Data Protection Atlas

Subject access requests — United Kingdom

Tier 1 Override

The UK deltas from the GDPR-family SAR archetype, post-DUAA 2025. Three steps change, one procedural step is added that the archetype does not have, and one criminal backstop applies that a generic SAR guide never mentions.

Applies to

Jurisdiction: United Kingdom

Instruments: DPA 2018

Mechanics

Item Position vs archetype
Deadline One calendar month (unchanged) Unchanged
Stop the clock Yes — codified by the DUAA 2025 while awaiting identity or scope clarification Changed
Search standard Explicit statutory "reasonable and proportionate" standard (DUAA 2025) Changed
Exemptions DPA 2018 Schedules 2, 3 and 4 — not a generic GDPR list Changed
Complaints route Controller's own internal complaints process first, then the ICO Changed

Steps that change

  1. Clarify scope — stop the clock Clarifies the archetype step

    The Data (Use and Access) Act 2025 puts this on a firmer statutory footing than the archetype default: the controller may pause the clock specifically while it is reasonably waiting for the requester to clarify their identity or the scope of a genuinely unclear request. More codified than the general GDPR position, and worth treating as a concrete UK mechanic rather than an informal practice.

  2. Search — "reasonable and proportionate" Clarifies the archetype step

    The DUAA introduces an explicit "reasonable and proportionate" standard for the searches a controller must carry out — a legislative anchor for an argument controllers were already making informally. Confirm the precise wording and any accompanying ICO guidance before relying on it as settled: case law interpreting the new standard will develop after commencement.

  3. Exemptions — Schedules 2, 3 and 4 DPA 2018 Replaces the archetype step

    The applicable exemption schedule is Schedule 2, 3 or 4 of the DPA 2018, not a generic GDPR list, and each exemption carries its own trigger conditions rather than a name alone. The immigration exemption (Sch 2 para 4) is the one most likely to be relevant to a live SAR and carries its own 2022-added safeguards.

    See DPA 2018

  4. Respond — with a criminal backstop Adds to the archetype step

    Response content is unchanged from the archetype, but note what sits behind it in the UK.

    See DPA 2018

    Criminal offence Intentionally altering, destroying or concealing records to defeat a SAR before responding is a specific criminal offence (DPA 2018 s.173), not merely a regulatory breach.

Steps that do not change

Inherited from the archetype exactly as written there.

Step Title Archetype position
1 Log and acknowledge Record the date received — this date drives the deadline. Acknowledge receipt. Do not require a specific form or a stated reason. There is no prescribed form: a request made verbally, by email, via a form, or embedded in a complaint letter all count, and the clock starts on receipt of a valid request, not on receipt of a form.
2 Verify identity Ask for identification only where there is genuine doubt about who is asking, and only for proportionate evidence — not a full KYC pack for a routine request. Over-verification is itself a common complaint upheld by regulators.
7 Timing One calendar month from receipt of a valid request. Extendable by a further two months for complex or numerous requests, provided the extension and its reason are communicated to the requester within the original month.
8 Cost Free by default. A reasonable fee is permitted only for manifestly unfounded or excessive requests, or for additional copies of the same information.
9 Refusal Manifestly unfounded or excessive requests may be refused or charged for. The controller must be able to demonstrate why, and must still tell the requester of their right to complain to the regulator and to a judicial remedy.

Additions not in the archetype

Internal complaints process first

A genuine procedural step the archetype does not have. Since 2024/DUAA-era guidance the expectation is that a complainant raises the issue with the controller's own internal complaints process first, and only escalates to the ICO if it is unresolved. Some GDPR-family jurisdictions allow going straight to the regulator, so this is a UK-specific addition and should not be assumed to generalise.

Three distinct consequences for one failure

Unresolved failures sit against the ICO's enforcement notice and penalty notice powers (s.155 DPA 2018), separate again from the s.173 criminal offence. The same failure to respond properly to a SAR can attract three different consequences depending on what exactly went wrong — under-searching is regulatory, destroying records to dodge it is criminal, and ignoring it outright is potentially both, plus a compensation claim under Art 82 / s.168.

Sources

  • Primary Data Protection Act 2018 (c. 12) legislation.gov.uk
  • Primary Data (Use and Access) Act 2025 legislation.gov.uk no verified URL yet

    URL not yet verified; confirm commencement before relying on the stop-the-clock provision.

Last verified 25 July 2026 by Owen S