A clock face, representing the one-month deadline for responding to a subject access request

How to Handle a Subject Access Request: The Clock, What to Send, What to Withhold

September 09, 202611 min read

An email lands. Somewhere in the second paragraph it says: please send me all the information you hold about me.

That is a subject access request. It does not need to say SAR. It does not need to mention GDPR. It does not need to come through a form, or be addressed to the right person, or arrive in writing at all. If someone asks for their personal data, the clock has started.

I have handled hundreds of these across more than ten years in data protection. Most of the problems I see are not about the law. They are about a business that found out too late that the clock was running, searched in a panic, and either sent too much or too little. This guide covers what starts the clock, what you have to hand over, what you can hold back, and what happens if you miss the deadline.

What starts the one-month clock

The clock starts on the day you receive the request. Not the day it reaches your data protection lead. Not the day someone reads it. The day it arrives anywhere in your organisation.

A request counts if it comes:

  • by email, letter, web form, text or social media message;

  • verbally, over the phone or in person;

  • to any member of staff, including reception, a sales inbox or a shop floor colleague;

  • buried inside a complaint, a grievance or a dispute about a bill.

You have one calendar month to respond. If a request arrives on 7 September, your deadline is 7 October. If the same date does not exist in the following month, the deadline is the last day of that month. If it lands on a weekend or bank holiday, you have until the next working day.

A clock face, the one-month deadline for a subject access request starts the day it arrives
The clock starts the day the request arrives, wherever in your business it arrives.

When the clock pauses

There are two situations where the clock legitimately stops.

The first is identity. If you have reasonable doubt about who is asking, you can request proof of identity, and the month starts when you receive it. This is not a stalling tactic. If the request comes from a customer's usual email address, from an account they are logged into, or from an employee you sit next to, you already know who they are, and asking for a passport in those cases will not hold up.

The second is clarification. The subject access reforms in the Data (Use and Access) Act 2025 apply to requests received on or after 5 February 2026. They confirm in law that where you genuinely need the person to narrow down what they want, you can ask, and the clock pauses from the day you ask until the day they reply. You have to actually need the clarification. Everything you hold about me, from a customer with a single order, is not ambiguous. The same request from an employee of fifteen years with tens of thousands of emails in the system usually is.

Write down what you asked, when you asked it, and when they answered. The ICO expects to see that record if the person complains.

When you can extend

You can extend by up to two further months if the request is complex, or you have received several from the same person. You must tell them within the first month that you are extending, and why. Volume alone is not complexity. Having to search a lot of emails is work, not complexity. Needing to redact a large amount of other people's information, or handling a request that sits inside live litigation, might be.

What you must provide

A subject access request is a right to a copy of the personal data you hold about the person. It is not a right to every document their name appears in. The distinction matters, and it cuts both ways.

Personal data is any information that relates to an identifiable person. That includes the obvious: name, contact details, account records, HR file. It also includes opinions about them, notes about them, and internal messages discussing them. Dave was difficult on the call again, in a team chat, is Dave's personal data.

Alongside the data itself, you have to tell them:

  • why you are processing it;

  • what categories of data you hold;

  • who you share it with, or the types of organisation you share it with;

  • how long you keep it, or how you decide that;

  • where you got it, if not from them;

  • whether you use it for automated decision making or profiling, and how that works;

  • their rights to correct, delete, restrict or object, and their right to complain to the ICO.

Most of this can come from your privacy notice. Do not just attach the privacy notice and hope. Answer the points for this person, with their data.

Stacked paper files, the kind of records searched during a subject access request
You owe them their personal data, not every document their name appears in.

How hard you have to search

You are required to make reasonable and proportionate efforts to find the data. The Data (Use and Access) Act 2025 put that standard on a statutory footing, so it is the law now, not only ICO guidance and old case law. It means you do not need to search every backup tape and every personal phone. It also means you cannot search the CRM, ignore the shared mailbox, and call it done.

What holds up is a written search plan: which systems you checked, which search terms you used, what date range, and who did it. If the same request came in tomorrow, someone else should be able to follow the plan and get the same result. A repeatable process is far stronger evidence than a one off best effort.

Format and cost

You must provide the data free of charge. If the request came in electronically, respond electronically unless they ask otherwise. Send it securely. A response containing 200 pages of someone's HR file, sent as an unencrypted attachment to the wrong address, is a data breach on top of a SAR.

What you can withhold

This is where most businesses either overshare, or panic and refuse. Neither ends well. There is a defined set of things you can hold back.

Other people's data. If a document contains someone else's personal data, you do not have to disclose that part unless the other person consents, or it is reasonable to disclose without consent. In practice this means redaction. A manager's name on an email they sent in a professional capacity is usually reasonable to leave in. A colleague's home address or medical detail is not.

Legally privileged material. Advice from your solicitor, and documents prepared for litigation, are exempt.

Confidential references. References you gave or received for employment, training or education are exempt.

Management forecasting and negotiations. If disclosing your plans, for example for a redundancy round, or your position in an ongoing negotiation with the person, would prejudice those plans, you can withhold that part. Once the plans are announced or the negotiation ends, the exemption falls away.

Crime, tax and regulatory functions. Data held for the prevention or detection of crime is exempt where disclosure would prejudice that purpose.

Every exemption applies to the specific information, not to the whole request. You cannot refuse a SAR because one email in the bundle is privileged. You remove that email and send the rest.

Manifestly unfounded or excessive

You can refuse a request, or charge a reasonable fee, if it is manifestly unfounded or excessive. Be very careful here. The bar is high, the ICO reads it narrowly, and in practice it is rarely met.

They are being difficult is not manifestly unfounded. They are in a dispute with us is not manifestly unfounded. People are entitled to use a subject access request to gather evidence for a grievance or a claim, and that is the right working as intended.

Manifestly unfounded means the person has no genuine intention of exercising their right, for example they have offered to withdraw the request in exchange for money, or they are sending requests purely to cause disruption and you can evidence it. Excessive usually means a repeat of a request you recently answered, with nothing having changed. If you are not certain it applies, respond to the request.

If you refuse, you must tell them why, within the month, and tell them they can complain to you, complain to the ICO, and go to court.

What happens if you miss the deadline

Miss your one month deadline and the person can complain to the ICO the very next day. For a request that arrived on the first of a 31 day month, that is day 32. The ICO can and does act on individual late SARs, and it publishes the results.

In October 2025 the ICO issued an enforcement notice to South Wales Police. Between April 2023 and March 2024 the force had answered only 29 percent of subject access requests on time. By August 2025 it had 352 overdue, one of them nearly two years old. The ICO ordered the force to clear the backlog and named it publicly in a press release.

Note that this was an enforcement notice, not a fine. The ICO does not need a data breach, or even a fine, to take action. A missed deadline and a public naming is enough, and the reputational hit is the real cost.

Police forces and NHS trusts appear in these notices most often because of volume, but the same tools apply to a thirty person business. The ICO can issue a reprimand, which is published. It can issue an enforcement notice requiring you to comply by a fixed date, as it did here. It can fine, and the maximum under UK GDPR is £17.5 million or 4 percent of global turnover, though penalties at that level are reserved for the most serious breaches and a late SAR on its own would not reach it. And separately from any of that, the person can go to court for an order forcing you to comply, and for compensation.

The quieter cost is the one I see more often. A late or incomplete SAR in the middle of an employment tribunal hands the other side a second complaint and makes your evidence look selective. A late SAR to an angry customer turns a refund dispute into a regulator complaint.

The new complaints duty, and why it matters here

There is a newer obligation that sits right next to this. Since 19 June 2026, under section 164A of the Data Protection Act 2018, inserted by the Data (Use and Access) Act 2025, every controller must have a formal process for handling data protection complaints. There are no exemptions, so it applies to a sole trader and a large employer alike.

You must give people an accessible way to complain, including a form they can complete electronically and at least one other route such as email or post. You must acknowledge a complaint within 30 days, investigate it without undue delay, and tell them the outcome.

One thing to get right, because it is widely misunderstood: this does not mean people have to come to you before the ICO. They can still complain to the regulator at any time. What changed is that you now have to run a proper complaints process of your own. A refused or late subject access request is exactly the kind of thing that lands in it.

Someone working through printed documents with a pen, reviewing a subject access request response
The ICO does not need a data breach to take action. A missed deadline is enough.

A process that works

You do not need software or a legal team. You need six things written down and followed.

  • Recognition. Every member of staff knows that send me my data is a SAR, and knows who to forward it to the same day.

  • A log. Date received, deadline, who is handling it, current status. A spreadsheet is fine.

  • An acknowledgement within two working days, confirming the deadline and asking for identity or clarification if you genuinely need it.

  • A search plan naming the systems, the search terms and the date range. Keep it with the log.

  • A review step where someone checks for other people's data and exemptions before anything is sent. Redact, do not delete.

  • A covering letter that explains what you have provided, what you have withheld and why, and how they can complain.

Run through that once on a real request and the next one takes half the time.

Three things to check this week

  • If a SAR came in through your website contact form today, who would see it, and would they recognise it?

  • Can you list every system that holds customer or employee data, right now, from memory?

  • Has anyone in your business ever been shown a redacted SAR response and told what good looks like?

If any of those gave you pause, the fix is a written process, and it takes an afternoon to set up.

I work with UK businesses as their outsourced DPO, and handling subject access requests is a large part of that. If one has just landed and you are not sure where to start, get in touch. Happy to have a no obligation chat.

Alex Goodman
Alex Goodman|DPO and GDPR expert|LinkedIn logo icon
Alex Goodman has over 10 years of experience in data protection. He has handled compliance for organisations across financial services, SaaS, healthcare, enforcement, charity, and children's data, first inside large regulated businesses and now as an independent adviser. He holds practitioner certifications in Data Protection Impact Assessments and Subject Access Requests, and is an accredited Counter Fraud Investigator.
Back to Blog

Alex Goodman is an experienced GDPR consultant and outsourced Data Protection Officer working with UK businesses to improve their DPO and GDPR compliance.

© 2026 - GDPR Consultant - All Rights Reserved.

Driven by expertise and personalised service, we’re here to guide you towards GDPR compliance every step of the way.

© 2026 - GDPR Consultant - All Rights Reserved.