Subject Access Request Ignored? (UK)
A subject access request is free and the deadline is short, which is exactly why being ignored is so common — and why it is one of the easier things to escalate, provided you can show when you asked.
The short answer
Under the UK GDPR an organisation must respond to a subject access request without undue delay and within one month of receiving it. That can be extended by up to a further two months where the request is genuinely complex or you have made several — but they must tell you, and explain why, within the first month. A SAR is free; a fee can only be charged where a request is manifestly unfounded or excessive.
Contents
The clock, and what legitimately pauses it
The month runs from receipt of the request. It can be extended by up to two further months, making three in total — but only for genuine complexity, and only if they tell you within the first month and say why. An extension announced in month two is not a valid extension.
The deadline rules
- One month from receipt, as the default
- Up to two further months where the request is complex or you have made several
- They must notify you of any extension, with reasons, within the first month
- It is free — a fee only where the request is manifestly unfounded or excessive
- They may ask for ID, and the clock can pause while they reasonably verify it
Make the request hard to lose
Most SARs that go unanswered were never routed to anyone responsible. You do not have to use a form or say any magic words — but making it unmistakable, and provable, is what protects your position later.
What a clean request looks like
- Say clearly that it is a subject access request under the UK GDPR
- Send it somewhere that timestamps — email, or the organisation's data protection contact
- Say what you want if you only need part of it: a date range, a department, a type of record
- Keep the sent copy — the date you asked is the fact everything else rests on
Going to the ICO
The Information Commissioner's Office is free. It expects you to have raised the matter with the organisation first, and asks that you come to it within three months of your last meaningful contact with them — so a complaint left to drift can time out. The ICO can tell an organisation to comply, and repeated failures can lead to enforcement.
What you are entitled to receive
A copy of your personal data, plus information about why it is held, who it has been shared with, and how long it will be kept. Some material can legitimately be withheld or redacted — third-party personal data in particular — so a partially redacted response is not automatically a breach.
SAR follow-up after silence
Edit this template with your facts, dates, and requested outcome before sending.
Subject: Subject access request — [your name], sent [date] Dear [Organisation], On [date] I made a subject access request under the UK GDPR for the personal data you hold about me. [Reference any acknowledgement or reference number.] The one-month period for responding has now passed and I have not received a response [or: I received an acknowledgement but no data]. I am asking you to provide the information without further delay, and to confirm within 14 days when it will be sent. If I do not receive a substantive response I intend to raise the matter with the Information Commissioner's Office. Kind regards, [Your Name]
Copy this as a starting point and adapt it to your own facts and dates.
Common mistakes to avoid
- Not keeping a dated copy of the request, so the deadline cannot be proved
- Accepting a late extension that was never notified within the first month
- Paying a fee that should not have been charged
- Asking for "everything" when a date range would have got a faster, fuller answer
- Letting the ICO's three-month window pass while waiting for a reply that is not coming
- Treating redactions of other people's data as evidence of bad faith — some are required
Next steps
- 1Find the date you sent the request and any acknowledgement
- 2Check whether an extension was notified within the first month, with reasons
- 3Send one clear follow-up citing the UK GDPR and setting a deadline
- 4Note your last meaningful contact — the ICO window runs from it
- 5If there is still no response, raise it with the ICO
Work out your next step
This guide explains the process and the deadlines. If you want help working out where you stand and what to do next, start with a situation check.
Check your situation →This guide is general information about the process, not legal advice.