Guides

Data protection complaint vs subject access request: how to tell them apart

A subject access request and a data protection complaint arrive the same way and are constantly confused — but they sit under different law and run on different clocks. This guide gives you a one-line test to tell them apart, a side-by-side comparison, and how to handle a message that is both.

TheDutyDesk Editorial18 July 20266 min readReviewed 18 July 2026

Two of the most common things a member of the public will send you about their personal data are a subject access request and a data protection complaint. They often arrive through the same inbox, in the same tone, sometimes in the same email — and they are routinely confused. Getting the classification wrong is not a filing error: it starts the wrong clock, and from 19 June 2026 one of those clocks carries a hard statutory deadline.[6]

This guide sets out what each one is, a one-line test to tell them apart, and how to handle the awkward case where a single message is both.

What a subject access request is

A subject access request — a DSAR — is a person exercising their right of access: the right to obtain a copy of the personal data you hold about them, and certain information about how and why you process it.[3] The right has existed for years and is unchanged in substance.

You must respond without undue delay and in any event within one month of receipt, extendable by up to two further months where the request is complex or numerous.[3] Two recent changes make the timeline more workable. Since 5 February 2026 you can, in defined situations, pause the one-month clock while you wait for something reasonable from the requester — for example, while you confirm their identity or ask them to narrow a very broad request.[1] An ICO-compliant proportionality standard also now limits how exhaustively you must search.[1]

The defining feature: a DSAR is a request to see data.

What a data protection complaint is

A data protection complaint is a person raising a concern about how you have handled their personal data — that you held it without a basis, kept it too long, shared it, lost it, or would not act on an earlier request. From 19 June 2026, section 164A of the Data Protection Act 2018 turns handling these into a statutory duty.[2][6]

Where you receive a data protection complaint, you must acknowledge receipt within 30 days[2] and respond substantively without undue delay.[2] The duty applies to every UK controller regardless of size, and the 30 days run from receipt on any channel, not from the moment someone internally notices. We read the deadline in full in the 30-day complaint clock explained.

The defining feature: a complaint is an expression of dissatisfaction about your handling of data.

The one-line test

Ask what the person actually wants:

  • If they want a copy of their data — "send me everything you hold on me" — it is a subject access request.
  • If they are unhappy about what you did with their data — "you should not still have this", "you shared my details without asking" — it is a data protection complaint.
  • If they want both — and they often do — treat it as both, on two parallel tracks with two separate clocks.

Side by side

Subject access requestData protection complaint
Legal basisRight of access, UK GDPR Art.15 [3]s.164A DPA 2018 [2]
What the person wantsA copy of their personal dataA concern about your handling addressed
The clockOne month from receipt, extendable to three for complex or numerous requests [3]Acknowledge within 30 days of receipt [2]; substantive response without undue delay [2]
Can you pause the clock?Yes — to verify identity or clarify a broad request [1]No equivalent statutory pause on the 30-day acknowledgement
In forceLong-standingThe statutory duty applies from 19 June 2026 [6]
The core evidenceThe data disclosed, and your search recordThat you acknowledged in time, on every channel, and what you did next

Why the distinction is worth getting right

Misclassify a DSAR as a complaint and you may miss the one-month access deadline while treating it as a grievance. Misclassify a complaint as a DSAR and you start a search for records while a 30-day statutory acknowledgement clock runs unacknowledged in the background.[2] The two duties are independent: satisfying one does not discharge the other. The ICO's February 2026 complaint-handling guidance treats the s.164A duty as its own obligation to evidence, separately from the access obligation.[4]

When one message is both

The hard cases are the blurry ones, and they are common. "Why do you still have my data, and send me a copy of everything you hold" is a complaint (about retention) and a subject access request (for a copy). "I asked you to delete my details months ago and nothing happened" is a complaint about your handling of an earlier erasure request.

The safe operating rule is to run each strand under its own duty rather than forcing the message into one box:

  1. Log it once, classify each strand. Record that the message contains both an access request and a complaint.
  2. Start both clocks from the same receipt date. The one-month access clock[3] and the 30-day acknowledgement clock[2] run in parallel, not in sequence.
  3. Acknowledge the complaint strand explicitly and early, even while you work the access strand — the acknowledgement is the cheap insurance against a s.164A breach.
  4. Keep the evidence trails separate. The access response is evidenced by what you disclosed and how you searched; the complaint response is evidenced by the acknowledgement, the timeline, and the outcome.

Keeping the two strands distinct on one record is exactly what a system of record is for, and it is how TheDutyDesk is built to handle a mixed request without either clock running in silence.

Frequently asked questions

Is a data protection complaint the same as a subject access request?

No. A subject access request is a request for a copy of the personal data you hold about someone, under UK GDPR Article 15.[3] A data protection complaint is a concern about how you have handled someone's data, which from 19 June 2026 you must acknowledge within 30 days under s.164A of the Data Protection Act 2018.[2][6] Different law, different deadline.

Can a single message be both a DSAR and a complaint?

Yes, and often is. Treat it as both: log it once, classify each strand, and start both clocks from the date you received it. Satisfying the access request does not discharge the complaint duty, or the other way round.

If a message is both, which deadline applies?

Both, in parallel. You have one month to deal with the access request[3] and 30 days to acknowledge the complaint.[2] The 30-day acknowledgement will usually fall first, so acknowledge the complaint strand early while you work the access strand.

Sources used in this article

  • [1]Data (Use and Access) Act 2025
  • [2]Data Protection Act 2018 (post-DUAA consolidated) — s.164A
  • [3]UK GDPR (retained EU regulation) — Articles 12 and 15
  • [4]ICO statutory guidance on complaint handling, February 2026
  • [6]SI 2026/82 (commencement order)

Source verification and SHA-256 hashes are maintained in our sources index.

Last reviewed: 18 July 2026. Next review: 18 July 2027, or sooner if relevant guidance changes.

TheDutyDesk helps you manage data protection complaints with a structured process and an audit trail.