ICO Data Protection Register

How long do we have to answer a subject access request in 2026?

One month, as before. What changed on 5 February 2026 is that the month now runs from 'the relevant time', and new UK GDPR Article 12A lets you formally pause it while you wait for clarification. That pause works for subject access requests only — not for erasure, rectification or any other right.

Last updated 31 July 2026. This page explains the law as it stands on that date. It is general information, not legal advice.

The bottom line

The deadline is still one month. New Article 12A UK GDPR, inserted by section 76(3) of the Data (Use and Access) Act 2025 and in force from 5 February 2026, changes when that month starts and lets you stop the clock while you wait for clarification. Article 12A(5) applies only to requests under Article 15 (subject access). It does not pause an erasure or objection request.

The deadline is still one month — but it starts at 'the relevant time'

Article 12(3) UK GDPR no longer says "within one month of receipt of the request". Section 76(2) of the DUAA substituted the words "before the end of the applicable time period (see Article 12A)". Article 12A(1) then defines that period as one month beginning with the relevant time.

Article 12A(2) says the relevant time is the latest of three things. Where the last two do not apply, it is simply the day the request arrives.

What starts the clock When the month begins
The request itself The day you receive it — including weekends and bank holidays
Identity information you asked for under Article 12(6) The day you receive that information
A fee you charged under Article 12(5) The day the fee is paid

Section 76(2)(c) also amended Article 12(6) so that a controller with reasonable doubts about identity may now expressly "delay dealing with the request until the identity is confirmed". Remember that for a standard subject access request there is no fee. A fee is only possible where a request is manifestly unfounded or excessive, or where someone asks for further copies.

On counting the month, ICO guidance says to start from the actual date you receive the request and count forward to the same date in the following month. If that date does not exist, use the last day of the shorter month. If the deadline falls on a weekend or public holiday, it moves to the end of the next working day. The ICO notes that organisations needing a fixed figure for their systems could adopt 28 days.

Stopping the clock is now in the statute, not just in guidance

Article 12A(5) provides that where a controller "reasonably requires further information in order to identify the information or processing activities to which a request under Article 15 relates", it may ask the data subject for that information, and the period from the day you ask to the day you receive it does not count towards the applicable time period.

The ICO puts the same rule in plainer terms: "If you do ask for clarification, the time limit pauses on the day you request clarification and resumes on the day after you receive it. This is referred to as 'stopping the clock'."

Correcting a common misreading

You will see it claimed that the requirement to hold "a large amount of information" has been removed. It has not been removed — it has been demoted. Article 12A(6) keeps it as a statutory example of when a controller may reasonably require further information, not as a precondition. The real test is whether you reasonably require further information to identify what is in scope. The ICO's right of access guidance gives two illustrations: you hold a large amount of information about the person, or the request is unclear.

  1. Step 1 Ask as early as you can The ICO warns that leaving clarification until late in the month can leave you unable to finish the search in time. If the need only becomes clear once searching starts, record why.
  2. Step 2 Ask about scope, and nothing else The clock only stops if you are seeking clarification about the information requested. Asking about the format of the response does not stop it.
  3. Step 3 Ask for ID at the same time The ICO says you should ask for identification and clarification together, rather than waiting until clarification arrives before checking who the requester is.
  4. Step 4 Explain the pause Tell the person the clock stops from the date you ask and resumes the day after they reply, and say if you need a reply by a certain date.
  5. Step 5 Record the dates Keep a note of the date you asked and the date you received the answer, including any phone conversations about scope.
  6. Step 6 Do not force a narrowing You cannot make someone narrow their request. If they repeat it or refuse to give more detail, you must still comply by making reasonable searches.

The ICO's worked example

A request arrives on 14 May, so the response would normally be due by 14 June. You ask for clarification on 15 May and receive it on 18 May; timing resumes on 19 May. The clock was stopped for four days, so the response is due by 18 June. Count any extension in days, not hours — and note that if you ask for clarification and receive it on the same day, the ICO says the clock does not stop at all.

It does not work for erasure or any other right

This is the most important limit in the new rules, and it is easy to miss. Article 12A(5) is drafted by reference to "a request under Article 15". Nothing else.

If someone asks you to erase "everything you hold" and you cannot tell what they mean, you can of course ask them. But the one-month period keeps running from the relevant time while you wait. Build that into your workflow, because a mixed request — a SAR plus an erasure request in the same email — can end up with two different deadlines.

Article 15(1A) UK GDPR, inserted by DUAA section 78, says the data subject "is only entitled to such confirmation, personal data and other information as the controller is able to provide based on a reasonable and proportionate search". This one was not part of the February 2026 tranche: it took effect at Royal Assent on 19 June 2025, and section 78(5) treats the amendments as having come into force on 1 January 2024.

The ICO says you must make reasonable efforts to find and retrieve the information, but are not required to conduct searches that would be unreasonable or disproportionate to the importance of providing access. It lists four factors to weigh:

  1. The circumstances of the request.
  2. The volume of information you may need to search.
  3. Any difficulties involved in finding the information.
  4. The fundamental nature of the right of access.

The burden sits with you: the ICO says you must be able to show why a search is unreasonable or disproportionate, and that even where one search would be disproportionate you should still search for other in-scope information. There is no technology exemption — archived and backed-up records are in scope, and you should use the same effort you would use to retrieve them for your own purposes. For genuinely deleted electronic records, the ICO says it will not seek enforcement against an organisation that has not used extreme measures to recreate them.

The two-month extension has not changed

Article 12A(3) lets you extend the applicable time period by two further months where that is necessary by reason of the complexity of the requests, or the number of requests, made by the data subject. Article 12A(4) requires the notice to be given before the end of one month beginning with the relevant time, and to state the reasons for the delay. Under Article 12A(5)(b)(ii), any clock-stop period does not count towards that notice deadline either.

Unlike the pause, the extension is available across the Chapter III rights, not just subject access. Points the ICO makes about using it:

Tactical SARs, and what you now have to say about complaints

Motive is irrelevant, and nothing in the DUAA changed that. The ICO's Q&As for employers are explicit: "You cannot simply refuse to comply because the worker is undergoing a grievance or tribunal process, and you believe they intend to use their personal information to obtain information for potential litigation." If you want to withhold something, you must identify the exemption and justify it. Disclosure already given in tribunal proceedings does not discharge the SAR. The separate power to refuse a manifestly unfounded or excessive request under Article 12(5) still exists and is unchanged.

What is new is the complaints wording. DUAA section 103 and Schedule 10 came into force on 19 June 2026. Schedule 10 paragraph 5 inserted a new point (ea) into Article 15(1): the right to make a complaint to the controller under section 164A of the Data Protection Act 2018. That sits alongside point (f), the right to make a complaint to the Commissioner under section 165. The ICO's guidance says you must tell people they can complain to you as well as to the ICO both at the point you collect personal information and "when you respond to a subject access request". Section 164A also requires you to acknowledge a complaint within the period of 30 days beginning when it is received.

Late responses do draw regulatory attention. On 20 February 2026 the ICO reprimanded the City of London Police for failing to respond to subject access requests within the statutory timeframe between April 2023 and July 2025, contrary to Article 12(3) UK GDPR and section 45(3) of the Data Protection Act 2018.

Which rules apply to which request

Regulation 4 of SI 2026/82 saves the old position for requests already in hand on commencement day.

Situation Which rules apply
Request received before 5 February 2026 The old Article 12(3) timing rules. The section 76 amendments do not apply at all (SI 2026/82 reg. 4)
Request received on or after 5 February 2026 Article 12A: one month from the relevant time, two-month extension, stop-the-clock for Article 15 only
Any subject access request, whenever received The reasonable and proportionate search limit in Article 15(1A), treated as in force from 1 January 2024
SAR response sent on or after 19 June 2026 Must include the right to complain to the controller (Article 15(1)(ea)) as well as to the ICO

Equivalent time-limit changes were made for law enforcement and intelligence services processing under Parts 3 and 4 of the Data Protection Act 2018, and the same 5 February 2026 saving applies to those requests.

This page is general information about what the law says, not legal advice about a particular request. The ICO is the regulator here; this site is not.

Common questions

Is the subject access deadline still one month in 2026?

Yes. Article 12A(1) UK GDPR sets the applicable time period at one month beginning with the relevant time. What changed on 5 February 2026 is when that month starts and the fact that you can now formally pause it for subject access requests. The two-month extension for complex or numerous requests also survives, in Article 12A(3).

Can we stop the clock just because a SAR is vague?

Only if you reasonably require further information to identify the information or processing activities the request relates to. Article 12A(6) gives holding a large amount of information about the person as an example of when that is reasonable, and ICO guidance adds that the request being unclear can also be enough. The ICO says you should not ask for clarification on a blanket basis, and that if the person repeats the request or refuses to give more detail you must still comply by making reasonable searches. Note too that if you ask for clarification and receive it the same day, the ICO says the clock does not stop.

Can we stop the clock on a right to erasure request?

No. Article 12A(5) is drafted by reference to a request under Article 15 only. There is no equivalent pause for erasure, rectification, restriction, portability or objection requests. You can still ask questions, but the one-month period keeps running.

An employee has made a SAR days before their tribunal hearing. Can we refuse it?

Not on that basis. The ICO's Q&As for employers say you cannot simply refuse because the worker is going through a grievance or tribunal process and you believe they want material for litigation. If you withhold anything you must show which exemption applies and why. A separate route exists under Article 12(5) for requests that are manifestly unfounded or excessive, but that is a high bar and must be justified case by case.

Do we have to search backups and archived email?

Generally yes, subject to Article 15(1A). The ICO says there is no technology exemption from the right of access and you should use the same effort to retrieve archived or backed-up information as you would for your own purposes. For information you have genuinely deleted from live systems, the ICO says it will not seek enforcement against an organisation that has not gone to extreme technical lengths to recreate it.

What do we now have to tell people about complaints when we respond?

Since 19 June 2026, Article 15(1)(ea) UK GDPR gives the right to make a complaint to the controller under section 164A of the Data Protection Act 2018, alongside the right to complain to the Commissioner under section 165 in point (f). ICO guidance says you must tell people they can complain to you as well as to the ICO when you respond to a subject access request. If someone does complain to you, section 164A requires you to acknowledge it within 30 days beginning when it is received.

Sources

This page summarises the following primary sources. Where they disagree with this summary, they take precedence.

Related guidance