- 12th Aug 2026
- 1 min read
Subject Access Request Timeframes: UK GDPR Deadlines
- Written by
In Short...
- The deadline runs by calendar month: Article 12(3) and Article 12A count from the exact date of receipt to the same date the following month.
- The clock has two separate pause mechanisms: DUAA 2025 delays the start for identity verification and pauses mid-flight for scope clarification, on top of the two-month extension.
- Extension notice is a hard requirement: You must notify the requester within the first month and explain why, or the extension itself becomes a breach.
- Missing the deadline is the most common route into ICO enforcement: Fines can reach £17.5 million or 4% of global turnover, and individuals can apply to court under DPA 2018 section 167.
So what: get the mechanics right and the deadline holds at any volume. Scaling the search itself is a separate operational problem.
UK GDPR gives organisations one calendar month to respond to a subject access request (SAR), the individual’s right under Article 15 to see the personal data an organisation holds about them. That deadline sounds simple until you factor in the Data (Use and Access) Act 2025 (DUAA), which introduced Article 12A UK GDPR on 5 February 2026 and changed how the clock actually runs. This guide sets out the exact SAR timeframe, when the clock starts and pauses, how the two-month extension works, and what happens if you miss it.
Expert View
|
Matt Davies Chief Product Officer, SureCloud |
What our experts say about SAR deadline mechanics
“Most teams treat the one-month SAR deadline as fixed. We’ve seen organisations lose a genuine three-month extension because nobody logged the exact day they requested ID verification. The stop-the-clock mechanism only protects you when that pause date is written down at the time.” |
How Long You Have to Respond to a SAR
Article 12(3) of UK GDPR requires a response without undue delay and, at the latest, within one calendar month of receipt. That’s the standard SAR timeframe, and it applies whatever the size of your organisation or the number of other requests you’re handling at the same time. A calendar month means exactly that, not 30 days: a request received on 15 March is due by 15 April, and a request received on 31 January is due by the end of February.
How to calculate the deadline
|
Request received |
Deadline |
|
15 March |
15 April |
|
31 January |
28 February (29 in a leap year) |
|
30 November |
30 December |
|
25 November |
27 December, since 25 and 26 December are bank holidays and the deadline moves to the next working day |
If the deadline falls on a weekend or bank holiday, it moves to the end of the next working day. Where the following month is shorter and has no matching date, the deadline falls on the last day of that month. The ICO’s own guidance on subject access confirms this calculation and suggests a 28-day operational buffer for organisations that need a consistent number of days across systems.
When Does the Clock Start, and When Does It Pause?
The one-month period starts on the day you receive the request, not the day it’s acknowledged, assigned or actioned. Any employee who receives a SAR has received it on the organisation’s behalf, whether it arrived by email, post, social media or a documented phone call.
Section 76 of the DUAA, in force since 5 February 2026, introduced Article 12A UK GDPR and changed the starting point itself. The applicable time period now runs from the latest of three dates: receipt of the request, receipt of any identity verification you’ve reasonably requested, or payment of a fee in the limited cases where one applies. If you ask for proof of identity, the clock begins only once you have it.
Article 12A also preserves the separate stop-the-clock mechanism for scope clarification. If a request is too broad to action, you can ask the requester to narrow it down; the period pauses on the day you ask and resumes the day after they respond. Identity verification delays when the clock starts, while clarification pauses a clock that’s already running, and the two work independently of each other.
|
Mechanism |
Trigger |
Effect on deadline |
|
Identity verification (Article 12A) |
You reasonably request proof of identity |
Clock does not start until identity is confirmed |
|
Clarification / stop-the-clock |
Request is genuinely too broad to action |
Clock pauses on the request date, resumes the day after clarification is received |
Both mechanisms require you to act promptly. The ICO expects identity checks and clarification requests to go out as soon as possible after the SAR arrives, and using either as a general delay tactic invites scrutiny. Format and delivery preferences sit outside both mechanisms; only genuine identity or scope questions qualify for a pause.
Can You Extend the Deadline?
Yes, by a further two months, but only in two circumstances: the request is complex, or you’ve received multiple requests from the same person at the same time. The extension runs from the original start date, giving a total of three months. Complexity has to be specific to the request. High volumes, staff absence and the difficulty of searching multiple systems don’t automatically qualify: the ICO expects organisations to show what makes this particular request complex.
The notification requirement is non-negotiable: you must tell the requester within the first calendar month that you’re extending and explain why, specific to their request rather than a generic statement. Sending the notice late is itself a breach of Article 12(3), even if you go on to respond within the extended deadline. No exceptions.
Legal commentary on the DUAA changes confirms the same point in practice: the reforms clarify existing ICO guidance rather than lowering the bar for organisations, and the notification obligation carries the same weight it always did.
What Happens If You Miss the Deadline
A missed SAR deadline is the most common route into ICO enforcement action on the right of access, and the consequences extend well past a single reprimand. The ICO can issue a formal reprimand, an enforcement notice requiring specific remedial steps, or in serious cases a fine of up to £17.5 million or 4% of global annual turnover, whichever is higher. Individuals also have their own route: under section 167 of the Data Protection Act 2018, they can apply to the court for a compliance order requiring you to search, disclose or respond.
Citing high SAR volumes as the reason for a missed deadline carries little weight with the ICO, which expects organisations to run a process capable of meeting the standard timeframe regardless of caseload. That’s the real test the stop-the-clock and extension provisions exist to support: whether your process can hold the deadline as SAR volume grows.
Getting SAR Deadlines Right at Volume
The deadline mechanics above hold regardless of how many SARs land on your desk in a month. What changes at volume is whether you can execute them: tracking multiple extension dates, multiple stop-the-clock pauses and multiple identity verifications in a spreadsheet becomes its own source of missed deadlines. Our guide to managing high-volume DSARs without manual workflows covers where manual tracking breaks down and what a defensible audit trail needs to include; our full guide to subject access requests covers the wider SAR lifecycle, from who can make a request to what exemptions apply.
Gracie AI Agents with Personas and Skills, SureCloud’s virtual GRC team, calculates each SAR deadline automatically, including DUAA 2025’s stop-the-clock pauses and extension windows, and can draft the extension notification itself with the reasons and new date already populated. Every calculation and notification is logged, so the deadline that mattered is the one your audit trail can prove.
See How SureCloud Tracks Every SAR Deadline Automatically
FAQ’s
How long do you have to respond to a subject access request in the UK?
One calendar month from the date you receive the request, under UK GDPR Article 12(3) and Article 12A. The deadline runs from the day of receipt to the corresponding date in the following month, and moves to the next working day if it falls on a weekend or bank holiday. If you’ve reasonably requested identity verification, the one-month period starts only once you receive it.
When does the SAR clock start?
The clock starts on the day your organisation receives the request, regardless of who received it or how long it takes to reach the right team. Since DUAA 2025 introduced Article 12A on 5 February 2026, the applicable start date is the latest of three points: receipt of the request, receipt of any identity verification you’ve requested, or payment of a fee in the rare cases one applies.
Can the SAR deadline be extended?
Yes, by two months, if the request is complex or you’ve received multiple requests from the same person at once. You must notify the requester within the first calendar month, explain the specific reason, and give the new deadline. Missing that notification is itself a breach, even if you respond within the extended period.
What is the stop-the-clock mechanism under DUAA 2025?
It’s a pause built into Article 12A that stops the one-month clock while you wait for the requester to clarify a request that’s genuinely too broad to action. The clock pauses on the day you ask and resumes the day after you get a response. It applies only to scope clarification, and delivery or format preferences sit outside it.
What happens if you respond to a SAR late?
A late response is the most common trigger for ICO enforcement action on the right of access. The regulator can issue reprimands, enforcement notices and fines of up to £17.5 million or 4% of global turnover for serious breaches. Individuals can also apply to court under section 167 of the Data Protection Act 2018 for an order requiring you to comply.
Does a high volume of SARs justify missing the deadline?
High volumes alone are unlikely to satisfy the ICO’s complexity test for an extension. The regulator expects organisations to run a process capable of meeting the standard timeframe at whatever caseload they carry, and reserves the complexity extension for requests that are individually difficult, such as those spanning large volumes of sensitive data across multiple systems.
Platform +
Frameworks +
Products +
Industries +
Resources +
Company +
London Office
1 Sherwood Street, London, W1F 7BL, United Kingdom
US Headquarters
6010 W. Spring Creek Pkwy., Plano, TX 75024, United States of America
© SureCloud 2026. All rights reserved.
