Compliance Colleague · Answers · GDPR

How long do we have to answer a GDPR subject access request, and can we extend it?

Standard: GDPR · Answered by Compliance Colleague on September 30, 2026

Question as asked: How long does a controller have to respond to a GDPR data subject access request, and can that be extended?

A controller has one month from receipt of a data subject access request to respond (Art. 12(3), GDPR). This applies whether it's an EU controller or a UK controller for requests received before 5 February 2026; UK requests are addressed separately below.

Extension: Yes. Art. 12(3) allows the one-month period to be extended by a further two months where necessary, taking into account the complexity and number of requests. The controller must inform the data subject of the extension within the original one-month period, together with the reasons for the delay.

If the controller does nothing (no response, no reasons): Art. 12(3) also requires that where the controller does not act on the request, it must inform the data subject without delay, and at the latest within one month, of the reasons for not acting and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

Fees/refusal in exceptional cases: If the request is manifestly unfounded or excessive (e.g., repetitive), Art. 12(5) lets the controller instead charge a reasonable fee or refuse to act, but the controller bears the burden of demonstrating this.

UK deciding fact: If this is a request under the UK GDPR, the position changes from 5 February 2026 onward, since the Data (Use and Access) Act 2025 introduced a new Art. 12A governing request time limits, which sits alongside the older one-month/two-month structure but includes provisions on stopping the clock while the controller seeks clarification of a request. If your request falls under the UK regime, ask again specifying the request date and whether clarification was sought, so the applicable clock-stopping rule under Art. 12A can be identified precisely.

Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.

This is one answer from Compliance Colleague, which answers questions like this against 30+ security, privacy and AI governance standards, with the clause cited, and reviews your policies against them. Ask your own question free, no card required →

More answers