https://www.noxia.co.uk/field-notes/you-do-not-have-to-leave-no-stone-unturned · printed from noxia.co.uk · sources checked 24 September 2026
Field note · What we found
You do not have to turn over every stone. You do have to say why.
The Data (Use and Access) Act made two changes to subject access requests, and both favour the organisation receiving one. Neither is a licence to do less. They are a licence to do the right amount, and to record why that was the right amount.
The short answer
The Data (Use and Access) Act 2025 writes into law that a requester gets what a controller can find through a reasonable and proportionate search, not an exhaustive one — in force since Royal Assent on 19 June 2025 and treated as law from 1 January 2024. Since 5 February 2026 the response clock also pauses while the controller seeks clarification it reasonably needs. The limit remains one month, extendable by two more for complex requests.
On this page · 5 sections
The useful way to hold this is as two columns, because almost every mistake made with a subject access request is a mistake about which column something is in.
The clock pause is narrower than it sounds
It pauses while you seek clarification of the scope of the request, and it restarts when the requester gives you what you asked for. It is not a pause for resourcing, for holidays, or for a legal review.
Which means a clarification request has to be a real one. "Could you confirm which period and which systems you are interested in" is clarification. "Could you confirm you still want this" is not, and using the second to buy time is the failure mode the codification invites.
Why "reasonable and proportionate" needs a record
The Act does not list factors. Guidance on it points to the volume of the request, the circumstances, how hard the data is to locate, the nature of the business and the resources available — the list Ashfords gives. Every one of those is a fact about your organisation on the day, and none of them will be remembered accurately eighteen months later when somebody complains.
So the practical consequence of a relaxed standard is more record-keeping, not less. The defensible version is a short note per request: what was asked, what you searched, what you did not search and why that was proportionate, what you asked for by way of clarification and when the clock stopped and started.
That is four fields and a timestamp. It is also exactly the kind of thing that never gets written down unless the system writes it — the same argument as the audit layer, applied to a duty rather than a decision.
What this does not tell you
It does not cover the exemptions, which are where most genuinely hard subject access questions live — third party data, legal privilege, negotiations, management forecasting. Those are unchanged and they are the part worth taking advice on.
Nor does it reach the Act's other provisions, several of which are more consequential for organisations doing large-scale processing.
And the dates and the wording above are the Act's, while the list of factors is a law firm's summary of how the standard is applied. We say which is which because the difference matters. Automated decisions are the neighbouring duty, and the eleven-duty grid maps which of these reach you.
Questions people actually ask
Do you have to search everything for a subject access request?
No. Section 78 of the Data (Use and Access) Act 2025 limits a requester to what the controller can provide “based on a reasonable and proportionate search”. It has been in force since 19 June 2025 and is treated as having applied from 1 January 2024. Guidance points to factors including the volume of the request, how hard the data is to locate, the nature of the business and the resources available.
Can you stop the clock on a subject access request?
Yes, since 5 February 2026, while you seek information you reasonably need to identify the data or processing the request is about. The clock restarts once the requester provides it. The pause is for narrowing a request, not for resourcing, holidays or legal review.
How long do you have to answer a subject access request?
One calendar month, extendable by up to two further months where the request is complex. The period runs from receipt of the request, or from the point at which the requester’s identity is verified if that is later.
What should you record when answering a subject access request?
What was asked, what you searched, what you did not search and why that was proportionate, what clarification you sought, and when the clock stopped and started. The proportionality standard is judged on facts about your organisation at the time, which nobody recalls accurately when a complaint arrives much later.
Sources
- Ashfords LLP, “The Data (Use and Access) Act: changes for data subject access requests”, read 23 September 2026: controllers have one calendar month to respond, extendable by two further months for complex requests, running from receipt or from verification of identity; the Act codifies a “stop the clock” provision which “pauses the timeframe for a response whilst the data controller seeks further clarification on the scope of the data subject access request from the data subject”; and controllers “are not required to conduct an exhaustive search for responsive data, leaving no stone unturned, but rather to make reasonable efforts”, judged against factors including volume, circumstances, difficulty of locating the data, the nature of the business and available resources. It dates the change to early February 2026, which is when section 76 started; section 78 has applied since Royal Assent. ashfords.co.uk ↗ — secondary; a law firm’s summary, used here for the factors only. For the wording and the dates, the Act governs re-checked every 6 months
- Data (Use and Access) Act 2025, section 78, “Searches in response to data subjects’ requests”: the data subject “is only entitled to such confirmation, personal data and other information as the controller is able to provide based on a reasonable and proportionate search”; subsection (5): “The amendments made by this section are to be treated as having come into force on 1 January 2024.” In force on Royal Assent, 19 June 2025. legislation.gov.uk ↗ — primary; the statute
- Data (Use and Access) Act 2025, section 76, “Time limits for responding to data subjects’ requests”: the clock pauses from when the controller asks for information it reasonably needs to identify the data or processing concerned until the data subject provides it, and the period can be extended by two further months for complexity or number of requests. In force 5 February 2026, by the Commencement No. 6 Regulations 2026. legislation.gov.uk ↗ — primary; the statute and its commencement
- The subject access exemptions — third party data, legal privilege, negotiations, management forecasting — are unchanged and are not covered here. Nor are the Act’s other commenced provisions. We are not lawyers. — a stated limit on the coverage above
- The argument that a relaxed standard produces more record-keeping rather than less, and the four fields and a timestamp, are ours. — our own argument, labelled as such
Checked 24 September 2026. Next scheduled check 23 March 2027. Numbers that move — leaderboards, live indices — are re-checked every 30 days; annual datasets and rules in force every six months; dated research once a year. If something here has gone stale before we got to it, tell us and we will correct it and say what changed.
Cite this note
Noxia, “You do not have to turn over every stone. You do have to say why”, Field notes, 23 September 2026; sources checked 24 September 2026. https://www.noxia.co.uk/field-notes/you-do-not-have-to-leave-no-stone-unturned
Four fields and a timestamp, written by the system.
What you searched, what you did not, why that was proportionate, and when the clock stopped — nobody writes that down under pressure, and nobody remembers it eighteen months later. We build it into the process so the record exists whether or not anyone thought to make one.
Talk to us about thisRead next
What we found
Eleven new duties in fifteen months. Which reach you?
Automated decisions, targeted support, sick pay, verification, dashboards, tax filing, accessibility, cyber, possession grounds, premises capacity and energy standards — on one grid, by who each one reaches.
What we found
Ranking job applicants is on the EU’s high-risk list. Most firms do it.
Employment and worker management is a named Annex III high-risk use. The deadline moved to 2 December 2027, but UK automated-decision duties arrived on 5 February 2026 and did not move.
Security
The Online Safety Act applies to all sizes. Including yours.
The duties apply to regulated user-to-user and search services regardless of size. The categories with extra duties start at 3 million UK users; the base duties do not.