DSAR response deadlines: how to meet the UK GDPR one-month clock

23rd September 2026BlogAnjela Ubogu

Are you ready to get in touch?

Request a Call back

DSAR response timescales are normally one calendar month from the day the request is received. Where information is reasonably required to verify the requester’s identity, the month begins when that information is received. The period can be extended by two further months where a request is complex or the individual has made a number of requests, but only if you tell them within the first month and explain why.

Key takeaways

  • In the ICO’s most recently published quarter, January to March 2026, 12,720 of 31,799 completed complaint cases cited Article 15: two in every five.
  • The clock is one calendar month, running from the day the request reaches your organisation, not the day it reaches the right person.
  • A further two months is available for complex or numerous requests, but you must tell the requester within the first month of the applicable response period, with reasons.
  • Clarification and identity verification are not the same mechanism. Reasonably required clarification pauses the existing clock. Where you need to verify identity, the month does not begin at all until you have what you asked for.

A common cause of a missed DSAR deadline is not that the search was hard. It is that nobody recognised the request for what it was until it had already been in the building for a while. With DSAR volumes rising, that gap gets more costly.

Northdoor branded graphic on a dark slate background with a clock motif, carrying the words The clock starts when it arrives

When does the DSAR clock start?

The response period begins on the day the request is received by the organisation, not the day it reaches the data protection team, the legal department or whoever is nominated to handle it.

That is worth stating plainly, because it is a common and avoidable failure. A subject access request does not have to mention the words ‘subject access request’, cite Article 15, use a form, or be in writing. It can be made verbally, to any member of staff, through any channel: a comment on a call to the contact centre, a line in a complaint email, a sentence in the middle of a letter about something else. If nobody recognised it for a fortnight, you have a fortnight left, not a month.

How is the one-month deadline calculated?

The deadline is the corresponding date in the following month. A request received on 4 August is due on 4 September. Where there is no corresponding date, for example a request received on 31 January, the deadline is the last day of the following month. Where it falls on a weekend or a public holiday, it moves to the next working day. The ICO takes a practical view: if you cannot easily calculate it, treating the deadline as one month from receipt and responding by then will keep you compliant.

When can you extend a DSAR deadline?

The period can be extended by a further two months, giving three in total, where the request is complex or the individual has made a number of requests. Two conditions attach, and both are commonly missed.

First, you must inform the requester within the first month of the applicable response period, and explain why. An extension applied silently, or communicated on day thirty-five, is not an extension. It is a late response with a note attached.

Second, complexity has to mean something. A large volume of information may add to the complexity of a request, but it does not automatically make the request complex. Relevant factors may include technical retrieval difficulties, specialist work, complex confidentiality considerations or the need for specialist legal advice. Being short-staffed or working to a manual process does not qualify. Routine reliance on the extension usually signals a process problem.

Can you stop the clock on a DSAR?

Sometimes, but the two situations that get run together work differently, and the difference changes the date in your diary.

Where you need clarification, the Data (Use and Access) Act 2025 codified what had previously been ICO guidance. If a request is genuinely so broad or ambiguous that you cannot sensibly identify what is being asked for, the response period pauses on the day you ask and resumes the day after you receive what you asked for. It pauses; it does not restart. The days already used are still used.

Where you need to verify identity, the clock does not pause, because it has not started. Where you have reasonable doubt about who the requester is, the response period does not begin until you have received the information you need. The practical effect looks similar, but the mechanics differ, and treating one as the other is how organisations miscalculate their own deadline.

Two cautions apply to clarification. It should only be sought where reasonably required, and a controller who asks for clarification it did not need has not validly paused anything. Where you hold only a modest amount of data about the individual, asking them to narrow the request is unlikely to be reasonable. The ICO has been clear that a request for ‘all my data’ is a valid request, not an invitation to negotiate.

“The test isn’t whether clarification would be convenient,” says Anjela Ubogu, Client Manager at Northdoor. “It’s whether you could reasonably respond without it. If you could, the clock is still running, and the fact that you asked a question doesn’t change that.”

How do you meet DSAR response timescales reliably?

Timeliness is an operational problem. What consistently works:

  • Train the front line to recognise a request, not just the data protection team. They do not need to handle it; they need to recognise it and route it the same day.
  • Log receipt centrally and immediately, with the date received. A single register, one owner, one deadline field.
  • Verify identity quickly and proportionately. Identity checking can cause early delay. Decide in advance what evidence is sufficient for each channel, and do not ask for more than you need.
  • Front-load the scoping decision, in line with the reasonable and proportionate search standard now written into UK GDPR.
  • Know your data map before the request arrives. Data discovery and classification done in advance can significantly reduce the time a DSAR takes.
  • Set internal milestones well inside the statutory deadline, and escalate anything not substantially complete by day twenty, so problems surface while there is still time.
  • Decide the complexity question early. If an extension is needed, that should be apparent in week one, while you can still notify within the month.

A related change to have on your radar

The Data (Use and Access) Act also introduced a statutory duty on organisations to handle data protection complaints themselves. It came into force on 19 June 2026. You must give people a clear route to raise a complaint, acknowledge it within 30 days, investigate it appropriately and tell them the outcome.

If your DSAR response templates, and particularly your refusal or partial-refusal templates, still point people straight to the regulator, they are out of date. The internal route sits alongside the right to complain to the ICO rather than replacing it, so templates need to offer both.

What this means for your organisation

One month from receipt, by anyone, through any channel, unless you reasonably need information to verify the requester’s identity. In that situation, the month begins when you receive the information needed. You can extend the period by two further months where the request is complex or the individual has made a number of requests. Reasonably required clarification pauses the existing clock; it does not reset it.

None of that is difficult to state. The organisations that get it right are the ones that recognise requests on day one and start work on day two.

Frequently asked questions

Not normally. Responses are free of charge. A reasonable fee may be charged for further copies, or where a request is manifestly unfounded or excessive, in which case you may alternatively refuse. Both are narrow exceptions, and the ICO expects a documented justification instead of a general policy.

Respond as quickly as possible and tell the requester where things stand. A late response is still a response, and the ICO takes account of how an organisation handles a delay once it is identified. Record why it happened, because a pattern of late responses is what turns an individual complaint into a wider question about your process.

1

Our Awards & Accreditations