
Unpopular opinion: Why Cyber Essentials should be mandatory
March 20, 2026With the introduction of the Data Use and Access Act (DUAA), organisations are facing increased scrutiny, shifting compliance expectations, and a notable rise in Data Subject Access Requests (DSARs). For many, what was once a manageable compliance function is becoming a significant operational and legal burden.
From a regulatory perspective, the DUAA operates in tandem with the UK GDPR rather than replacing it. The core data protection principles remain unchanged, but the emphasis has shifted toward flexibility in application and demonstrable accountability. Organisations are no longer assessed purely on whether they follow prescribed steps, but on whether they can clearly evidence responsible and justified data use.
In this article, we explore what the DUAA means in practice, why DSARs are becoming more frequent and strategic, and how organisations can protect themselves through effective Data Protection Officer (DPO) support.
What the DUAA means for organisations
The DUAA represents a shift toward more flexible, pro-innovation data use while maintaining core data protection principles. However, this flexibility does not reduce accountability; it increases the expectation that organisations can demonstrate responsible data handling.
Key implications include:
- Greater emphasis on risk-based decision-making rather than rigid compliance checklists.
- Increased responsibility on organisations to justify how and why personal data is used.
- Stronger expectations around transparency and governance.
In practice, this means organisations must be able to evidence their data protection processes clearly, placing greater weight on documentation and decision-making Organisations must be able to evidence how lawful bases were determined, how data minimisation has been applied, and how risks to individuals have been assessed and mitigated.
This is particularly important in the context of DSARs. A DSAR response now serves as a real-time test of an organisation’s accountability framework. If data cannot be located, explained, or justified, it exposes gaps in process and governance.
The rise of DSARs
DSARs are no longer rare or routine administrative requests. They are becoming:
- More frequent across all sectors.
- Broader in scope, often requesting extensive datasets and communications.
- Increasingly complex, involving multiple systems and third parties.
Many organisations underestimate the resources required to respond effectively. A single DSAR can involve:
- Searching emails, CRM systems, HR records, and archived data.
- Redacting third-party information.
- Applying legal exemptions correctly.
Failure to respond accurately or on time can trigger complaints to the Information Commissioner’s Office (ICO).
The weaponisation of DSARs
A growing trend is the strategic use of DSARs in disputes. Individuals, often employees or customers, are using DSARs to:
- Gather evidence for employment tribunals or litigation.
- Apply pressure during disputes or complaints.
- Test an organisation’s compliance maturity.
This ‘weaponisation’ increases both the volume and sensitivity of requests. Poor handling can quickly escalate a situation, turning a routine request into a legal or reputational issue.
In particular, AI tools / large language models such as ChatGPT are being used to heavily influence and even script such requests for data subjects to issue to controllers, and in certain cases, the AI tools have no concept as to what determines a “reasonable” DSAR over one that may not be.
When can you extend a DSAR deadline?
Under UK GDPR, organisations must respond to DSARs within one month. This can be extended by a further two months, but only where the request is:
- Complex (e.g. involves large volumes of data or multiple systems).
- Numerous (e.g. repeated requests from the same individual).
However, ‘exceptional’ does not mean inconvenient. The ICO expects organisations to:
- Justify clearly why an extension is necessary.
- Inform the requester within the initial one-month period.
- Demonstrate that delays are not due to poor internal processes.
Simply lacking resources or organisation will not be accepted as a valid reason.
What happens during an ICO investigation?
If a complaint is escalated, the ICO may launch an investigation. This typically involves:
- Requests for detailed evidence of how the DSAR was handled.
- Assessment of internal policies, procedures, and accountability structures.
- Evaluation of whether exemptions and redactions were applied correctly.
Potential outcomes include:
- Enforcement notices requiring changes to processes.
- Reputational damage through public findings.
- Significant fines in cases of serious or repeated non-compliance.
Critically, the ICO looks not just at the individual incident but at the organisation’s overall data protection framework.
Why DPO support is now essential
The core principles and individual rights set out in the UK GDPR remain fully in force, while the DUAA refines how certain requirements are interpreted and applied.
This dual framework increases the importance of clear, expert guidance. A qualified DPO helps organisations interpret where the UK GDPR sets non-negotiable requirements and where the DUAA allows for flexible, risk-based application. This ensures that DSAR responses, data use decisions, and internal governance remain compliant across both regimes, even as expectations evolve.”
A qualified DPO can:
- Oversee DSAR handling and ensure compliance with legal requirements.
- Implement efficient processes to reduce response time and risk.
- Advise on when extensions or exemptions are appropriate.
- Act as a point of contact during ICO investigations.
- Provide ongoing governance aligned with DUAA expectations.
Outsourcing this function offers a cost-effective way to access senior expertise without the overhead of a full-time hire.
How Economit can help
Economit’s DPO services are designed to support organisations navigating this increasingly complex landscape. We combine practical experience with regulatory insight to help you:
- Manage DSARs efficiently and defensibly.
- Strengthen your data protection framework.
- Reduce regulatory risk and exposure.
- Stay compliant as legislation evolves.
Whether you are experiencing a surge in DSARs or preparing for increased scrutiny under the DUAA, we provide the expertise and assurance you need.