← Insights

Data protection

Handling a subject access request inside the one-month clock

July 2026 · 6 min read

A subject access request rarely arrives looking official. It turns up as a line in an email - "please send me all the data you hold about me" - or a sentence in a complaint, sometimes from a customer, often from a departing employee. There is no form to fill in and no magic words required. And the moment it lands, a statutory clock starts: under the UK GDPR you have one calendar month to respond.

The response itself is usually manageable. The failure, when it comes, is almost never about the work - it is about the deadline slipping past unnoticed while the request sat in someone's inbox. So the discipline that matters is not doing the search faster; it is never losing the clock.

How the one-month deadline actually works

The month runs from the day you receive the request, and it is a calendar month - so a request received on the 3rd is due on the 3rd of the following month, whatever that does to the day count. You can extend it by a further two months where a request is complex or where someone has made a number of requests, but you must tell the person within the first month that you are extending, and why. The extension is a real tool, not a default; leaning on it for an ordinary request will not hold up.

One more wrinkle worth knowing: the clock does not truly start until you have confirmed the requester's identity, where you have reasonable doubt about it. If you need to verify who someone is, ask promptly - the pause is only reasonable while you genuinely cannot be sure, and dragging it out to buy time is exactly the kind of thing a regulator sees through.

The steps, in order

A dependable DSAR process is short and always the same:

None of this is hard in isolation. The risk lives entirely in the gaps between the steps, where a request can go quiet.

Why a log beats a good memory

Most small organisations handle their first DSAR out of the inbox and get away with it. The trouble is the second one that arrives while the first is still open, or the request that lands the week the person handling it is on leave. Memory does not scale, and it does not hand over. A simple log fixes both: one row per request, with the date received, the type, whether identity is verified, and the outcome.

The part worth automating is the deadline. If the log works out the due date from the date received, applies the extension when you flag one, and counts the days remaining, the one number that actually matters is never something a busy person has to calculate under pressure. Better still, let the status decide itself - open, closed, or overdue - so a request that has quietly run past its month raises its hand instead of hiding. A dashboard that keeps the nearest deadline in front of you every time you open the file turns the whole thing from a memory test into a glance.

The mindset that keeps you clean

Treat every request as genuine and time-critical from the first minute, even the ones that look like a negotiating tactic in a dispute. The law does not care about the requester's motive, and the safest habit is to log first and assess afterwards. A request you recorded on arrival and answered a week early is a non-event. A request you found in an old email thread two days after the deadline is a breach of someone's rights - and one you cannot undo.

Get the logging habit and the computed clock in place, and DSARs stop being the thing that keeps you up at night. They become routine, which is exactly what they should be.

A DSAR log that runs the clock for you

Enter the date received and the request type; the log works out the one-month due date, applies the extension when you flag it, counts the days down and decides Open, Closed or Overdue on its own - with a dashboard that keeps the nearest deadline on top. A template, not legal advice.

Get the DSAR Log on Etsy

Never miss a guide

New articles and templates, straight to your inbox. Plus a free tool to start.

By subscribing you consent to receive emails from Axiom. Your address is stored with Kit, our email provider, and never shared. Unsubscribe any time via the link in every email. Privacy policy.