Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.
"We carried out a reasonable and proportionate search"
high likelihoodThe Data (Use and Access) Act 2025 requires only a reasonable and proportionate search. We searched our main system and found nothing further.
What answers it
Proportionate is not the same as minimal, and the controller has to be able to describe what it did. Ask, in writing, for: the systems searched, the systems NOT searched and why, the search terms and identifiers used, the date range covered, and whether backups, archived mailboxes, call recordings, CRM notes and third-party processors were within scope. Then name the systems you know they hold your data in — the ones you have interacted with. A search that omits a system you can prove exists is not proportionate.
Data (Use and Access) Act 2025
The clock stopped because they asked you something
high likelihoodWe wrote to you asking for clarification on 3 March. The statutory period was suspended until you replied.
What answers it
Check two things. First, was the request for information the controller reasonably required — a genuine need to identify you or to narrow a genuinely unclear request — or a pro-forma stall sent to everyone? Second, did the clock restart when you answered? Reply in writing, dated, and restate the deadline as running from the date of your reply. If you already answered and they carried on treating the clock as stopped, that is a straightforward breach with a paper trail.
Data (Use and Access) Act 2025
The ICO bounces you back to the organisation
high likelihoodThe ICO cannot look at this until you have raised it with the organisation and given them the chance to respond.
What answers it
This is now the intended route rather than a brush-off, so work with it rather than against it. Send a formal complaint to the organisation, using the word "complaint", to its data protection officer or privacy team. The organisation must acknowledge within 30 days. Diarise it. When it lapses, go back to the ICO with the complaint, the acknowledgment (or its absence), and the dates — a complaint with a documented failed internal stage is much stronger than one without.
Data (Use and Access) Act 2025
Endless identity verification
high likelihoodWe cannot action your request until you verify your identity. Please send a copy of your passport, a utility bill, and a selfie holding your ID.
What answers it
A controller may use reasonable measures to verify identity, but it may only ask for information it actually needs and already holds a basis to check. Demanding a passport scan from someone whose account you identify by email address is disproportionate and is itself a data-minimisation problem. Offer to verify through the same channel you already use to log in, state that you consider the demand excessive, and note that the response clock is running.
"We hold no personal data about you"
high likelihoodA search of our systems returned no personal data relating to you.
What answers it
Ask for that in writing, signed, together with a description of the systems searched and the search terms used. A nil return is a substantive answer that the controller must stand behind, and it is frequently wrong: it usually means one production database was searched and backups, CRM, marketing, support tickets, call recordings, and third-party processors were not. Name the systems you believe hold your data, including any you have interacted with.
Blanket confidentiality or trade-secret refusal
medium likelihoodThe information you have requested is commercially confidential / contains our trade secrets / is proprietary.
What answers it
Confidentiality and intellectual-property carve-outs are narrow and must be applied item by item, not as a blanket. The correct response is redaction of the protected element and disclosure of the rest, with a schedule explaining what was withheld and why. Ask for that schedule.
Refusal because the data mentions someone else
medium likelihoodWe cannot disclose these records because they contain the personal data of other individuals.
What answers it
The presence of third-party data is a reason to redact, not to refuse. The controller must consider whether it can disclose with the third party removed, whether the third party has consented, and whether it is reasonable to disclose without consent. A blanket refusal on this ground is not a lawful answer.
"Your request is manifestly excessive"
medium likelihoodYour request is manifestly unfounded or excessive, so we are refusing it / charging a fee.
What answers it
The burden of showing that a request is manifestly unfounded or excessive is on the controller, and it is a high bar — the regulator guidance treats it as exceptional, not as a routine response to a broad request. Ask the controller to state, in writing, the specific grounds and the evidence for them. If you have made only one request, say so. A single, first, ordinary request is not excessive.