DSARs and the Reasonable and Proportionate Search Standard: What Has Actually Changed

5th August 2026BlogAJ Thompson

Are you ready to get in touch?

Request a Call back

Key takeaways

  • The Data (Use and Access) Act 2025 has written a “reasonable and proportionate search” standard directly into UK GDPR, as a new Article 15(1A), rather than leaving it as guidance alone.
  • This does not lower the bar for DSAR compliance. ICO guidance confirms the right of access still carries a high threshold, and the High Court has already found a search too narrow, in Ashley v HMRC.
  • A related change, the Section 103 statutory complaints handling duty, took effect on 19 June 2026 and applies to every organisation with no exemptions.
  • The practical shift is about evidence: organisations need to show, after the fact, what was searched, what was not, and why that scope was proportionate.

For years, “reasonable and proportionate search” was a phrase that lived in ICO guidance: useful, but not law. That changed with the Data (Use and Access) Act 2025 (DUAA), which inserted a new Article 15(1A) directly into UK GDPR. An individual, it now states, “is only entitled to such confirmation, personal data and other information as the controller is able to provide based on a reasonable and proportionate search.” The ICO has since updated its Right of Access guidance to reflect the change. For organisations handling DSARs, it is worth understanding properly, because the headline, that a search does not have to be exhaustive, is easy to misread as a loosening of the rules.

What actually changed

Contrary to how some commentary has framed it, this is not a new, lower bar for DSAR compliance. The ICO’s pre-DUAA guidance already said organisations are not required to conduct searches that would be unreasonable or disproportionate to the importance of providing access. What DUAA does is move that principle from guidance into primary legislation, giving it statutory weight rather than leaving it as regulator interpretation.

The ICO’s updated guidance sets out factors relevant to what counts as reasonable and proportionate:

  • the circumstances of the request
  • the volume of information that may need to be searched
  • any difficulties involved in finding the information
  • the fundamental nature of the right of access

That last factor matters most. It signals a high threshold: the right of access is a fundamental one, and the “reasonable and proportionate” exception is not an easy way out of a thorough search.

The courts are already testing the boundary

This is not theoretical. In Ashley v HMRC, decided in the High Court in January 2025, the court found that HMRC had adopted too narrow a view of what counted as personal data, had failed to carry out appropriate searches, and had wrongly applied exemptions. HMRC was ordered to reconsider its response. It is a useful reminder that “reasonable” is judged against what a well run search process should have covered, not what was administratively convenient.

“The mistake we see most often is treating ‘reasonable and proportionate’ as permission to search less,” says AJ Thompson, Chief Commercial Officer at Northdoor. “It isn’t. It’s permission to search deliberately, and then prove you did. Organisations that can show their search strategy, not just their search results, are the ones who’ll be comfortable if a DSAR response is ever challenged.”

The other change worth planning for: Section 103

Alongside the search standard, DUAA introduces a statutory complaints handling duty under Section 103, inserting a new Section 164A into the Data Protection Act 2018. It took effect on 19 June 2026. Organisations must now have their own documented complaints procedure that individuals can use before escalating to the ICO, must make it easy to complain including by electronic means, and must acknowledge a complaint within 30 days. The ICO confirmed in its February 2026 guidance that there are no exemptions: the duty applies to every controller regardless of size or sector. If your DSAR process, or your refusal templates, still route people only to the ICO, that needs reviewing.

What this means in practice

The direction of travel across both changes is the same: evidence. A “reasonable and proportionate” search is a legitimate, lawful way to scope a DSAR response, but only if an organisation can show, after the fact, what was searched, what was not, and why that scope was proportionate to the request. That is difficult to demonstrate from an ad hoc search built on institutional memory of where things usually are. It is straightforward to demonstrate from a documented, repeatable search process with a clear audit trail.

The practical takeaway for compliance and IT teams:

  • Review how DSAR search scope decisions are made and recorded, not just the search itself.
  • Check refusal and response templates reflect the current complaints handling requirements.
  • Make sure whoever signs off a DSAR response can explain, on paper, why the search was reasonable and proportionate for that specific request.

None of this replaces legal advice, and organisations should take their own view on specific cases. But the direction is clear: DSAR compliance is increasingly a documentation exercise as much as a search exercise. If you would like to talk through how your organisation’s current DSAR process would hold up against the updated standard, take a look at our Subject Access Requests solution or get in touch with the Northdoor team.


AJ Thompson All Author's Posts
1

Our Awards & Accreditations