How long do we have to answer a GDPR subject access request, and can we extend it?
Question as asked: How long does a controller have to respond to a GDPR data subject access request, and can that be extended?
A controller has one month from receipt of a data subject access request to respond (Art. 12(3), GDPR). This applies whether it's an EU controller or a UK controller for requests received before 5 February 2026; UK requests are addressed separately below.
Extension: Yes. Art. 12(3) allows the one-month period to be extended by a further two months where necessary, taking into account the complexity and number of requests. The controller must inform the data subject of the extension within the original one-month period, together with the reasons for the delay.
If the controller does nothing (no response, no reasons): Art. 12(3) also requires that where the controller does not act on the request, it must inform the data subject without delay, and at the latest within one month, of the reasons for not acting and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
Fees/refusal in exceptional cases: If the request is manifestly unfounded or excessive (e.g., repetitive), Art. 12(5) lets the controller instead charge a reasonable fee or refuse to act, but the controller bears the burden of demonstrating this.
UK deciding fact: If this is a request under the UK GDPR, the position changes from 5 February 2026 onward, since the Data (Use and Access) Act 2025 introduced a new Art. 12A governing request time limits, which sits alongside the older one-month/two-month structure but includes provisions on stopping the clock while the controller seeks clarification of a request. If your request falls under the UK regime, ask again specifying the request date and whether clarification was sought, so the applicable clock-stopping rule under Art. 12A can be identified precisely.
Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.
More answers
- Can we use SAQ A with a payment processor's iframe, and do we still need ASV scans? (PCI DSS v4.0.1)
- How many Annex A controls are in ISO 27001:2022, and how are they grouped? (ISO/IEC 27001:2022)
- When do the EU AI Act's high-risk obligations apply to Annex III and Annex I systems? (EU AI Act)
- Does India's DPDP Act apply to a US SaaS company with no Indian entity, and to paper records? (India DPDPA)