Data Protection Act 2018 (c. 12) – Section 53 – Manifestly unfounded or excessive requests by the data subject
Sections
Section 53Manifestly unfounded or excessive requests by the data subject
(1) Where a request [F1made by a data subject under or by virtue of any of sections 45, 46, 47, 50C or 50D] is manifestly unfounded or excessive, the controller may—
- (a)charge a reasonable fee for dealing with the request, or
- (b)refuse to act on the request.
(2) An example of a request that may be excessive is one that merely repeats the substance of previous requests.
(3) In any proceedings where there is an issue as to whether a request [F2described in subsection (1)] is manifestly unfounded or excessive, it is for the controller to show that it is.
(4) The Secretary of State may by regulations specify limits on the fees that a controller may charge in accordance with subsection (1)(a).
(4A) [F3 The Secretary of State may by regulations—
- (a)require controllers of a description specified in the regulations to produce and publish guidance about the fees that they charge in accordance with subsection (1)(a), and
- (b)specify what the guidance must include.]
(6) [F5 If, in reliance on subsection (1)(b), the controller does not take action on the request, the controller must inform the data subject of—
- (a)the reasons for not doing so, and
- (b)the data subject’s right to lodge a complaint with the [F6Commission].
(7) The controller must comply with subsection (6)—
- (a)without undue delay, and
- (b)in any event, before the end of the applicable time period (as to which see section 54).]
Amended text
This Section is shown as amended by the Data (Use and Access) Act 2025 (c. 18), among other instruments (see the annotations below) (commenced provisions as at 30 September 2026, ELI), as incorporated in the text in force on 30 September 2026 as published on legislation.gov.uk.
Annotations
Textual Amendments
- F1 Words in s. 53(1) substituted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), s. 142(1), Sch. 6 para. 14(2); S.I. 2026/82, reg. 2(z8) (with reg. 5)
- F2 Words in s. 53(3) substituted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), s. 142(1), Sch. 6 para. 14(3); S.I. 2026/82, reg. 2(z8) (with reg. 5)
- F3 S. 53(4A) inserted (19.6.2025 for specified purposes, 5.2.2026 in so far as not already in force) by Data (Use and Access) Act 2025 (c. 18), ss. 75(2)(a), 142(1)(2)(h); S.I. 2026/82, reg. 2(g)
- F4 Words in s. 53(5) substituted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 75(2)(b), 142(1); S.I. 2026/82, reg. 2(g)
- F5 S. 53(6)(7) inserted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 75(2)(c), 142(1); S.I. 2026/82, reg. 2(g)
- F6 Word in s. 53(6)(b) substituted (30.9.2026) by The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 (S.I. 2026/386), reg. 1(2), Sch. 2 para. 23(2)(3); S.I. 2026/1015, reg. 2(c)
Commencement Information
- I1 S. 53 in force at Royal Assent for specified purposes, see s. 212(2)(f)
- I2 S. 53 in force at 25.5.2018 in so far as not already in force by S.I. 2018/625, reg. 2(1)(c)
https://dpa2018.digiphile.law/article/article-53.html
Text as at 18 September 2026.
This is an unofficial convenience version of the Data Protection Act 2018. It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.