GuidesSME

You no longer have to search everything for a data request

When someone asks for their data, you now only have to make a 'reasonable and proportionate' search, not an exhaustive one. Here is what that means day to day, and where the limit sits.

TheDutyDesk Editorial23 February 20263 min readReviewed 7 June 2026

One of the quiet fears around data access requests has always been the search. Someone asks for "all my data", and a small team imagines combing through years of email, old laptops, backup drives and a dozen apps, terrified of missing something.

Since 5 February 2026, the law is clearer and kinder about this. You only have to carry out a search that is "reasonable and proportionate".[1]

What "reasonable and proportionate" means

It means the effort should fit the situation.[1] [3] A request that points to a specific issue deserves a focused search in the obvious places. A vague request does not oblige you to dismantle every system you own on the off-chance.

This is not a loophole to do less than you should. It is permission to be sensible. You still have to look properly in the places where the data is likely to be. You just do not have to prove you searched every corner of the business when that would be wildly out of proportion to what was asked.

The standard was already recommended in regulator guidance. What changed is that it now sits in the law itself, so you can rely on it with more confidence.[1]

Where the limit sits

A few practical markers help.

Search the systems where you would genuinely expect the data to live. Do not ignore a system just because it is awkward to search. If you decide something is out of scope because searching it would be disproportionate, write down why. That short note is your defence if the decision is ever questioned.

If a request is so broad that a proportionate search is impossible, that is also your cue to go back and ask the person to narrow it, which you are now clearly allowed to do.

What this means for you

The fear was always worse than the duty. Respond in good faith, look where the data really is, and keep a brief record of the decisions you made about scope.

That record turns a stressful, open-ended task into a defensible, finite one.

DSARs and data protection complaints are frequently confused. If you're unsure which you have received — they run on different clocks and sit under different law — our guide sets out the one-line test to tell them apart.

Sources used in this article

  • [1]Data (Use and Access) Act 2025
  • [3]UK GDPR (retained EU regulation)

Source verification and SHA-256 hashes are maintained in our sources index.

Last reviewed: 7 June 2026. Next review: 23 August 2026, or sooner if relevant guidance changes.

TheDutyDesk helps you manage data protection complaints with a structured process and an audit trail.