Guide
Subject Access Request Time Limit UK
Plain-English guide to the SAR one calendar month deadline under UK GDPR, including when the clock starts, what can extend it, and how to calculate the exact due date.
Quick answer
Under Article 12(3) of the UK GDPR, a data controller must respond to a subject access request (SAR) without undue delay and in any event within one calendar month of receiving the request. A calendar month means the matching date in the following month - for example, a SAR received on 15 June must be answered by 15 July. The deadline can be extended by up to two further months for complex or numerous requests, but the controller must inform the requester within the first month.
The legal basis: Article 12(3) UK GDPR
Article 12(3) of the UK GDPR states that the controller must provide the information "without undue delay and in any event within one month of receipt of the request." That one-month period may be extended by two further months where necessary, taking into account the complexity and number of the requests. Crucially, if the controller intends to rely on that extension, it must inform the individual within one month of receipt, together with the reasons for the delay. Article 15 sets out what the individual is actually entitled to: confirmation that their data is being processed, access to that data, and details such as the purposes of processing, the categories of data, recipients, and the retention period.
One calendar month, not 30 days or 4 weeks
The one calendar month time limit is not the same as 30 days or 4 weeks - it means the same day of the following month. Here is how to count it:
| SAR received | Deadline | Notes |
|---|---|---|
| 5 January | 5 February | Standard one calendar month |
| 31 January | 28 February (or 29 in leap year) | February has fewer days; the deadline moves to the last day |
| 15 March | 15 April | Standard |
| 30 June | 30 July | Standard |
| 1 December | 1 January (or next working day if 1 Jan is a bank holiday) | If deadline lands on weekend/bank holiday, it moves to next working day |
Worked example: SAR with ID verification delay
| Event | Date | Clock status |
|---|---|---|
| SAR received | Monday 10 March 2025 | Clock starts |
| ID requested by controller (same day) | Monday 10 March 2025 | Clock pauses |
| ID documents provided by requester | Wednesday 19 March 2025 | Clock resumes (9 days used before pause) |
| Deadline (one calendar month from receipt, less pause) | Thursday 10 April 2025 | 11-19 March clock was paused, so deadline = 10 April |
When the clock starts
The ICO's guidance states that the one calendar month period starts on the day the SAR is received, not the day after. This is different from FOI, where the clock starts the day after receipt. However, the ICO also recognises that the clock should not run while the controller is waiting for the requester to provide reasonable identification or clarification. The clock pauses during that period.
If the deadline falls on a Saturday, Sunday, or UK bank holiday, it moves to the next working day.
Extension for complex or numerous requests
Under Article 12(3) of UK GDPR, a controller may extend the time limit by up to two further calendar months if the request is complex or if the individual has made a number of requests. The controller must:
- Inform the individual within the first calendar month that an extension is needed.
- Explain the reasons for the delay.
- Notify the individual of their right to complain to the ICO.
This means the total time to respond can be up to three calendar months from receipt, but only where the request genuinely qualifies and the extension is notified in time.
What counts as a valid SAR?
For the clock to start, the SAR must be valid. The ICO expects that:
- The request is made in writing (email, letter, social media, or via a web form). A verbal SAR is also valid, though controllers are advised to record it.
- The requester has provided enough information for the controller to identify them and locate their personal data.
- If the controller reasonably needs more information to verify identity or clarify what data is sought, the clock pauses until that information is provided.
A SAR does not have to use the words "subject access request" - any clear request for one's own personal data counts. It does not need a reason, and the controller cannot refuse it just because it covers a lot of material.
Manifestly unfounded or excessive requests
Under Article 12(5) of UK GDPR, a controller can refuse to comply with a SAR if it is manifestly unfounded or excessive, or charge a reasonable fee based on administrative costs in those cases. However, the ICO sets a high bar for this, and the controller must be able to justify the refusal and inform the requester of their right to complain to the ICO. A request is not excessive simply because it covers a lot of data or a long period. The first copy of the information must be provided free of charge in the normal course; fees apply only to further copies or to manifestly unfounded or excessive requests.
What happens if the deadline is missed?
If a controller fails to respond within one calendar month (or within a valid extension), the individual can complain to the ICO. The ICO can investigate and, where appropriate, require the controller to comply. Under Article 82 of the UK GDPR, an individual who suffers material or non-material damage as a result of an infringement also has a right to seek compensation. Responding late - or failing to respond at all - is one of the most common grounds for ICO complaints, so keeping a clear record of the receipt date and any pauses is essential.
Law-enforcement and intelligence processing
The one-month rule in Article 12(3) applies to general processing under the UK GDPR. Separate SAR rights exist under Part 3 (law enforcement) and Part 4 (intelligence services) of the Data Protection Act 2018 - for example, section 45 sets out the right of access for law-enforcement processing, with its own time limits in section 54. If you are requesting data held by the police, a government agency, or the security services for law-enforcement or intelligence purposes, the applicable deadline may differ, so check the relevant provisions.
Step-by-step: calculating a SAR deadline
- Record the date the SAR was received. This is day zero - the clock starts on this date.
- Check whether you need ID or clarification. If yes, request it immediately and pause the clock until you receive it.
- Calculate one calendar month from receipt. If received on the 15th, the deadline is the 15th of the next month. Handle month-end edge cases carefully.
- Adjust for pauses. If the clock was paused for ID or clarification, add the pause duration to the deadline.
- Check whether the deadline falls on a weekend or bank holiday. If yes, move to the next working day.
- If you need an extension, notify the requester within the first month and record the new deadline (up to three calendar months total).
- Use a SAR deadline calculator to verify your calculation.
Key takeaways
- The SAR time limit is one calendar month (not 30 days, not 4 weeks) from receipt of a valid request.
- The clock can be extended by up to two further months if the request is complex or numerous - the requester must be told within the first month.
- The clock pauses while you wait for ID verification or clarification from the requester.
- If the deadline lands on a weekend or bank holiday, it moves to the next working day.
- Manifestly unfounded or excessive requests can be refused or charged for, but the bar is high.
- Always communicate with the requester before the deadline passes.
References
Important: This site is a planning aid, not legal advice. Deadlines can depend on facts, policy wording, jurisdiction, service rules, pauses, extensions and changing law. Always verify important deadlines with the official guidance or a qualified adviser.