Skip to content

Evidence request lists

Data (Use and Access) Act 2025

Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

DUAA 2025: Part 1 - Access to Customer and Business Data (Smart Data)

DUAA-P1-AUTH
Authorised persons and accreditation under smart data schemes

Provides for the accreditation and oversight of authorised persons (third parties) who may receive customer or business data under a smart data scheme, including conditions and enforcement.

Artefacts an auditor will ask for
  • Verification of an authorised person's accreditation before sharing data
  • Records of data shared with authorised persons
Where this commonly fails
  • Sharing smart data with unaccredited third parties
DUAA-P1-FEESENF
Fees, levies and enforcement of smart data schemes

Allows fees and levies to fund scheme operation and provides enforcement mechanisms (including for interface standards and IT supplier obligations) where data holders or others fail to comply.

Artefacts an auditor will ask for
  • Compliance with scheme interface/technical standards
  • Records demonstrating timely response and fee handling
Where this commonly fails
  • Non-compliant interfaces
  • Failure to meet scheme enforcement requirements
DUAA-P1-SMARTDATA
Smart data schemes for customer and business data

Empowers the Secretary of State / Treasury to make smart data scheme regulations requiring data holders to provide customer data and business data to customers or authorised third parties on request, enabling data portability across regulated sectors.

Artefacts an auditor will ask for
  • Identification of whether the entity is a data holder under an in-scope smart data scheme
  • Capability to provide customer/business data to customers or authorised persons on request
Where this commonly fails
  • Not tracking applicability of smart data scheme regulations
  • No mechanism to respond to authorised data-access requests

DUAA 2025: Part 2 - Digital Verification Services

DUAA-P2-DVS
Digital verification services and the DVS trust framework

Establishes a regime for digital verification services (DVS), including the DVS trust framework, a register of accredited providers, and the conditions for registration and continued listing.

Artefacts an auditor will ask for
  • For DVS providers: registration on the DVS register and conformity to the trust framework
  • Certification against the trust framework by an accredited conformity body
Where this commonly fails
  • Providing digital verification services without registration
  • Claiming trust-framework conformity without certification
DUAA-P2-GATEWAY
Information gateway for identity verification

Provides an information gateway enabling public authorities to share information with registered DVS providers to support identity verification, subject to safeguards.

Artefacts an auditor will ask for
  • Lawful-basis and safeguard records for any information shared through the gateway
Where this commonly fails
  • Using the gateway outside its statutory purpose or safeguards
DUAA-P2-TRUSTMARK
DVS trust mark usage

Controls the use of the digital verification services trust mark, which only registered providers conforming to the trust framework may display.

Artefacts an auditor will ask for
  • Trust-mark usage only by registered DVS providers in good standing
Where this commonly fails
  • Displaying the trust mark without registration

DUAA 2025: Part 3 - National Underground Asset Register

DUAA-P3-NUAR
National Underground Asset Register

Establishes the National Underground Asset Register (NUAR) and obligations on undertakers to provide and keep up to date information about apparatus located underground.

Artefacts an auditor will ask for
  • For relevant undertakers: provision and currency of underground-asset information to the NUAR
Where this commonly fails
  • Failing to register or update underground-asset data where required

DUAA 2025: Part 4 - Registers of Births and Deaths

DUAA-P4-REGISTERS
Digitisation of registers of births and deaths

Provides for the form in which registers of births and deaths are kept, enabling electronic registration and amending the Births and Deaths Registration Act 1953.

Artefacts an auditor will ask for
  • For registration bodies: compliance with the electronic-register requirements
Where this commonly fails
  • Maintaining registers in a non-compliant form where digitisation is required

DUAA 2025: Part 5 - Data Protection and Privacy Reforms

DUAA-P5-ADM
Automated decision-making reforms

Reforms the rules on automated decision-making, permitting a wider range of solely automated decisions subject to safeguards (information to data subjects, the ability to make representations, obtain human intervention and contest decisions), with tighter rules for special-category data.

Artefacts an auditor will ask for
  • Inventory of solely automated decisions and the safeguards applied
  • Mechanisms for human intervention, representations and contestation
Where this commonly fails
  • Solely automated decisions without the required safeguards
  • Special-category ADM without the stricter conditions
DUAA-P5-CHILDREN
Children's data protection by design (ISS)

Requires providers of information society services likely to be accessed by children to consider how to protect children when designing data processing, reinforcing higher protection for children's data.

Artefacts an auditor will ask for
  • Child-protection considerations in the design of in-scope information society services
  • Age-appropriate design records
Where this commonly fails
  • No child-protection design assessment for services likely accessed by children
DUAA-P5-COMPLAINTS
Complaints to data controllers

Introduces a duty for controllers to facilitate and handle data protection complaints from data subjects, including acknowledging and responding within prescribed timeframes, before escalation to the regulator.

Artefacts an auditor will ask for
  • A complaints-handling procedure with acknowledgement and response timeframes
  • Records of complaints received and resolved
Where this commonly fails
  • No controller-level complaint channel
  • Complaints not acknowledged or logged
DUAA-P5-DSR
Data subject access requests (reasonable and proportionate searches)

Clarifies the handling of data subject access requests, including that controllers need only carry out reasonable and proportionate searches and that the response clock can be paused while seeking clarification or identity verification.

Artefacts an auditor will ask for
  • DSAR procedure reflecting reasonable-and-proportionate search and stop-the-clock provisions
  • Logs of DSARs, clarifications sought and timelines
Where this commonly fails
  • Unbounded or no-search DSAR handling
  • Not documenting the basis for search scope
DUAA-P5-LAWFUL
Lawful processing and recognised legitimate interests

Reforms the lawful bases under the UK GDPR, including a new list of recognised legitimate interests for which a balancing test is not required, and clarifies the legitimate-interests assessment.

Artefacts an auditor will ask for
  • Updated records of processing showing reliance on recognised legitimate interests where applicable
  • Legitimate-interests assessments for non-recognised interests
Where this commonly fails
  • Treating all legitimate interests as exempt from a balancing test
  • No LIA where still required
DUAA-P5-PECR
PECR reforms (cookies, direct marketing, penalties)

Amends the Privacy and Electronic Communications Regulations: relaxes consent for certain low-risk cookies, adjusts direct-marketing rules (including the soft opt-in for charities), and raises PECR penalties towards UK GDPR levels.

Artefacts an auditor will ask for
  • Cookie-consent configuration reflecting the relaxed low-risk categories
  • Direct-marketing consent/soft-opt-in records
Where this commonly fails
  • Treating all cookies as consent-exempt
  • Marketing without a valid lawful basis or soft opt-in
DUAA-P5-RESEARCH
Research, statistics and archiving processing

Clarifies and consolidates the rules for processing for scientific or historical research, statistical and archiving purposes, including broad consent for areas of research subject to safeguards.

Artefacts an auditor will ask for
  • Safeguards for research/statistical/archiving processing
  • Documentation of broad-consent scope where relied on
Where this commonly fails
  • Research processing without the required safeguards
DUAA-P5-TRANSFERS
International transfers data protection test

Reforms the international transfer regime, introducing a data protection test for adequacy regulations and transfer mechanisms (whether the standard of protection is not materially lower than under the UK regime).

Artefacts an auditor will ask for
  • Transfer mechanism records assessed against the data protection test
  • Transfer risk assessments where no adequacy applies
Where this commonly fails
  • Transfers without applying the data protection test
  • No assessment for non-adequate destinations

DUAA 2025: Part 6 - The Information Commission

DUAA-P6-INFOCOMM
The Information Commission

Abolishes the office of the Information Commissioner and establishes the Information Commission as a body corporate, transferring functions and setting its governance, duties and powers.

Artefacts an auditor will ask for
  • Awareness that the Information Commission is the successor regulator to the ICO
  • Updated references to the Information Commission in policies
Where this commonly fails
  • Outdated references assuming the ICO rather than the Information Commission

DUAA 2025: Part 7 - Other Provision (Health Information Standards)

DUAA-P7-HEALTH
Information standards for health and adult social care

Provides for mandatory information standards for IT used in health and adult social care in England, requiring conformance to specified standards to support interoperability.

Artefacts an auditor will ask for
  • For health/social-care IT: conformance to the mandated information standards
Where this commonly fails
  • Deploying non-conformant health/social-care IT where standards apply
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Data (Use and Access) Act 2025 framework page.