Tools
Subject Access Request Deadline Calculator: Reply Date
A subject access request does not come with a countdown on it, and the one-month limit in the UK GDPR is not thirty days. It runs to the corresponding date in the next month, so the same request gives you 31 days in July and as few as 28 in February, before weekends and bank holidays push the date out further. Enter the date it landed and this calculator gives you the exact day your response is due, allowing for weekends and England and Wales bank holidays.
When must you respond?
The day it arrived anywhere in your organisation, including a shared inbox, a shop counter or a social media message. Not the day it reached the right desk.
All six rights run on the same one-month clock under Article 12(3).
Only if you reasonably asked the person to prove who they are, or to say what they actually want. Leave blank if you did not need to ask.
General guidance on the UK GDPR response deadlines, not legal advice. Bank holiday dates are for England and Wales, 2024 to 2028; Scotland and Northern Ireland differ.
How the one-month deadline is actually counted
The clock starts the day the request arrives, and it arrives when it reaches your organisation, not when it reaches the person who deals with these. A request sitting unread in a shared sales inbox for a fortnight has already burned a fortnight. The deadline is then the same date in the next month: received on the 12th, due on the 12th. Where that date does not exist, 31 January plus a month, you get the last day of the month instead. Where it falls on a Saturday, Sunday or bank holiday, you have until the next working day.
That is why the calculator hands back 28 days for one request and 35 for another. The month a request lands in changes how long you really have, and one that arrives in late November picks up extra days off the back of the Christmas bank holidays.
When the clock pauses, and when it does not
- Identity checks. If you genuinely cannot tell who the requester is, ask promptly. The month runs from the point you receive what you asked for, not from the original request.
- Clarification. If you process a large amount of data about someone and you genuinely need to know what they want, you can ask, and the clock pauses until they answer. You cannot use this to stall a request you understand perfectly well.
- A fee. There is no fee for a normal request. You can only charge a reasonable admin fee where a request is manifestly unfounded or excessive, or where someone asks for further copies.
- Being busy. Staff holidays, a system migration, the person who knows the files being off sick: none of these stop the clock. Nor does an ongoing complaint or a dispute with the requester.
The two-month extension is real but narrow. It applies where a request is complex, or where you have received a number of requests from the same individual, and you must tell the person you are extending, and why, within the first month. Miss that message and you are relying on an extension you never claimed. The calculator gives you both dates so you can diary the notification as well as the response.
Why the deadline matters to your insurer
Missed subject access requests are one of the most common things people complain to the ICO about, and a pattern of late responses is the sort of governance failure that turns a small incident into a regulatory one. Insurers and certification assessors look at the same signal: whether you can find personal data quickly when someone asks for it. If a hand search of backups is the only way you can answer a SAR, that is also how long a breach investigation will take. See our GDPR audit guide for the wider review, the 72-hour ICO breach notification calculator for the shorter clock that runs after an incident, and what counts as a data subject if you are unsure whether the request even qualifies.