The DUAA compliance challenge: Why retailers can’t afford to overlook return data 

The DUAA compliance challenge: Why retailers can’t afford to overlook return data 

Return data is a powerhouse of insight that helps retailers fix product issues, improve sizing, manage warehouse space and streamline supply chains. But now, with the UK’s new Data (Use and Access) Act 2025 (DUAA) in play, how that data is handled is under closer scrutiny than ever. Steve Lovell, IT Director at Advanced Supply Chain Group, explores how retailers cannot afford to overlook return data.  

Just as the EU’s General Data Protection Regulation (GDPR) reshaped how retailers approach customer privacy, the DUAA is poised to transform how businesses handle data generated by products, not just people. This includes often-overlooked return data, which now falls under greater scrutiny.

Returns logistics, once viewed as a low-risk, back-end operation, is moving into the regulatory spotlight. DUAA grants users of smart products and connected packaging new rights to access the data those products produce. For retailers managing cross-border returns, this introduces a complex challenge: the very data that drives efficiency can now also pose significant regulatory risk, especially when multiple systems, partners, and jurisdictions are involved.

From operational advantage to regulatory risk

The modern retail returns ecosystem is a complex web of carriers, third-party logistics providers, customs agents and platform partners – all working together to deliver the seamless experience consumers now expect. But with so many players involved, data often flows across systems without a clear understanding of where it resides or who controls it.

DUAA marks a paradigm shift in how this data is governed. It grants users of smart products and traceable packaging the right to access the data these items generate. In the context of returns, this could include timestamps, condition reports, chain-of-custody records and route logs. Notably, DUAA also allows authorised third parties, especially in cross-border scenarios, to access this data.

While DUAA doesn’t override GDPR, it adds a new layer of regulatory expectations. Retailers must now navigate overlapping legal frameworks, ensuring their privacy notices, data-sharing practices and processor agreements can withstand scrutiny. This includes revisiting GDPR Articles 25 (data protection by design), 26 (joint controllership) and 28 (processor obligations).

Assumed compliance – a retailer’s blind spot

Retailers frequently rely on third-party partners to manage returns, often operating under the assumption that these vendors are fully compliant. But as the regulatory landscape becomes more nuanced, those assumptions can become risky.

Return data typically includes personal information such as names, addresses, order details and reasons for return. This data can travel across borders, systems and vendors in just a single return journey. When these flows aren’t carefully mapped or governed, responsibility becomes murky. Due diligence is often limited to onboarding checklists or outdated contracts. In many cases, compliance is implied rather than confirmed.

As your retail operations grow, it can be easy for visibility to reduce and compliance protections to slip. It is this tipping point where retailers may start to breach DUAA or GDPR without even realising it.

The spectre of cyberthreat

In addition to growing regulatory pressures, retailers must safeguard their data to protect against cyberattacks. High-profile incidents highlight the real and rising threat.

Returns operations are especially vulnerable. They often rely on outdated infrastructure and involve multiple third-party partners. Compounding the risk, data generated during returns is typically treated as operational rather than sensitive. This perception leads to underinvestment in security and fewer safeguards against breaches or misuse.

A single breach within a carrier’s system could compromise sensitive returns data and trigger investigations – not just for the carrier, but for every retail brand involved. The DUAA amplifies this risk by codifying user access rights and expanding accountabilities for all entities that handle product-generated data.

Time to act – responding to DUAA effectively

Retailers don’t need to overhaul everything overnight. But now is the time to step back and reassess how return data is handled across the entire journey.

· Build a clear picture

Retailers need to understand where their return data lives – across systems, partners, and geographies. Without a clear picture of data flows, it’s impossible to identify gaps or assign responsibility. Mapping this out allows organizations to see where DUAA and GDPR intersect, and where their obligations begin and end.

· Review your contracts

Once data flows are visible, contracts must follow. Existing agreements with logistics providers, platform vendors, and processors must be reviewed and updated to reflect the expanded data rights and transfer restrictions under DUAA. It’s essential to establish whether those partners are acting as controllers or processors, and to formalize obligations on everything from data minimization to incident notification.

· Check your data setup

Beyond contracts, retailers must ensure that the systems handling return data are interoperable and secure. DUAA emphasizes data portability and interoperability across vendors. This means that data must be exportable in standardized formats, and platforms should be capable of both receiving and sending information in a compliant, secure manner.

· Prioritise cybersecurity

Security itself must evolve from a checkbox to a discipline. Returns data should be subject to the same cybersecurity controls as customer purchase data. That includes employee training, encryption, access management, and breach response planning – both internally and across the entire return chain.

Don’t let returns be the compliance gap

DUAA compliance must be embedded into operations from the ground up. Privacy by design is not just a principle – it’s a regulatory requirement. That means building data protection into return platforms, workflows and customer touchpoints from day one.

With DUAA in force, return operations must be reimagined for both efficiency and accountability. The retailers who act now, by securing data, revalidating contracts and enforcing interoperability, will not only stay on the right side of the law, but unlock new value from their return flows.

Browse our latest issue

Intelligent Retail.tech

View Magazine Archive