July 31, 2025

eDiscovery

eDiscovery compliance: a UK guide to legal and data protection obligations

eDiscovery compliance: a UK guide to legal and data protection obligations

By Jonathan Krause | Founder, Forensic Control | Updated 18 August 2026

eDiscovery compliance is the work of finding, preserving, reviewing and producing electronically stored information in a way that satisfies the court or regulator asking for it and the data protection law that governs it at the same time. Electronic discovery, usually shortened to eDiscovery, covers the identification, collection and review of electronically stored information for legal proceedings, investigations or audits, which in practice means emails, chat messages, text messages, cloud documents, collaboration platforms, metadata, system logs and mobile device data. For a UK organisation the request arrives from one of four directions, and each carries a different deadline.

This guide is written for the people who have to answer these requests: in-house legal and compliance teams, and the information technology and security staff they turn to when a request is about finding data rather than interpreting law. It covers the four obligations that create eDiscovery work in the United Kingdom, the deadline attached to each, the preservation duty running alongside them, and what to have in place before a request arrives.

I have spent eighteen years in legal technology, and the review itself is seldom the hard part. The difficulty is that the request lands on an organisation whose data sits across systems nobody has mapped, with a retention schedule quietly deleting material while counsel is still deciding what to ask for.

Subject access, complaints, litigation and regulation each create eDiscovery compliance work

Four obligations create this work, and the first is a data subject access request (DSAR) under the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, where an individual asks for the personal data you hold on them. The second, in force since 19 June 2026, is a formal data protection complaint made directly to the organisation under section 164A of the Data Protection Act 2018. The third is disclosure in civil litigation, governed in the High Court’s Business and Property Courts by Practice Direction 57AD and in most other claims by Part 31 of the Civil Procedure Rules. The fourth is a regulatory investigation or audit, where the requesting body sets its own timetable and the underlying exercise is the same.

All four ask you to find material that was not filed with retrieval in mind. The instruction usually reaches us through the organisation’s own legal team or the firm acting for it, and our work with law firms is where a good share of instructions begin. Either way the first task is a map of where business communications are actually held, which is often not where the acceptable use policy assumes.

The duty to preserve documents starts before proceedings are issued

Practice Direction 57AD has governed disclosure in the Business and Property Courts of England and Wales since 1 October 2022, when the disclosure pilot that ran under Practice Direction 51U was made permanent in substantially the same form. It does not apply in the County Court, where Part 31 of the Civil Procedure Rules and Practice Direction 31B continue to govern multi-track claims. In both regimes the duty to preserve documents attaches as soon as litigation is contemplated, which is well before anyone has issued a claim form.

Under Practice Direction 57AD the parties suspend deletion processes and tell employees and relevant third parties to preserve material that might otherwise be destroyed, and legal representatives confirm those steps when they serve their statements of case. Extended Disclosure then runs on one of five models, from Model A, covering only known adverse documents, through Model D’s narrow search based disclosure, to Model E’s wider search reserved for exceptional cases. Model and scope are settled in the Disclosure Review Document before the first case management conference, which is where the cost of the exercise is effectively decided.

Outside the Business and Property Courts, Practice Direction 31B gives the parties an Electronic Documents Questionnaire to exchange, setting out the scope and extent of the electronic material each side holds and the formats it can be produced in, verified by a statement of truth. It also lists the factors that decide whether a search is reasonable, among them the number of documents, the complexity of the case, and the cost of retrieving material from back-up or archived systems. Those factors are the argument you will be making if the volume turns out larger than anyone expected, so read them before you agree a scope.

Documents are produced in native format in a manner that preserves metadata, and Practice Direction 57AD encourages parties to use software and analytical tools, including technology assisted review, to keep the burden proportionate. In the matters I have worked on, the organisations that came through this stage well were the ones that could say, in writing and with dates, which systems had been placed on hold and when. The ones that struggled were rarely careless about it; they had no way to stop an automated deletion rule once somebody had set it running.

Two changes landed on 6 April 2026. A new rule 31.12A of the Civil Procedure Rules allows the court to order a party to request that any person produce a document which may support or adversely affect any party’s case, and the 193rd Practice Direction Update added a matching paragraph 18.5 to Practice Direction 57AD. Because it compels a request rather than production, how much this new non-party route achieves is still being worked out.

Practice Direction 57AD is itself under review, which matters if you are budgeting a matter that runs into 2027. The Disclosure Review Working Group surveyed the legal market over the winter and published a summary on 29 July 2026. Of 215 respondents, 64% said the reforms had not been successful, 67% said costs had risen since they came in, and 51% wanted the practice direction kept with modifications. The group has said it will not recommend a simple return to Part 31, and hopes to consult on proposals later in 2026 or early in 2027.

Subject access timings and the complaints duty both changed in 2026

A subject access request must be answered without undue delay and within one month, though the month does not necessarily start when the request lands. Since 5 February 2026, Article 12A of the UK GDPR, inserted by section 76 of the Data (Use and Access) Act 2025, starts the period at the latest of three points: the day you receive the request, the day you receive whatever you reasonably needed to confirm the requester’s identity, and the day any fee is paid.

You can extend by up to a further two months where the requests are complex or numerous, provided you give notice stating your reasons before the end of the first month. Where you reasonably need more information to identify what has been asked for, the period between asking and receiving it does not count. That pause now sits in Article 12A(5) rather than in guidance, and it is the step organisations most often fail to record at the time.

The search itself has to be reasonable and proportionate, and that too is now statute rather than regulator guidance. Article 15(1A) of the UK GDPR, inserted by section 78 of the same Act, entitles the data subject only to what the controller can provide on the basis of a reasonable and proportionate search. It was treated as coming into force on 1 January 2024, so it covers requests you have already handled. Our DSAR support and compliance work often spends longer documenting why a search was scoped as it was than running the search, because that documentation is what the limit rests on.

The complaints route changed on 19 June 2026, and in both directions. Section 103 of the Data (Use and Access) Act 2025 inserted section 164A into the Data Protection Act 2018, letting a data subject complain directly to the controller, and omitted Article 77 of the UK GDPR, which had carried the right to complain to the Commissioner. That right survives, relocated to section 165 of the Data Protection Act 2018, so a complainant can still go to the Information Commissioner’s Office (ICO), whose own advice is to let the organisation work through its process first.

Section 164A does three things and attaches a deadline to only one of them. It requires you to facilitate complaints, giving the example of a form that can be completed electronically, to acknowledge receipt within 30 days of the complaint arriving, and to respond without undue delay, meaning enquiries into the subject matter to the extent appropriate, progress updates, and notification of the outcome. No statutory deadline attaches to that outcome, which is the part most often misread.

Section 164B also lets the Secretary of State require controllers to report complaint numbers to the Commissioner. Investigating a complaint properly means locating and reviewing personal data across several systems, which is the same work as a subject access request on a different statutory footing.

A litigation hold suspends the deletion your retention schedule requires

Article 5 of the UK GDPR requires personal data to be adequate, relevant and limited to what is necessary, and kept in a form that identifies people no longer than necessary. Read alone that argues for deleting early and often, and for most purposes it should. The complication is that once litigation or a regulatory investigation is contemplated, the preservation duty suspends the deletion the retention schedule requires.

The organisations that manage this without drama tend to have three things: a retention schedule that names systems rather than data categories in the abstract, a documented way to switch deletion off on each of them, and somebody with the authority to do it on the day. In eighteen years I have more often seen the reverse, a well drafted policy that nobody can act on inside a week. If your interest is preventative compliance rather than disclosure, our GDPR compliance guide for SMEs covers that ground instead.

Retaining less does reduce disclosure cost, because review volume is the largest single driver of what an exercise costs. That saving is only available to organisations that settled their retention position while no dispute was in view.

Collection creates a copy of your most sensitive data, so treat it as a security exercise

Collection takes the most sensitive material in the organisation, copies it, and moves it somewhere else. That is a security event in its own right, and one the organisation has chosen to create. Encrypted transfer, access control scoped to the review team rather than a whole department, and an audit trail that cannot be edited afterwards are what make it defensible as well as complete.

Chain of custody determines whether the material is usable at the end. Our collections follow the Association of Chief Police Officers (ACPO) principles for handling digital evidence, the same standard our digital forensics work runs to, because a dataset that cannot be shown to be unaltered is worth very little to the party relying on it. The usual consequence of getting this wrong is not a lost case but an argument about admissibility, which tends to cost more than the collection did. Handled without those controls an eDiscovery exercise is among the larger data risks an organisation takes on in a year, which is why we treat it as part of the security programme.

Three checks you can run against your own estate this week

Open your subject access log and confirm the last three responses left inside the month. Where the period was paused for clarification, check the log records both the date you asked and the date it came back, because that is the evidence the ICO would ask to see.

List every system holding business communications: Microsoft 365 including Exchange, SharePoint, OneDrive and Teams, then Google Workspace, Slack, and WhatsApp on company handsets. For each, establish whether you can place data on hold without deleting it, and who holds the permission to do that.

Check whether automated deletion is running right now: the retention policies in Microsoft Purview, and the retention rules in Google Vault. Note the age at which each rule deletes and whether anyone outside the IT team knows it exists. If the answer to any of the three is that you would have to go and ask somebody, that is the gap worth closing while there is no request outstanding.

Frequently Asked Questions

What is eDiscovery in a UK legal context?

eDiscovery, short for electronic discovery, is the identification, preservation, collection, review and production of electronically stored information for legal proceedings, regulatory investigations or audits. In the United Kingdom it covers court disclosure under the Civil Procedure Rules and Practice Direction 57AD, and it also covers data protection work such as subject access requests and data protection complaints. The material involved is typically email, chat and messaging platforms, cloud documents, collaboration tools, system logs, metadata and mobile device data.

How long does an organisation have to respond to a subject access request?

One month, but the month does not necessarily start on the day the request arrives. Since 5 February 2026, Article 12A of the UK GDPR starts the period at the latest of three points: the day the controller receives the request, the day it receives information it reasonably needed to confirm the requester’s identity, and the day any fee is paid. The period can be extended by up to a further two months where the requests are complex or numerous, provided notice stating the reasons is given before the end of the first month. Where the controller reasonably needs more information to identify what is being asked for, the time between asking and receiving it does not count.

Do we have to acknowledge a data protection complaint, and how quickly?

Yes, within 30 days. Section 164A of the Data Protection Act 2018, inserted by section 103 of the Data (Use and Access) Act 2025 and in force from 19 June 2026, requires a controller to acknowledge receipt of a data protection complaint within 30 days of receiving it, to facilitate complaints in the first place (the section gives the example of a form that can be completed electronically), and to respond without undue delay by making enquiries, updating the complainant on progress and telling them the outcome. No statutory deadline applies to the outcome itself. The same section omitted Article 77 of the UK GDPR, so the separate right to complain to the Information Commissioner’s Office now sits in section 165 of the Data Protection Act 2018.

When does the duty to preserve documents start in litigation?

Certification is valid for 12 months and must be reneAs soon as litigation is contemplated, which is before proceedings are issued. Under Practice Direction 57AD in the Business and Property Courts, parties must suspend relevant deletion processes and notify employees and relevant third parties to preserve documents that might otherwise be destroyed. Practice Direction 31B imposes an equivalent duty in multi-track claims outside that jurisdiction, and legal representatives are expected to notify their clients of the need to preserve disclosable documents.

Can we keep deleting data under our retention policy once a dispute is contemplated?

No, not for material that falls within the preservation duty. A litigation hold suspends routine deletion for the data in scope, which means the retention schedule stops running against those systems and custodians until the hold is lifted. Data protection law still requires personal data to be kept no longer than necessary, so the hold should be scoped to what is genuinely relevant, documented, and released once the matter ends.

How long does it take to get Cyber Essentials certified?

With the right preparation and support, many organisations can achieve certification in a few days, depending on their current security posture.

Ready to take control of your cyber security?

Safeguard your business with our expert cyber security solutions. Whether you require digital forensics, penetration testing or proactive security assessments, our team is ready to assist. Contact us today to discuss your security needs and take the first step towards a more secure future.

Forensic Control
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.