Challenging delayed subject access request

Question
How do I challenge an incomplete or seriously delayed subject access response?

The legal position

A subject access request (SAR) is your right under Article 15 of the UK GDPR, supplemented by the Data Protection Act 2018. When you make a SAR, the organisation (the data controller) must respond without undue delay and at the latest within one calendar month, starting from the day it receives your request.

The organisation can extend this by up to a further two months, but only where the request is complex or you have made a number of requests. If it relies on an extension it must tell you within the first month and explain why. It can also legitimately “stop the clock” if it genuinely needs proof of your identity or genuine clarification of an unclear request; in that case the month runs from when it receives what it reasonably needs.

The response must be complete. The controller must provide a copy of your personal data it is processing, together with the supplementary information required by Article 15 (such as the purposes of processing, the recipients or categories of recipient, the retention period, and the source of the data where not collected from you). It can withhold or redact material only where a recognised exemption applies, for example third party personal data that cannot reasonably be disclosed, legal professional privilege, or material covered by the crime and taxation exemptions. A controller that withholds material should generally tell you it has done so and why, unless doing so would itself defeat the exemption.

Two different problems

It helps to separate a delayed response from an incomplete one, because the arguments differ.

Delay means the deadline has passed with no proper response, or an extension has been claimed but is not justified. Here the key question is simply whether the one month (or lawfully extended period) has expired and whether any stop-the-clock argument is genuine.

Incompleteness means you have received something, but you believe data is missing, that redactions or exemptions have been misapplied, or that the required Article 15 supplementary information was not given. Here you need to be able to point to specific material you reasonably expect to exist.

Step one: chase and complain to the organisation first

Both the ICO and good practice expect you to raise the problem with the organisation before escalating.

If it has been over a month with no proper response, send a short, dated follow-up in writing (email is best because it creates a record). State the date of your original request, that the statutory period under the UK GDPR has expired, and ask it to comply in full within a defined short period, for example within 14 days.

If the response arrived but looks incomplete, complain in writing and be specific. Do not simply say “this is incomplete”. List the particular records, systems, mailboxes, date ranges, or categories of data you reasonably expect to exist and have not received, for example emails between named individuals in a stated period, notes of a particular meeting, CCTV, call recordings, or HR file entries. This makes it much harder for the organisation to brush off, and it gives the ICO something concrete to assess later. If exemptions or redactions have been applied, ask it to identify which exemption it relies on for each withholding and to reconsider.

Keep every request, reminder and reply. This correspondence is your evidence trail.

Step two: complain to the Information Commissioner’s Office

If the organisation does not put matters right, you can complain to the ICO. The ICO is under a duty in section 165 of the Data Protection Act 2018 to consider complaints that data protection rights have been infringed, to investigate to the extent it considers appropriate, and to tell you the outcome.

Practical points on the ICO route:

1. Complain only after you have first raised it with the organisation and given it a reasonable chance to respond.

2. There is an important timing expectation: raise your complaint with the ICO within three months of your last meaningful contact with the organisation. Do not let the matter go quiet for too long.

3. Give the ICO the full picture: the request date, the deadline, the chasing correspondence, what you received, and precisely what you say is missing or wrongly withheld.

The ICO does not usually order the organisation to hand over the specific data to you, and it does not award compensation. What it can do is assess whether the organisation has complied, tell the organisation to take steps, and take regulatory action in appropriate cases. In practice an ICO intervention often prompts a reluctant controller to comply.

Step three: court enforcement

You have a separate right to enforce the SAR through the courts under section 167 of the Data Protection Act 2018. A court can order the controller to comply with the request, including ordering it to disclose data it has wrongly withheld. This is a genuine remedy where the data really matters to you and the organisation will not budge.

You may also have a claim for compensation under Article 82 of the UK GDPR and section 168 of the Data Protection Act 2018 for damage, including in appropriate cases distress, caused by a failure to comply. Compensation for a bare late or incomplete SAR is often modest and not guaranteed, so litigating purely for damages is rarely worthwhile on its own.

You do not have to complain to the ICO before going to court, and the two routes are independent, but court action carries cost, delay and litigation risk, so it is usually sensible to try the earlier steps first unless the data is urgently needed.

What could legitimately explain the delay or gaps

Before treating the organisation as in breach, it is worth checking whether there is an innocent explanation, because this affects both your tone and your prospects.

The clock may not have started, or may have been paused, if the organisation reasonably asked you to verify your identity or to clarify a very broad request and you have not yet replied. A lawful two-month extension for a genuinely complex request is not a breach. Data may be “missing” simply because it was never held, or because it has been deleted in line with a genuine retention policy that predates your request; a controller is not required to recreate data it no longer holds, though it should not delete data to avoid a SAR once the request is made. Redactions may reflect a proper exemption, particularly for third party data, rather than concealment. Addressing these points head-on in your complaint strengthens it, because you can explain why the ordinary explanations do not apply on your facts.

Practical next steps

1. Pull together your original SAR, proof of when it was sent, and all subsequent correspondence.

2. Work out the exact deadline: one month from receipt, adjusted only for any genuine identity or clarification delay, plus any properly notified two-month extension.

3. Send one clear, dated written complaint to the organisation. If it is late, demand full compliance within a short fixed period. If it is incomplete, list the specific data you say is missing or wrongly withheld and ask which exemption applies to each redaction.

4. If that fails, complain to the ICO within three months of your last meaningful contact, enclosing your evidence and your specific list of missing items.

5. Consider a court application under section 167 (and any compensation claim) only if the data genuinely matters and earlier steps have not worked, weighing cost, delay and enforceability.

Information that would sharpen the advice

The strongest answer for your situation depends on a few facts: the exact date you made the request and how it was sent; whether the organisation asked for ID or clarification; whether it claimed an extension and when; what you have actually received; and precisely what you believe is missing or has been withheld and why you expect it to exist. If you set those out, the delay-versus-incompleteness analysis and the best route become much clearer.

Current sources checked

This answer draws on broad legal knowledge and checks current law, guidance and procedure against relevant sources.

What to do if you don't get a response or you're unhappy ...ico.org.ukTime limits for responding to data protection rights requests | ICOico.org.ukWhat to expect after making a subject access request | ICOico.org.ukA guide to subject access | ICOico.org.uk
Verify important information before relying on it.
Was this helpful?
471 people found this helpful

Ready to stop guessing?

The above is just an example answer. Sign up now to get personalised guidance and ask follow-up questions based on your own situation. Bring your legal issue, your contract, or your question. Lawyer Destroyer gives you clear, practical guidance so you can move forward with confidence.