Two people using laptops.

COMMERCIAL LAW

The Data (Use and Access) Act 2025 & Subject Access Requests - What you need to know

The Data (Use and Access) Act 2025 (‘DUAA’) brings a significant update to the UK’s data protection landscape, introducing targeted reforms to the UK GDPR and the Data Protection Act 2018.  The DUAA received royal assent in June 2025 and its provisions will come into force in stages, between June 2025 and June 2026.

As those on the receiving end will know, Data Subject Access Requests (‘DSARs’) can be costly and time consuming, often involving complex and large amounts of data that must be carefully considered. The DUAA codifies ICO guidance and existing case law, and introduces key changes which impact on controllers.

Below, we summarise the key changes and their effect on your business.

 

Key changes to Data Subject Access Requests (DSAR) under the DUAA

  1. Only ‘Reasonable and Proportionate Searches’ required

A central change is the requirement that businesses only need conduct ‘reasonable and proportionate’ searches when responding to DSARs. Previously, the law was less clear, and some organisations felt compelled to undertake exhaustive and resource-intensive searches.

The new standard means that you are not expected to search through every possible system or archive if it would be disproportionate to do so. Instead, you should focus on sources where relevant personal data is most likely to be found.

In determining what is ‘reasonable and proportionate’, you should consider the nature of your business, the request, and the resources available to you.

  1. Requirement to introduce a complaints procedure

You can no longer tell a dissatisfied data subject to go directly to the ICO with their complaint.

The DUAA requires controllers to have a complaint-handling process, which enables data subjects to lodge complaints directly with them.

You must:

  • provide readily accessible methods for the submission of complaints – for example, a form on your website;
  • acknowledge receipt of complaint within 30 days;
  • take appropriate steps to investigate and respond to complaints without ‘undue delay’ –you can’t ‘sit on it’ and hope it goes away; and
  • keep complainants informed of progress and outcomes.

The Secretary of State may introduce regulations requiring organisations to report the number of complaints they have received to the ICO.

  1. Court Procedures and Legal Privilege

The DUAA introduces a new court procedure for DSAR disputes. If a dispute arises, the court can require you to disclose to it relevant data for its inspection. There is, however, no disclosure to the data subject until the court has ruled in their favour.  You should, therefore, take extra care considering DSARs as there may be a litigation threat.

The DUAA also clarifies that information protected by legal professional privilege does not need to be disclosed in response to a DSAR.

  1. Confirms into law ICO Guidance on timeframes

The DUAA retains the standard one-month timeframe for responding to DSARs. If a request is complex or if an individual submits multiple requests, you may extend the response period by up to two additional months. Importantly, the DUAA codifies the “stop the clock” principle: if you need further information from the requester to clarify the scope of their request or to verify their identity, you can pause the response period until you receive the necessary details. Provided you inform the requester promptly, the time taken to obtain clarification /verification does not count toward the mandated timeframe.

 

Practical implications for businesses

For  controllers, these changes offer clarity and relief from some of the more burdensome aspects of DSAR compliance. However, they also introduce new procedural requirements which will impact on your business.

We recommend you:

  • Review and update your DSAR policies to ensure they reflect the new “reasonable and proportionate” search standard and, if it’s not already there, the “stop-the-clock” principle.
  • Establish a complaints procedure, ensuring it is communicated to requestors in correspondence.
  • Document your search process and any decisions to refuse or charge for requests, as you may need to justify your actions to the ICO or a court.
  • Ensure your privacy notices and internal procedures are updated to reflect the new rights and processes.

If you need help with your Data Subject Access Requests processes, or replying to a specific Data Subject Access Request, then please contact one of our Commercial team by email or call on 01293 558562.

About the authors


about the author img

Jay Barnett

Partner

Advises on all areas of commercial law including business contracts, data protection compliance, IT and intellectual property.

Stay connected, sign up for updates

Stay connected

Recent articles

Insights

Business rates: Box shifting mitigation scheme

Court of Appeal sees case concerning box shifting mitigation scheme promoted by Principled Offsite Logistics Limited.

06/08/2026

Insights

Proposed Amendments to the City Code on Takeovers and Mergers Consultation Paper

Consultation paper published by the Panel on Takeovers and Mergers on 9 July 2026, proposes miscellaneous amendments to the City Code on Takeovers and Mergers.

31/07/2026

Insights

Protecting your loved ones: The importance of Wills, LPAs and planning ahead for tax changes

A regular review of your Will and wider estate planning doesn't have to be complicated. With the right professional advice, you can be confident your plans still provide peace of mind for the future.

30/07/2026

Insights

DMH Stallard advises Sygna Holdings shareholders on majority investment by Apleona

DMH Stallard has advised the shareholders of Sygna Holdings Limited on the sale of a majority stake in the business to leading European integrated facilities management company Apleona.

16/07/2026

DISCLAIMER:

THIS INFORMATION IS FOR ILLUSTRATIVE PURPOSES AND IS NOT INTENDED TO AMOUNT TO LEGAL ADVICE ON WHICH RELIANCE SHOULD BE PLACED. WE, DMH STALLARD LLP, DISCLAIM ALL LIABILITY AND RESPONSIBILITY ARISING FROM ANY RELIANCE PLACED ON THIS INFORMATION. ANY RELIANCE ON THIS INFORMATION IS SOLELY AT YOUR RISK. The provision of this information does not create a business or professional services relationship. This information is not exhaustive and does not attempt to address every issue relevant to a particular situation. If you require advice on a specific legal issue, please contact a lawyer listed on our website, dmhstallard.com, or send an email to [email protected].