Guides

A customer asked for their data — you have 30 days (UK DSAR guide)

20 May 2026 5 min read GuardianStack
On this page

Short answer: under UK GDPR, anyone can ask for a copy of all the personal data you hold on them — a subject access request, or DSAR — and you have one calendar month to respond, free of charge. The clock starts the moment they ask, not when you get round to reading the email. But the deadline isn’t the hard part. The clock is easy; the map is hard — because most stores have never mapped where a single customer’s data actually lives.

What is a subject access request?

A DSAR is a person exercising their right of access under UK GDPR. They can ask you to confirm whether you hold data about them, to give them a copy of it, and to explain how and why you use it. It doesn’t have to be formal — an email, a message, even a verbal request can count. There’s no special wording; “send me everything you have on me” is a valid DSAR.

The 30-day clock — and when it can pause or extend

You must respond without undue delay and within one calendar month of receiving the request. The month runs from the day you receive it, and it’s normally free. Two things can change the timing: you may ask for reasonable information to confirm the requester’s identity before you start (which pauses the clock until they reply), and you can extend by up to a further two months where a request is genuinely complex or someone has made several — as long as you tell them, and why, within the first month.

Framework · The one-month clock

From request to response — one calendar month

Verification can pause the clock; a genuinely complex request, or several at once, can extend it — but only if you tell them why inside the first month.

Request landsclock starts Verify identitypauses clock Gather the dataacross the stack Respondcopy + context + up to 2 months complex / numerous only 1 calendar month · free of charge · starts once you can identify the requester
Source: ICO — Right of access · UK GDPR Art. 12(3)

Verification is a legitimate step, not a stalling tactic. Ask only for what you reasonably need to be sure who you’re dealing with — don’t demand a passport for a request about an email address you can already tie to their account. And what you owe is a reasonable and proportionate search, not proof you’ve turned over every last byte — a point the ICO reinforced under the Data Use and Access Act 2025.

Why the deadline is not the hard part

A month sounds generous until you try to collect everything. “Their personal data” is broader than a store owner expects: it isn’t just the order record. The same person’s data sits in your email marketing platform, your helpdesk and chat logs, your reviews app, your analytics, your CRM, and your inbox. If it identifies them and you hold it, it’s usually in scope.

Concept · The map is the hard part

A single customer’s data is scattered across your app stack

A DSAR asks for all of it. The deadline is easy; finding every copy — without a map — is the scramble.

Orders Email tool Helpdesk Reviews Analytics CRM / inbox Onecustomer
Source: GuardianStack methodology · illustrative UK store app stack

That’s the real difficulty — customer data is scattered across your app stack, and most stores have never mapped where it all sits. It’s the same operational gap behind most compliance stress: the business grew, the tools multiplied, and nobody kept a map. This is exactly the drift a privacy notice quietly develops against your live app stack, and the apps in scope are usually the same ones that need a data processing agreement.

What a lawful response actually includes

Getting the data together is most of the job, but a response has to carry more than a data dump. At its core it confirms you’re processing their data, provides a copy, and explains the supporting picture — purposes, recipients, retention, their rights, and where relevant the data’s source, any automated decision-making, and transfer safeguards. And it respects the limits, because a DSAR is a right of access, not an unconditional right to every document with their name on it.

Diagnostic · A lawful response

What to include — beyond just the data

A copy of the data plus the supporting picture. Don’t disclose other people’s data caught in the same records unless it’s reasonable to; withhold only what an exemption covers.

1
Confirmation

State clearly that you are processing their personal data.

2
A copy

Provide the personal data itself, in an accessible format.

3
The why

Explain your purposes, and the categories of data involved.

4
Who sees it

Name the recipients or categories you share the data with.

5
How long

Give the retention period, or how you decide it.

6
Their rights

Note their rights to rectify, erase, object, and complain to the ICO.

Source: ICO — Right of access · UK GDPR Arts 15 & 12

Honest note: DSARs have real grey areas — exemptions, redacting other people’s data caught up in the same records, and what counts as “manifestly unfounded or excessive”. This guide gets you a lawful, calm response for the common case; a genuinely contested or high-volume request is worth checking against the ICO’s own guidance or with a specialist. It’s guidance, not legal advice.

The mistakes that turn a routine request into a problem

Most DSAR trouble isn’t the deadline — it’s how the request gets handled once it lands.

Analysis · How routine requests go wrong

Four mistakes that turn a DSAR into a problem

None of these is about the deadline — they’re about the process once the request lands.

MistakeWhat it looks likeWhy it bites
Ignore or sit on itTreating it as junk, or waiting to 'get round to it'The clock runs from the day it arrives — silence is a breach
Miss data sourcesSending the order record but forgetting email, chat, reviewsAn incomplete response is not a compliant one
Over-collect to verifyDemanding a passport for a request tied to a known accountVerification must be proportionate, not a barrier
Dump everythingIncluding other customers' data caught in the same recordsDon't disclose third-party personal data unless it's reasonable to
Source: ICO — Right of access · UK GDPR Arts 12 & 15

What being ready actually buys you

The point isn’t fear of a regulator — it’s that a request stops being a fire drill. A store that already knows where personal data lives can answer in an afternoon instead of a fortnight, and answer completely. That readiness is the same muscle that lets you handle a data protection complaint or a partner’s due diligence calmly — and it’s what separates a business that looks organised from one that looks like it’s guessing.

The bottom line

A DSAR is a one-month, no-charge obligation that can arrive any day, by any channel. The deadline is manageable; the scramble to find scattered data is not. Map where personal data lives now, keep it current, and a request becomes a routine task instead of a fire drill. GuardianStack’s checks surface the tools processing customer data so the map is there when you need it — the wider GDPR picture for a UK store is where that map fits in.

Sources

The primary sources behind this guide — check them yourself:

Frequently asked questions

How long do I have to respond to a DSAR in the UK?

One calendar month from receiving the request, free of charge. It can be extended by up to two further months for complex or numerous requests, but you must tell the requester about the extension and the reason within the first month.

Can I charge for a subject access request?

Usually no — the first response is free. You can charge a reasonable fee for further copies of the same data, or where a request is manifestly unfounded or excessive (which can also let you refuse) — and you'd need to be able to justify that. You may also withhold data covered by an exemption. A fee can't be used to discourage legitimate requests.

What data do I have to include in a DSAR response?

A copy of the personal data you hold about the person, plus supporting information: the purposes of processing, who you share the data with, how long you keep it, and their rights. Personal data can sit across many tools — email platforms, helpdesk, analytics, CRM — so a reasonable, proportionate search usually means checking each. You can withhold data covered by an exemption, and you shouldn't disclose other people's personal data caught up in the same records unless they agree or it's reasonable to do so — otherwise redact it and provide the rest.

See where your store actually stands

Run a free outside-in compliance check of your website — no login required, results in about 30 seconds.

Run the free website check
← Back to all articles