What If They Don't Respond?

    Companies are legally required to respond to GDPR requests within 30 days. Here's what to do if they don't.

    Step-by-Step Escalation Guide

    1

    Wait the Full 30 Days

    Companies have one calendar month to respond. Mark your calendar and don't escalate too early.

    • Count from the day after they received your request
    • If the deadline falls on a weekend or bank holiday, it extends to the next working day
    • Complex requests can be extended by 2 months, but they must notify you
    2

    Send a Follow-Up

    After 30 days with no response, send a polite reminder referencing your original request.

    • Reference the date of your original request
    • Note that the legal deadline has passed
    • Give them 7 more days to respond
    • Keep your tone professional
    3

    Escalate Internally

    If no response after your reminder, try contacting their Data Protection Officer directly.

    • Look for DPO details on their privacy policy
    • Many companies list DPO email separately from general contact
    • Mention you'll be contacting the ICO if they don't respond
    4

    Complain to the ICO

    If the company still doesn't respond, file a formal complaint with the Information Commissioner's Office.

    • You can complain online at ico.org.uk
    • Include copies of all correspondence
    • ICO investigations can take several months
    • Companies can face fines up to £17.5m or 4% of turnover

    About the ICO

    Information Commissioner's Office

    The ICO is the UK's independent authority set up to uphold information rights in the public interest. They have the power to investigate complaints and fine organisations that breach data protection law.

    File a Complaint with ICO

    Ready to Take Control?

    Start sending GDPR requests with Claim Your Data. We'll help you track responses and escalate when necessary.