UK GDPR 2026 · 6 min read

Reasonable and Proportionate DSAR Searches

The DUA Act put the search standard on a statutory footing. What it changes, what it does not, and why search scope is really redaction scope.

The Data (Use and Access) Act 2025 wrote into UK GDPR something courts and the ICO had been converging on for years: when you respond to a subject access request, you must make a reasonable and proportionate search for the requester’s personal data, and you are not required to conduct searches that would be unreasonable or disproportionate to the importance of the information. The principal data protection provisions of the Act came into force on 5 February 2026, and the ICO updated its right of access guidance in December 2025 to reflect them. If your DSAR procedure predates that, it is describing a stricter world than the one you now operate in, and probably also a vaguer one, because the new standard cuts both ways.

What the Standard Actually Says

The ICO’s current guidance is short and worth reading in its own words: you must make a reasonable and proportionate search to respond to a SAR, which means making reasonable efforts to find and retrieve the requested information. Whether a search is proportionate depends on the circumstances of the request, the difficulty of finding the information, and the fundamental importance of the right of access itself. Two boundaries stop the standard becoming an escape hatch. First, even where searching one location would be disproportionate, you must still search everywhere else within scope. Second, you cannot make a requester narrow their request; they are entitled to ask for everything you hold about them, and if you ask for clarification and receive none, your obligation is to run a reasonable and proportionate search over the full request and disclose what you find.

The guidance also confirms that the response clock can pause while you wait for clarification or identity verification, where that is reasonably required. Used honestly, that removes the worst version of the old dilemma, where a broad request burned its own response window while you negotiated scope. Used as a delay tactic, it will read exactly that way to the ICO later, so record when the clock stopped, what you asked, and when it restarted.

What It Does Not Change

The temptation is to read the codified standard as permission to search less. Practitioner experience points the other way: the proportion of requests where a search is genuinely unreasonable or disproportionate is small, and the burden of demonstrating it sits with you. What the statute really rewards is documentation. A scope decision you can defend names the systems searched, the custodians and date ranges applied, anything excluded and the specific reason, and who made the call. That record is the difference between a judgment and an omission when a requester complains that something is missing.

Search Scope Sets Redaction Scope

Here is the part legal commentary tends to skip: the search standard is really a review standard. Every file your search returns has to be read for other people’s personal data before it can be disclosed, because the third-party protections in the legislation do not shrink just because the search got easier to justify. A DSAR’s cost lives mostly in that review and redaction stage, not in the query that produced the files. So a disciplined, proportionate, well-documented search is also the thing that keeps the review burden survivable: over-collection means over-review, and over-review is how one-month deadlines die. Scope tightly, record why, then review everything that made the cut properly.

Running a Proportionate Case in Microsoft 365

In practice most UK DSAR searches are Microsoft 365 searches. The proportionality record writes itself if you let the tooling reflect the decision: a Purview or Content Search scoped to named custodians, a date range, and search terms tied to the request is a search you can describe in one paragraph to the ICO. Export what that scope returns, then move to review. Our guides to Microsoft 365 DSAR redaction and Purview eDiscovery exports cover the export mechanics, including the package settings that keep the downstream review workable.

How SafeRedact Fits

Files never leave your browser: documents are processed client-side, only extracted text is sent for AI detection, and no documents are stored on servers. Detection text is never used for training and is deleted within 30 days. DSAR mode lets you name the data subject whose information should be preserved while other individuals’ personal information is flagged for redaction across every file in the case. Every detection is reviewed by a human before anything is exported, and the output includes a processing summary and audit trail your privacy officer can stand behind if the ICO asks how the response was produced.

A Data Processing Agreement is available, and enterprise cases are priced per case, with the price set with you and shown before you download. See the enterprise overview or the enterprise FAQ for how cases run end to end.

If the Response Is Challenged

From 19 June 2026, a requester who thinks your search was too narrow or your redactions too broad has a statutory route to say so: every controller must operate a data protection complaints procedure, and DSAR handling is historically the ICO’s most complained-about issue. The search record and the review audit trail you kept are what your complaint response will be built from. We cover the new procedure and what it means for redaction accuracy in our guide to the section 164A complaints procedure.

Scope Tightly, Review Properly, Deliver On Time

AI-assisted detection, human review, and an audit trail that shows exactly what was reviewed. Files never leave your browser.

Start Your Evaluation
The DSAR practitioner briefing
One email a month on subject access, redaction, and the rules changing around them. No tracking pixels. Unsubscribe anytime.

Related Guides

Microsoft, Microsoft 365, SharePoint, Exchange Online, OneDrive, Teams, and Purview are trademarks of Microsoft Corporation. SafeRedact is not affiliated with or endorsed by Microsoft. This page is informational, not legal advice; the legislation, ICO guidance, and your counsel govern.

Found this useful?
Link copied!