A New Era for Insurance Fraud Investigators

On 19 June 2025, The Data (Use and Access) Act 2025 received Royal Assent—marking the UK Government’s latest attempt to streamline data protection law post-Brexit. Touted as a business-friendly reform designed to reduce bureaucracy, the Act introduces significant changes that will be of interest to insurance claims handlers, legal professionals, and particularly those working in the detection and prevention of fraudulent claims.

One of the Act’s headline changes is the introduction of “recognised legitimate interests” as a lawful basis for processing personal data. The key difference between “recognised legitimate interests” in the Data (Use and Access) Act 2025 and “legitimate interests” under the UK GDPR / Data Protection Act 2018 is the requirement for a balancing test (against the individual’s rights and freedoms). Among the recognised legitimate interests is the prevention, detection, investigation, or prosecution of crime.

On the surface, this appears to be a win for fraud teams and counter-fraud professionals. Processing data to detect and prevent insurance fraud should now be faster and legally simpler. No balancing test means fewer compliance hurdles when analysing suspicious claims or running intelligence searches on claimants. In addition, when sharing data with third parties (e.g. DPA requests and covert intelligence), there may be greater flexibility in doing so lawfully in a fraud context. However, these should not be seen as carte blanche to snoop. The ICO is likely to keep a close eye on how these exemptions are applied—particularly if individuals complain that they were unfairly profiled or investigated. These activities are also among the most high-risk in terms of data subject rights. Ironically, by removing the balancing requirement, the Act exposes data controllers to greater risk if this power is used indiscriminately

For HF and other law firms representing insurers, the overall impact is that we may be able to more confidently advise clients to process data under the “recognised” legitimate interest of crime prevention, but we need to be ready to defend this position if challenged—especially where the data processed is sensitive, or where automated tools are involved. The Act promises to ease the compliance burden for UK businesses—but for insurers and law firms, it’s not a free pass. Used wisely, the new recognised legitimate interests could help speed up fraud detection and claims validation. Used carelessly, they could expose organisations to reputational and regulatory risk. Now is a good time to review your data processing activities, revisit your privacy documentation, and ensure your use of these new powers is both proportionate and purposeful.

For expert help and advise in navigating the new changes, contact us here: info@h-f.co.uk