How Long Do You Have to Respond to a DSAR — and Can You Pause the Clock?

by

in ,

You have one calendar month to respond to a data subject access request, but since 5 February 2026 that month is measured from the “relevant time” — the latest of when you received the request, when you received any identification you reasonably asked for, or when you received any permitted fee — and you can pause the clock while you wait for information you reasonably need to identify what has been requested. This applies to every UK controller answering a request under Article 15 of the UK GDPR. The change comes from new Article 12A, inserted by the Data (Use and Access) Act 2025.

When does the one-month clock actually start?

Under Article 12A, the month runs from the “relevant time,” which is the latest of three points: the day you received the request, the day you received any identity confirmation you were entitled to ask for under Article 12(6), or the day you received any fee you may lawfully charge. For a straightforward request from a known individual, that is simply the day it arrived — and note that it arrives when any part of your organisation receives it, not when it reaches the right desk. The ICO’s right of access guidance, updated for the new framework, sets out how to calculate the deadline in practice.

What is the “stop the clock” rule, and when can you use it?

Where you reasonably need further information to identify the scope of what is being requested — for example, a request for “all my data” against a large volume of records — you can ask the requester to clarify, and the time limit pauses until they respond. This “stop the clock” mechanism now sits on a statutory footing in Article 12A(5); previously it existed only as ICO guidance. The key word is reasonably: the clarification must be genuinely necessary to respond, not a device to buy time. Record why it was needed, because you may have to justify it.

When can you extend the deadline by two months?

Where a request is complex, or where you have received a number of requests from the same person, you may extend the response period by up to two further months, giving a maximum of three. You must tell the requester about the extension, with your reasons, before the first month expires. Volume alone does not automatically make a request complex, but a genuinely large or intricate request can justify the extension — provided you can explain why.

What happens if you miss the deadline?

A late response is a breach of the right of access, and since 19 June 2026 the requester’s first step is a complaint to you as the controller under the new complaints procedure in section 164A of the Data Protection Act 2018, which you must acknowledge within 30 days. Only if they remain dissatisfied does the matter go to the ICO. The practical lesson is that timing is the easiest part of a DSAR to get demonstrably right — and the hardest to explain away if your records do not show when the clock started and why it paused. Timeliness is only one measure of a good response, as we discuss in why speed is the wrong primary metric for disclosure.

Frequently asked questions

When does the DSAR clock start under the rules in force from February 2026?

From the “relevant time” under Article 12A UK GDPR: the latest of the date you received the request, the date you received any identity confirmation you reasonably requested, or the date you received any permitted fee. For a straightforward request from a known person, that is the day it arrived.

Can you stop the clock just because a DSAR is large?

Not by volume alone. You can pause the clock under Article 12A(5) only where you reasonably need clarification to identify the scope of what is requested. A large volume of data may make clarification reasonable, but you must be able to show the clarification was genuinely needed to respond, not used to gain time.

Does responding late mean an automatic fine?

No. A late response is a breach, but since 19 June 2026 the requester complains first to the controller under section 164A of the Data Protection Act 2018, which must be acknowledged within 30 days. The ICO becomes involved only if the requester remains dissatisfied, and enforcement is discretionary rather than automatic.