Subject Access Request Time Limit UK: The Complete Guide
One calendar month sounds simple until you're the one counting it. Here's exactly how the clock works, when it starts, and where businesses trip up.
The headline rule: one calendar month
Under UK GDPR, a business must respond to a Subject Access Request without undue delay, and in any event within one calendar month. A calendar month means the equivalent date the following month — a request received on 3 June is due by 3 July, not “30 days later.” If the following month is shorter and has no equivalent date, the deadline is the last day of that month.
When does the clock actually start?
From the day the request is received — not the day it's read, forwarded, or recognised as a SAR. If you reasonably need to confirm the requester's identity first, the clock starts from the day you receive that confirmation instead. But you can't use identity checks as a delaying tactic — you should only ask for the minimum needed to confirm who someone is.
Weekends and bank holidays
If the calculated deadline lands on a Saturday, Sunday, or an England & Wales bank holiday, it rolls forward to the next working day. This is one of the most common sources of off-by-one errors when businesses calculate deadlines by hand — our free SAR deadline calculator applies this automatically.
Extending the deadline
For complex or numerous requests, you can extend the response window by up to two further months — three months in total. Two conditions apply:
- You must tell the requester you're extending, and explain why.
- You must do this within the original one-month window — you can't retroactively extend a deadline that's already passed.
“Complex” genuinely means complex — a large volume of data, technical difficulty separating one person's data from another's, or special category data requiring careful review. It's not a general-purpose excuse for being busy.
What if you miss the deadline?
The requester can complain directly to the Information Commissioner's Office. SAR-related complaints are consistently the single most common category of complaint the ICO receives, and in serious or repeated cases, the ICO can fine a business up to £17.5 million or 4% of annual global turnover, whichever is higher. In practice, most cases don't escalate that far — but a missed deadline still creates real regulatory and reputational exposure, and it's entirely avoidable with a proper tracking process.
The easiest way to stay on top of it
Most missed deadlines aren't caused by bad faith — they're caused by nobody having a system to catch the date. Use the free SAR deadline calculator for a one-off request, or create a free DataDeadline account to have every request tracked automatically the moment it comes in.
For guidance only — this isn't legal advice, and you should verify anything deadline-critical against current ICO guidance.