Subject Access Request Time Limit: What UK Organisations Must Know in 2026
If your organisation receives a subject access request (SAR), one of the first questions is likely to be: how long do we have to respond?
Under the UK GDPR, organisations must respond without undue delay and generally within one calendar month. In most cases, the response period begins when the request is received. Where proof of identity or authority is reasonably required, the time limit begins once the organisation receives the necessary information. If clarification is reasonably required to identify the information or processing covered by a SAR, the response period may be paused while the organisation waits for that clarification.
Where a request is complex, or an individual has made a number of requests, the deadline may be extended by up to two further months. This gives a maximum response period of three months, but the requester must be informed of the extension and the reasons for it within the original one-month period.
That is the short answer. In practice, calculating the subject access request time limit, knowing when the clock can be paused and deciding whether an extension is justified can require careful assessment.
When Does the One-Month Clock Start?
e one-month period will usually begin on the date the request is received, not when it is read, logged or forwarded to the relevant department. This remains the position where a request arrives on a weekend or public holiday.
For example, if a SAR arrives in a shared inbox on a Friday evening, the organisation should not wait until Monday to start calculating the deadline. Staff should therefore be trained to recognise and escalate requests promptly, regardless of where or how they are received.
The deadline is calculated by calendar month, rather than as a fixed period of 30 days. A request received on 3 September would normally be due by the end of 3 October. If there is no corresponding date in the following month, the deadline falls on the final day of that month. Where the deadline falls on a weekend or public holiday, it moves to the end of the next working day.
The starting date may be later where the organisation reasonably requires information to confirm the requester’s identity, evidence that a third party is authorised to act for them, or payment of a fee that may lawfully be charged in limited circumstances.
Identity Checks and the Response Period
An organisation may ask for information to confirm a requester’s identity where it has reasonable doubts about who is making the request. Any identity check should be necessary and proportionate to the circumstances. Formal photographic identification should not be requested automatically if the organisation can verify the individual through less intrusive information that it already holds.
Where identity information is reasonably required, the one-month response period begins when that information is received. Organisations should request it promptly and should not use identity checks simply to delay their response.
The same principle applies where a request is submitted through a solicitor, representative or other third party. The organisation may reasonably require evidence that the person is authorised to act on behalf of the data subject before releasing personal information.
When Can an Organisation Stop the Clock?
The Data (Use and Access) Act 2025 placed the ability to pause the response period for SAR clarification on a statutory footing.
An organisation may request clarification where it reasonably requires further information to identify the personal data or processing activities covered by the request. The period between asking for clarification and receiving it does not count towards the response deadline.
Clarification should not be requested as a matter of routine. It must be reasonably necessary to enable the organisation to respond. For example, clarification may be appropriate where a request is unclear or where the organisation holds a large amount of information about the individual and cannot reasonably identify what information is being sought.
The organisation should explain what clarification would assist, provide appropriate advice and assistance to the requester, and make the request as soon as reasonably possible. It should also record why clarification was considered necessary.
Importantly, the statutory clarification pause applies to subject access requests. It should not be treated as a general power to pause the deadlines for every type of data protection rights request.
When Can the Deadline Be Extended to Three Months?
An organisation may extend the response period by up to two further months where a request is complex or where the same individual has submitted a number of requests.
Relevant considerations may include the volume of information involved, the number of systems that require searching, the need to review substantial amounts of third-party information and the extent of any necessary redaction. Whether a request is complex will depend on its particular circumstances.
A request is not necessarily complex simply because the organisation needs clarification. The need for clarification and the decision to extend the deadline are separate issues and should be assessed independently.
If an extension is required, the organisation must notify the requester within the original one-month period. The notification should explain why the extension is necessary and confirm when the response is expected. An extension should not be applied automatically simply because a request is broad, inconvenient or time-consuming.
Failing to notify the requester until after the original deadline has passed does not retrospectively create a valid extension.
What Changed Under the Data (Use and Access) Act 2025?
The Data (Use and Access) Act 2025 amended the UK’s existing data protection framework rather than replacing the UK GDPR or Data Protection Act 2018.
Many of the provisions affecting SAR handling came into force on 5 February 2026. The new statutory data protection complaints regime followed on 19 June 2026.
Three changes are particularly relevant to organisations managing subject access requests.
Stop the clock for clarification
The Act places the ability to pause the SAR response period on a clearer statutory footing. Where clarification is reasonably required to identify the information or processing covered by the request, the time spent awaiting that clarification does not count towards the response period.
Reasonable and proportionate searches
An individual is entitled to the personal data and related information that an organisation can provide following a reasonable and proportionate search. This reflects the circumstances of the request, the volume of information that may need to be searched, any difficulty in locating it and the fundamental nature of the right of access.
This does not permit an organisation to carry out a superficial search or ignore a likely source of relevant personal data. Organisations should identify the systems, locations and custodians likely to hold relevant information and document how the search scope was determined.
Proportionality concerns the search effort. It does not create a general discretion to withhold relevant personal data that has already been found.
Data protection complaints
From 19 June 2026, controllers must provide a way for individuals to make data protection complaints directly to them. Complaints must be acknowledged within 30 days. Controllers must take appropriate steps to respond, keep complainants informed and communicate the outcome without undue delay.
Organisations should ensure that privacy notices, complaint procedures and staff guidance clearly explain how an individual can raise a data protection complaint.
How Can a Subject Access Request Be Made?
A SAR does not need to follow a particular format. It may be made verbally or in writing, including by email or social media. It may also be submitted to any part of the organisation.
The individual does not need to use the words “subject access request”, cite Article 15 of the UK GDPR or explain why they want the information. A request is valid if it is clear that the person is asking for access to their personal data.
This means that a SAR may be contained within a grievance, complaint or other correspondence. Front-line employees, managers and HR teams should know how to recognise requests and where to send them.
Common Subject Access Request Timeline Mistakes
Treating one month as 30 days
A calendar month is not the same as 30 days. Depending on the date received, the response period may contain 28, 29, 30 or 31 days. The ICO suggests that organisations needing a consistent internal target could use 28 days to help ensure compliance within the statutory calendar month.
Starting the clock too late
The response period does not begin when the request reaches the data protection team. In a straightforward case, it begins when the organisation receives the request, even if it arrives through a shared inbox or another communication channel.
Requesting identification automatically
Identity evidence should only be requested where it is necessary and proportionate. Organisations should consider whether they already hold enough information to identify the person before asking for additional documents.
Seeking unnecessary clarification
The stop-the-clock provision should not be used simply because a request is broad or inconvenient. The organisation must reasonably require the clarification to identify the personal data or processing covered by the SAR.
Treating clarification as proof of complexity
A request does not automatically become complex because clarification is required. Complexity must be assessed separately by reference to the circumstances of the request.
Failing to communicate an extension
An organisation relying on an extension must tell the requester within the original one-month period and explain why more time is required. Silence beyond the original deadline is not a valid extension.
What Happens If the Subject Access Request Time Limit Is Missed?
Missing the subject access request time limit may lead to a complaint to the organisation or the Information Commissioner’s Office. It may also create further difficulty where the request is connected with an employment grievance, disciplinary process, customer complaint or legal dispute.
If a deadline is at risk, the organisation should not ignore the requester. It should communicate promptly, explain the position and complete the response without further avoidable delay. An explanation does not remove the breach, but clear communication may help limit unnecessary escalation.
Organisations should keep an audit trail recording:
- the date and method by which the SAR was received;
- any reasonable identity or authority checks;
- clarification requested and received;
- the calculation of the response deadline;
- the reasons for any extension;
- the systems, locations and individuals searched;
- decisions concerning redactions and exemptions; and
- when and how the final response was provided.
uilding a Reliable SAR Response Process
Meeting the subject access request time limit consistently depends on early recognition, accurate deadline calculation and clear ownership.
Organisations should have a documented process for logging requests, checking identity where necessary, identifying relevant systems, issuing searches, reviewing results, applying lawful redactions and completing quality assurance before disclosure.
Early triage is particularly important where a request concerns employee records, [internal link: employer and employee data disputes], large email archives or third-party information. Requests involving several systems or processors may require additional coordination, making it important to identify potential complexity at the outset.
Organisations developing or reviewing their procedures may also benefit from a [internal link: SAR response checklist for data controllers] and guidance on [internal link: responding to third-party subject access requests].
Calculating the deadline correctly is only one part of responding to a SAR. Organisations must also determine what personal data falls within scope, conduct reasonable and proportionate searches, consider applicable exemptions and protect the rights of other individuals before making a disclosure.