If you handle DSARs for a living, you’ll know the feeling: another wave of data protection reform, another set of processes to revisit.
The good news is that the Data (Use and Access) Act 2025 (DUAA) and updated Information Commissioner’s Office (ICO) guidance aren’t asking you to start over. For legal, privacy and compliance teams dealing with contentious or high-volume requests, the shift is toward tighter governance, defensible decisions and documentation that holds up under scrutiny.
In other words: building on what you already do, not replacing it.
What's changed
The DUAA puts long-debated ICO guidance and case law onto a statutory footing.
Three DSAR changes, in particular, are worth your attention:
- You now have express backing to limit yourself to reasonable and proportionate searches – a relief when data is scattered across multiple systems, archives and years of correspondence.
- A “stop the clock” provision lets you pause the one-month response period while you seek genuine clarification or verify identity.
- There’s now an explicit statutory exemption for legally privileged material – though, as we’ll see, it comes with strings attached.
How this plays out in practice
The reasonable and proportionate standard can ease the pressure to run exhaustive searches, but it raises the bar on justification. You can’t simply search the most convenient inbox and call it done. If a request is challenged, you may need to explain why certain custodians, systems or date ranges were prioritised and others weren’t. (Ashley v HMRC [2025] EWHC 134 (KB) is a useful warning here, where treating a related internal agency as out of scope fell short of the standard.)
That makes early triage matter more – working out what a request is really after, and which custodians and systems are most likely to hold it, before you launch a broad and costly review. Where scope genuinely isn’t clear, the “stop the clock” provision lets you pause the response period to clarify rather than guess.
The practical burden, then, hasn’t disappeared so much as moved: toward defensibility, closer work with IT, HR and compliance, and a clear record of how you reached your decisions.
The new complaints duty
Running alongside the DSAR-specific changes is a broader one. Since 19 June 2026, controllers must follow a formal process for handling data protection complaints, with each one acknowledged within 30 days – no exceptions.
In practice, that means you can no longer wave a disgruntled requester off toward the ICO and hope for the best. Dissatisfaction with a DSAR response – a weak search, an unclear refusal, a redaction nobody explained – can now become a formal complaint you’re obliged to handle. Privacy notices and DSAR responses will need to spell out how to complain to you directly. And because complaints can surface anywhere – the privacy team, customer services, HR – you’ll want clear routes for picking them up and passing them to whoever should respond.
Bear in mind, when handled well, this is more of an opportunity than a chore: sorting things out internally is far cheaper than an escalation to the regulator or the courts.
Privilege, process and defensibility
Privilege is where defensibility gets tested most directly. The exemption gives firmer grounds for withholding material, but it isn’t a free pass. You generally have to tell the requester you’re relying on it and keep a record the ICO can review – so claims need to be valid, consistent and properly documented.
More broadly, DSAR disputes are increasingly judged on process as much as outcome: not just what was disclosed or withheld, but how you got there. Audit trails, decision logs, search rationales and clearly worded correspondence are what show you acted fairly and proportionately – and they matter most when a request lands alongside a grievance, an employment dispute or pre-action correspondence.
What to do now
Thankfully, none of this calls for a wholesale overhaul. For most teams it’s really about revisiting what’s already in place – checking that DSAR policies, playbooks and templates reflect the current position on clarification, complaints, refusals, exemptions and search methodology.
The one genuinely new piece to the puzzle is the complaints process. It’s worth taking a proper look at this, and ensuring the people who field requests can recognise a complaint when it lands.
Data mapping is the other area worth fresh attention: the more scattered your data, the harder it is to show a search was proportionate. The teams that fare best when a request is challenged are the ones that use every request, and each change in the rules, as a chance to sharpen their DSAR process into one that’s efficient, repeatable and resilient.
Need help with a complex DSAR?
If you’re dealing with a DSAR linked to a dispute, whistleblowing allegation, sensitive HR matter or large, fragmented data set, Salient Discovery can help you respond with confidence.
Our specialist-led DSAR service combines legal, digital forensic and eDiscovery expertise with advanced review technology to support defensible collection, proportionate searching, careful handling of privileged or confidential material, and robust reporting under deadline pressure. Get in touch at discover@salientdiscovery.com.



