How long do we have to answer a subject access request in 2026?
One month, as before. What changed on 5 February 2026 is that the month now runs from 'the relevant time', and new UK GDPR Article 12A lets you formally pause it while you wait for clarification. That pause works for subject access requests only — not for erasure, rectification or any other right.
Last updated 31 July 2026. This page explains the law as it stands on that date. It is general information, not legal advice.
The bottom line
The deadline is still one month. New Article 12A UK GDPR, inserted by section 76(3) of the Data (Use and Access) Act 2025 and in force from 5 February 2026, changes when that month starts and lets you stop the clock while you wait for clarification. Article 12A(5) applies only to requests under Article 15 (subject access). It does not pause an erasure or objection request.
The deadline is still one month — but it starts at 'the relevant time'
Article 12(3) UK GDPR no longer says "within one month of receipt of the request". Section 76(2) of the DUAA substituted the words "before the end of the applicable time period (see Article 12A)". Article 12A(1) then defines that period as one month beginning with the relevant time.
Article 12A(2) says the relevant time is the latest of three things. Where the last two do not apply, it is simply the day the request arrives.
| What starts the clock | When the month begins |
|---|---|
| The request itself | The day you receive it — including weekends and bank holidays |
| Identity information you asked for under Article 12(6) | The day you receive that information |
| A fee you charged under Article 12(5) | The day the fee is paid |
Section 76(2)(c) also amended Article 12(6) so that a controller with reasonable doubts about identity may now expressly "delay dealing with the request until the identity is confirmed". Remember that for a standard subject access request there is no fee. A fee is only possible where a request is manifestly unfounded or excessive, or where someone asks for further copies.
On counting the month, ICO guidance says to start from the actual date you receive the request and count forward to the same date in the following month. If that date does not exist, use the last day of the shorter month. If the deadline falls on a weekend or public holiday, it moves to the end of the next working day. The ICO notes that organisations needing a fixed figure for their systems could adopt 28 days.
Stopping the clock is now in the statute, not just in guidance
Article 12A(5) provides that where a controller "reasonably requires further information in order to identify the information or processing activities to which a request under Article 15 relates", it may ask the data subject for that information, and the period from the day you ask to the day you receive it does not count towards the applicable time period.
The ICO puts the same rule in plainer terms: "If you do ask for clarification, the time limit pauses on the day you request clarification and resumes on the day after you receive it. This is referred to as 'stopping the clock'."
Correcting a common misreading
You will see it claimed that the requirement to hold "a large amount of information" has been removed. It has not been removed — it has been demoted. Article 12A(6) keeps it as a statutory example of when a controller may reasonably require further information, not as a precondition. The real test is whether you reasonably require further information to identify what is in scope. The ICO's right of access guidance gives two illustrations: you hold a large amount of information about the person, or the request is unclear.
- Step 1 Ask as early as you can The ICO warns that leaving clarification until late in the month can leave you unable to finish the search in time. If the need only becomes clear once searching starts, record why.
- Step 2 Ask about scope, and nothing else The clock only stops if you are seeking clarification about the information requested. Asking about the format of the response does not stop it.
- Step 3 Ask for ID at the same time The ICO says you should ask for identification and clarification together, rather than waiting until clarification arrives before checking who the requester is.
- Step 4 Explain the pause Tell the person the clock stops from the date you ask and resumes the day after they reply, and say if you need a reply by a certain date.
- Step 5 Record the dates Keep a note of the date you asked and the date you received the answer, including any phone conversations about scope.
- Step 6 Do not force a narrowing You cannot make someone narrow their request. If they repeat it or refuse to give more detail, you must still comply by making reasonable searches.
The ICO's worked example
A request arrives on 14 May, so the response would normally be due by 14 June. You ask for clarification on 15 May and receive it on 18 May; timing resumes on 19 May. The clock was stopped for four days, so the response is due by 18 June. Count any extension in days, not hours — and note that if you ask for clarification and receive it on the same day, the ICO says the clock does not stop at all.
It does not work for erasure or any other right
This is the most important limit in the new rules, and it is easy to miss. Article 12A(5) is drafted by reference to "a request under Article 15". Nothing else.
- Article 15 — subject access. The clock can be stopped.
- Article 16 — rectification. No pause.
- Article 17 — erasure. No pause.
- Article 18 — restriction of processing. No pause.
- Article 20 — data portability. No pause.
- Article 21 — objection to processing. No pause.
If someone asks you to erase "everything you hold" and you cannot tell what they mean, you can of course ask them. But the one-month period keeps running from the relevant time while you wait. Build that into your workflow, because a mixed request — a SAR plus an erasure request in the same email — can end up with two different deadlines.
How far you actually have to search
Article 15(1A) UK GDPR, inserted by DUAA section 78, says the data subject "is only entitled to such confirmation, personal data and other information as the controller is able to provide based on a reasonable and proportionate search". This one was not part of the February 2026 tranche: it took effect at Royal Assent on 19 June 2025, and section 78(5) treats the amendments as having come into force on 1 January 2024.
The ICO says you must make reasonable efforts to find and retrieve the information, but are not required to conduct searches that would be unreasonable or disproportionate to the importance of providing access. It lists four factors to weigh:
- The circumstances of the request.
- The volume of information you may need to search.
- Any difficulties involved in finding the information.
- The fundamental nature of the right of access.
The burden sits with you: the ICO says you must be able to show why a search is unreasonable or disproportionate, and that even where one search would be disproportionate you should still search for other in-scope information. There is no technology exemption — archived and backed-up records are in scope, and you should use the same effort you would use to retrieve them for your own purposes. For genuinely deleted electronic records, the ICO says it will not seek enforcement against an organisation that has not used extreme measures to recreate them.
The two-month extension has not changed
Article 12A(3) lets you extend the applicable time period by two further months where that is necessary by reason of the complexity of the requests, or the number of requests, made by the data subject. Article 12A(4) requires the notice to be given before the end of one month beginning with the relevant time, and to state the reasons for the delay. Under Article 12A(5)(b)(ii), any clock-stop period does not count towards that notice deadline either.
Unlike the pause, the extension is available across the Chapter III rights, not just subject access. Points the ICO makes about using it:
- Calculate it as three months from the original start date, not two months from the end of the first month.
- A request is not automatically complex just because it involves a large amount of information.
- A request is not complex just because you rely on a processor to supply information.
- A request is not complex just because you need to seek clarification.
Tactical SARs, and what you now have to say about complaints
Motive is irrelevant, and nothing in the DUAA changed that. The ICO's Q&As for employers are explicit: "You cannot simply refuse to comply because the worker is undergoing a grievance or tribunal process, and you believe they intend to use their personal information to obtain information for potential litigation." If you want to withhold something, you must identify the exemption and justify it. Disclosure already given in tribunal proceedings does not discharge the SAR. The separate power to refuse a manifestly unfounded or excessive request under Article 12(5) still exists and is unchanged.
What is new is the complaints wording. DUAA section 103 and Schedule 10 came into force on 19 June 2026. Schedule 10 paragraph 5 inserted a new point (ea) into Article 15(1): the right to make a complaint to the controller under section 164A of the Data Protection Act 2018. That sits alongside point (f), the right to make a complaint to the Commissioner under section 165. The ICO's guidance says you must tell people they can complain to you as well as to the ICO both at the point you collect personal information and "when you respond to a subject access request". Section 164A also requires you to acknowledge a complaint within the period of 30 days beginning when it is received.
Late responses do draw regulatory attention. On 20 February 2026 the ICO reprimanded the City of London Police for failing to respond to subject access requests within the statutory timeframe between April 2023 and July 2025, contrary to Article 12(3) UK GDPR and section 45(3) of the Data Protection Act 2018.
Which rules apply to which request
Regulation 4 of SI 2026/82 saves the old position for requests already in hand on commencement day.
| Situation | Which rules apply |
|---|---|
| Request received before 5 February 2026 | The old Article 12(3) timing rules. The section 76 amendments do not apply at all (SI 2026/82 reg. 4) |
| Request received on or after 5 February 2026 | Article 12A: one month from the relevant time, two-month extension, stop-the-clock for Article 15 only |
| Any subject access request, whenever received | The reasonable and proportionate search limit in Article 15(1A), treated as in force from 1 January 2024 |
| SAR response sent on or after 19 June 2026 | Must include the right to complain to the controller (Article 15(1)(ea)) as well as to the ICO |
Equivalent time-limit changes were made for law enforcement and intelligence services processing under Parts 3 and 4 of the Data Protection Act 2018, and the same 5 February 2026 saving applies to those requests.
This page is general information about what the law says, not legal advice about a particular request. The ICO is the regulator here; this site is not.
Common questions
Is the subject access deadline still one month in 2026?
Yes. Article 12A(1) UK GDPR sets the applicable time period at one month beginning with the relevant time. What changed on 5 February 2026 is when that month starts and the fact that you can now formally pause it for subject access requests. The two-month extension for complex or numerous requests also survives, in Article 12A(3).
Can we stop the clock just because a SAR is vague?
Only if you reasonably require further information to identify the information or processing activities the request relates to. Article 12A(6) gives holding a large amount of information about the person as an example of when that is reasonable, and ICO guidance adds that the request being unclear can also be enough. The ICO says you should not ask for clarification on a blanket basis, and that if the person repeats the request or refuses to give more detail you must still comply by making reasonable searches. Note too that if you ask for clarification and receive it the same day, the ICO says the clock does not stop.
Can we stop the clock on a right to erasure request?
No. Article 12A(5) is drafted by reference to a request under Article 15 only. There is no equivalent pause for erasure, rectification, restriction, portability or objection requests. You can still ask questions, but the one-month period keeps running.
An employee has made a SAR days before their tribunal hearing. Can we refuse it?
Not on that basis. The ICO's Q&As for employers say you cannot simply refuse because the worker is going through a grievance or tribunal process and you believe they want material for litigation. If you withhold anything you must show which exemption applies and why. A separate route exists under Article 12(5) for requests that are manifestly unfounded or excessive, but that is a high bar and must be justified case by case.
Do we have to search backups and archived email?
Generally yes, subject to Article 15(1A). The ICO says there is no technology exemption from the right of access and you should use the same effort to retrieve archived or backed-up information as you would for your own purposes. For information you have genuinely deleted from live systems, the ICO says it will not seek enforcement against an organisation that has not gone to extreme technical lengths to recreate it.
What do we now have to tell people about complaints when we respond?
Since 19 June 2026, Article 15(1)(ea) UK GDPR gives the right to make a complaint to the controller under section 164A of the Data Protection Act 2018, alongside the right to complain to the Commissioner under section 165 in point (f). ICO guidance says you must tell people they can complain to you as well as to the ICO when you respond to a subject access request. If someone does complain to you, section 164A requires you to acknowledge it within 30 days beginning when it is received.
Sources
This page summarises the following primary sources. Where they disagree with this summary, they take precedence.
- Data (Use and Access) Act 2025, section 76 — time limits, inserting UK GDPR Article 12A
- Data (Use and Access) Act 2025, section 78 — searches in response to data subjects' requests
- SI 2026/82 — Commencement No. 6 and Transitional and Saving Provisions Regulations 2026 (reg. 2, reg. 3, reg. 4, reg. 7)
- UK GDPR Article 15 — right of access, including new point (ea) and paragraph 1A
- Data (Use and Access) Act 2025, Schedule 10 — complaints: amendments to Articles 12 to 15
- Data (Use and Access) Act 2025, section 103 — inserting sections 164A and 164B of the Data Protection Act 2018
- Data Protection Act 2018, section 164A — complaints to controllers
- ICO — What should we consider when responding to a request? (right of access)
- ICO — How do we find and retrieve the relevant information?
- ICO — Subject access request Q and As for employers
- ICO — Reprimand: City of London Police, 20 February 2026
Related guidance
-
How to ask a company for all the data it holds on you — and what to do if they ignore or redact it
How to make a subject access request under Article 15 UK GDPR, what an organisation may redact, the new stop-the-clock rule, and how to complain in 2026.
-
New rule from 19 June 2026: every UK organisation must have a data protection complaints process
From 19 June 2026 every UK controller must accept data protection complaints, acknowledge them within 30 days and give an outcome. No size exemption.