important

In practice, the strongest protection often comes not from legislation but from carefully drafted contracts. 

Voice cloning technology has prompted agencies, brands, production companies and rights holders to revisit standard agreements and address issues that would barely have featured in negotiations a few years ago. 

Questions increasingly arise around whether recordings may be used to train AI models, whether synthetic voices can be created, how long usage rights extend, whether approval is required for future uses, and what obligations apply when a commercial relationship ends.

The distinction between an authorised recording and an unauthorised synthetic recreation can be commercially significant. A voice artist may agree to record a campaign without expecting those recordings to become the basis of an AI-generated version of their voice. Similarly, a founder may appear in marketing content without anticipating that their voice could later be replicated through AI. 

Where contracts fail to address these issues, parties may find themselves relying on legal principles developed long before AI-generated media became commercially viable.

For that reason, many organisations are now introducing provisions covering AI training, synthetic voice generation, reuse rights, approval processes and deletion obligations. These clauses need not be overly complex, but they should clearly define what is being licensed, for what purpose, for how long and on what terms.  

Beyond Intellectual Property

It would be a mistake to view voice cloning solely as an intellectual property issue.  

The technology also raises important questions around advertising regulation, consumer protection, cybersecurity, fraud prevention and corporate governance. 

The same tools capable of generating synthetic voiceovers for marketing campaigns can also create convincing impersonations for scams, social engineering attacks and false endorsements. 

For brands, authenticity and consumer trust are key concerns. If a synthetic voice is used in a campaign, audiences may assume the individual has approved or endorsed the content. Where that assumption is incorrect, the issue may quickly extend beyond intellectual property into misleading advertising, reputation management and consumer protection.

For businesses more broadly, the ability to imitate senior executives or public-facing spokespeople presents obvious governance and security risks. As synthetic content becomes increasingly sophisticated, discussions around voice replication are moving beyond legal teams and into marketing, procurement, compliance and risk functions.

How your agency should respond

The UK Government’s recent consideration of personality rights and AI-related issues suggests these questions are receiving greater attention. Whether that ultimately results in dedicated protection for voices, likenesses or digital replicas remains to be seen.

For now, businesses, agencies and talent continue to operate within a patchwork of intellectual property, privacy, reputation and contractual rights. While the law continues to evolve, agencies do not need to wait for legislative reform before taking practical steps.

Agencies should review both their client contracts and agreements with freelancers, creators and talent. In particular, businesses should consider whether existing terms adequately address AI training rights, synthetic voice generation, ownership of AI outputs and approval for future uses.

You can find further information on drafting a solid contract here.

The Creative, Digital & Media Team at Glaisyers ETL advises agencies, brands, production companies, creators and rights holders on the legal and commercial issues shaping the sector, including AI, intellectual property, data protection, advertising regulation and emerging technologies.  

If AI-generated voices, synthetic content or digital replica rights are beginning to appear in your contracts, campaigns or commercial negotiations, we’d be happy to discuss the issues with you and help you navigate this rapidly evolving area.

Partner, Head of Creative, Digital & Media

Steve Kuncewicz

The Contract Risks That Catch Growing Agencies Off Guard

 

Contracts offer security and set out the terms by which both parties must abide. When entering into a deal, though, there are some areas of the contract that – if not scrutinised properly – can lead to costly repercussions further down the line. 

At Glaisyers ETL, our team has years of experience in contract law and can expertly pinpoint areas within your contracts that could trip you up.

Common Areas of Risk in Contracts  

When your business or agency is small, things that worked within contracts may not provide adequate depth further down the line, and often, vagueness or incompleteness in contracts can lead to costly legal battles once operations scale up.  

Below, we will detail five key areas of early contracts that can often lead to risk: 

Poorly defined deliverables: Early contracts often don’t have specific wording; they may say things such as ‘provide marketing services’ or ‘ongoing digital support’. This can lead to agencies doing extra unpaid work as a business’s needs increase.Intellectual property (IP) ownership: Contracts may state that clients own everything immediately, even before payment, or, in some cases, may not define ownership of tools, templates, or frameworks, which can lead agencies to give away valuable processes or creative assets.Termination clauses: Clients can terminate immediately without notice if they are not adequately set up, leaving agencies stuck mid-project without payment protection.Data protection and compliance: As agencies grow, they take on more customer data and analytics. If a contract doesn’t clarify the roles of data controller and processor, it can lead to data being misused, which opens them up to potential legal issues.Subcontractors and freelancers: Scaling agencies often rely heavily on freelancers; if client contracts don’t allow subcontracting, bringing in a freelancer could be a breach of those contracts. It could also mean that a freelancer may end up owning the IP of the things they create; therefore, this must be clearly set out in the contract. 

For in-depth advice on the contracts your business or agency has, and consultation on the risks they present, contact our expert team at Glaisyers ETL today.

The Commercial Consequences of Outdated Agreements 

If contracts contain areas of ambiguity or simply miss some details early on, then the knock-on effects can be disastrous for your business later.

For example, issues regarding who owns IP can end up in court, meaning time and money is taken away from your company and injected into something that was at one stage completely avoidable.  

How Early Review Supports Growth 

At Glaisyers ETL, our expert team can provide you with a thorough audit of your company’s contracts, ensuring that no stone is left unturned. The benefit of doing this, even at an early stage in your business’s life, is that it means you are protected from legal battles further down the line, meaning you could end up saving yourself vast sums, which can then be spent on growing your business.

For a contract review and to see if yours are up to date with how your business operates, get in touch with our team.

The UK’s Social Media Ban for Under-16s: A Line in the Sand for Platforms, Brands and Agencies

The UK’s Social Media Ban for Under-16s: A Line in the Sand for Platforms, Brands and Agencies

 

The UK Government’s announcement of a ban on social media access for under-16s is one of those moments where the headline is simple, but the implications aren’t as straightforward. The position is this: children under 16 will be prevented from accessing mainstream social media platforms, with implementation expected around spring 2027.

In isolation this is a significant step, but stop there and you miss the bigger point. This isn’t just about children and social media. The Government are looking to mandate a fundamental shift in how the UK – regardless of age – will have their social media usage regulated, and beyond the perceived societal benefits, that has very real consequences for platforms, brands, and agencies. 

The move from, ‘make social media safe’ to, ‘maybe you shouldn’t be here’

The Online Safety Act – which came into force in October 2023 – was based around an intention to make the UK the safest place in the world to be online. This would be achieved by platforms accepting more ownership for what happens on them via risk assessments, content moderation and child safety protections intended to deter harm to their users, especially children. 

What’s just been announced takes a different view entirely. The Government has framed its full ban on under-16s accessing social media platforms as a response to what it views as a “failing system”. That’s a huge shift, with potentially huge and unforeseen consequences.  

The ban is the headline, but the details tell the real story 

The ban isn’t itself may not be the most important part of the new proposals. The Government is also looking at: 

blocking livestreaming and contact with strangers for under-16s;  
tightening rules around AI chatbots and similar tools;  
limiting “addictive” features like infinite scrolling;
potentially introducing curfews or usage controls for teenagers; and
applying protections to 16- and 17-year-olds by default, to avoid a regulatory cliff edge  

In other words, this isn’t just about who can access platforms; it’s about how those platforms work. That’s where this new approach moves much closer to home for agencies and brands. Once regulators other than the ICO start looking at product design, feeds, engagement mechanics and messaging features, they’re addressing the DNA of the platforms themselves. 

Enforcement: same model, bigger ask 

One thing that hasn’t changed is where responsibility for social media compliance sits. As with the Online Safety Act, the burden isn’t on parents or on children, it’s on the platforms. They’ll be expected to take ‘reasonable steps’ to prevent under-16s from accessing their services, likely through a mix of facial age estimation, digital ID and wider age verification technologies. As with the Online Safety Act, OFCOM will be central to developing what ‘effective’ age assurance actually looks like. 

At scale, that raises some significant questions around how far platforms can go in verifying a user’s age and what personal data they need to collect (and can justify collecting). In addressing safety concerns, the Government is already creating new privacy issues as one of many consequences of a well-intentioned policy supported by the vast majority of parents.   

Why now? A political and cultural shift as much as a legal one

The tone coming out of the Government is also worth noting. This initiative isn’t being presented as a technical adjustment or a tweak to existing rules, but an acknowledgment that the current system isn’t working and that social media platforms are now seen as inherently risky for children. This led to a willingness to intervene more directly than has been the case under the remit of the Online Safety Act; the idea that social media is an inevitable part of growing up with risks that parents can monitor and foresee seems like old news. 

But does a ban actually solve the problem?

Unsurprisingly, not everyone is convinced. Some of the early criticism focuses on a fairly simple point; a ban doesn’t necessarily fix what’s creating the risk in the first place. There are ongoing concerns that harmful content will continue to be driven by algorithms and recommendation systems. Engagement will be shaped by design choices and children will find ways to access social media platforms anyway, potentially creating a false sense of security, the illusion of safety, and a veneer of compliance. From a legal and policy perspective, that tension is going to be important.  If the new regime doesn’t deliver the intended outcomes, the next step may well be even more intervention. 

What this means in practice for agencies and brands
1. Audience assumptions need revisiting 

If under-16s disappear (at least officially) from key platforms: 

youth-focused strategies will have to adapt
targeting models will need to be reassessed
‘where’ you reach younger audiences becomes a much more complex, risky question 

2. Platform risk becomes part of media planning 

Choosing a platform is no longer just about reach and engagement. It’s increasingly going to involve an assessment of regulatory exposure, and compliance maturity how that platform is dealing with age assurance and safety That’s a different conversation with clients. 

3. Targeting will come under more scrutiny 

As platforms lean harder into age assurance, the way audiences are identified and segmented will attract greater attention and the use of inferred or behavioural data may become even more contentious. 

4. ‘Safer design’ becomes a commercial expectation 

Finally, and this is probably the longer-term point, there’s a clear move towards expecting not just platforms, but the wider ecosystem, to support healthier and less exploitative digital experiences. That’s not just a legal issue, it’s reputational and commercial. 

What’s next?

The Online Safety Act was a big moment. This feels like the next step. For agencies and brands, the takeaway isn’t just “there’s a new rule coming”- the whole environment is changing. The agencies who understand how regulation could reshape social media platforms and help their clients to navigate that change may well just inherit the earth.  

For more information on how this legislation will affect you and your business, contact the Creative, digital and media team at Glaisyers ETL – lets figure this out together.

Partner, Head of Creative, Digital & Media

Steve Kuncewicz

Who Is Liable When an AI Agent Makes a Mistake?

Who Is Liable When an AI Agent Makes a Mistake?

 

 A practical guide for UK businesses deploying AI agents

AI is moving well beyond chatbots. The latest generation of tools – now commonly referred to as “AI agents” – can act autonomously: sending emails, reviewing contracts, placing orders and interacting with third–party systems, often without a single human in the loop. The technology is developing rapidly, and the law has not kept pace, but that doesn’t mean businesses are operating in a legal vacuum.

AI can’t be liable, so who is? 

The starting point is important: AI systems have no legal personality under English law and therefore cannot be held liable for their actions. This principle is consistent across all major common law jurisdictions and was affirmed in the UK government’s own consultations on AI and intellectual property. 

In practice, responsibility falls on one or more of three parties:  

The developer who built the model 
The business that deployed it 
The end user who directed its actions. 

In most commercial settings, the deploying business carries the greatest exposure – it is typically the data controller, the principal whose authority the agent exercises, and the entity whose staff relied on the output. 

The key legal risks 

Data protection 

UK GDPR and the Data Protection Act 2018 apply in full wherever an AI agent processes personal data. Article 22 of the UK GDPR places specific restrictions on automated decision-making that produces legal or similarly significant effects; without meaningful human review, certain automated decisions may be unlawful altogether. The ICO’s 2023 AI guidance expects organisations to be able to explain and audit how AI decisions are made.  

Breach of confidence

business may be liable if its AI agent routes confidential information to the wrong recipient – even if the disclosure was entirely unintentional. This can also become incredibly complex where trade secrets are involved under the Trade Secrets (Enforcement, etc.) Regulations 2018. 

Intellectual property 

Under s.9(3) of the Copyright, Designs and Patents Act 1988, copyright in computer-generated works vests in the person who made the necessary arrangements for its creation – in most cases, the deploying business. That business therefore also bears responsibility if AI-generated content infringes a third party’s copyright. If that content contains misleading claims, the Consumer Protection from Unfair Trading Regulations 2008 and the CAP Code may also be engaged. 

Contractual liability 

If an AI agent is authorised to interact with third parties – accepting quotes, negotiating fees, placing orders, agreeing terms – the business may be bound by those agreements under ordinary principles of apparent authority, even where the agent acted beyond its intended scope. 

Why supplier contracts matter

Most AI supplier agreements are drafted to minimise the supplier’s liability as far as possible. Businesses should pay close attention to liability caps (often limited to fees paid in the preceding 12 months), broad exclusions for consequential loss, and disclaimers that outputs are accurate or fit for purpose. Where personal data is processed, a compliant data processing agreement under Article 28 of the UK GDPR is a legal requirement, not an optional extra. 

What should businesses do? 

Define the agent’s permissions precisely – understand exactly what it can access, process and do.
Build in human oversight for consequential decisions: significant orders, sensitive disclosures, public–facing content.
Conduct a DPIA before deploying any agent that processes personal data at scale.
Negotiate supplier contracts – standard terms are rarely adequate.
Document governance – regulators expect accountability, not just compliance. 

The unchanging principle

The legal framework will continue to evolve – the EU AI Act is already in force with obligations rolling in through 2027, and UK reform is ongoing. But one principle remains constant: delegating a task to an AI agent does not delegate liability. The business that deploys the agent, benefits from its actions, and authorised its operation will ordinarily bear the consequences when things go wrong. 

For questions or further advice surrounding this topic, please contact [email protected] 

Associate

Peter Pegasiou