A customer asked for their data — you have 30 days (UK DSAR guide)
On this page
Short answer: under UK GDPR, anyone can ask for a copy of all the personal data you hold on them — a subject access request, or DSAR — and you have one calendar month to respond, free of charge. The clock starts the moment they ask, not when you get round to reading the email. But the deadline isn’t the hard part. The clock is easy; the map is hard — because most stores have never mapped where a single customer’s data actually lives.
What is a subject access request?
A DSAR is a person exercising their right of access under UK GDPR. They can ask you to confirm whether you hold data about them, to give them a copy of it, and to explain how and why you use it. It doesn’t have to be formal — an email, a message, even a verbal request can count. There’s no special wording; “send me everything you have on me” is a valid DSAR.
The 30-day clock — and when it can pause or extend
You must respond without undue delay and within one calendar month of receiving the request. The month runs from the day you receive it, and it’s normally free. Two things can change the timing: you may ask for reasonable information to confirm the requester’s identity before you start (which pauses the clock until they reply), and you can extend by up to a further two months where a request is genuinely complex or someone has made several — as long as you tell them, and why, within the first month.
From request to response — one calendar month
Verification can pause the clock; a genuinely complex request, or several at once, can extend it — but only if you tell them why inside the first month.
Verification is a legitimate step, not a stalling tactic. Ask only for what you reasonably need to be sure who you’re dealing with — don’t demand a passport for a request about an email address you can already tie to their account. And what you owe is a reasonable and proportionate search, not proof you’ve turned over every last byte — a point the ICO reinforced under the Data Use and Access Act 2025.
Why the deadline is not the hard part
A month sounds generous until you try to collect everything. “Their personal data” is broader than a store owner expects: it isn’t just the order record. The same person’s data sits in your email marketing platform, your helpdesk and chat logs, your reviews app, your analytics, your CRM, and your inbox. If it identifies them and you hold it, it’s usually in scope.
A single customer’s data is scattered across your app stack
A DSAR asks for all of it. The deadline is easy; finding every copy — without a map — is the scramble.
That’s the real difficulty — customer data is scattered across your app stack, and most stores have never mapped where it all sits. It’s the same operational gap behind most compliance stress: the business grew, the tools multiplied, and nobody kept a map. This is exactly the drift a privacy notice quietly develops against your live app stack, and the apps in scope are usually the same ones that need a data processing agreement.
What a lawful response actually includes
Getting the data together is most of the job, but a response has to carry more than a data dump. At its core it confirms you’re processing their data, provides a copy, and explains the supporting picture — purposes, recipients, retention, their rights, and where relevant the data’s source, any automated decision-making, and transfer safeguards. And it respects the limits, because a DSAR is a right of access, not an unconditional right to every document with their name on it.
What to include — beyond just the data
A copy of the data plus the supporting picture. Don’t disclose other people’s data caught in the same records unless it’s reasonable to; withhold only what an exemption covers.
State clearly that you are processing their personal data.
Provide the personal data itself, in an accessible format.
Explain your purposes, and the categories of data involved.
Name the recipients or categories you share the data with.
Give the retention period, or how you decide it.
Note their rights to rectify, erase, object, and complain to the ICO.
Honest note: DSARs have real grey areas — exemptions, redacting other people’s data caught up in the same records, and what counts as “manifestly unfounded or excessive”. This guide gets you a lawful, calm response for the common case; a genuinely contested or high-volume request is worth checking against the ICO’s own guidance or with a specialist. It’s guidance, not legal advice.
The mistakes that turn a routine request into a problem
Most DSAR trouble isn’t the deadline — it’s how the request gets handled once it lands.
Four mistakes that turn a DSAR into a problem
None of these is about the deadline — they’re about the process once the request lands.
| Mistake | What it looks like | Why it bites |
|---|---|---|
| Ignore or sit on it | Treating it as junk, or waiting to 'get round to it' | The clock runs from the day it arrives — silence is a breach |
| Miss data sources | Sending the order record but forgetting email, chat, reviews | An incomplete response is not a compliant one |
| Over-collect to verify | Demanding a passport for a request tied to a known account | Verification must be proportionate, not a barrier |
| Dump everything | Including other customers' data caught in the same records | Don't disclose third-party personal data unless it's reasonable to |
What being ready actually buys you
The point isn’t fear of a regulator — it’s that a request stops being a fire drill. A store that already knows where personal data lives can answer in an afternoon instead of a fortnight, and answer completely. That readiness is the same muscle that lets you handle a data protection complaint or a partner’s due diligence calmly — and it’s what separates a business that looks organised from one that looks like it’s guessing.
The bottom line
A DSAR is a one-month, no-charge obligation that can arrive any day, by any channel. The deadline is manageable; the scramble to find scattered data is not. Map where personal data lives now, keep it current, and a request becomes a routine task instead of a fire drill. GuardianStack’s checks surface the tools processing customer data so the map is there when you need it — the wider GDPR picture for a UK store is where that map fits in.
Sources
The primary sources behind this guide — check them yourself:
Frequently asked questions
How long do I have to respond to a DSAR in the UK?
One calendar month from receiving the request, free of charge. It can be extended by up to two further months for complex or numerous requests, but you must tell the requester about the extension and the reason within the first month.
Can I charge for a subject access request?
Usually no — the first response is free. You can charge a reasonable fee for further copies of the same data, or where a request is manifestly unfounded or excessive (which can also let you refuse) — and you'd need to be able to justify that. You may also withhold data covered by an exemption. A fee can't be used to discourage legitimate requests.
What data do I have to include in a DSAR response?
A copy of the personal data you hold about the person, plus supporting information: the purposes of processing, who you share the data with, how long you keep it, and their rights. Personal data can sit across many tools — email platforms, helpdesk, analytics, CRM — so a reasonable, proportionate search usually means checking each. You can withhold data covered by an exemption, and you shouldn't disclose other people's personal data caught up in the same records unless they agree or it's reasonable to do so — otherwise redact it and provide the rest.
See where your store actually stands
Run a free outside-in compliance check of your website — no login required, results in about 30 seconds.
Run the free website check