The subject access request time limit UK organisations must meet changed on 5 February 2026. The one-month period no longer runs simply from receipt; it runs from the “relevant time” defined in the new Article 12A of the UK GDPR, it can be paused while the controller waits for clarification, and it can be extended by two months where the request is complex or the person has made several. A second change, in force since 19 June 2025, limits what the controller must search for. This guide sets out the timeline as it now works, with a worked example, and the mistakes that put an organisation over time or in breach.
What this guide covers
- The subject access request time limit UK rule, in one paragraph
- The three events that set the relevant time
- The clarification pause in the subject access request time limit UK rule
- The extension
- A worked subject access request time limit UK timeline
- The reasonable and proportionate search
- Where organisations go over the subject access request time limit UK rule
- What happens when the subject access request time limit UK period is missed
- The procedure and the log
- Frequently asked questions on the subject access request time limit UK

The subject access request time limit UK rule, in one paragraph
A controller must respond to a subject access request within the “applicable time period”. Under Article 12A, inserted by section 76 of the Data (Use and Access) Act 2025, that period is one month beginning with the relevant time, or, where the controller has extended it, up to three months.
The relevant time is the latest of three events: the day the request is received; the day the controller receives any additional information it asked for to confirm the requester’s identity under Article 12(6); and the day any fee charged under Article 12(5) is paid. Days during which the controller is waiting for clarification it reasonably requested do not count. The Commissioner’s right of access guidance is the reference for how it expects each element to be applied.
The three events that set the relevant time
For the subject access request time limit UK controllers apply, receipt is the day the request arrives anywhere in the organisation, in any form. A request does not have to use the words “subject access request” or cite the law, and a request sent to a shop email address or a social media account counts from the day it landed there, not the day it reached the privacy team. Staff training that says “forward it the same day” exists to keep those two days the same.
Identity information moves the relevant time only where the controller has reasonable doubts about who is asking and has asked for information to resolve them. Where the request comes from an email address the organisation already corresponds with, there is usually no reasonable doubt and no identity step, and the relevant time stays at receipt. Asking for a passport copy as a routine hurdle does not move the clock; it is a breach of Article 12, which requires the controller to facilitate the exercise of rights.
A fee can be charged only where the request is manifestly unfounded or excessive, or where the person asks for further copies. It is rare, and where it is charged, the relevant time becomes the day it is paid.
The clarification pause in the subject access request time limit UK rule
Article 12A(5) and (6) provide that where the controller reasonably requires further information to identify the information or processing activities the request relates to, and has asked the requester for it, the period between asking and receiving the answer does not count. The Act gives the example of a controller that processes a large amount of information about the person. Three things follow. The pause is a stop, not a restart: the days already used before the question stay used.
It applies only where clarification is reasonably required; a clear request for “all the emails you hold about me” cannot be paused with a question about which emails. And the requester is not obliged to narrow the request; if they answer “all of it”, the pause ends and the search covers everything. Our full data subject access request guide covers the response itself.
The extension
The subject access request time limit UK controllers work to may be extended by up to two further months where necessary, taking into account the complexity of the request or the number of requests made by that data subject. Two conditions attach. The controller must inform the person of the extension, with the reasons, within one month of the relevant time; an extension notice sent on day 35 is too late and the request is already overdue. And the number of requests counted is the number from that individual; a controller swamped by requests from many people cannot extend any of them on that ground. The extension is for complex requests, not for busy controllers.
A worked subject access request time limit UK timeline
| Day | Event | Effect on the period |
|---|---|---|
| 1 March | Request received from an unfamiliar Gmail address asking for “everything” | Received; identity in reasonable doubt |
| 2 March | Controller asks for confirmation of account details | Clock has not started |
| 6 March | Identity confirmed | Relevant time is 6 March; period ends 6 April |
| 9 March | Controller, holding twelve years of records, asks which period or matters the person wants | Clock stops on 9 March with 3 days used |
| 16 March | Person replies: the last three years, and the complaint file | Clock restarts; 7 days not counted; period now ends 13 April |
| 28 March | Controller sends an extension notice: complex, third-party data across many mailboxes | Within the first month; period extended by two months to 13 June |
| 2 June | Response sent with the data, supplementary information and exemptions applied | Within the applicable time period |
A subject access request time limit UK log needs to carry each of those dates separately: received, identity requested and received, clarification requested and received, days paused, relevant time, due date, extension sent, extended due date, responded. A log with a single “received” and “due” column cannot show the Commissioner that the period was calculated correctly.
The reasonable and proportionate search
Article 15(1A), inserted by section 78 of the 2025 Act and in force from Royal Assent on 19 June 2025, provides that the data subject is entitled only to the personal data that the controller is able to provide based on a reasonable and proportionate search. This is not a subject access request time limit UK provision, but it is what makes the time limit achievable. The controller decides and records the scope of the search: which systems, mailboxes, custodians and date ranges, and why anything is excluded.
The test is what is reasonable and proportionate having regard to the importance of the right of access; it is not a licence to search only where it is convenient, and a search that omits the system where the person’s data obviously sits will not meet it. The scope record is part of the response file. Our guide to the Data (Use and Access) Act 2025 sets both changes in context.
Where organisations go over the subject access request time limit UK rule
- Counting from the day the privacy team got it, not the day the organisation did. The receptionist’s inbox counts.
- Treating the identity step as automatic. Where there is no reasonable doubt, the relevant time is receipt, and days spent waiting for a passport are days lost.
- Using clarification to delay a clear request. The pause applies only where clarification is reasonably required.
- Sending the extension notice late, or extending because other people’s requests are piling up.
- Restarting the clock after clarification rather than resuming it.
- Searching nothing that was not convenient, and calling it proportionate. The scope must be recorded and defensible.
- Applying EU rules to UK data. The EU period still runs from receipt with no clarification pause; the UK rules apply to UK data only. See UK GDPR vs EU GDPR.
What happens when the subject access request time limit UK period is missed
A late response is an infringement of Article 12 and, since 19 June 2026, the likely subject of a statutory complaint to the controller under Data Protection Act 2018 section 164A, which itself must be acknowledged within 30 days. The individual may also complain to the Commissioner under section 165 and may seek a court order under section 167. The Commissioner’s published enforcement on DSAR backlogs has included reprimands and enforcement notices, and a pattern of lateness across many requests is exactly the kind of systemic failure that an assessment notice is designed to find. Our guide to the data protection complaints procedure covers the new complaint route.
The procedure and the log
A DSAR procedure written for the UK now needs: a recognition step that starts the clock on receipt anywhere; an identity step that applies only on reasonable doubt; a clarification step with a recorded pause; a search-scope record for every request; an extension decision with a notice deadline; and a log that carries every date. The UK GDPR Toolkit ships that procedure, an identity and clarification procedure, the letters for each step, a Schedule 2 exemptions guide, and a DSAR log with the relevant-time and days-paused columns built in. For the wider set of rights and their shared clock, see our guide to the UK GDPR.
Frequently asked questions on the subject access request time limit UK
Is the subject access request time limit UK rule still one month?
Yes, but it runs from the relevant time rather than from receipt, it can be paused for clarification, and it can be extended by two months for complex or numerous requests. Three months is the maximum.
Is it one month or 30 days?
One month, calculated to the corresponding date in the following month; where there is no corresponding date, the last day of that month. The 30-day figure belongs to the complaints acknowledgement under section 164A, which is a different clock.
Can we stop the clock every time we ask a question?
No. Only where the controller reasonably requires the information to identify what the request relates to, and only for the days between asking and receiving the answer.
Does the reasonable search mean we can leave out old backups?
Usually, where the live systems can answer the request; the record should say so and why. It does not mean leaving out a live system that plainly holds the person’s data.